Legal · Data Processing Agreement

SAMMY Labs, Data Processing Agreement.

Version 2.0 · 25 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the applicable Order Form or account registration ("Customer") and the Sammy Labs entity that is party to that agreement, Sammy Labs Ltd (England and Wales) or Sammy Labs, Inc. (Delaware), ("SAMMY Labs") for the provision of the SAMMY platform and related services (the "Principal Agreement"). It applies where SAMMY Labs processes Personal Data on Customer's behalf.

  • 01

    Definitions

    "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 ("EU GDPR"), and applicable US state privacy laws including the CCPA as amended by the CPRA. "Personal Data", "Controller", "Processor", "Data Subject", "Personal Data Breach", "Processing", and "Supervisory Authority" have the meanings given in the applicable Data Protection Laws. "Customer Personal Data" means Personal Data contained in Customer Data (as defined in the Principal Agreement) processed by SAMMY Labs on Customer's behalf. "Subprocessor" means a third party engaged by SAMMY Labs to process Customer Personal Data. For US state privacy laws, SAMMY Labs acts as Customer's "service provider"/"processor" and the parties intend this DPA to satisfy the contractual requirements of those laws.

  • 02

    Roles and scope of processing

    2.1 Customer is the Controller (or, where Customer is itself a processor for a third-party controller, SAMMY Labs is a subprocessor) and SAMMY Labs is the Processor of Customer Personal Data. The subject matter, duration, nature and purposes of processing, and the categories of Personal Data and Data Subjects, are set out in Annex I.

    2.2 SAMMY Labs shall process Customer Personal Data only on Customer's documented instructions, including as set out in the Principal Agreement and this DPA, unless required otherwise by law to which SAMMY Labs is subject, in which case SAMMY Labs shall inform Customer of that requirement before processing unless the law prohibits it. SAMMY Labs shall inform Customer without delay if, in its opinion, an instruction infringes Data Protection Laws.

    2.3 SAMMY Labs shall not sell or share Customer Personal Data (as those terms are defined in the CCPA/CPRA), retain, use, or disclose it other than to provide the services, or combine it with Personal Data from other sources except as permitted for service providers, and certifies that it understands and will comply with these restrictions.

  • 03

    Personnel

    SAMMY Labs shall ensure that persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality and receive appropriate data protection and security training, and shall limit access to those who need it to perform the Principal Agreement.

  • 04

    Security

    SAMMY Labs shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the factors in Article 32 UK GDPR / EU GDPR, including at minimum the measures set out in Annex II. SAMMY Labs maintains an information security management system aligned with ISO/IEC 27001, is pursuing certification by an accredited certification body, and shall not materially reduce the overall protection of Customer Personal Data during the term of the Principal Agreement.

  • 05

    Subprocessors

    5.1 Customer grants SAMMY Labs general authorisation to engage Subprocessors. The current list is published at sammylabs.com/subprocessors.

    5.2 SAMMY Labs shall give Customer at least 14 days' prior notice of the addition or replacement of a Subprocessor, by email to Customer's account or notice contact. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith, Customer may terminate the affected services and receive a pro-rata refund of prepaid unused fees.

    5.3 SAMMY Labs shall impose on each Subprocessor, by written contract, data protection obligations materially no less protective than this DPA, and remains fully liable to Customer for each Subprocessor's performance.

  • 06

    Data subject rights

    Taking into account the nature of the processing, SAMMY Labs shall assist Customer by appropriate technical and organisational measures in fulfilling Customer's obligations to respond to Data Subject requests. SAMMY Labs shall promptly (and in any event within 5 business days) notify Customer of any Data Subject request it receives relating to Customer Personal Data and shall not respond to it except on Customer's documented instructions or as required by law.

  • 07

    Personal Data Breach

    SAMMY Labs shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall, to the extent then known, describe the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. SAMMY Labs shall cooperate with Customer and take reasonable steps to investigate, mitigate, and remediate the breach. SAMMY Labs' notification is not an admission of fault.

