Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between MYPAYLIST LTD, a company registered in England and Wales (Company No. 16935308) ("Paylist", "we", "us" or "our"), and the customer identified in the applicable Paylist subscription, order form or account ("Customer", "you" or "your").

This DPA applies where and to the extent that Paylist processes Personal Data on behalf of the Customer as a Processor within the meaning of applicable Data Protection Legislation.

This DPA is intended to satisfy the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR") and applicable provisions of the Data Protection Act 2018 and related UK data-protection legislation.

1. Definitions

In this DPA:

"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and any applicable legislation, regulations or binding regulatory requirements relating to the processing of personal data in force in the United Kingdom from time to time.

"Personal Data" means personal data processed by Paylist on behalf of the Customer under the Agreement.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and other terms relating to the processing of personal data have the meanings given to them under applicable Data Protection Legislation.

"Agreement" means the agreement between Paylist and the Customer governing the Customer's use of the Paylist Services, including any applicable terms of service, subscription agreement or order form.

"Services" means the Paylist software, website and related services provided by Paylist under the Agreement.

"Sub-processor" means any third party engaged by Paylist to process Personal Data on behalf of the Customer.

2. Scope and roles of the parties

2.1 The Customer is the Controller of Customer Personal Data covered by this DPA.

2.2 Paylist is the Processor of Customer Personal Data where Paylist processes that data solely on behalf of the Customer and in accordance with the Customer's documented instructions.

2.3 This DPA applies only to processing where Paylist acts as Processor.

2.4 Paylist may act as an independent Controller for certain processing activities where Paylist determines the purposes and means of processing. Such processing is governed by Paylist's Privacy Policy and applicable provisions of the Agreement rather than by this DPA.

2.5 In particular, where a Customer or Data Subject actively chooses Paylist's directory or bank-account visibility functionality, including changing the bank-account visibility setting from the default Private setting to Public, Paylist may process the relevant information for its own purposes in providing and administering that functionality. Such processing is outside the scope of this DPA where Paylist determines the purposes and means of that processing.

2.6 Nothing in this DPA transfers ownership of Customer Personal Data to Paylist.

3. Customer's responsibilities

3.1 The Customer is responsible for:

  1. determining the purposes and means of processing Customer Personal Data;
  2. ensuring that its processing of Customer Personal Data complies with Data Protection Legislation;
  3. identifying and establishing an appropriate lawful basis for processing Customer Personal Data;
  4. providing any required privacy notices to Data Subjects;
  5. ensuring that it has all necessary rights, permissions and lawful authority to provide Customer Personal Data to Paylist;
  6. providing Paylist with lawful and documented instructions for processing Customer Personal Data;
  7. ensuring that the instructions given to Paylist are lawful and do not require Paylist to breach Data Protection Legislation; and
  8. responding to Data Subjects where the Customer is responsible for doing so.

3.2 Where the Customer provides Paylist with personal data relating to another person, including a customer, supplier, employee, company officer, authorised signatory or business contact, the Customer is responsible for ensuring that it is entitled to provide that information to Paylist and that any required transparency information has been provided.

4. Paylist's processing instructions

4.1 Paylist will process Customer Personal Data only:

  1. to provide and support the Services;
  2. in accordance with the Customer's documented instructions;
  3. as necessary to comply with applicable UK law; or
  4. as otherwise permitted by this DPA and the Agreement.

4.2 The Customer's instructions are documented by this DPA, the Agreement, the Customer's configuration of the Services and any further written instructions accepted by Paylist.

4.3 Paylist will inform the Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Legislation.

4.4 If Paylist is required by UK law to process Personal Data other than in accordance with the Customer's instructions, Paylist will, unless prohibited by law, inform the Customer of that legal requirement before carrying out the relevant processing.

5. Confidentiality

5.1 Paylist will ensure that all persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.

5.2 Paylist will ensure that access to Customer Personal Data is limited to persons who require access for the purpose of providing, securing, maintaining or supporting the Services.

