Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between MYPAYLIST LTD, a company registered in England and Wales (Company No. 16935308) ("Paylist", "we", "us" or "our"), and the customer identified in the applicable Paylist subscription, order form or account ("Customer", "you" or "your").
This DPA applies where and to the extent that Paylist processes Personal Data on behalf of the Customer as a Processor within the meaning of applicable Data Protection Legislation.
This DPA is intended to satisfy the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR") and applicable provisions of the Data Protection Act 2018 and related UK data-protection legislation.
In this DPA:
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and any applicable legislation, regulations or binding regulatory requirements relating to the processing of personal data in force in the United Kingdom from time to time.
"Personal Data" means personal data processed by Paylist on behalf of the Customer under the Agreement.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and other terms relating to the processing of personal data have the meanings given to them under applicable Data Protection Legislation.
"Agreement" means the agreement between Paylist and the Customer governing the Customer's use of the Paylist Services, including any applicable terms of service, subscription agreement or order form.
"Services" means the Paylist software, website and related services provided by Paylist under the Agreement.
"Sub-processor" means any third party engaged by Paylist to process Personal Data on behalf of the Customer.
2.1 The Customer is the Controller of Customer Personal Data covered by this DPA.
2.2 Paylist is the Processor of Customer Personal Data where Paylist processes that data solely on behalf of the Customer and in accordance with the Customer's documented instructions.
2.3 This DPA applies only to processing where Paylist acts as Processor.
2.4 Paylist may act as an independent Controller for certain processing activities where Paylist determines the purposes and means of processing. Such processing is governed by Paylist's Privacy Policy and applicable provisions of the Agreement rather than by this DPA.
2.5 In particular, where a Customer or Data Subject actively chooses Paylist's directory or bank-account visibility functionality, including changing the bank-account visibility setting from the default Private setting to Public, Paylist may process the relevant information for its own purposes in providing and administering that functionality. Such processing is outside the scope of this DPA where Paylist determines the purposes and means of that processing.
2.6 Nothing in this DPA transfers ownership of Customer Personal Data to Paylist.
3.1 The Customer is responsible for:
3.2 Where the Customer provides Paylist with personal data relating to another person, including a customer, supplier, employee, company officer, authorised signatory or business contact, the Customer is responsible for ensuring that it is entitled to provide that information to Paylist and that any required transparency information has been provided.
4.1 Paylist will process Customer Personal Data only:
4.2 The Customer's instructions are documented by this DPA, the Agreement, the Customer's configuration of the Services and any further written instructions accepted by Paylist.
4.3 Paylist will inform the Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Legislation.
4.4 If Paylist is required by UK law to process Personal Data other than in accordance with the Customer's instructions, Paylist will, unless prohibited by law, inform the Customer of that legal requirement before carrying out the relevant processing.
5.1 Paylist will ensure that all persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
5.2 Paylist will ensure that access to Customer Personal Data is limited to persons who require access for the purpose of providing, securing, maintaining or supporting the Services.
5.3 Paylist will take reasonable steps to ensure that personnel with access to Customer Personal Data understand and comply with applicable confidentiality and security requirements.
6.1 Paylist will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
6.2 Taking into account the nature of the processing and the risks involved, Paylist's security measures may include:
6.3 Paylist will periodically review the effectiveness of its technical and organisational measures and may update them where reasonably necessary to maintain an appropriate level of security.
7.1 Paylist will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 To the extent reasonably available, Paylist's notification will include:
7.3 Paylist will provide reasonable assistance to the Customer in investigating, mitigating and responding to the breach.
7.4 The Customer remains responsible for determining whether it is required to notify the Information Commissioner's Office or affected Data Subjects.
7.5 Nothing in this clause prevents Paylist from notifying a competent authority where Paylist is independently required to do so by law.
8.1 Taking into account the nature of the processing, Paylist will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under applicable Data Protection Legislation.
8.2 Where Paylist receives a request from a Data Subject relating to Customer Personal Data and Paylist is acting as Processor, Paylist will, where reasonably possible, refer the request to the Customer.
