Data Protection Agreement
Data Processing Agreement — CrowdHandler Ltd
Version 2 — 14 September 2026
This Data Processing Agreement ("DPA") forms part of the Contract between CROWDHANDLER LTD (company number 12677268, registered address Windsor House, Bayshill Road, Cheltenham, Gloucestershire, GL50 3AT, United Kingdom — "We/Us/Our") and the Customer under Our Terms of Service (https://www.crowdhandler.com/terms) and any Enterprise Order (together, the "Contract"). It applies wherever We process Personal Data on the Customer's behalf in providing the Application, and prevails over the Terms of Service in respect of that processing, save that liability is governed by Clause 12 of the Terms of Service. Capitalised terms not defined here have the meanings given in the Terms of Service.
1. Definitions
1.1. "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Contract, including (where applicable) the EU General Data Protection Regulation and equivalent or corresponding laws in other jurisdictions. "Personal Data", "controller", "processor", "data subject" and "processing" have the meanings given in applicable Data Protection Laws.
1.2. "Customer Personal Data" means Personal Data processed by Us on the Customer's behalf in providing the Application, as described in the Annex. "Data Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. "Sub-processor" means a third party engaged by Us to process Customer Personal Data.
2. Roles
2.1. For Customer Personal Data, the Customer is the controller (or a processor authorised to instruct Us) and We are the processor. Where the privacy laws of a US state or another jurisdiction apply, We act as the Customer's "service provider" or equivalent, and will not sell or share Customer Personal Data, nor retain, use or disclose it other than to provide the Application or as permitted by those laws.
2.2. We are an independent controller, and this DPA does not apply, in respect of Personal Data relating to the Customer's own personnel and Users (account administration, billing, support) and the email address of an end user who opts in to queue-position notifications, which is provided to Us directly. That processing is governed by Our Privacy Policy (https://www.crowdhandler.com/privacy).
3. Instructions
3.1. We will process Customer Personal Data only on the Customer's documented instructions, including as regards international transfers, unless required otherwise by law (in which case We will inform the Customer unless prohibited). The Contract, this DPA and the Customer's configuration of the Application constitute the complete documented instructions. We will inform the Customer if, in Our opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until instructions are confirmed or amended.
3.2. We may retain a copy of Customer Personal Data where necessary to document Our provision of the Application or to establish, exercise or defend legal claims, processed only for those purposes and protected in accordance with this DPA.
4. Confidentiality and security
4.1. We will ensure that persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality and access it only on a need-to-know basis.
4.2. We will implement and maintain industry standard technical and organisational measures, appropriate to the nature and risk of the processing, to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
5. Sub-processors
5.1. The Customer grants Us general authorisation to engage Sub-processors. The current list is maintained at https://www.crowdhandler.com/privacy. We will give at least 14 days' notice of any addition or replacement, and will impose on each Sub-processor data protection obligations materially equivalent to those in this DPA, remaining responsible to the Customer for each Sub-processor's performance.
5.2. The Customer may object to a new Sub-processor on reasonable data-protection grounds within the notice period, in which case the parties will discuss the objection in good faith. If it cannot be resolved and no commercially reasonable alternative is available, We may discontinue the affected feature or service, or the Customer may terminate the affected Subscription on written notice.
6. International transfers
6.1. Where applicable Data Protection Laws restrict the transfer of Customer Personal Data to another country, We (and Our Sub-processors) will make such a transfer only where it is covered by an adequacy decision or equivalent recognition, or subject to standard contractual clauses or another transfer mechanism approved under those laws. Where standard contractual clauses are required between the parties, they are incorporated into this DPA by reference, populated with the information in the Annex, with the Customer as exporter and Us as importer.
7. Assistance
7.1. Taking into account the nature of the processing and the information available to Us, We will assist the Customer, by appropriate measures, in responding to data subjects exercising their rights and in meeting the Customer's obligations regarding security, breach notification, data protection impact assessments and consultation with supervisory authorities. If We receive a data subject request relating to Customer Personal Data, We will forward it to the Customer and not respond except on the Customer's instructions or as required by law. Unless prohibited by law, We will notify the Customer of any legally binding request for disclosure of Customer Personal Data by a public authority.
8. Data Security Incidents
8.1. We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Data Security Incident, providing the information reasonably available to Us (in phases where necessary, without delaying initial notification for an ongoing investigation), and will take reasonable steps to mitigate its effects. We will not make a public announcement identifying the Customer in connection with a Data Security Incident without the Customer's prior written consent, except for disclosures or notifications required by law or a regulator, or to data subjects or other affected customers (without identifying the Customer).
9. Verification and audit
9.1. We will maintain records of Our processing of Customer Personal Data as required by Data Protection Laws.
9.2. The Customer's verification rights will in the first instance be satisfied by Our provision, on request and under confidentiality, of written information about Our security measures and responses to reasonable security questionnaires.
9.3. Where that information is insufficient for a specific, justified purpose (a material Data Security Incident affecting the Customer, or a requirement of a competent supervisory authority), We will allow for and contribute to an audit by the Customer or an independent auditor it mandates (not a competitor of Ours, and acceptable to Us acting reasonably), limited to once in any 12-month period, on at least 30 days' written notice, scoped to the processing of Customer Personal Data under this DPA, under appropriate confidentiality undertakings, without unreasonable disruption to Our operations or risk to other customers' data, and with the Customer bearing its own costs and Our reasonable costs of supporting the audit.
9.4. We maintain no physical premises at which Customer Personal Data is processed: processing takes place on cloud infrastructure operated by Our Sub-processors, whose facilities We neither control nor can grant access to. Audits are accordingly conducted remotely, by way of records, written responses and interviews; the physical and platform controls of hosting facilities are verified by way of the relevant provider's own assurance documentation, which We will make available or reference where relevant.
10. Return and deletion
10.1. Upon termination of the Contract, or earlier written request in respect of particular Customer Personal Data, We will, at the Customer's choice, return or securely delete the Customer Personal Data (certifying deletion on request), except to the extent retention is required by law, in which case We will protect it under this DPA, process it only as that law requires, and delete it when the requirement ends. Absent a choice within 30 days of termination, We will delete it.
11. General
11.1. Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations in Clause 12 of the Terms of Service, and nothing in this DPA excludes or restricts liability that cannot lawfully be excluded or restricted. This DPA takes effect on formation of the Contract, continues until We cease to process Customer Personal Data, and is governed by the same law and subject to the same jurisdiction as the Terms of Service.
Annex — Details of Processing
Subject matter, nature and purpose: processing of end-user request data in providing the Application (a virtual waiting room service) for the duration of the Contract — queuing, admitting, rate-limiting and redirecting end users to the Customer's website; anonymised traffic profiling to detect and prevent malicious activity (bots, scrapers and similar); and, where enabled, notifying an end user by email when their session reaches the front of the queue.
Data subjects: end users passing through Waiting Rooms on the Customer's websites.
Categories of Personal Data: IP address; browser type / user agent; operating system; language preferences; and, optionally, an end-user email address (only where the end user opts in to queue-position notification and the Customer has enabled that feature — provided by the end user directly to Us under Our Privacy Policy, used solely to send the notification, deleted once sent, and not shared with the Customer).
Special or sensitive categories of Personal Data (as defined under applicable Data Protection Laws): none are stored in providing the Application.
Transfers: as set out in the Sub-processor list at https://www.crowdhandler.com/privacy, subject to Clause 6.
Signature (for customers requiring an executed copy)
For and on behalf of CrowdHandler Ltd
Name: JACOB GRIMLEY Job Title: CEO Date:
For and on behalf of the Customer
Name: Job Title: Date: