Last updated: May 2026 (v1.1)
This Data Processing Agreement (“DPA”) forms part of your agreement with Rowpa and governs how we process personal data on your behalf under Article 28 of the UK GDPR and, where applicable, the EU GDPR. By using Rowpa, you agree to the terms of this DPA.
In this DPA:
As your Processor, we process the following categories of Customer Personal Data on your behalf:
| Data Category | Purpose | Data Subjects | Lawful Basis | Retention |
|---|---|---|---|---|
| Business profile | Service delivery and account management | Your employees and representatives | Contract (Rowpa Terms of Service) | Duration of agreement plus 30 days |
| Account data | Authentication and access control | Your users | Contract | Duration of agreement plus 30 days |
| ROPA content | Generating Records of Processing Activity | Your employees, customers, vendors, and service providers | Legitimate interest (GDPR compliance) | Duration of agreement plus 30 days |
| DSR metadata | Tracking Data Subject Requests | Your data subjects | Legal obligation (UK GDPR Articles 15-22) | Duration of agreement plus 30 days |
You decide what data to input into Rowpa. We only process data you choose to upload or enter. We do not collect Customer Personal Data from external sources on your behalf.
You will not provide special category data or criminal-offence data through the Services unless we have agreed in writing that you may, and have recorded that fact in our records.
As your Processor, we commit to the following:
We will not process Customer Personal Data for our own purposes, including without limitation: developing or improving our products (except as strictly necessary to provide the Services to you), marketing, profiling, analytics beyond your instructed use, or onward sale, licensing, or transfer to any third party other than authorised Sub-processors.
We will not, and we will procure that our Sub-processors do not, use Customer Personal Data to train, fine-tune, or otherwise improve any artificial intelligence, machine learning, or generative model. Rowpa's AI features (delivered via the Anthropic API) process your inputs to produce the output you have requested. Standard Anthropic API retention may be up to 30 days, with exceptions described in Anthropic's commercial data retention terms, including legal requirements and usage-policy enforcement. Zero data retention requires a separate applicable arrangement and is not promised by this DPA.
Nothing in this DPA or the Rowpa Terms of Service creates a joint controller relationship under Article 26 of the UK GDPR or EU GDPR. If a proposed change to your use of the Services would, in our reasonable view, create joint controllership, we will discuss it with you in good faith before implementing it.
We maintain professional indemnity insurance and cyber liability insurance at levels appropriate to the nature and scale of the Services. We will, on reasonable written request, provide a redacted certificate or summary evidencing such cover.
We implement technical and organisational measures appropriate to the risk, designed to ensure a level of security in line with Article 32 of the UK GDPR. For our current security posture in detail, please visit our Security page.
Key measures include:
You authorise us to engage the following Sub-processors to deliver Rowpa:
The complete current Sub-processor list, with locations, purposes, and transfer mechanisms, is maintained at our Sub-processors page and is incorporated into this DPA by reference.
Before adding or replacing a Sub-processor, we will notify you at least 30 days in advance. You may object on reasonable grounds related to the protection of Personal Data; if we cannot resolve the objection within 30 days, you may terminate the affected Services without penalty for early termination.
We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA. We remain fully liable to you for each Sub-processor's performance.
We process Customer Personal Data in the configured locations recorded for the account. A supplier headquarters or default region does not prove where a particular operation occurs. Transfers outside the UK and EEA must be listed for the relevant activity and supported by the recorded safeguard.
UK Adequacy. Transfers to UK Sub-processors benefit from the UK GDPR domestic regime.
EU Adequacy. Where EU GDPR applies, transfers within the EEA benefit from the GDPR's free-flow principle. A UK adequacy decision may apply while it remains in force; confirm scope and expiry for the relevant activity.
International transfers. The applicable transfer safeguard, module and parties must be confirmed for each processing activity and supplier. This template does not establish that an IDTA, EU SCC module, UK Addendum, adequacy decision or certification applies to a particular account. Record the executed instrument and its scope in the supplier and activity records before relying on it.
Transfer Impact Assessment. Where a transfer requires one, the relevant activity record must contain a current Transfer Impact Assessment and its evidence. Do not treat a supplier name or template clause as proof that an assessment was completed. We can share the recorded assessment in summary form on reasonable written request where permitted.
Honest acknowledgement. You acknowledge that transfers to the United States carry residual legal risk due to US surveillance laws (FISA s.702, EO 12333). If you require strict EU-or-UK-only processing without any US Sub-processor, please contact compliance@rowpa.app. We will work with you to find a viable configuration; some Services rely on US-hosted infrastructure and may not be available on an EU-only basis.
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and in any event within 48 hours of becoming aware. Our notification will include, to the extent then known:
We will provide further information as it becomes available. You remain responsible for notifying your own data subjects and supervisory authorities where the Applicable Data Protection Law requires.
We will not publicly disclose, including to press, any breach affecting your Customer Personal Data without your prior written consent, except where required by law or by a supervisory authority.
On reasonable prior written notice (and no more than once in any 12-month period unless you have reasonable grounds to suspect non-compliance), we will:
Audits must take place during normal business hours, with reasonable advance notice, and in a manner that does not unreasonably disrupt our operations or the security of other customers' data. You bear our reasonable costs for any audit beyond a once-yearly desktop review.
Duration. This DPA applies for the duration of the Rowpa Terms of Service.
On termination. Within 30 days of termination, we will at your choice:
You may request deletion or export at any time during the term; we will comply within 5 business days, except where retention is required by law.
On request, we will provide written confirmation of deletion.
Acceptance. This DPA is incorporated by reference into the Rowpa Terms of Service. By accepting the Terms of Service or by using Rowpa, you accept this DPA. For a separately signed copy, contact compliance@rowpa.app.
Updates. We may update this DPA from time to time. Any change that materially reduces your rights or our obligations will be notified to you at least 30 days in advance, and you may object on reasonable grounds related to the protection of Personal Data. If we cannot resolve your objection within 30 days, you may terminate the affected Services without penalty for early termination. Changes that improve protection for data subjects or are required by changes to law take effect on publication.
Conflict. In case of conflict between this DPA, the Rowpa Terms of Service, and any other document, the order of precedence is: (i) the UK IDTA / EU SCCs, (ii) this DPA, (iii) the Rowpa Terms of Service, (iv) any other document.
For data protection notices to us, use compliance@rowpa.app. Notices sent by email are deemed received at the time of transmission, provided the sender has not received a non-delivery message. We will respond to substantive notices within a reasonable timeframe and confirm receipt within 5 business days where you have provided a return address.
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction over disputes arising under it, subject to any mandatory provisions of the UK IDTA or EU SCCs.