Legal
Data Processing Agreement
Under UK GDPR Article 28 and equivalent international standards
Effective 25 June 2026 · Version 1.1 · Governing law: England & Wales
1. Definitions
Capitalised terms used but not defined in this DPA have the meanings given in the Agreement or, where the term is defined in the UK GDPR or EU GDPR, the meaning given in those regulations.
- "Annex" means an annex attached to this DPA.
- "Applicable Data Protection Law" means (i) the UK GDPR, (ii) the Data Protection Act 2018, (iii) the EU GDPR and Member State implementing laws, (iv) PECR and equivalent ePrivacy laws in the EU, (v) the CCPA/CPRA and other comprehensive United States state privacy laws, (vi) PIPEDA, (vii) LGPD, (viii) APP, (ix) PDPA, (x) APPI, and (xi) any other data protection or privacy law applicable to the processing of Personal Data under this DPA.
- "Customer Personal Data" means any Personal Data that McNif processes on behalf of the Controller in providing the Service, as further described in Annex 2.
- "International Transfer" means a transfer of Personal Data from a jurisdiction with restrictions on cross-border data flow to a Restricted Country.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- "Restricted Country" means a country which, in respect of transfers from the originating jurisdiction, has not been deemed to provide an adequate level of protection for Personal Data under the law of the originating jurisdiction.
- "Sub-processor" means any third party engaged by McNif to process Customer Personal Data on McNif's behalf as part of providing the Service.
- "EU SCCs" means the European Commission's standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as published in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 or as subsequently amended.
- "UK Addendum" means the United Kingdom Information Commissioner's International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 or any subsequent version.
- "UK IDTA" means the United Kingdom Information Commissioner's International Data Transfer Agreement, version A1.0 or any subsequent version.
2. Roles of the Parties
2.1 The parties acknowledge that, in respect of the processing of Customer Personal Data under this DPA:
- the Controller is the controller (or, under the CCPA/CPRA, the "business"); and
- McNif is the processor (or, under the CCPA/CPRA, the "service provider" or, where applicable, the "contractor").
2.2 The Controller is responsible for the lawfulness of its instructions to McNif and for the lawfulness of the collection, processing, and transmission of Customer Personal Data to McNif under the privacy law(s) applicable to the Controller and to the relevant Data Subjects.
2.3 McNif is responsible for the compliance of its own processing activities with this DPA and Applicable Data Protection Law.
2.4 Where McNif processes Personal Data of the Controller's own employees, contractors or representatives in connection with administering the Agreement, McNif acts as a controller (or business) for that processing, as described in the McNif Privacy Policy. That processing is outside the scope of this DPA.
3. Subject Matter, Nature, Purpose and Duration of Processing
3.1 The subject matter, nature, purpose, type of Personal Data, categories of Data Subjects and duration of the processing of Customer Personal Data are described in Annex 2.
3.2 McNif shall process Customer Personal Data only for the purposes described in Annex 2 and only in accordance with the Controller's documented instructions under clause 4.
4. Processing on Documented Instructions
4.1 McNif shall process Customer Personal Data only on documented instructions from the Controller, including with regard to International Transfers, unless required to do so by law to which McNif is subject; in such a case, McNif shall inform the Controller of that legal requirement before processing, unless prohibited.
4.2 The Controller's instructions are set out in this DPA, the Agreement, and the Controller's use of the Service from time to time.
4.3 The Controller may issue additional documented instructions in writing during the Term.
4.4 McNif shall promptly notify the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
5. Confidentiality
5.1 McNif shall ensure that all personnel authorised to process Customer Personal Data are bound by appropriate written obligations of confidentiality or are under an appropriate statutory obligation of confidentiality.
5.2 Access to Customer Personal Data shall be limited to those McNif personnel whose access is necessary.
6. Security
6.1 McNif shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the UK GDPR and EU GDPR and equivalent provisions of other Applicable Data Protection Law.
6.2 The technical and organisational measures implemented by McNif are described in Annex 3.
7. Sub-processors
7.1 The Controller authorises McNif to engage Sub-processors to provide the Service.
7.2 Current Sub-processors are listed in Annex 1 and on McNif's website.
7.3 McNif shall enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set out in this DPA, including obligations equivalent to Article 28(3) of the UK GDPR and EU GDPR. McNif remains fully liable to the Controller for the performance of each Sub-processor.
