Account-holder terms
Version 2026-07-29 · SHA-256 9043627474b5a272…
TERMS OF SERVICE
Effective date: 29 July 2026
These Terms of Service govern access to and use of Pen Free Signatures, including its website, applications, document-signing facilities and related services.
Please read these Terms carefully. By creating an account, accessing the Service or using the Service to upload, send or manage a document, you agree to these Terms.
1. About the Service and the Operator
The Service is operated by:
Legal name: L4M3 Heavy Industries
Email: support@penfreesig.com
Website: www.penfreesig.com
In these Terms, “Operator”, “we”, “us” and “our” refer to the person identified above.
“User”, “you” and “your” refer to the person or organisation creating or using an account.
The Service enables Users to upload PDF documents, position electronic-signature and date fields, invite recipients to review documents and obtain simple electronic signatures supported by an electronic audit trail.
2. Business use only
The Service is currently provided only for business, professional, trade, organisational or employment-related use.
By creating an account, you confirm that:
- you are acting wholly or mainly for purposes connected with your trade, business, craft, profession or organisation;
- you are not creating the account as a consumer for purely personal, family or household purposes;
- you are at least 18 years old and have legal capacity to enter into these Terms; and
- where you act for an organisation, you have authority to bind that organisation to these Terms.
An individual may be invited to sign a document in their personal capacity without becoming an account-holding User. Separate signer disclosures apply to recipients.
We may decline, suspend or terminate accounts where we reasonably believe that the Service is being used primarily for consumer transactions.
3. Free beta service
The Service is currently provided as a free, experimental beta service.
You acknowledge that:
- the Service is under active development;
- functions may be incomplete, changed or removed;
- interruptions, errors and document-rendering problems may occur;
- the Service is not intended to be your sole document-storage or record-retention system;
- no service level, uptime commitment or response time is guaranteed; and
- you must maintain your own copies of all original and completed documents.
We may introduce paid services in the future. We will not charge you without giving you details of the applicable fees and obtaining any acceptance required by law.
4. Nature of the electronic signature
The Service provides a process for creating simple electronic signatures.
Unless we expressly state otherwise in writing for a particular feature, the Service does not provide:
- a qualified electronic signature;
- an advanced electronic signature;
- a qualified electronic seal;
- a qualified electronic timestamp;
- a notarisation service;
- a witnessing service;
- independent identity verification;
- certification of a signer’s authority or legal capacity;
- legalisation or apostille services;
- escrow, legal, conveyancing or trust services; or
- any assurance level required by a government, regulator, court, public registry or qualified trust-service scheme.
A visible signature, date, email verification event, IP address, timestamp or audit record does not by itself guarantee that a signature or document is legally valid or enforceable.
5. No legal advice
The Operator is not acting as your lawyer, notary, witness, conveyancer, compliance adviser or other professional adviser.
The Service does not:
- determine whether electronic signatures are permitted for a particular document;
- determine what type of electronic signature is legally required;
- determine whether a witness or notary is required;
- determine whether a signer has authority, capacity or proper understanding;
- verify the truth, legality or completeness of a document;
- advise which country’s law governs a document;
- determine whether mandatory disclosures or formalities have been satisfied; or
- guarantee that a court, regulator, registry or third party will accept a document.
You are responsible for obtaining independent legal advice before relying on the Service for an important, high-value, regulated or cross-border transaction.
6. Your responsibility for legal validity
You are solely responsible for determining whether use of the Service is appropriate and lawful for each document and transaction.
Before sending a document, you must determine:
- the law governing the document;
- the location and legal status of each party;
- whether electronic execution is permitted;
- the required form and level of signature;
- whether witnesses, notarisation, identity checks or physical presence are required;
- whether consent to electronic records is required;
- whether the document must be filed with or accepted by a public authority;
- whether any party has capacity and authority to sign;
- whether required notices and disclosures have been given; and
- whether the completed record must be retained in a particular form or for a particular period.
You must not rely solely on the fact that the Service allowed a document to be uploaded, sent or signed.
Availability of a feature does not mean that the feature is legally sufficient in your country or for your transaction.
