Data Processing Agreement
Last updated 21 July 2026
This agreement is required by Article 28 of the GDPR. It applies whenever we handle personal data on your behalf, and it forms part of our Terms of Service. You do not need to sign anything separately. For a plain explanation of how responsibility splits, see our GDPR page.
On this page
- Parties and scope
- Acting on your instructions
- Confidentiality
- Security
- Sub-processors
- Helping with data subject rights
- Breach notification
- Audits and information
- International transfers
- Deletion and return
- Your responsibilities
- Term and liability
- Annex 1: Details of processing
- Annex 2: Security measures
- Annex 3: Sub-processors
1 Parties and scope
This agreement is between you, the customer using Arthur (the controller), and Tsagkaraki Broadworks, based in Greece (the processor).
It covers the personal data we handle on your behalf when you use Arthur, as described in Annex 1. It does not cover data where we are the controller, such as your own account details, which our Privacy Policy deals with.
2 Acting on your instructions
We process personal data only on your documented instructions. Using the Arthur service as it is intended counts as your instruction, along with anything you tell us in writing.
We do not use your data for our own purposes, we do not sell it, and we do not use it for advertising or to train anything.
If we believe an instruction breaks data protection law, we will tell you rather than quietly carry it out. If the law requires us to process data beyond your instructions, we will let you know first unless the law forbids it.
3 Confidentiality
Anyone who can access your data is bound by a duty of confidentiality, and only gets access where they genuinely need it to do their job or to support you.
4 Security
We put in place appropriate technical and organisational measures to protect personal data, taking account of the risk. The measures in place are listed in Annex 2.
We keep those measures under review, and we may change them as long as protection is not reduced.
5 Sub-processors
You give us general permission to use sub-processors. The current list is in Annex 3.
- Every sub-processor is bound by obligations no weaker than the ones in this agreement.
- We remain fully responsible to you for what they do.
- Before a new sub-processor starts, we will update Annex 3 and give you at least 30 days notice.
- If you reasonably object within that time, we will work with you on an alternative. If there is none, you may stop using the affected part of the service and cancel without penalty.
6 Helping with data subject rights
Arthur is built so you can handle most requests yourself, directly in your workspace: viewing, correcting, exporting, and deleting the records you hold.
Where you need more, we will help you, in good time for you to meet your own one-month deadline. If a request reaches us directly, we will not answer it ourselves. We will pass it to you, because it is your data and your call.
7 Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and no later than 72 hours after becoming aware of it.
We will tell you what we know: what happened, the categories and rough number of people and records involved, the likely consequences, and the steps we are taking. If we cannot give you everything at once, we will send it in stages rather than delay the first warning.
We will also help you meet your own duties to your supervisory authority and to the people affected.
8 Audits and information
We will give you the information you reasonably need to show that we are meeting Article 28, and we will allow and contribute to audits.
In practice, we will answer written questions and share what documentation we have. An on-site audit can be requested where there is a genuine reason, with reasonable notice, no more than once a year unless a regulator or a breach requires otherwise.
9 International transfers
We aim to keep personal data inside the European Economic Area. Where data goes outside it, we put a valid transfer mechanism in place first, such as the European Commission's standard contractual clauses, together with any extra safeguards the situation calls for.
10 Deletion and return
You can export your data at any time while your account is open.
When this agreement ends, we will delete the personal data we hold for you within 30 days, and remove it from backups within 90 days, unless the law requires us to keep something for longer. If you ask for a copy before deletion, we will provide one in a common, machine-readable format.
11 Your responsibilities
- Make sure you have a lawful basis for the data you put into Arthur.
- Tell your staff and anyone else whose data you record what you are doing with it, and how they can exercise their rights.
- Only enter data you actually need. Arthur is not the place for sensitive data you have no reason to hold.
- Keep your account secure and manage roles carefully, since you decide who sees what.
12 Term and liability
This agreement starts when you begin using Arthur and runs until you stop and your data has been deleted under section 10.
Liability under this agreement is subject to the limits in our Terms of Service, except where the law does not allow those limits to apply.
If any part of this agreement conflicts with the Terms of Service on the handling of personal data, this agreement wins.
Details of processing
Security measures
Sub-processors
Questions about this agreement? Write to .