7.4 McNif shall give the Controller at least thirty (30) days' prior notice of any intended change concerning the addition or replacement of Sub-processors.
7.5 The Controller may object, on reasonable grounds related to data protection, by giving written notice within fifteen (15) days. The parties shall co-operate to find a workable resolution; failing that, the Controller may terminate the affected portion of the Service as its sole remedy.
8. International Transfers
8.1 McNif may transfer Customer Personal Data outside the originating jurisdiction only:
- in accordance with the Controller's documented instructions, including those embodied in the Controller's choice to use the Service and the Sub-processors described in Annex 1;
- where there is an applicable adequacy decision under the originating jurisdiction's privacy law; or
- where the parties have put in place appropriate safeguards under the applicable privacy law.
8.2 The appropriate safeguard varies according to the jurisdiction from which the data is exported:
- Transfers from the United Kingdom: the UK IDTA, or the EU SCCs supplemented by the UK Addendum, or another approved transfer mechanism.
- Transfers from the European Economic Area: the EU SCCs in the form applicable to the relevant transfer (Module 2 "Controller-to-Processor" or Module 3 "Processor-to-Sub-processor").
- Transfers from Brazil: the contractual clauses or other mechanism required by the ANPD under the LGPD.
- Transfers from California: McNif acts as a service provider under the CCPA/CPRA service-provider terms set out in this DPA; standard contractual clauses are not required by the CCPA/CPRA, but the service-provider obligations in this DPA, Annex 3, and the Sub-processor cascade apply.
- Transfers from other jurisdictions: the transfer mechanism required by the privacy law applicable to that transfer.
8.3 The parties agree that, where the Controller is the data exporter and McNif is the data importer in a transfer from the United Kingdom, the UK IDTA shall apply between them, with the parties' details, the description of the transfer, and the supplementary terms as set out in Annex 4 Part A. Where the Controller is established in the European Economic Area, the EU SCCs Module 2 shall apply on equivalent terms as set out in Annex 4 Part B.
8.4 Where McNif transfers Customer Personal Data to a Sub-processor in a Restricted Country, McNif shall ensure that an appropriate transfer mechanism is in place.
8.5 McNif shall conduct a transfer impact assessment for any International Transfer where required by Applicable Data Protection Law and shall provide a summary on reasonable written request.
9. Personal Data Breach
9.1 McNif shall notify the Controller of any Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of the breach, and in any event within seventy-two (72) hours of becoming aware.
9.2 Such notification shall include, to the extent then known, the information required by Article 33(3) of the UK GDPR / EU GDPR and equivalent provisions of other Applicable Data Protection Law.
9.3 Where information is not all available at once, it may be provided in phases without further undue delay.
9.4 McNif shall provide reasonable assistance to the Controller in fulfilling the Controller's obligations to notify the relevant supervisory authority and (where applicable) Data Subjects.
10. Data Subject Rights
10.1 McNif shall assist the Controller in fulfilling its obligation to respond to requests for exercising Data Subject rights under Applicable Data Protection Law (including UK GDPR Articles 12 to 22, EU GDPR Articles 12 to 22, CCPA/CPRA consumer rights, and equivalent provisions of other Applicable Data Protection Law).
10.2 Where the Controller can fulfil such requests through the self-service controls available in the Service, McNif's assistance is provided through those controls.
10.3 Where McNif receives a request from a Data Subject directly in relation to Customer Personal Data, McNif shall promptly forward the request to the Controller and shall not respond except as instructed by the Controller or as required by law.
11. Data Protection Impact Assessments and Prior Consultation
11.1 Taking into account the nature of the processing and the information available to McNif, McNif shall provide reasonable assistance to the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR and EU GDPR and equivalent provisions of other Applicable Data Protection Law.
12. Audit
12.1 McNif shall make available to the Controller all information necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR and EU GDPR (and equivalent service-provider obligations under other Applicable Data Protection Law).
12.2 The Controller acknowledges that the Service is a multi-tenant cloud service, and McNif shall normally satisfy its audit obligations by providing:
- a summary description of the technical and organisational measures implemented (Annex 3);
- the most recent independent third-party audit report or industry certification held by McNif (where available);
- written responses to reasonable written enquiries from the Controller.