7. Restricted documents
Unless the Operator has expressly approved a particular use in writing, you must not use the Service for:
- wills, codicils, testamentary trusts or inheritance instruments;
- lasting, enduring or general powers of attorney;
- adoption, divorce, marriage, civil-partnership or other family-law documents;
- deeds or documents that must be executed as deeds;
- documents requiring an independent witness;
- documents requiring notarisation, certification, legalisation or an apostille;
- transfers, dispositions, mortgages or charges over land or real property;
- documents intended for registration with a land or property registry;
- residential eviction, repossession, foreclosure or utility-disconnection notices;
- court documents, pleadings, service of process, sworn statements or affidavits;
- negotiable instruments, bills of exchange, promissory notes, documents of title or electronic transferable records;
- documents relating to securities, public offerings or regulated investments;
- regulated consumer-credit agreements or statutory consumer disclosures;
- medical consent, advance healthcare directives or do-not-resuscitate instructions;
- documents relating to assisted reproduction or organ donation;
- documents whose validity requires a qualified, advanced, government-issued or regulated electronic signature;
- documents requiring biometric, face-to-face or government-identity verification;
- documents that must be retained by an approved archive or regulated custodian;
- documents whose electronic execution is prohibited by applicable law; or
- any document designated as restricted in our website guidance.
This list is not exhaustive. You remain responsible for identifying additional restrictions imposed by applicable law.
8. Sensitive and regulated information
During the beta period, you must not upload documents containing unusually sensitive or high-risk information unless we have expressly permitted that category in writing.
Restricted information includes:
- passwords, authentication secrets or private cryptographic keys;
- complete payment-card details;
- online-banking credentials;
- copies of passports, identity cards or driving licences;
- national identification or social-security numbers;
- detailed medical records;
- genetic or biometric data used for identification;
- information about children;
- criminal convictions or alleged criminal conduct;
- classified, defence-controlled or export-controlled information;
- information protected by legal professional privilege unless appropriate safeguards have been agreed;
- highly confidential merger, acquisition or securities information; and
- any information you are not legally authorised to provide to us.
You must apply appropriate redaction before uploading a document where sensitive information is not necessary for the signing process.
9. Account security
You must:
- provide accurate account information;
- maintain control of your registered email address;
- keep passwords, magic links, passkeys and authentication credentials secure;
- use multi-factor authentication where available;
- prevent unauthorised access to your account;
- promptly notify us of suspected unauthorised access;
- review account activity regularly; and
- ensure that people using your account are properly authorised.
You are responsible for activity carried out through your account unless that activity resulted directly from our failure to use reasonable security measures.
You must not share an individual account between multiple people unless the Service expressly supports team accounts.
10. Recipient details and invitations
You must only enter a recipient’s name, email address or other personal information where you have a lawful reason to do so.
You warrant that:
- the recipient has a genuine connection to the relevant document or transaction;
- the invitation is not unsolicited marketing or spam;
- the recipient’s details are accurate to the best of your knowledge;
- you are authorised to send the document to that recipient;
- sending the document does not breach confidentiality obligations;
- you have provided any privacy information required by law; and
- the recipient is not being impersonated, deceived or coerced.
You must independently verify important recipient details. We are not responsible where an invitation is sent to an incorrect, compromised, shared or inaccessible email account.
11. Authentication limitations
The Service may use an email link, email one-time passcode, account login, IP address, device information or similar measures as evidence associated with a transaction.
These measures may help demonstrate that someone had access to a particular email account or device. They do not conclusively establish:
- the signer’s legal identity;
- that the signer is the named person;
- the signer’s age;
- the signer’s mental capacity;
- the signer’s authority to represent another person or organisation;
- that the signer was free from coercion;
- that the signer understood the document; or
- that the account or device was not compromised.
Where reliable identification is important, you must use additional independent verification appropriate to the risk and applicable law.
12. Consent and intention to sign
You must not invite a person to sign unless you reasonably believe they intend and are entitled to participate in the transaction.
