Version 2.0 · 25 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the applicable Order Form or account registration ("Customer") and the Sammy Labs entity that is party to that agreement, Sammy Labs Ltd (England and Wales) or Sammy Labs, Inc. (Delaware), ("SAMMY Labs") for the provision of the SAMMY platform and related services (the "Principal Agreement"). It applies where SAMMY Labs processes Personal Data on Customer's behalf.
"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 ("EU GDPR"), and applicable US state privacy laws including the CCPA as amended by the CPRA. "Personal Data", "Controller", "Processor", "Data Subject", "Personal Data Breach", "Processing", and "Supervisory Authority" have the meanings given in the applicable Data Protection Laws. "Customer Personal Data" means Personal Data contained in Customer Data (as defined in the Principal Agreement) processed by SAMMY Labs on Customer's behalf. "Subprocessor" means a third party engaged by SAMMY Labs to process Customer Personal Data. For US state privacy laws, SAMMY Labs acts as Customer's "service provider"/"processor" and the parties intend this DPA to satisfy the contractual requirements of those laws.
2.1 Customer is the Controller (or, where Customer is itself a processor for a third-party controller, SAMMY Labs is a subprocessor) and SAMMY Labs is the Processor of Customer Personal Data. The subject matter, duration, nature and purposes of processing, and the categories of Personal Data and Data Subjects, are set out in Annex I.
2.2 SAMMY Labs shall process Customer Personal Data only on Customer's documented instructions, including as set out in the Principal Agreement and this DPA, unless required otherwise by law to which SAMMY Labs is subject, in which case SAMMY Labs shall inform Customer of that requirement before processing unless the law prohibits it. SAMMY Labs shall inform Customer without delay if, in its opinion, an instruction infringes Data Protection Laws.
2.3 SAMMY Labs shall not sell or share Customer Personal Data (as those terms are defined in the CCPA/CPRA), retain, use, or disclose it other than to provide the services, or combine it with Personal Data from other sources except as permitted for service providers, and certifies that it understands and will comply with these restrictions.
SAMMY Labs shall ensure that persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality and receive appropriate data protection and security training, and shall limit access to those who need it to perform the Principal Agreement.
SAMMY Labs shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the factors in Article 32 UK GDPR / EU GDPR, including at minimum the measures set out in Annex II. SAMMY Labs maintains an information security management system aligned with ISO/IEC 27001, is pursuing certification by an accredited certification body, and shall not materially reduce the overall protection of Customer Personal Data during the term of the Principal Agreement.
5.1 Customer grants SAMMY Labs general authorisation to engage Subprocessors. The current list is published at sammylabs.com/subprocessors.
5.2 SAMMY Labs shall give Customer at least 14 days' prior notice of the addition or replacement of a Subprocessor, by email to Customer's account or notice contact. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith, Customer may terminate the affected services and receive a pro-rata refund of prepaid unused fees.
5.3 SAMMY Labs shall impose on each Subprocessor, by written contract, data protection obligations materially no less protective than this DPA, and remains fully liable to Customer for each Subprocessor's performance.
Taking into account the nature of the processing, SAMMY Labs shall assist Customer by appropriate technical and organisational measures in fulfilling Customer's obligations to respond to Data Subject requests. SAMMY Labs shall promptly (and in any event within 5 business days) notify Customer of any Data Subject request it receives relating to Customer Personal Data and shall not respond to it except on Customer's documented instructions or as required by law.
SAMMY Labs shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall, to the extent then known, describe the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. SAMMY Labs shall cooperate with Customer and take reasonable steps to investigate, mitigate, and remediate the breach. SAMMY Labs' notification is not an admission of fault.
SAMMY Labs shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, in each case solely relating to processing of Customer Personal Data and taking into account the information available to SAMMY Labs.
On termination or expiry of the services, SAMMY Labs shall, at Customer's election, return Customer Personal Data in a commonly used format or delete it (and procure deletion by Subprocessors) within 30 days, and certify deletion on request, except to the extent retention is required by applicable law, and except for data in routine backups, which is deleted in the ordinary course of backup rotation within 30 days and is not otherwise accessed.
10.1 SAMMY Labs shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including its ISO/IEC 27001 certificate and summaries of third-party audit reports, which the parties agree shall satisfy Customer's audit rights where reasonably sufficient.
10.2 Where those materials are not reasonably sufficient, Customer (or an independent auditor bound by confidentiality, not a SAMMY Labs competitor) may audit SAMMY Labs' compliance no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at Customer's cost, and without unreasonable disruption. Nothing limits audits required by a Supervisory Authority.
11.1 SAMMY Labs shall not transfer Customer Personal Data outside the UK or EEA except in compliance with Data Protection Laws.
11.2 Where a restricted transfer is made: (a) from the UK, the parties incorporate the ICO's International Data Transfer Addendum to the EU SCCs (or the IDTA, as applicable); and (b) from the EEA, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor), completed with the information in Annex I and Annex II, with SAMMY Labs as data importer and Customer as data exporter. If any such mechanism is invalidated or superseded, the parties shall cooperate to implement a lawful successor mechanism.
12.1 This DPA is subject to the limitations and exclusions of liability in the Principal Agreement, which apply in aggregate across the Principal Agreement and this DPA.
12.2 In case of conflict, this DPA prevails over the Principal Agreement with respect to processing of Customer Personal Data; any executed Standard Contractual Clauses or UK Addendum prevail over this DPA.
12.3 This DPA is governed by the law governing the Principal Agreement, for contracts with Sammy Labs Ltd, the laws of England and Wales, with the courts of England and Wales having exclusive jurisdiction.
Subject matter: Provision of the SAMMY platform, compilation of regulatory rules and Customer operating procedures into engines that audit Customer records, generate reports, and support compliance workflows, together with related support.
Duration: The term of the Principal Agreement plus the return/deletion period in Section 9.
Nature and purposes: Hosting, storage, computation, analysis, report generation, transmission, and support-related access, solely to provide the services.
Categories of Data Subjects: Customer's personnel and authorised users.
Categories of Personal Data: Identity and business contact details of Customer's authorised users (first name, work email address, and related account data). The Service is configured and validated using synthetic or sample data provided by Customer, which is not intended to contain personal data. Customer shall not submit records containing real personal data unless agreed in the Order Form, and shall not submit special category data unless separately agreed in writing.
Frequency: Continuous, for the duration of the services.