Legal · draft
Data Processing Agreement
Last updated 4 October 2026. Draft for review.
1. Parties and scope
This agreement is between the organisation using the team platform (the "Controller") and [legal entity name and legal form], registration number [registration number], of [registered address] (the "Processor"). It applies when we process personal data for the Controller through the team platform, and it forms part of our Terms of Service. If the two conflict on data protection, this agreement prevails.
KOZMO is a working name for the service currently provided at thebimethod.com.
2. Details of processing
- Subject and purpose: running team scans for the Controller and producing team results.
- Duration: while the Controller uses the team platform, then as set out in section 11.
- People concerned: the Controller's employees, contractors and other people it invites to respond.
- Personal data: respondent email addresses, answers and derived scores, timestamps, and basic usage data.
- Special category data: not intended. The Controller must not ask respondents for it.
3. Our obligations as processor
- We process personal data only on the Controller's documented instructions, which are this agreement and the Controller's use of the platform, unless the law requires otherwise.
- People authorised to access the data are bound by confidentiality.
- We apply the security measures in section 7.
- We help the Controller respond to individuals' rights requests, and tell the Controller within [period] if a respondent contacts us directly.
- We help the Controller with security, breach notification, impact assessments and prior consultation, so far as the nature of the processing allows.
- We tell the Controller if we think an instruction breaches data protection law.
4. The Controller's obligations
The Controller confirms that it has a lawful basis for the processing and has told respondents clearly what the scan is, why it is run, who sees results and for how long. It will not use individual responses for discipline or dismissal, and will meet any works council or employee representative requirements that apply to it.
5. Sub-processors
The Controller gives general authorisation for the sub-processors below. We will give [notice period] notice of changes. The Controller may object on reasonable data protection grounds; if we cannot resolve it, it may end the subscription [refund terms]. We bind each sub-processor by contract to equivalent obligations and remain responsible for their performance.
| Sub-processor | Purpose | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Database, authentication, server functions | Respondent emails, answers, accounts | [confirm project region] | [confirm DPA and SCCs] |
| Stripe | Payments (Controller's billing contacts) | Billing details | [confirm] | [confirm] |
| Mailgun | Email delivery (invitations and notices) | Email addresses, message content | [confirm: US or EU region] | [confirm] |
| Netlify | Hosting of the web application | Request and log data | [confirm] | [confirm] |
| Google Analytics 4 | Website analytics, consent only | Usage data of visitors; not respondents' answers | [confirm] | [confirm] |
| Microsoft Clarity | Session recordings, consent only | Interaction data; must exclude answer inputs | [confirm] | [confirm] |
6. International transfers
We do not transfer personal data outside the UK and EEA unless the destination has an adequacy decision or we have put in place standard contractual clauses (and, for UK data, the UK addendum or IDTA) or another lawful safeguard. [Confirm per sub-processor before this paragraph is published.]
7. Security
We apply measures appropriate to the risk. [List only measures verified by engineering. The live DPA claims MFA for staff, row-level security, AES-256 at rest, TLS 1.2 or higher, API rate limiting, anomaly monitoring, staff training and a logically isolated benchmark store. Row-level security and HTTPS are typical of the stack; the rest were not confirmed in this review.]
8. Personal data breaches
We tell the Controller without undue delay and within [hours, to be decided] of becoming aware of a breach affecting its data, with the information we have, and we help it meet its duty to notify the regulator.
9. Audits
We give the Controller information needed to show compliance and allow reasonable audits on [notice period] notice, not more than once a year unless there has been a breach, during business hours and under confidentiality. We may satisfy an audit request with relevant reports or certifications.
10. Aggregated and derived data
[We will not use personal data processed under this agreement for our own purposes, except as set out in a separately agreed clause on aggregated and anonymised data, if any.]
11. End of the agreement
When the subscription ends we will, at the Controller's choice, return or delete the personal data, and delete existing copies after [period, to be decided] unless the law requires us to keep them. On request we will confirm deletion in writing. The Controller may export results during [export window].
12. Liability
Each party is liable under this agreement subject to the limits in the Terms of Service [confirm whether data protection claims have a separate cap]. Each party bears the fines imposed on it for its own breach.
13. Governing law
This agreement is governed by [governing law], and disputes go to [courts]. The Controller's data protection law supervisory authority is [supervisory authority].
14. Contact
[Legal entity name], [registered address], [privacy contact email]. Data protection officer: [name and contact, or none appointed].