You must not:
- obscure the effect of the signing button;
- misrepresent a document as something else;
- conceal pages or material terms;
- preselect consent dishonestly;
- interfere with the recipient’s opportunity to review the document;
- pressure or coerce a recipient;
- submit a signature on behalf of another person without lawful authority; or
- use another person’s email account or authentication code.
A recipient must be given a meaningful opportunity to review the document before signing.
13. Document preparation and field placement
You are responsible for:
- uploading the correct and complete PDF;
- checking every page before sending;
- placing signature, date and other fields accurately;
- checking page rotation, dimensions and rendering;
- ensuring that fields do not conceal important text;
- ensuring that the correct recipient is assigned to each field;
- confirming that dates and names are displayed appropriately; and
- conducting any necessary test before relying on the document.
We may display a preview, but the preview is not a legal review or guarantee that every PDF viewer will display the document identically.
Once a document has been sent, it may be locked against editing. Any corrected document should be created and sent as a new version.
14. Evidence and audit records
The Service may create an audit record containing information such as:
- envelope or transaction identifiers;
- document filenames and cryptographic hashes;
- account and recipient email addresses;
- sending, viewing, authentication and signing timestamps;
- IP addresses;
- browser or device information;
- the wording of electronic-consent statements;
- signing status and delivery events; and
- records of revocation, expiry or refusal.
You acknowledge that:
- audit evidence is evidential material and not a guarantee of enforceability;
- timestamps may be affected by infrastructure or clock errors;
- email-delivery records do not guarantee that a particular person read a message;
- IP addresses may be shared, translated, proxied or inaccurate;
- cryptographic hashes demonstrate file matching but do not prove identity or authority; and
- the weight given to audit evidence is determined by the relevant court, regulator or decision-maker.
You must preserve your own copy of any audit certificate and completed document.
15. User content
“User Content” means documents, text, signatures, recipient information, messages and other material submitted through your account.
You retain ownership of your User Content.
You grant us a non-exclusive, worldwide, limited licence to host, copy, transmit, process, display, convert, secure, back up and otherwise use User Content only as reasonably necessary to:
- operate the Service;
- carry out your instructions;
- maintain security and integrity;
- prevent misuse and fraud;
- comply with law; and
- enforce these Terms.
This licence ends when the relevant content is deleted from active systems, subject to reasonable backup cycles, legal obligations and records that must be retained for security or legal claims.
16. Your warranties concerning content
You warrant that:
- you own or are authorised to use all User Content;
- processing the User Content does not infringe another person’s rights;
- you have a valid legal basis for all personal data you submit;
- you have issued all required privacy notices;
- the document is not unlawful, fraudulent or misleading;
- you are entitled to invite each recipient;
- the document does not contain malware or malicious code;
- the document does not breach sanctions, export controls or confidentiality restrictions; and
- your instructions to us are lawful.
17. Prohibited use
You must not use the Service:
- for fraud, forgery, impersonation or identity theft;
- to fabricate or alter evidence dishonestly;
- to obtain a signature through deception, threats or coercion;
- to send spam or unsolicited advertising;
- to distribute malware, ransomware or harmful code;
- to violate intellectual-property, confidentiality or privacy rights;
- to evade legal signing, witnessing, identity or filing requirements;
- to create false records of consent or approval;
- to interfere with the Service or another account;
- to probe, scan or test vulnerabilities without written permission;
- to reverse engineer the Service except where the law expressly permits it;
- to automate access in a way that places an unreasonable load on the Service;
- to resell, sublicense or white-label the beta Service without written permission;
- to provide regulated legal, financial or trust services without the necessary authorisation;
- for activity involving sanctioned persons or prohibited jurisdictions;
- to breach export-control, anti-money-laundering or anti-bribery law;
- to facilitate illegal goods, exploitation, terrorism or organised crime; or
- in any manner that creates material legal, security or reputational risk for the Operator or other users.
18. Sanctions and restricted territories
You represent that neither you nor, to your knowledge, the organisation you represent is:
- subject to applicable asset-freeze or blocking sanctions;
- owned or controlled by a sanctioned person;
- located in a territory where providing the Service would be prohibited; or
- using the Service for the benefit of a sanctioned person or prohibited activity.