  • 08

    Assistance

    SAMMY Labs shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, in each case solely relating to processing of Customer Personal Data and taking into account the information available to SAMMY Labs.

  • 09

    Deletion or return

    On termination or expiry of the services, SAMMY Labs shall, at Customer's election, return Customer Personal Data in a commonly used format or delete it (and procure deletion by Subprocessors) within 30 days, and certify deletion on request, except to the extent retention is required by applicable law, and except for data in routine backups, which is deleted in the ordinary course of backup rotation within 30 days and is not otherwise accessed.

  • 10

    Audit

    10.1 SAMMY Labs shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including its ISO/IEC 27001 certificate and summaries of third-party audit reports, which the parties agree shall satisfy Customer's audit rights where reasonably sufficient.

    10.2 Where those materials are not reasonably sufficient, Customer (or an independent auditor bound by confidentiality, not a SAMMY Labs competitor) may audit SAMMY Labs' compliance no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at Customer's cost, and without unreasonable disruption. Nothing limits audits required by a Supervisory Authority.

  • 11

    International transfers

    11.1 SAMMY Labs shall not transfer Customer Personal Data outside the UK or EEA except in compliance with Data Protection Laws.

    11.2 Where a restricted transfer is made: (a) from the UK, the parties incorporate the ICO's International Data Transfer Addendum to the EU SCCs (or the IDTA, as applicable); and (b) from the EEA, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor), completed with the information in Annex I and Annex II, with SAMMY Labs as data importer and Customer as data exporter. If any such mechanism is invalidated or superseded, the parties shall cooperate to implement a lawful successor mechanism.

  • 12

    General

    12.1 This DPA is subject to the limitations and exclusions of liability in the Principal Agreement, which apply in aggregate across the Principal Agreement and this DPA.

    12.2 In case of conflict, this DPA prevails over the Principal Agreement with respect to processing of Customer Personal Data; any executed Standard Contractual Clauses or UK Addendum prevail over this DPA.

    12.3 This DPA is governed by the law governing the Principal Agreement, for contracts with Sammy Labs Ltd, the laws of England and Wales, with the courts of England and Wales having exclusive jurisdiction.

  • A1

    Annex I, Description of processing

    Subject matter: Provision of the SAMMY platform, compilation of regulatory rules and Customer operating procedures into engines that audit Customer records, generate reports, and support compliance workflows, together with related support.

    Duration: The term of the Principal Agreement plus the return/deletion period in Section 9.

    Nature and purposes: Hosting, storage, computation, analysis, report generation, transmission, and support-related access, solely to provide the services.

    Categories of Data Subjects: Customer's personnel and authorised users.

    Categories of Personal Data: Identity and business contact details of Customer's authorised users (first name, work email address, and related account data). The Service is configured and validated using synthetic or sample data provided by Customer, which is not intended to contain personal data. Customer shall not submit records containing real personal data unless agreed in the Order Form, and shall not submit special category data unless separately agreed in writing.

    Frequency: Continuous, for the duration of the services.

  • A2

    Annex II, Technical and organisational measures

    • ISMS aligned with ISO/IEC 27001 (certification by an accredited body in progress); policies reviewed at least annually
    • Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
    • Access on least-privilege basis; SSO and MFA enforced; access logged and reviewed
    • Production infrastructure hosted with AWS, Supabase, and Vercel, in the region corresponding to the Customer (US, EU, or UK)
    • Segregation of customer environments; segregation of production and development
    • Vulnerability management, including dependency scanning and prioritised patching, and penetration testing at least annually by an independent third party
    • Backups with defined retention and periodic restore testing
    • Incident response procedure with defined roles and customer notification path
    • Personnel confidentiality undertakings, pre-employment screening (identity, right-to-work, and reference checks, per documented process), and security training
    • Vendor/Subprocessor due diligence and contractual flow-down of obligations
    • Business continuity and disaster recovery procedures; where an Order Form specifies recovery time or recovery point objectives, the Order Form prevails