5.3 Paylist will take reasonable steps to ensure that personnel with access to Customer Personal Data understand and comply with applicable confidentiality and security requirements.

6. Security of processing

6.1 Paylist will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

6.2 Taking into account the nature of the processing and the risks involved, Paylist's security measures may include:

  1. encryption of Personal Data in transit using TLS or equivalent technology;
  2. encryption of sensitive Personal Data at rest using appropriate industry-standard encryption;
  3. role-based access controls;
  4. least-privilege access principles;
  5. authentication and session-management controls;
  6. appropriate password and credential controls;
  7. logging and monitoring of administrative activity and access to sensitive resources;
  8. security testing and reviews appropriate to the nature and scale of the Services;
  9. measures designed to maintain the confidentiality, integrity, availability and resilience of processing systems;
  10. backup and recovery measures appropriate to the Services;
  11. measures designed to detect and respond to security incidents; and
  12. procedures for securely deleting or disposing of Personal Data when it is no longer required.

6.3 Paylist will periodically review the effectiveness of its technical and organisational measures and may update them where reasonably necessary to maintain an appropriate level of security.

7. Personal data breaches

7.1 Paylist will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 To the extent reasonably available, Paylist's notification will include:

  1. the nature of the breach;
  2. the categories and approximate number of Data Subjects affected;
  3. the categories and approximate amount of Personal Data affected;
  4. the likely consequences of the breach; and
  5. the measures taken or proposed to address and mitigate the breach.

7.3 Paylist will provide reasonable assistance to the Customer in investigating, mitigating and responding to the breach.

7.4 The Customer remains responsible for determining whether it is required to notify the Information Commissioner's Office or affected Data Subjects.

7.5 Nothing in this clause prevents Paylist from notifying a competent authority where Paylist is independently required to do so by law.

8. Data subject rights

8.1 Taking into account the nature of the processing, Paylist will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under applicable Data Protection Legislation.

8.2 Where Paylist receives a request from a Data Subject relating to Customer Personal Data and Paylist is acting as Processor, Paylist will, where reasonably possible, refer the request to the Customer.

8.3 Paylist will not respond substantively to the Data Subject except:

  1. on the Customer's documented instructions;
  2. where required by applicable law; or
  3. where necessary to establish, exercise or defend Paylist's own legal rights.

8.4 Where reasonably requested, Paylist will provide appropriate technical assistance to enable the Customer to access, correct, export or delete Customer Personal Data using the functionality available through the Services.

9. Assistance with compliance

9.1 Taking into account the nature of the processing and the information available to Paylist, Paylist will provide reasonable assistance to the Customer in relation to:

  1. its obligations under Article 32 of the UK GDPR concerning security of processing;
  2. notification of Personal Data Breaches;
  3. communications with Data Subjects following a Personal Data Breach;
  4. data protection impact assessments;
  5. consultation with the ICO or another competent supervisory authority where required; and
  6. other reasonable compliance obligations directly arising from Paylist's processing as Processor.

9.2 The Customer will reimburse Paylist for reasonable costs incurred in providing assistance that is materially outside the ordinary operation of the Services or that is required as a result of the Customer's specific processing instructions.

10. Sub-processors

10.1 The Customer gives Paylist general written authorisation to appoint Sub-processors for the processing of Customer Personal Data where necessary to provide the Services.

10.2 Paylist's current principal Sub-processors are:

Sub-processorPurpose
SupabaseHosting, database, authentication and file storage
StripePayment processing and subscription management
ResendTransactional email delivery
UmamiCookieless analytics
XeroAccounting integration where connected by Customer
Intuit QuickBooksAccounting integration where connected by Customer
SageAccounting integration where connected by Customer
FreeAgentAccounting integration where connected by Customer

10.3 The Customer authorises Paylist to use the Sub-processors listed above from the effective date of this DPA.

10.4 Paylist may appoint or replace Sub-processors where reasonably necessary to provide or improve the Services.

10.5 Paylist will notify the Customer of material changes to its Sub-processors in accordance with the Agreement or by another reasonable written means.