You must comply with all sanctions and export-control laws applicable to you, the Operator and the transaction.
We may block countries, territories, persons, organisations, email domains, transactions or documents where we reasonably believe access may breach sanctions or create unacceptable legal risk.
We are not required to complete or preserve a transaction where doing so would be unlawful.
19. Privacy and data protection
Our processing of personal information for our own purposes is described in the Pen Free Signatures Privacy Notice.
Where you submit personal data relating to recipients or other persons for us to process on your behalf:
- you will generally act as the controller or business determining the purpose of the processing;
- we will generally act as your processor or service provider;
- the Data Processing Schedule below applies; and
- you instruct us to process that personal data to provide and secure the Service.
For account administration, fraud prevention, security, legal compliance and management of our own business, we may act as an independent controller.
Nothing in these Terms reduces any rights an individual has under applicable data-protection law.
20. International processing
The Service uses internet and cloud-service providers that may process information in more than one country.
You authorise us to use the subprocessors identified in our current subprocessor list.
Where applicable law requires a particular international-transfer mechanism, the parties will apply the legally recognised mechanism stated in our Data Processing Schedule or transfer addendum.
You must not use the Service where the transfer or processing of the relevant information would be unlawful.
21. Retention and deletion
Current retention periods are described in our Privacy Notice and retention schedule.
Unless a different period is expressly agreed:
- drafts and incomplete documents may be deleted after a period of inactivity;
- expired or voided transactions may be deleted;
- completed documents and their associated signing data are deleted seven days after signing;
- detailed technical logs may be retained for a shorter security period;
- backups may persist until the next scheduled deletion cycle; and
- minimal records may be retained where reasonably necessary for legal compliance, fraud prevention or legal claims.
The Service is not a permanent archive.
You must download and independently preserve each original document, completed document and audit certificate promptly after completion.
Deletion from the Service does not invalidate copies already downloaded or lawfully retained by another party.
22. Confidentiality
We will use reasonable measures designed to protect User Content from unauthorised access and disclosure.
We may access or disclose User Content only:
- to provide or support the Service;
- at your instruction;
- to investigate security incidents or misuse;
- to our authorised subprocessors under confidentiality obligations;
- where required by law or a binding legal request; or
- where reasonably necessary to protect legal rights, safety or the integrity of the Service.
You acknowledge that no internet-based service can guarantee absolute security or confidentiality.
23. Security incidents
You must notify us promptly at support@penfreesig.com if you become aware of:
- unauthorised account access;
- an exposed signing link;
- a compromised recipient email account;
- an incorrect recipient;
- an unauthorised document disclosure; or
- any other suspected security incident.
We may suspend access, revoke links, preserve evidence and take other reasonable protective action.
Where we become aware of a personal-data breach affecting personal data processed on your behalf, we will notify you without undue delay as required by applicable law and the Data Processing Schedule.
24. Third-party services
The Service may depend on third-party hosting, storage, database, email, security and authentication providers.
Those providers may have their own terms, privacy practices, service limits and outages.
We are not responsible for a third-party service to the extent that a failure is outside our reasonable control, but this clause does not remove responsibilities that applicable law places directly on us.
Links to third-party websites are provided for convenience and do not constitute endorsement.
25. Intellectual property
The Operator and its licensors own all intellectual-property rights in the Service, including its software, interface, branding, templates and documentation, except for User Content and open-source components owned by their respective licensors.
These Terms grant you a limited, non-exclusive, non-transferable and revocable right to use the Service during the term of your account in accordance with these Terms.
No rights are granted except those expressly stated.
26. Feedback
Where you voluntarily provide ideas, suggestions or feedback about the Service, you permit us to use that feedback without restriction or payment.
This does not transfer ownership of confidential documents or personal information contained in User Content.
27. Availability and maintenance
We may:
- carry out planned or emergency maintenance;
- impose usage, file-size, document-count or email limits;
- change supported browsers and formats;
- suspend features that create security or legal risk;
- restrict access from particular territories; and
- discontinue the free beta.