12.3 Where the Controller requires additional audit information not satisfied by clause 12.2, the Controller may request an on-site audit by giving at least thirty (30) days' prior written notice; such audit shall be at the Controller's cost, during normal business hours, no more than once per twelve-month period (save for following a Personal Data Breach or where required by a supervisory authority), and shall not interfere unreasonably with the Service.
13. Return and Deletion of Customer Personal Data
13.1 On termination of the Agreement, or on the Controller's earlier written request, McNif shall, at the Controller's choice, return or delete Customer Personal Data within thirty (30) days.
13.2 During the thirty-day window following termination, the Controller may export Customer Personal Data.
13.3 Customer Personal Data in backups and audit logs may be retained for the standard retention periods of those backups and logs, with continued protection.
13.4 McNif may retain Customer Personal Data where required by law.
13.5 McNif shall, on the Controller's written request, certify that it has complied with this clause 13.
14. CCPA/CPRA Service Provider Terms
Where Customer Personal Data includes "personal information" of California consumers under the CCPA/CPRA, the following service-provider terms apply in addition to (and not in derogation of) the other clauses of this DPA:
- McNif will not (a) sell or share personal information; (b) retain, use, or disclose personal information for any purpose other than the specific purposes set out in this DPA and the Agreement, including not using or disclosing personal information outside the direct business relationship between the parties; (c) combine personal information received from or on behalf of the Controller with personal information received from any other source, except as expressly permitted by the CCPA/CPRA.
- McNif certifies that it understands and will comply with the restrictions and obligations set out in this clause 14.
- If McNif determines that it can no longer meet its obligations under the CCPA/CPRA, McNif shall promptly notify the Controller. On such notice, the Controller may take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.
15. Term and Termination
15.1 This DPA takes effect on the Effective Date and continues for so long as the Agreement remains in force and McNif processes any Customer Personal Data.
15.2 Termination does not relieve McNif of its obligations under clauses 5, 8 (for historic transfers), 9 (for breaches notified before termination), 12 (for audits requested before termination), 13, and 16.
16. Liability
The liability of each party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Where the parties' liability falls within the scope of the SCCs, UK IDTA or another transfer instrument, the liability provisions of those instruments shall apply to that extent.
17. Conflict; Order of Precedence
Order of precedence: (i) the SCCs as supplemented by the UK Addendum or the UK IDTA, in respect of the matters they address; (ii) this DPA; (iii) the Agreement.
18. Governing Law and Jurisdiction
This DPA and any dispute or claim arising out of or in connection with it shall be governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction, subject to provisions of the SCCs, UK Addendum or UK IDTA which require a different jurisdiction or forum, and subject to mandatory consumer protection rights granted by the law of the Controller's jurisdiction.
— End of Data Processing Agreement —
ANNEX 1 — LIST OF SUB-PROCESSORS
Same Sub-processor list as published on McNif's website. McNif may update this list in accordance with clause 7 of the DPA.
[Note for solicitor review: the named entities below are illustrative; before publication, confirm exact corporate names, principal places of business and current data-centre regions for each provider.]
| Sub-processor | Service provided | Data centre region | Categories of data |
|---|---|---|---|
| Supabase Inc. | Cloud database and authentication infrastructure | EU (Frankfurt) primary; US for management plane | Subscriber Account Data, Customer Personal Data, system logs |
| Hetzner Online GmbH | Application server hosting (the McNif relay) | Germany | Encrypted access tokens, processed Personal Data in transit, system logs |
| Stripe, Inc. | Payment processing and subscription billing | United States; Ireland | Subscriber billing data, transaction history |
| Twilio SendGrid, LLC | Transactional email sending and inbound email parsing | United States | Sender and recipient email addresses, message content, delivery status |
| Twilio, Inc. | SMS and instant-messaging delivery | United States; United Kingdom | Recipient phone numbers, message content, delivery status |
| Anthropic, PBC | AI inference services for AI-assisted features | United States | Prompt content, which may include Customer Personal Data |
| Cloudflare, Inc. | CDN and security layer | Global (anycast network) | Visitor IP addresses, session identifiers, log data |
| Google LLC | Internal email and productivity for McNif staff | EU; US | Administrative data only; not Customer Personal Data |
| Meta Platforms, Inc. | Where the Subscriber has connected a Meta Business Account | United States; EU | Subscriber's Meta Page identifiers, ad-account identifiers, lead-form responses |
ANNEX 2 — DESCRIPTION OF PROCESSING
This Annex is the parties' description of the processing of Customer Personal Data as required by Article 28(3) of the UK GDPR and EU GDPR.