10.6 Where required by applicable Data Protection Legislation, the Customer may object to the appointment of a new Sub-processor on reasonable data-protection grounds.

10.7 If the Customer objects to a proposed Sub-processor and the parties cannot reasonably resolve the objection, either party may terminate the affected Services in accordance with the Agreement.

10.8 Paylist will enter into a written agreement with each Sub-processor requiring protections for Customer Personal Data that are materially equivalent to those required of Paylist under this DPA.

10.9 Paylist remains responsible for the acts and omissions of its Sub-processors to the extent required by applicable Data Protection Legislation.

11. International transfers

11.1 Paylist will not transfer Customer Personal Data outside the United Kingdom except where permitted by applicable Data Protection Legislation.

11.2 Where a restricted transfer requires an appropriate safeguard, Paylist will implement an applicable lawful transfer mechanism, which may include:

  1. UK adequacy regulations;
  2. the UK International Data Transfer Agreement;
  3. the UK International Data Transfer Addendum to EU Standard Contractual Clauses; or
  4. another lawful transfer mechanism recognised under applicable Data Protection Legislation.

11.3 Where Paylist uses a Sub-processor that processes Customer Personal Data outside the United Kingdom, Paylist will take appropriate steps to ensure that the relevant transfer is subject to an appropriate legal safeguard where required.

11.4 The Customer may request reasonable information about the safeguards applicable to international transfers relevant to its use of the Services.

12. Data protection impact assessments

12.1 Taking into account the nature of the processing and the information available to Paylist, Paylist will provide reasonable assistance to the Customer where the Customer is required to carry out a Data Protection Impact Assessment in relation to processing performed through the Services.

12.2 The Customer remains responsible for determining whether a DPIA is required and for carrying it out.

12.3 Paylist may provide information about its security measures, processing activities, Sub-processors and other relevant matters reasonably necessary for the Customer's DPIA.

13. Records and information

13.1 Paylist will maintain information reasonably necessary to demonstrate compliance with its obligations under this DPA and applicable Data Protection Legislation.

13.2 On reasonable request, Paylist will make available information necessary to demonstrate compliance with Article 28 obligations applicable to processors.

13.3 Information may include relevant security documentation, descriptions of technical and organisational measures, Sub-processor information and other compliance documentation reasonably available to Paylist.

14. Audits and inspections

14.1 The Customer may, subject to the restrictions in this clause, request information or carry out an audit of Paylist's processing of Customer Personal Data where necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.

14.2 The Customer will first request relevant compliance information from Paylist.

14.3 Where that information is insufficient to address a reasonable compliance concern, the Customer may request a further audit.

14.4 Audits must:

  1. be carried out on reasonable notice;
  2. take place during normal business hours;
  3. be conducted in a manner that does not unreasonably disrupt Paylist's operations or compromise the security or confidentiality of other customers' information;
  4. be limited to processing relevant to the Customer; and
  5. be subject to appropriate confidentiality obligations.

14.5 The Customer will bear its own costs of an audit unless the audit identifies a material breach of this DPA by Paylist, in which case Paylist will bear its reasonable costs of remediation.

14.6 Where Paylist provides an independent audit report, certification, security assessment or equivalent documentation that reasonably demonstrates compliance with the relevant obligations, the parties will consider that information in determining whether a further audit is necessary.

15. Return and deletion of Personal Data

15.1 On termination or expiry of the Services, the Customer may request that Paylist:

  1. return Customer Personal Data to the Customer; or
  2. securely delete Customer Personal Data,

subject to applicable legal requirements.

15.2 Unless otherwise agreed, the Customer must make any request for return of data within 30 days of termination.

15.3 Following the applicable return period, Paylist will delete or anonymise Customer Personal Data unless:

  1. applicable law requires its continued retention; or
  2. the data is contained in routine backups that cannot reasonably be deleted immediately.