Where reasonably practicable, we will give advance notice of a material discontinuation and an opportunity to export completed documents.
Emergency, legal or security circumstances may require immediate action without prior notice.
28. Suspension and termination
You may stop using the Service and close your account at any time.
We may suspend or terminate access where:
- you breach these Terms;
- your use creates a legal, security or operational risk;
- we suspect fraud or unauthorised activity;
- you fail to respond to a reasonable compliance request;
- continued service would breach law, sanctions or a provider’s requirements;
- the beta is discontinued; or
- your account has been inactive for an extended period.
Before closing an account, you are responsible for exporting all documents and records you need.
Termination does not affect rights and obligations that arose before termination.
Clauses concerning ownership, privacy, confidentiality, evidence, liability, indemnity, disputes and other provisions intended to survive will continue after termination.
29. No warranties
To the maximum extent permitted by law, the Service is provided “as is” and “as available”.
We do not warrant that:
- the Service will be uninterrupted, error-free or secure;
- every PDF will render correctly;
- emails or authentication codes will be delivered;
- a signer is who they claim to be;
- a document is legally effective;
- a signature will be accepted by a court, regulator or third party;
- the audit trail will be given any particular evidential weight;
- data will never be lost or corrupted;
- the Service will meet a particular legal or business requirement; or
- every defect will be corrected.
Any warranties or terms implied by law are excluded only to the extent that exclusion is legally permitted.
30. User responsibility for backups and verification
You must independently:
- retain the unsigned original;
- download the completed PDF;
- download the audit certificate;
- verify that all pages and signatures appear correctly;
- preserve the records for the required legal period; and
- maintain appropriate backups.
You should not complete, transfer money, release goods or take irreversible action solely because the Service reports that a document has been signed.
For significant transactions, you should independently contact the signer using trusted contact details.
31. Limitation of liability
Nothing in these Terms excludes or limits liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- deliberate unlawful conduct; or
- any liability that cannot legally be excluded or limited.
Subject to the paragraph above, the Operator will not be liable for:
- indirect or consequential loss;
- loss of profits, revenue, business or opportunity;
- loss of anticipated savings;
- loss of goodwill or reputation;
- loss arising from a document being invalid or unenforceable;
- loss arising from unauthorised or mistaken signing;
- loss caused by an incorrect recipient or compromised email account;
- loss of or damage to data where you failed to maintain an independent copy;
- loss caused by third-party systems outside our reasonable control;
- decisions made in reliance on a signature status or audit record; or
- regulatory penalties resulting from your documents, instructions or legal obligations.
Subject to the exclusions above, our total aggregate liability arising from or connected with the free Service, whether in contract, tort, negligence, misrepresentation, breach of statutory duty or otherwise, will not exceed £100.
This liability cap applies only to the extent permitted by applicable law.
Nothing in these Terms limits the statutory rights of an individual whose rights cannot lawfully be limited by contract.
32. Indemnity
To the extent permitted by law, you will indemnify the Operator against third-party claims, reasonable legal costs, losses and liabilities arising from:
- your User Content;
- your breach of these Terms;
- your unlawful or unauthorised processing of personal data;
- your use of the Service for a restricted document;
- your failure to obtain required consent or authority;
- an allegation that your document infringes another person’s rights;
- fraud, impersonation, coercion or misleading conduct by you or your authorised users; or
- your violation of sanctions, export controls or applicable law.
This indemnity does not apply to the extent that the claim was caused by the Operator’s own breach, negligence or unlawful conduct.
33. Changes to these Terms
We may update these Terms to reflect:
- changes to the Service;
- legal or regulatory requirements;
- security risks;
- new features; or
- the introduction of paid plans.
We will give reasonable notice of material changes where practicable.
A change will not retrospectively alter the legal effect of a document completed before the change.
Where a change materially affects your rights, we may require you to accept the updated Terms before continuing to use the Service.
34. Governing law and jurisdiction
These Terms and any non-contractual obligations connected with them are governed by the law of England and Wales.
