DATAP · LEGAL
Seller data-processing agreement
Version 2026-09-21 · Published 21 September 2026
This agreement governs personal data Datap processes on a seller’s documented instructions. It supplements the platform terms and must be accepted as part of the seller’s agreement before this processing begins.
1. Parties, scope and roles
Datap is operated by 21 Holdings Limited, registered in England and Wales (company number 10815109). Registered office: 167–169 Great Portland Street, London, England, W1W 5PF. Write to this address, marked “Datap — legal/privacy”, or use private support in Settings. You do not need an account to write to us.
The other party is the seller identified in its Datap account and acceptance record. The seller is the controller, or a processor authorised by its controller to appoint Datap as subprocessor. It must identify that controller on request and secure the necessary authority. Datap acts as processor or subprocessor only for the seller-instructed activities covered here. UK GDPR, the Data Protection Act 2018 and EU GDPR apply where relevant to the processing.
Datap’s independent processing of account, billing, security and legal records is described in the privacy policy. This agreement does not relabel that activity or override roles imposed by law. It prevails over conflicting general terms for the processing it covers.
2. Processing schedule and seller instructions
Subject and purpose: hosting the seller’s dataset and supplying authorised samples, filtered selections, snapshots and updates to the recipients and for the uses the seller permits. Duration: the service period and the time required to return or delete data under the seller’s instructions and applicable law.
Operations: receipt, storage, validation, formatting, authorised filtering, lineage deduplication, access control, export, transmission, updating and deletion. The seller selects the categories of individuals and data fields through its dataset schema and recorded instructions. These may include creator or business-contact profiles, public identifiers, professional details and activity metrics, but only the actually authorised fields are in scope. Sensitive categories and children’s data require a separate written approval and safeguards.
The seller’s approved instruction version, schema, listing, licence and accepted order together specify data subjects and fields, sample visibility, uses, recipients, geographic restrictions, retention, updates and deletion. Instructions must be sufficiently specific before publication or processing. Changes must be recorded and must not unlawfully defeat existing rights. The seller may issue further lawful written instructions through the authorised controls or support.
The seller retains the right and duty to decide lawful purposes, collection, disclosures and retention, respond to individuals, assess risks and oversee its processors. It warrants that the instructions and supply are lawful and supported by appropriate notices and permissions. Datap must notify the seller immediately if it considers an instruction infringes applicable data-protection law and may suspend that operation while the issue is resolved.
3. Limits on use and confidentiality
Datap processes contents only on documented instructions, including for international transfers, unless law requires otherwise. In that case it informs the seller before processing unless the law prohibits notice. Datap chooses practical technical methods within the permitted purpose and essential scope.
Dataset contents must not be used for Datap’s own advertising, model training, cross-seller identity matching, profiling or independent enrichment. Staff access is limited to authorised work and people bound by confidentiality obligations. This duty survives the end of the service.
4. Security and assistance
Datap must maintain measures appropriate to risk, considering the data, processing and available technology. These include private storage, encrypted transmission, scoped access and credentials, isolation of seller authorisations, audit records, recovery procedures and testing of relevant controls. The seller must assess suitability for its dataset before supply and must not upload data requiring safeguards that have not been agreed.
Datap must notify the seller without undue delay after becoming aware of a personal-data breach affecting its dataset. Available information must cover its nature, affected data/individuals, likely consequences, contact point and containment/remediation, with further information supplied as it becomes available. The seller determines required notifications to regulators and individuals, without limiting Datap’s direct obligations.
Taking account of the processing and information available, Datap must assist the seller with rights requests, security duties, breach assessment, impact assessments and prior regulator consultation. It must promptly pass on requests concerning seller-controlled contents and follow authorised instructions, unless legally obliged to act otherwise. Reasonable assistance costs beyond the ordinary service must be agreed in advance and must not obstruct mandatory obligations.
5. Subprocessors and transfers
The seller gives general written authorisation for these dataset infrastructure providers: Cloudflare (hosting, network delivery/security and private R2 object storage); Supabase (database records, dataset metadata and authorised sample storage); and Fly.io (ingestion, filtering, export and deletion compute). Datap remains responsible to the seller for each subprocessor’s performance of the applicable data-protection duties and must impose equivalent protections by written contract.
The primary database and compute use Frankfurt; R2 uses a Western Europe location preference. Providers operate internationally and support or network processing may occur outside the UK/EEA, including the US. Before any restricted transfer, Datap must ensure a valid transfer mechanism and any required assessment and supplementary safeguards. The region setting is not a transfer mechanism. Details of relevant provider contracting entities, locations and safeguards are available on request.
Datap must give affected sellers at least 30 days’ prior notice of a proposed new or replacement dataset subprocessor so they can object on reasonable data-protection grounds. The parties will seek an appropriate alternative; if none is reasonably available, the seller may end the affected processing before the change, with return/deletion arrangements. A public list update alone is not notice to an affected seller.
Stripe’s payment services and providers used solely for Datap-controlled account communications are not appointed here to process dataset row contents. Their separate information processing is covered by the privacy policy.
6. Return, withdrawal and deletion
At the end of the relevant service, Datap must, at the seller’s choice, return or delete personal data and delete remaining copies unless retention is legally required. The seller must state the return/deletion instruction and authorised retention period. Pending deletion, the data must be restricted to necessary secure storage and required legal processing.
Withdrawal blocks affected new access; audited jobs then purge or compact data and invalidate cached exports. Restricted backup copies must expire through the backup lifecycle and any restoration must reapply deletion instructions before use. Datap must provide reasonable completion information and identify any required retained data. Old uploads must not restore erased records.
Necessary financial records are separate from dataset contents. Datap can record and relay downstream deletion notices, but cannot erase copies already held by independent buyers. The seller remains responsible for instructing recipients where required; recipients retain their own obligations.
7. Accountability and review
Datap must provide information reasonably necessary to demonstrate these obligations and allow and contribute to audits, including inspections, by the seller or its authorised independent auditor. Reasonable notice, confidentiality and protection of other customers apply without defeating legal or regulator rights. Material findings must be addressed promptly. Both parties must cooperate with competent supervisory authorities.
This agreement forms part of the accepted platform terms. Publication alone does not establish a seller’s acceptance, a completed transfer assessment, or the lawfulness of a dataset. The seller’s versioned instructions and acceptance evidence must be retained with the relevant service records.