15.4 Where Personal Data remains in backups, Paylist will maintain appropriate safeguards and will not restore or otherwise use that data except where necessary for disaster recovery or as required by law.

15.5 Personal Data retained because of a legal obligation will remain subject to the confidentiality and security obligations in this DPA for as long as it is retained.

16. Data minimisation

16.1 The Customer should only provide Paylist with Personal Data that is reasonably necessary for the Customer's use of the Services.

16.2 Paylist will not knowingly require the Customer to provide Personal Data that is unnecessary for the relevant Service.

16.3 The Customer should not use the Services to process special-category personal data or criminal-offence data unless the relevant functionality expressly permits it and the Customer has established all necessary legal conditions for that processing.

17. Security incidents and cooperation

17.1 The parties will cooperate reasonably in relation to security incidents affecting Customer Personal Data.

17.2 The Customer will provide Paylist with relevant information reasonably required to investigate and respond to a security incident where the Customer becomes aware of an incident affecting the Services.

17.3 Neither party will make public statements concerning a security incident involving the other party without first consulting the other party where reasonably practicable, except where disclosure is required by law or a competent authority.

18. Confidentiality of the DPA

The terms of this DPA and information exchanged between the parties concerning security arrangements, audits, incidents or processing activities are confidential, except where disclosure is required by law or reasonably necessary to demonstrate compliance with Data Protection Legislation.

19. Liability

19.1 The liability of each party under this DPA is subject to the liability provisions and limitations contained in the Agreement, except to the extent that applicable Data Protection Legislation prevents a limitation of liability.

19.2 Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited under applicable law.

20. Term and termination

20.1 This DPA comes into effect when the Customer begins using the Services and remains in force for so long as Paylist processes Customer Personal Data as Processor.

20.2 If the Agreement is terminated, this DPA will continue to apply for so long as Paylist retains or processes Customer Personal Data.

20.3 Provisions relating to confidentiality, security, deletion, liability and any other provisions intended by their nature to survive termination will continue to apply after termination for so long as relevant.

21. Governing law

This DPA and any non-contractual obligations arising from it are governed by the laws of England and Wales.

The courts of England and Wales will have exclusive jurisdiction over disputes arising out of or in connection with this DPA, subject to any mandatory rights or jurisdiction applicable under Data Protection Legislation.

Schedule 1 — Details of Processing

1. Subject matter

The processing of Personal Data necessary for Paylist to provide the Services to the Customer, including account administration, storage, organisation, retrieval, synchronisation, verification, communications, integrations and other functionality configured or requested by the Customer.

2. Duration

Personal Data will be processed for the duration of the Customer's use of the Services and for any additional period reasonably necessary for deletion, backup management, legal obligations, dispute resolution or other purposes permitted under this DPA.

3. Nature and purpose of processing

Processing may include:

  • collection;
  • recording;
  • organisation;
  • structuring;
  • storage;
  • retrieval;
  • consultation;
  • use;
  • transmission;
  • synchronisation;
  • disclosure where instructed or authorised by the Customer;
  • restriction;
  • deletion; and
  • other processing necessary to provide the Services.

The purposes may include:

  • providing the Services;
  • maintaining Customer accounts;
  • storing Customer information;
  • synchronising information with connected accounting platforms;
  • providing requested integrations;
  • managing contacts and business information;
  • providing verification functionality;
  • providing reporting and administration functionality;
  • maintaining security;
  • detecting fraud and abuse;
  • providing customer support; and
  • maintaining and improving the Services where Paylist is acting as Processor.