The courts of England and Wales will have exclusive jurisdiction over disputes between the Operator and an account-holding User.
This clause does not exclude any mandatory law or jurisdictional right that cannot lawfully be excluded.
The governing law of a document signed through the Service is determined by that document and applicable law, not by these Terms.
35. Notices
We may send notices to the email address registered to your account or display notices within the Service.
You must keep your contact details current.
Legal notices to the Operator should be sent to:
Email: support@penfreesig.com
An email is not treated as formal service of court proceedings unless applicable procedural rules permit it.
36. Assignment
You may not assign or transfer your rights under these Terms without our written consent.
We may transfer these Terms and operation of the Service to another person or organisation, provided that the transfer does not materially reduce your existing rights and any required data-protection steps are completed.
37. Entire agreement
These Terms, the Privacy Notice, the Data Processing Schedule, any applicable transfer addendum and any plan-specific terms form the entire agreement concerning the Service.
They do not replace or modify the terms of documents signed between Users and recipients.
38. Severability
If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary or, where modification is not possible, severed.
The remaining provisions will continue in effect.
39. Waiver
A failure or delay in enforcing a right is not a waiver of that right.
A waiver is effective only if made in writing by the party granting it.
40. Third-party rights
Except where these Terms expressly state otherwise, a person who is not a party to these Terms has no right to enforce them.
This clause does not affect rights that a recipient or data subject has independently under applicable law.
41. Contact and complaints
Questions, complaints or reports of misuse should be sent to:
General support: support@penfreesig.com
Privacy enquiries: support@penfreesig.com
Security reports: support@penfreesig.com
Legal notices: support@penfreesig.com
SCHEDULE 1 — DATA PROCESSING TERMS
1. Application
This Schedule applies where the Operator processes personal data on behalf of a User in connection with documents, recipients and signing transactions.
If there is a conflict between this Schedule and the main Terms concerning personal-data processing, this Schedule prevails.
2. Definitions
“Applicable Data Protection Law” means data-protection and privacy law applicable to the relevant processing, including, where applicable, the UK GDPR, Data Protection Act 2018, EU GDPR and equivalent local laws.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach” and “Processing” have the meanings given by Applicable Data Protection Law.
“Subprocessor” means another processor appointed by the Operator to process personal data on the User’s behalf.
3. Roles
For personal data contained in User documents and recipient instructions:
- the User is the Controller or is authorised to act for the Controller; and
- the Operator is the Processor.
For account administration, service security, misuse prevention, legal compliance and the Operator’s own business records, the Operator may act as an independent Controller.
4. Processing details
Subject matter: Provision of document-upload, electronic-signature, authentication, storage, delivery and audit services.
Duration: From submission of the personal data until deletion in accordance with the User’s instructions, the applicable retention schedule or termination of the Service.
Nature of processing: Collection, receipt, storage, organisation, display, transmission, authentication, signing, PDF generation, hashing, logging, backup, retrieval and deletion.
Purpose: Providing, securing and supporting the Service in accordance with the User’s instructions.
Data subjects may include:
- Users and authorised account members;
- document issuers;
- recipients and signers;
- witnesses where a future approved feature supports them;
- representatives, employees, contractors and customers of Users; and
- persons identified in uploaded documents.
Personal-data categories may include:
- names and contact information;
- professional and organisational information;
- signatures and signing representations;
- document contents;
- IP addresses and device information;
- authentication and access records;
- timestamps and audit events; and
- transaction identifiers and document hashes.
The User must not submit restricted sensitive information except where expressly permitted.
5. Documented instructions
The Operator will process personal data only:
- on the User’s documented instructions;
- as necessary to provide the Service;
- as stated in these Terms; or
- where required by applicable law.
Creating an envelope, entering recipient details, sending an invitation, requesting generation of a signed document, setting retention options and deleting a document constitute documented instructions.
If we believe an instruction infringes Applicable Data Protection Law, we may notify the User and suspend the relevant processing.
