Data Processing Agreement
The Article 28 data processing terms between Panelicious and customers whose personal data we process.
This Data Processing Agreement (“Agreement”) forms part of and is incorporated into the agreement for services between Panelicious Limited, a company registered in England and Wales with company number 17258409 (“Supplier”) and the Customer pursuant to the Main Agreement. This Agreement takes effect on the date of the Main Agreement.
A PDF copy of this Agreement is available for download at the foot of this page.
Background
A. The Supplier provides the Services to the Customer pursuant to the Main Agreement.
B. In providing the Services, the Supplier processes Personal Data on behalf of the Customer. The parties enter into this Agreement to document their respective obligations in relation to that processing in accordance with Data Protection Laws.
The parties have agreed as follows.
1. Definitions
In this Agreement:
Controller has the meaning given to that term in Data Protection Laws.
Customer means the person or entity identified as the customer, subscriber or contracting party in the Main Agreement.
Data Protection Laws means, as applicable and binding on the relevant party: (a) in the United Kingdom, the Data Protection Act 2018 and the UK GDPR; and (b) in the European Union and/or European Economic Area, the EU GDPR and all applicable laws or regulations giving effect to or corresponding with it; in each case as amended, re-enacted or replaced from time to time.
Data Protection Losses means all liabilities, including costs (including legal costs), claims, demands, actions, settlements, charges, expenses, losses and damages (including in relation to material or non-material damage) and, to the extent permitted by applicable law, administrative fines, penalties, sanctions or other remedies imposed by a Supervisory Authority, compensation ordered by a Supervisory Authority to be paid to a Data Subject, and the reasonable costs of compliance with any Supervisory Authority investigation.
Data Subject has the meaning given to that term in Data Protection Laws.
Data Subject Request means a request by a Data Subject to exercise any right under Data Protection Laws.
EU GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council.
Lawful Safeguards means such legally enforceable mechanism(s) for Transfers of Personal Data as may be permitted under Data Protection Laws from time to time, including standard contractual clauses adopted by the European Commission and (in respect of UK transfers) the International Data Transfer Agreement issued by the UK Information Commissioner’s Office.
Main Agreement means the agreement for services pursuant to which the Services are provided (whether in the form of the Supplier’s terms and conditions, terms of service, or such other written agreement as may be in place between the parties from time to time).
Personal Data has the meaning given to that term in Data Protection Laws.
Personal Data Breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Personal Data.
Processing has the meaning given to that term in Data Protection Laws (and related terms such as process and processed shall be construed accordingly).
Processing Instructions has the meaning given in clause 3.1.
Processor has the meaning given to that term in Data Protection Laws.
Services means the services provided by the Supplier to the Customer under the Main Agreement.
Sub-Processor means another Processor engaged by the Supplier to carry out processing activities in respect of the Personal Data on behalf of the Customer.
Supplier means Panelicious Limited.
Supervisory Authority means any local, national or multinational agency, department, official or other body responsible for administering Data Protection Laws.
Transfer bears the same meaning as the word “transfer” in Article 44 of the EU GDPR (and related expressions such as Transfers, Transferred and Transferring shall be construed accordingly).
UK GDPR has the meaning given to that term in the Data Protection Act 2018.
2. Processor and Controller
-
The parties agree that, in relation to the Personal Data processed in connection with the Services, the Customer is the Controller and the Supplier is the Processor. Nothing in this Agreement relieves the Customer of its own responsibilities and liabilities under Data Protection Laws.
-
The Supplier shall process Personal Data in compliance with:
- the obligations applicable to Processors under Data Protection Laws in respect of the performance of its obligations under this Agreement; and
- the terms of this Agreement.
-
The Customer shall comply with:
- all Data Protection Laws in connection with the processing of Personal Data and the exercise of its rights and obligations under this Agreement, including maintaining all relevant registrations and notifications as required under Data Protection Laws; and
- the terms of this Agreement.
-
The Customer warrants, represents and undertakes that:
- all Personal Data provided by the Customer for use in connection with the Services shall comply with Data Protection Laws, including in terms of its collection, storage and processing (including by having provided all required fair processing information to, and obtained all necessary consents from, Data Subjects);
- all instructions given by it to the Supplier in respect of Personal Data shall at all times be in accordance with Data Protection Laws; and
- it has undertaken appropriate due diligence in relation to the Supplier’s processing operations and is satisfied that the Supplier has sufficient expertise, reliability and resources to implement appropriate technical and organisational measures in compliance with Data Protection Laws.