A. Subject Matter
Provision of the McNif CRM software-as-a-service platform to the Controller.
B. Duration
For the Term of the Agreement plus any post-termination return / deletion period in clause 13.
C. Nature of the Processing
Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to Sub-processors or third-party integrations as instructed by the Controller, erasure or destruction, and any other operation necessary to provide the Service.
D. Purpose of the Processing
McNif processes Customer Personal Data solely to provide the Service to the Controller in accordance with the Agreement and the Controller's instructions.
E. Categories of Personal Data
As determined by what the Controller uploads, but typically including: identification data; contact data; commercial relationship data; content data; device and usage data; and data received from third-party platforms the Controller has connected.
Special category Personal Data (Article 9 UK/EU GDPR), sensitive Personal Information (CCPA/CPRA), and Personal Data relating to criminal convictions and offences (Article 10 UK/EU GDPR) are not intended to be processed through the Service. The Controller is responsible for ensuring no such data is uploaded except in accordance with appropriate legal bases and safeguards required by Applicable Data Protection Law.
F. Categories of Data Subjects
Prospects, leads, customers, suppliers, business partners, the Controller's own employees and representatives, and end users who interact with the Controller through any channel integrated with the Service.
G. Frequency of Transfer
Continuous, in line with the use of the Service by the Controller.
H. Retention
For the Term plus the post-termination periods set out in clause 13.
ANNEX 3 — TECHNICAL AND ORGANISATIONAL MEASURES
This Annex describes McNif's technical and organisational measures ("TOMs") to ensure the security of Customer Personal Data, in accordance with Article 32 of the UK GDPR and EU GDPR and equivalent provisions of other Applicable Data Protection Law.
1. Information Security Governance
- Documented information security policies, reviewed at least annually.
- Defined roles and responsibilities for information security.
- Regular security awareness training for McNif personnel.
- Background checks where lawful in the relevant jurisdiction on McNif employees with access to production systems.
- Confidentiality undertakings from McNif employees, contractors and consultants.
2. Access Control
- Role-based access control (RBAC) on the principle of least privilege.
- Multi-factor authentication (MFA) required for production system access.
- Row-Level Security (RLS) for tenant data isolation.
- Regular access reviews; prompt revocation on departure or role change.
- Strong password policies; passwords stored as salted hashes.
3. Encryption
- Encryption in transit using TLS 1.2 or higher.
- Encryption at rest using AES-256 (or equivalent industry standard).
- Sensitive credentials encrypted in a dedicated secrets store.
- Periodic key rotation.
4. System and Network Security
- Production environments segregated from development and test.
- Regular patching of OS, runtimes, and dependencies.
- SAST and SCA in the CI pipeline.
- Web application firewall and rate-limiting at the perimeter.
- Logging, monitoring, and alerting for security-relevant events.
- DNS, SPF, DKIM and DMARC configured for outbound email.
5. Operational Security
- Change-management procedures for production deployments.
- Peer-reviewed pull-request workflow.
- Automated CI testing (unit, integration, end-to-end).
- Backups on a defined schedule; integrity tested periodically.
- Business continuity and disaster recovery plans.
6. Incident Response
- Documented incident response plan covering identification, containment, eradication, recovery, post-incident review.
- On-call rotation.
- Personal Data Breach notification procedure aligned with clause 9 of this DPA.
7. Supplier Management
- Sub-processor onboarding includes data protection due diligence.
- Written data processing terms with each Sub-processor.
- Periodic review of Sub-processor security posture.
8. Audit and Assurance
- Internal audit of security controls on a periodic basis.
- McNif intends to obtain independent third-party certification (SOC 2 Type II or ISO 27001) within the first three years of commercial operation; not warranted as in place at the Effective Date of this DPA.
9. Physical Security
- All Customer Personal Data hosted in third-party data centres operated by reputable cloud infrastructure providers whose physical security is subject to their own audit and certification regimes.
ANNEX 4 — INTERNATIONAL TRANSFER MECHANISMS
This Annex sets out the particulars of International Transfers requiring application of the UK IDTA, EU SCCs supplemented by the UK Addendum, or another approved transfer mechanism.