6. User obligations
The User must:
- comply with Applicable Data Protection Law;
- have a lawful basis for the processing;
- provide required privacy information;
- obtain any required consent;
- respond to Data Subject requests;
- ensure that its instructions are lawful;
- minimise personal data;
- avoid restricted sensitive information;
- maintain accurate recipient information; and
- assess whether the Service provides security appropriate to the risk.
7. Confidentiality
The Operator will ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations.
Access will be limited to persons who reasonably require it for operation, security, legal compliance or support.
8. Security
Taking into account the nature of the processing, available technology, implementation costs and relevant risks, the Operator will maintain reasonable technical and organisational measures designed to protect personal data.
Measures may include:
- encryption in transit;
- encryption at rest where supported by the provider;
- access controls;
- authentication and account-security controls;
- private document storage;
- expiring document links;
- hashing of signing tokens;
- logging and monitoring;
- backups;
- vulnerability and dependency management;
- incident-response procedures; and
- separation of customer records.
The User acknowledges that no security measure eliminates all risk.
9. Subprocessors
The User gives general written authorisation for the Operator to appoint Subprocessors.
The current Subprocessor list is available in the Pen Free Signatures Privacy Notice.
We will require Subprocessors to provide data-protection obligations appropriate to the services they perform.
Where required by Applicable Data Protection Law, we will give notice of a material new Subprocessor and allow the User a reasonable opportunity to object on genuine data-protection grounds.
If the parties cannot resolve a valid objection, either party may terminate the affected Service.
10. International transfers
The User authorises processing in the countries identified in the Privacy Notice and Subprocessor list.
Where a restricted international transfer requires a recognised safeguard, the parties agree to use the applicable mechanism identified by the Operator, which may include:
- an adequacy decision or regulation;
- an approved data-privacy framework;
- standard contractual clauses;
- the UK International Data Transfer Agreement;
- the UK Addendum to standard contractual clauses; or
- another legally recognised transfer mechanism.
The Operator will make applicable transfer terms available where required.
11. Data-subject rights
Taking into account the nature of processing, the Operator will provide reasonable assistance to enable the User to respond to requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- portability; and
- rights relating to automated decision-making.
Where a request relates to data controlled by the User, we may direct the requester to the User.
We will not independently respond on the User’s behalf unless authorised or legally required.
12. Personal-data breaches
The Operator will notify the User without undue delay after becoming aware of a Personal Data Breach affecting personal data processed on the User’s behalf.
Where reasonably available, the notice will include:
- the nature of the breach;
- affected data and persons;
- likely consequences;
- measures taken or proposed;
- available mitigation steps; and
- a contact point.
The Operator’s notice is not an admission of fault or liability.
The User remains responsible for determining whether notification to regulators or individuals is required.
13. Compliance assistance
Taking into account the nature of processing and information available, the Operator will provide reasonable assistance concerning:
- processing security;
- breach notification;
- data-protection impact assessments;
- prior consultation with regulators; and
- demonstrating compliance.
Extensive or bespoke assistance may be subject to reasonable charges once paid plans are introduced, unless the assistance is required because of our breach.
14. Deletion and return
During the account term, the User may download supported records and request deletion through available controls.
Following termination, we will delete or return personal data in accordance with the User’s choice where reasonably practicable, unless retention is required by law or reasonably necessary for legal claims, fraud prevention or security.
Data in backups may remain protected and beyond ordinary use until the relevant backup cycle expires.
15. Information and audits
We will make available information reasonably necessary to demonstrate compliance with this Schedule.
Where legally required, we will permit a reasonable audit by the User or an independent auditor, subject to:
- reasonable prior written notice;
- confidentiality obligations;
- avoidance of disruption;
- protection of other users and systems;
- use of existing independent reports where sufficient; and
- the User paying reasonable costs unless the audit identifies a material breach by the Operator.
Audits may not include access to another user’s information, penetration testing or access to systems that would create security risk without separate written agreement.
16. Liability and rights
Liability between the Operator and User under this Schedule is subject to the liability provisions in the main Terms, to the extent permitted by Applicable Data Protection Law.
Nothing in these Terms limits the rights of a Data Subject or the powers of a regulator.