4. Types of Personal Data

Depending on how the Customer uses the Services, Personal Data may include:

  • names;
  • business contact details;
  • email addresses;
  • telephone numbers;
  • postal addresses;
  • job titles;
  • company officer information;
  • authorised signatory information;
  • customer and supplier contact information;
  • bank account names;
  • sort codes;
  • account numbers;
  • IBANs;
  • BIC/SWIFT information;
  • transaction and accounting information;
  • identification information where required for verification;
  • information contained in connected accounting systems;
  • authentication and account information;
  • technical information; and
  • other Personal Data submitted by the Customer through the Services.

The Customer should not provide special-category Personal Data unless the relevant Service expressly supports such processing and the Customer has established an appropriate lawful basis and condition for doing so.

5. Categories of Data Subjects

Depending on how the Customer uses the Services, Data Subjects may include:

  • the Customer's employees;
  • customers;
  • suppliers;
  • contractors;
  • company officers;
  • directors;
  • shareholders where relevant;
  • authorised signatories;
  • business contacts;
  • customers' customers;
  • sole traders;
  • representatives of businesses;
  • Paylist account users; and
  • other individuals whose Personal Data the Customer lawfully provides to Paylist.

6. Processing operations

Paylist may perform the following operations on Customer Personal Data:

  • storing and retrieving information;
  • displaying information to authorised Customer users;
  • synchronising information with connected third-party services at the Customer's direction;
  • sending transactional communications;
  • performing administrative operations;
  • providing customer support;
  • maintaining backups;
  • monitoring and securing the Services;
  • detecting and preventing fraud and abuse;
  • responding to Customer instructions; and
  • deleting or returning information at the end of the Services.

Schedule 2 — Technical and Organisational Measures

Paylist's technical and organisational measures include, as appropriate to the nature and risks of processing:

Access control

  • role-based access controls;
  • least-privilege principles;
  • restricted administrative access;
  • authentication and session-management controls;
  • controls governing access to production systems; and
  • procedures for removing access when no longer required.

Encryption

  • encryption of Personal Data in transit using TLS or equivalent;
  • encryption of sensitive Personal Data at rest;
  • encryption of relevant authentication credentials and integration tokens; and
  • appropriate protection of encryption keys.

Monitoring and logging

  • logging of relevant administrative activity;
  • monitoring of security events;
  • logging of verification activity where appropriate;
  • monitoring for suspicious or unauthorised activity; and
  • investigation procedures for security incidents.

Infrastructure security

  • appropriately secured hosting infrastructure;
  • access controls for databases and storage;
  • network and application security measures;
  • backup and recovery procedures;
  • system maintenance and security updates; and
  • procedures for managing vulnerabilities.

Organisational security

  • confidentiality obligations for personnel;
  • access limited according to business need;
  • security policies and procedures appropriate to the Services;
  • security reviews and testing appropriate to the risks;
  • incident-response procedures; and
  • data retention and deletion procedures.

Availability and resilience

Paylist maintains measures designed to support the availability and resilience of the Services and the ability to restore access to Personal Data following an incident, taking into account the nature of the Services and the risks involved.

Schedule 3 — Approved Sub-processors

The Customer authorises the following Sub-processors:

Sub-processorProcessing activity
SupabaseHosting, database, authentication and file storage
StripePayment processing and subscription management
ResendTransactional email delivery
UmamiCookieless analytics
XeroAccounting integration where connected by Customer
Intuit QuickBooksAccounting integration where connected by Customer
SageAccounting integration where connected by Customer
FreeAgentAccounting integration where connected by Customer

Paylist may update this list in accordance with clause 10 of this DPA.

Schedule 4 — Customer Authorisation

By accepting the Agreement or continuing to use the Services after this DPA becomes effective, the Customer confirms that:

  • it has read and understood this DPA;
  • it authorises Paylist to process Customer Personal Data as described in this DPA;
  • it provides general written authorisation for the Sub-processors listed in Schedule 3;
  • it authorises Paylist to appoint further Sub-processors in accordance with clause 10; and
  • it will provide Paylist with lawful and documented instructions for processing Customer Personal Data.

This DPA forms part of the Agreement between Paylist and the Customer.