8.3 Paylist will not respond substantively to the Data Subject except:
8.4 Where reasonably requested, Paylist will provide appropriate technical assistance to enable the Customer to access, correct, export or delete Customer Personal Data using the functionality available through the Services.
9.1 Taking into account the nature of the processing and the information available to Paylist, Paylist will provide reasonable assistance to the Customer in relation to:
9.2 The Customer will reimburse Paylist for reasonable costs incurred in providing assistance that is materially outside the ordinary operation of the Services or that is required as a result of the Customer's specific processing instructions.
10.1 The Customer gives Paylist general written authorisation to appoint Sub-processors for the processing of Customer Personal Data where necessary to provide the Services.
10.2 Paylist's current principal Sub-processors are:
| Sub-processor | Purpose |
|---|---|
| Supabase | Hosting, database, authentication and file storage |
| Stripe | Payment processing and subscription management |
| Resend | Transactional email delivery |
| Umami | Cookieless analytics |
| Xero | Accounting integration where connected by Customer |
| Intuit QuickBooks | Accounting integration where connected by Customer |
| Sage | Accounting integration where connected by Customer |
| FreeAgent | Accounting integration where connected by Customer |
10.3 The Customer authorises Paylist to use the Sub-processors listed above from the effective date of this DPA.
10.4 Paylist may appoint or replace Sub-processors where reasonably necessary to provide or improve the Services.
10.5 Paylist will notify the Customer of material changes to its Sub-processors in accordance with the Agreement or by another reasonable written means.
10.6 Where required by applicable Data Protection Legislation, the Customer may object to the appointment of a new Sub-processor on reasonable data-protection grounds.
10.7 If the Customer objects to a proposed Sub-processor and the parties cannot reasonably resolve the objection, either party may terminate the affected Services in accordance with the Agreement.
10.8 Paylist will enter into a written agreement with each Sub-processor requiring protections for Customer Personal Data that are materially equivalent to those required of Paylist under this DPA.
10.9 Paylist remains responsible for the acts and omissions of its Sub-processors to the extent required by applicable Data Protection Legislation.
11.1 Paylist will not transfer Customer Personal Data outside the United Kingdom except where permitted by applicable Data Protection Legislation.
11.2 Where a restricted transfer requires an appropriate safeguard, Paylist will implement an applicable lawful transfer mechanism, which may include:
11.3 Where Paylist uses a Sub-processor that processes Customer Personal Data outside the United Kingdom, Paylist will take appropriate steps to ensure that the relevant transfer is subject to an appropriate legal safeguard where required.
11.4 The Customer may request reasonable information about the safeguards applicable to international transfers relevant to its use of the Services.
12.1 Taking into account the nature of the processing and the information available to Paylist, Paylist will provide reasonable assistance to the Customer where the Customer is required to carry out a Data Protection Impact Assessment in relation to processing performed through the Services.
12.2 The Customer remains responsible for determining whether a DPIA is required and for carrying it out.
12.3 Paylist may provide information about its security measures, processing activities, Sub-processors and other relevant matters reasonably necessary for the Customer's DPIA.
13.1 Paylist will maintain information reasonably necessary to demonstrate compliance with its obligations under this DPA and applicable Data Protection Legislation.
13.2 On reasonable request, Paylist will make available information necessary to demonstrate compliance with Article 28 obligations applicable to processors.
13.3 Information may include relevant security documentation, descriptions of technical and organisational measures, Sub-processor information and other compliance documentation reasonably available to Paylist.
14.1 The Customer may, subject to the restrictions in this clause, request information or carry out an audit of Paylist's processing of Customer Personal Data where necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.
14.2 The Customer will first request relevant compliance information from Paylist.
14.3 Where that information is insufficient to address a reasonable compliance concern, the Customer may request a further audit.
14.4 Audits must:
14.5 The Customer will bear its own costs of an audit unless the audit identifies a material breach of this DPA by Paylist, in which case Paylist will bear its reasonable costs of remediation.
14.6 Where Paylist provides an independent audit report, certification, security assessment or equivalent documentation that reasonably demonstrates compliance with the relevant obligations, the parties will consider that information in determining whether a further audit is necessary.