3. Instructions and details of processing
-
Insofar as the Supplier processes Personal Data on behalf of the Customer, the Supplier shall:
- process the Personal Data only in accordance with the Customer’s documented instructions as set out in this Agreement and Appendix 1, as updated from time to time (Processing Instructions), unless required by applicable law to process otherwise, in which case the Supplier shall (where not prohibited by applicable law) notify the Customer of that requirement before processing; and
- promptly inform the Customer if, in the Supplier’s opinion, a Processing Instruction infringes Data Protection Laws. To the maximum extent permitted by applicable law, the Supplier shall have no liability for any losses arising from processing carried out in accordance with the Processing Instructions following such notification.
-
The processing to be carried out by the Supplier under this Agreement is set out in Appendix 1.
4. Technical and organisational measures
-
The Supplier shall implement and maintain appropriate technical and organisational measures:
- to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects; and
- to assist the Customer, insofar as reasonably possible, in fulfilling the Customer’s obligations to respond to Data Subject Requests. The parties agree that the Supplier’s compliance with clause 6 constitutes the Supplier’s sole obligation under this clause 4.1(b).
5. Sub-Processors
-
The Customer grants the Supplier general authorisation to appoint Sub-Processors for the processing of Personal Data.
-
The Supplier shall:
- prior to the relevant Sub-Processor carrying out any processing activities in respect of the Personal Data, appoint each Sub-Processor under a written contract containing obligations materially equivalent to those imposed on the Supplier under clauses 2 to 12 of this Agreement; and
- remain fully liable for the acts and omissions of each Sub-Processor as if they were the Supplier’s own.
-
The Supplier shall ensure that all persons authorised by it (or by any Sub-Processor) to process Personal Data are subject to an appropriate obligation of confidentiality in respect of that data, except where disclosure is required by applicable law (in which case the Supplier shall, where permissible and practicable, notify the Customer before such disclosure).
6. Assistance with compliance and data subject rights
-
The Supplier shall promptly refer all Data Subject Requests it receives to the Customer. To the extent legally permitted, the Customer shall be responsible for any reasonable costs incurred by the Supplier in providing such assistance.
-
Taking into account the nature of the processing and the information available to the Supplier, the Supplier shall provide such reasonable assistance as the Customer requires to comply with the Customer’s obligations under Data Protection Laws with respect to:
- security of processing;
- data protection impact assessments;
- prior consultation with a Supervisory Authority regarding high-risk processing; and
- notifications to a Supervisory Authority and/or communications to Data Subjects in response to any Personal Data Breach,
provided that the Customer shall be responsible for any reasonable costs arising from the provision of such assistance.
7. International transfers
-
The Supplier shall not Transfer Personal Data to any country or territory outside the United Kingdom or European Economic Area (as applicable) unless:
- the Transfer is to a country or territory recognised as providing an adequate level of protection for Personal Data under applicable Data Protection Laws; or
- Lawful Safeguards are in place with respect to that Transfer.
-
The Supplier shall ensure that any Transfer made pursuant to clause 7.1(b) is made under a legally binding instrument incorporating appropriate Lawful Safeguards binding on the recipient, in accordance with Data Protection Laws.
-
The Customer shall cooperate with the Supplier and promptly execute any documents (including standard contractual clauses or an International Data Transfer Agreement) as the Supplier may reasonably require to give effect to any Lawful Safeguards in connection with the Services.
8. Records, information and audit
-
The Supplier shall maintain written records of all categories of processing activities carried out on behalf of the Customer in accordance with Data Protection Laws.
-
The Supplier shall make available to the Customer such information as is reasonably necessary to demonstrate the Supplier’s compliance with this Agreement. Where the Customer reasonably considers that such information alone is insufficient to demonstrate compliance, the Customer may conduct (or commission) an audit of the Supplier’s relevant processing activities, subject to:
- providing the Supplier with at least 30 days’ prior written notice (unless an audit is required urgently by a Supervisory Authority or directly in connection with a confirmed Personal Data Breach);
- audits being limited to once per calendar year, unless required by a Supervisory Authority or conducted following a confirmed Personal Data Breach;
- the audit being conducted during normal business hours with minimal disruption to the Supplier’s business;
- any third-party auditor being mutually agreed in advance with the Supplier (other than where the auditor is a Supervisory Authority); and
- the Customer bearing its own costs and the Supplier’s reasonable costs in connection with the audit, and keeping all information obtained strictly confidential (save for disclosure required by a Supervisory Authority or by applicable law).
-
Where the Supplier provides the Customer with a relevant third-party certification or audit report (including ISO 27001, SOC 2 or equivalent) issued within the preceding twelve months and confirming no known material changes in the controls audited, the Customer agrees to accept the findings in that report as evidence of the Supplier’s compliance with those controls in lieu of requesting a direct audit of the same controls.