Part A — UK IDTA Particulars (Transfers from the United Kingdom)
Where the UK IDTA applies between the Controller (as data exporter) and McNif (as data importer), the particulars required by Tables 1 to 4 of the UK IDTA are as follows.
Table 1 — Parties' Details
| Item | Exporter (Controller) | Importer (McNif) |
|---|---|---|
| Full legal name | [Controller's full legal name as on the Account] | McNif Global Limited |
| Address | [Controller's address as on the Account] | [Registered office to be inserted at publication] |
| Activities relevant to the transfer | Operating its business using the McNif CRM Service | Provision of the McNif CRM Service |
| Role | Controller | Processor |
| Key contact | [Controller's registered contact] | privacy@mcnifglobal.com |
| Signature and date | By acceptance of the DPA and Agreement | By acceptance of the DPA and Agreement |
Table 2 — Transfer Details
UK country: United Kingdom. Linked Agreement: this DPA and the Agreement. Term: as set out in clause 15. The transfer is ongoing.
Table 3 — Transferred Data
As described in Annex 2.
Table 4 — Security Requirements
As described in Annex 3.
Part B — EU SCCs Particulars (Transfers from the European Economic Area)
Where the EU SCCs apply between the Controller (as data exporter) and McNif (as data importer) for transfers from the EEA, the EU SCCs Module 2 (Controller to Processor) shall apply, with the following details completed.
Annex I.A — List of Parties
| Item | Exporter (Controller) | Importer (McNif) |
|---|---|---|
| Name | [Controller's legal name as on the Account] | McNif Global Limited |
| Address | [Controller's address as on the Account] | [Registered office to be inserted at publication] |
| Contact | [Controller's contact] | privacy@mcnifglobal.com |
| Activities relevant to the transfer | Operating its business using the McNif CRM Service | Provision of the McNif CRM Service |
| Role | Controller | Processor |
| Signature and date | By acceptance | By acceptance |
Annex I.B — Description of Transfer
Categories of data subjects, categories of personal data, sensitive data, frequency of transfer, nature of processing, purposes, period of retention: all as described in Annex 2 of this DPA.
Annex I.C — Competent Supervisory Authority
The supervisory authority of the EU Member State where the Controller is established. Where the Controller is established in more than one Member State, the lead supervisory authority of the Controller, identified in accordance with Article 56 EU GDPR. Where the Controller is not established in the EU, the supervisory authority of the Member State in which the Controller's EU representative is established, or in default, the supervisory authority where the data subjects whose data is transferred are located.
Annex II — Technical and Organisational Measures
As described in Annex 3 of this DPA.
Annex III — List of Sub-processors
As described in Annex 1 of this DPA.
Clause 7 (Docking clause)
Applies — accession by additional parties permitted in accordance with the EU SCCs.
Clause 11 (Redress) Option
Option NOT activated — Data Subjects can lodge a complaint with the competent supervisory authority and seek judicial redress against any party in accordance with clauses 11 and 18 of the EU SCCs without independent dispute resolution body.
Clause 17 (Governing Law)
The EU SCCs shall be governed by the law of an EU Member State that allows for third-party beneficiary rights — specifically, the law of Ireland.
Clause 18 (Choice of Forum and Jurisdiction)
The parties agree that disputes arising from the EU SCCs shall be resolved by the courts of Ireland.
Part C — Onward Transfers to Sub-processors
Where McNif transfers Customer Personal Data to a Sub-processor located in a Restricted Country, McNif shall ensure an appropriate transfer mechanism is in place, including (without limitation) the UK IDTA, the EU SCCs Module 3, or any other safeguard recognised under Applicable Data Protection Law.
Part D — Notice of Government Access Requests
Where McNif receives a legally binding request from a public authority in a Restricted Country for access to Customer Personal Data, McNif shall, to the extent permitted by law: (i) notify the Controller without undue delay; (ii) challenge the request where there are reasonable grounds; (iii) provide only the minimum information necessary; (iv) keep a record.
Where notification to the Controller is prohibited by law, McNif shall use reasonable endeavours to obtain a waiver.
Part E — Termination
If the UK IDTA, EU SCCs or other applicable transfer mechanism ceases to provide a valid basis for the International Transfer, the parties shall, in good faith and without undue delay, agree on an alternative transfer mechanism or suspend the affected International Transfer.