15.1 On termination or expiry of the Services, the Customer may request that Paylist:
subject to applicable legal requirements.
15.2 Unless otherwise agreed, the Customer must make any request for return of data within 30 days of termination.
15.3 Following the applicable return period, Paylist will delete or anonymise Customer Personal Data unless:
15.4 Where Personal Data remains in backups, Paylist will maintain appropriate safeguards and will not restore or otherwise use that data except where necessary for disaster recovery or as required by law.
15.5 Personal Data retained because of a legal obligation will remain subject to the confidentiality and security obligations in this DPA for as long as it is retained.
16.1 The Customer should only provide Paylist with Personal Data that is reasonably necessary for the Customer's use of the Services.
16.2 Paylist will not knowingly require the Customer to provide Personal Data that is unnecessary for the relevant Service.
16.3 The Customer should not use the Services to process special-category personal data or criminal-offence data unless the relevant functionality expressly permits it and the Customer has established all necessary legal conditions for that processing.
17.1 The parties will cooperate reasonably in relation to security incidents affecting Customer Personal Data.
17.2 The Customer will provide Paylist with relevant information reasonably required to investigate and respond to a security incident where the Customer becomes aware of an incident affecting the Services.
17.3 Neither party will make public statements concerning a security incident involving the other party without first consulting the other party where reasonably practicable, except where disclosure is required by law or a competent authority.
The terms of this DPA and information exchanged between the parties concerning security arrangements, audits, incidents or processing activities are confidential, except where disclosure is required by law or reasonably necessary to demonstrate compliance with Data Protection Legislation.
19.1 The liability of each party under this DPA is subject to the liability provisions and limitations contained in the Agreement, except to the extent that applicable Data Protection Legislation prevents a limitation of liability.
19.2 Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited under applicable law.
20.1 This DPA comes into effect when the Customer begins using the Services and remains in force for so long as Paylist processes Customer Personal Data as Processor.
20.2 If the Agreement is terminated, this DPA will continue to apply for so long as Paylist retains or processes Customer Personal Data.
20.3 Provisions relating to confidentiality, security, deletion, liability and any other provisions intended by their nature to survive termination will continue to apply after termination for so long as relevant.
This DPA and any non-contractual obligations arising from it are governed by the laws of England and Wales.
The courts of England and Wales will have exclusive jurisdiction over disputes arising out of or in connection with this DPA, subject to any mandatory rights or jurisdiction applicable under Data Protection Legislation.
The processing of Personal Data necessary for Paylist to provide the Services to the Customer, including account administration, storage, organisation, retrieval, synchronisation, verification, communications, integrations and other functionality configured or requested by the Customer.
Personal Data will be processed for the duration of the Customer's use of the Services and for any additional period reasonably necessary for deletion, backup management, legal obligations, dispute resolution or other purposes permitted under this DPA.
Processing may include:
The purposes may include:
Depending on how the Customer uses the Services, Personal Data may include:
The Customer should not provide special-category Personal Data unless the relevant Service expressly supports such processing and the Customer has established an appropriate lawful basis and condition for doing so.
Depending on how the Customer uses the Services, Data Subjects may include:
Paylist may perform the following operations on Customer Personal Data:
Paylist's technical and organisational measures include, as appropriate to the nature and risks of processing:
Paylist maintains measures designed to support the availability and resilience of the Services and the ability to restore access to Personal Data following an incident, taking into account the nature of the Services and the risks involved.
The Customer authorises the following Sub-processors:
| Sub-processor | Processing activity |
|---|---|
| Supabase | Hosting, database, authentication and file storage |
| Stripe | Payment processing and subscription management |
| Resend | Transactional email delivery |
| Umami | Cookieless analytics |
| Xero | Accounting integration where connected by Customer |
| Intuit QuickBooks | Accounting integration where connected by Customer |
| Sage | Accounting integration where connected by Customer |
| FreeAgent | Accounting integration where connected by Customer |
Paylist may update this list in accordance with clause 10 of this DPA.
By accepting the Agreement or continuing to use the Services after this DPA becomes effective, the Customer confirms that:
This DPA forms part of the Agreement between Paylist and the Customer.