Condit

Data Processing Agreement

Last updated: 19 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Condit Ltd] ("Processor", "we") and the business customer ("Controller", "you"). It applies whenever we process personal data on your behalf. Customers who need a signed copy can request one at hello@condit.co.uk.

1. Roles and scope

For personal data contained in the content you enter into Condit, you are the controller and we are the processor. We process that personal data only to provide the service and only on your documented instructions, including those set out in this DPA and the Terms of Service.

2. Our obligations as processor

  1. Process personal data only on your documented instructions, unless required by law (in which case we will tell you, unless the law prohibits it).
  2. Ensure that people authorised to process the data are bound by confidentiality.
  3. Implement appropriate technical and organisational security measures (see section 5).
  4. Engage sub-processors only as set out in section 4.
  5. Assist you, taking into account the nature of processing, in responding to data subject rights requests.
  6. Assist you with security, breach notification, and data protection impact assessments.
  7. Notify you without undue delay after becoming aware of a personal data breach affecting your data.
  8. On termination, delete or return your personal data as set out in section 6.
  9. Make available information needed to demonstrate compliance, and allow for and contribute to audits as set out in section 7.

3. Your obligations as controller

You are responsible for the lawfulness of the personal data you provide and the instructions you give, for having a valid legal basis for the processing, and for the accuracy of the data.

4. Sub-processors

You give general authorisation for us to engage the sub-processors listed in Annex B to deliver the service. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you reasonable notice of any new sub-processor and an opportunity to object on reasonable data protection grounds.

5. Security

We maintain measures appropriate to the risk, including encryption in transit, encrypted password storage, access controls, and database row-level security isolating each organisation's data. We review these measures periodically.

6. Return and deletion

By design, Condit holds as little personal data as possible: it is a working tool, not a long-term archive. Finished reports are exported as PDFs that you store on your own systems and which remain your definitive record; we do not keep a database of your finished reports. Drafts and tasks are working data, intended to be kept only while a report or job is in progress; when deleted they are moved to a recycle bin and then automatically and permanently erased shortly afterwards (currently within around 48 hours). On termination, we will delete the personal data we hold within 30 days, except where retention is required by law; residual copies in encrypted backups are deleted on the normal backup cycle.

7. Audits

On reasonable written request, and no more than once per year unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with this DPA.

8. International transfers

Where personal data is transferred outside the UK, we rely on a recognised transfer mechanism such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum.

9. Liability and term

This DPA is subject to the liability provisions of the Terms of Service and remains in force for as long as we process personal data on your behalf.

Annex A - Details of processing

Annex B - Approved sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageEuropean Union (Ireland, AWS eu-west-1)
ResendTransactional email (invitations, password resets)United States (under appropriate safeguards)