Roles of the parties

For personal data processed in connection with TryEntitle’s services under a client engagement, the client is the controller and TryEntitle is the processor, except where TryEntitle acts as an independent controller for its own business operations (for example, its own billing records, website analytics if introduced later, or compliance with its own legal obligations).

Scope, nature, and duration of processing

The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are set out in Annex 1. Engagements involving healthcare, legal, insurance, accounting, or similar document workflows may involve special-category or otherwise regulated data; those cases are addressed in Annex 1 for the relevant engagement.

Processing continues for the term of the engagement and until deletion or return under the “Deletion or return on termination” section below.

Processor obligations

TryEntitle will:

  • process personal data only on the client’s documented instructions, unless required to do otherwise by applicable law (in which case we will notify the client unless legally prohibited from doing so);
  • ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations;
  • implement the technical and organisational measures described in Annex 3;
  • assist the client, taking into account the nature of processing, with responding to data-subject requests;
  • assist the client with security, breach, impact-assessment, and consultation obligations to the extent reasonably related to TryEntitle’s processing; and
  • make available information reasonably necessary to demonstrate compliance with this Agreement.

Subprocessors

TryEntitle is authorized to engage the subprocessors listed in Annex 2. That list must remain consistent with the Privacy Policy and Security page for website-related processors, and with any engagement-specific annex for delivery systems.

TryEntitle will notify the client of intended additions or replacements to the subprocessor list and give the client a reasonable opportunity to object before the change takes effect for that client’s processing.

Security measures

The technical and organisational measures implemented for the services are set out in Annex 3 and are intended to match the commitments described on the Security page.

International transfers

Where personal data is transferred outside the United Kingdom or European Economic Area, the parties will rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism to ensure an adequate level of protection.

Deletion or return on termination

On termination of the engagement, TryEntitle will, at the client’s written election, delete or return personal data processed as processor within 30 days, except to the extent retention is required by applicable law or needed to establish, exercise, or defend legal claims. Certified deletion can be provided on request once deletion is complete.

Audit rights

The client may request information demonstrating TryEntitle’s compliance with this Agreement. The client may conduct an audit of TryEntitle’s relevant controls no more than once per calendar year, on 30 days’ prior written notice, during normal business hours, and in a manner that does not unreasonably disrupt operations. Remote questionnaires and existing SOC/ISO reports (where available from subprocessors) will be used first where they reasonably satisfy the request.

Breach notification

TryEntitle will notify the client of a personal data breach affecting personal data processed under this Agreement without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will include the information reasonably available at the time and needed for the client to meet its own notification obligations, with updates as more information becomes available.

Precedence

If there is a conflict between this Agreement and a master services or engagement agreement regarding data protection, this Agreement controls for data protection matters unless the engagement agreement expressly states otherwise with reference to this DPA.

Contact

Data-protection notices under this Agreement: privacy@tryentitle.com

Annex 1 — Details of processing

Unless a signed engagement schedule states otherwise, the default processing description is:

  • Subject matter — personal data contained in documents, forms, messages, and systems involved in workflow redesign and automation services.
  • Duration — the engagement term plus the retention/deletion period above.
  • Nature and purpose — intake, extraction, validation, human review routing, and synchronization of workflow data as instructed by the client.
  • Types of personal data — may include names, contact details, identifiers, and document contents supplied by the client; healthcare, legal, insurance, or financial engagements may include special-category or regulated data only as necessary for the instructed workflow.
  • Categories of data subjects — the client’s customers, patients, employees, vendors, claimants, or other persons whose data appears in the client’s workflows.

Engagement-specific annexes may narrow or expand this description.

Annex 2 — Authorized subprocessors

Website and early sales processors (always authorized for related processing):

SubprocessorRoleProcessing location
CalendlySchedulingUnited States
VercelWebsite hosting / CDNUnited States / global edge

Delivery subprocessors for a specific engagement (for example, cloud storage, email, CRM, or automation runtime) will be listed in that engagement’s schedule and kept consistent with the client’s instructions.

Annex 3 — Technical and organisational measures

TryEntitle maintains the following measures for personal data it processes:

  • encryption in transit (TLS) for the public website and for processor systems we configure;
  • access limited to personnel who need it for the engagement, with credentials revoked when access is no longer required;
  • multi-factor authentication on TryEntitle-controlled accounts that hold client data wherever the platform supports it;
  • confidentiality expectations for personnel handling client materials;
  • logging and monitoring appropriate to the systems in use; and
  • an incident response process aligned with the breach-notification commitment above and the Security page.

Only controls that are actually in place are described. Engagement-specific systems may add further measures documented in the engagement schedule.