9. Breach notification
-
On becoming aware of a Personal Data Breach, the Supplier shall, without undue delay and in any event within 72 hours:
- notify the Customer of the Personal Data Breach; and
- provide the Customer with such details of the Personal Data Breach as are then reasonably available, including (to the extent known) its nature, the categories and approximate number of Data Subjects and Personal Data records affected, its likely consequences, and the measures taken or proposed to address it.
-
The Customer shall coordinate with the Supplier in relation to the content of any public statements, communications to Data Subjects, or notifications to a Supervisory Authority regarding a Personal Data Breach.
10. Customer indemnity
- The Customer shall indemnify and keep indemnified the Supplier against all Data Protection Losses arising out of or in connection with any breach by the Customer of its obligations under this Agreement.
11. Deletion or return of Personal Data
-
Following the termination or expiry of the Main Agreement (or such earlier time as the Supplier is no longer required to process Personal Data to perform its obligations under the Main Agreement), the Supplier shall, at the Customer’s written election made within 30 days:
- return all Personal Data to the Customer in a commonly used electronic format; or
- securely delete all Personal Data,
and in either case delete all existing copies, unless storage is required by applicable law (in which case the Supplier shall notify the Customer of that requirement and the expected retention period).
12. Survival
- Clauses 1 to 12 of this Agreement shall survive the termination or expiry of the Main Agreement. Clauses 11 and 12 shall survive indefinitely. Clauses 1 to 10 shall survive until no Personal Data remains in the possession or control of the Supplier or any Sub-Processor, without prejudice to any accrued rights or remedies of either party at the time of such termination or expiry.
Appendix 1 — Data processing details
1. Subject-matter of Processing
Provision of the Panelicious display management platform, comprising a web-based management dashboard, a mobile application, and display software capable of running on any browser-capable device, together with associated customer support services, to the Customer.
2. Duration of Processing
The term of the Main Agreement, and thereafter as required to complete the deletion or return of Personal Data in accordance with clause 11.
3. Nature and Purpose of Processing
Processing carried out to provide the Services to the Customer, including:
- account creation, management and authentication for the Customer’s authorised users;
- configuration and remote management of the Customer’s display devices;
- scheduling and delivery of content to display devices;
- monitoring of device status, connectivity and activity;
- provision of usage analytics; and
- customer support.
4. Types of Personal Data
- Identity Data: first name, last name and username of the Customer’s users.
- Contact Data: email address and telephone number of the Customer’s users and account contacts.
- Technical Data: IP addresses (including user browser IP addresses and the IP addresses of devices configured to display content), device and browser identifiers (where applicable), browser type and version, operating system and platform.
- Profile Data: usernames, passwords, authentication credential identifiers (where passkey-based authentication is enabled), account roles and permissions, and subscription plan details. Billing name and address are also held; payment card details are processed by Panelicious’s third-party payment processor and are not stored by Panelicious.
- Device Data: device names, registration identifiers, location labels, content schedules and configuration settings assigned to devices, and device connectivity and status logs.
- Usage Data: analytics relating to use of the web dashboard and display device activity.
5. Categories of Data Subjects
The Customer (where the Customer is an individual, sole trader or partner); and the Customer’s employees, contractors and other authorised users of the Services.
6. Processing Instructions
The Supplier is instructed to process Personal Data as necessary to provide the Services as described in the Main Agreement and this Agreement. The Customer may provide further documented instructions from time to time, provided such instructions are consistent with this Agreement and Data Protection Laws.
7. Special Categories of Personal Data
N/A. Panelicious does not process special category personal data (within the meaning of Article 9 EU GDPR / UK GDPR) in the ordinary course of providing the Services.
Appendix 2 — Sub-Processors
The Supplier engages the Sub-Processors listed below in connection with the provision of the Services. This list is generated from the same source as our published sub-processors page, which is authoritative and kept current.
| Provider | What they do for us | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery, and network and application security. | Account data, service usage data, IP addresses, and customer content. | United States, with processing at global edge locations | UK IDTA and EU Standard Contractual Clauses |
| Google Cloud EMEA Limited | Cloud infrastructure and data storage. | Account data, device configuration data, and service usage data. | United States and European Union | UK IDTA and EU Standard Contractual Clauses |
| Google Ireland Limited | Business email and internal document storage. | Contact details and the content of correspondence with us. | European Union and United States | UK IDTA and EU Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Payment processing and subscription billing. | Billing details and contact details. Full card numbers are handled by Stripe and are not stored by Panelicious. | Ireland and United States | UK IDTA and EU Standard Contractual Clauses |
| Jitbit Ltd | Customer support ticketing and knowledge base. | Contact details and the content of correspondence with us. | United Kingdom (provider); United States (hosting) | UK-established provider; US hosting under the provider's own processing terms |
| Resend, Inc. | Delivery of transactional email. | Contact details and the content of the messages sent. | United States | EU Standard Contractual Clauses |
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 15 August 2026 | First published version. |