Padoc

Data Processing Agreement

Last updated: 25 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Insight Automate Ltd (trading as "Padoc", the "Processor") and the customer organisation that uses the Platform (the "Customer" or "Controller") (together, the "Parties"), for the provision of the Padoc platform and services (the "Services").

This DPA reflects the Parties' agreement on the processing of personal data in connection with the Services, in accordance with the UK GDPR and the Data Protection Act 2018 ("Data Protection Laws"). Where the Customer's Service Agreement and this DPA conflict on the subject of data protection, this DPA prevails.


1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the Data Protection Laws.

"Customer Personal Data" means personal data that Padoc processes on behalf of the Customer in providing the Services.

"Sub-processor" means any third party engaged by Padoc to process Customer Personal Data.


2. Roles of the Parties

2.1 The Parties acknowledge that, in respect of Customer Personal Data, the Customer is the controller and Padoc is the processor.

2.2 Each Party will comply with its respective obligations under the Data Protection Laws. The Customer is responsible for ensuring it has a lawful basis for the processing it instructs and for the accuracy, quality and legality of Customer Personal Data and the means by which it was obtained.

2.3 Padoc acts as a controller for limited purposes connected with operating its business — including account administration, security, billing, and improving its products and services (including its algorithms and AI models) — as described in its Privacy Policy. This DPA governs Padoc's processing as a processor on the Customer's behalf.

2.4 Padoc may use Customer Personal Data internally — including in identifiable form — to analyse usage and to research, develop, test, train and improve its products, features, algorithms and models, under appropriate safeguards and access controls. Padoc may also create anonymised and aggregated data from Customer Personal Data; once data has been anonymised so that it no longer identifies any individual, horse or organisation, it is not personal data, and Padoc may use, share, license, sell and publish it, and any insights derived from it, for research, benchmarking, statistical and commercial purposes. Padoc will not share, publish, sell or otherwise disclose Customer Personal Data outside Padoc in a form that identifies any individual horse, person or organisation, except as necessary to provide the Services or as required by law.


3. Scope and instructions

3.1 Padoc will process Customer Personal Data only:

  • to provide, secure, support and improve the Services in accordance with the Service Agreement and this DPA;
  • in accordance with the Customer's documented instructions (including instructions given through the Platform's configuration and use); and
  • as required by law, in which case Padoc will, where legally permitted, inform the Customer.

3.2 Padoc will inform the Customer if, in its opinion, an instruction infringes the Data Protection Laws.

3.3 The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1.


4. Confidentiality

Padoc will ensure that persons authorised to process Customer Personal Data are subject to appropriate obligations of confidentiality and are made aware of the confidential nature of the data.


5. Security

5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Padoc will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A summary of these measures is set out in Annex 2.

5.2 Padoc regularly reviews and, where appropriate, improves these measures, provided it does not materially reduce the overall level of security of the Services.


6. Sub-processors

6.1 The Customer provides general authorisation for Padoc to engage Sub-processors to process Customer Personal Data, subject to this clause.

6.2 Padoc's current Sub-processors are listed in Annex 3 (and in the sub-processor table in our Privacy Policy). Padoc will impose data protection obligations on its Sub-processors that are no less protective than those in this DPA.

6.3 Padoc will give the Customer reasonable notice of any intended addition or replacement of a Sub-processor. The Customer may object on reasonable data protection grounds; the Parties will work in good faith to resolve the objection, and if it cannot be resolved, the Customer may terminate the affected Services in accordance with the Service Agreement.

6.4 Padoc remains responsible for the performance of its Sub-processors' obligations.


7. International transfers

Padoc may transfer Customer Personal Data outside the United Kingdom only where it has put in place an appropriate transfer mechanism required by the Data Protection Laws (for example the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or transfer to a jurisdiction the UK has deemed adequate). Details of relevant transfers are available on request.


8. Assistance to the Customer

8.1 Data subject requests. Taking into account the nature of the processing, Padoc will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. If Padoc receives such a request directly, it will, where permitted, direct the data subject to the Customer and promptly inform the Customer.

8.2 Compliance assistance. Padoc will assist the Customer, taking into account the nature of the processing and the information available to Padoc, in ensuring compliance with its obligations relating to security, personal data breach notification, data protection impact assessments and prior consultation with the supervisory authority.


9. Personal data breaches

Padoc will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the Customer with information reasonably available to it to help the Customer meet its own breach-notification obligations.


10. Deletion and return

On termination or expiry of the Services, Padoc will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless it is required to retain the data by law. Consistent with the Service Agreement, Padoc will retain Customer Personal Data for 90 days following termination to allow for export, after which it will delete or anonymise it. One data export on termination is provided free of charge.


11. Audits and information

Padoc will make available to the Customer information reasonably necessary to demonstrate compliance with this clause and the Data Protection Laws, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality obligations, frequency limits and Padoc's security and operational requirements. Where appropriate, Padoc may satisfy audit requests by providing existing reports or documentation.


12. Liability and precedence

12.1 Each Party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Service Agreement.

12.2 This DPA is incorporated into and forms part of the Service Agreement. Except as expressly modified here, the Service Agreement remains in full force.

12.3 Padoc may assign, transfer or novate this DPA, the Services and Customer Personal Data to an affiliate, or to a buyer or successor in connection with a merger, acquisition, reorganisation, financing or sale of all or part of its business or assets, provided that the recipient is bound by obligations no less protective of Customer Personal Data than those in this DPA.


13. Governing law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.


Annex 1 — Details of processing

  • Subject matter: Provision of the Padoc horse management and performance-analysis Platform and related services.
  • Duration: For the term of the Service Agreement, plus the post-termination retention period described in clause 10.
  • Nature and purpose: Hosting, storage, organisation, transcription, analysis, display and transmission of Customer data to deliver, secure, support and improve the Services, and otherwise as instructed by the Customer through its use of the Services and the Service Agreement. The Services evolve over time and may add or change features.
  • Types of personal data: Such personal data as the Customer chooses to submit to or process through the Services, including, without limitation: names, contact details (email, phone, address), job titles and roles; account and authentication data; IP addresses and device/usage data; audio, voice and other recordings, transcriptions and derived outputs; notes, files and free-text content; and details of owners, contacts and riders recorded by the Customer.
  • Special categories: Not intentionally processed. The Platform records veterinary and health information about horses, not about individuals. The Customer should not submit special category personal data about individuals unless strictly necessary.
  • Categories of data subjects: The Customer's staff and authorised users; horse owners; contacts (such as vets, physios and farriers); riders; and other individuals whose personal data the Customer chooses to record.

Annex 2 — Technical and organisational measures

Padoc maintains measures including:

  • Encryption of personal data in transit (TLS) and at rest;
  • Role-based access controls and the principle of least privilege;
  • Private storage for uploaded files, with time-limited access links;
  • Encryption of sensitive secrets, tokens and API keys;
  • Two-factor authentication for user accounts;
  • Logical separation of each Organisation's data within a multi-tenant architecture;
  • Monitoring, logging and error tracking;
  • Secure software development practices and dependency management;
  • Regular backups; and
  • Use of reputable infrastructure and sub-processors that maintain recognised security standards.

Annex 3 — Sub-processors

Sub-processor Purpose Location
Vercel Application hosting USA
Neon Database hosting USA / EU
Cloudflare (R2) File and object storage Global / EU
Resend Transactional and service emails USA
Sentry Error monitoring and diagnostics EU (Germany)
Trigger.dev Background job processing USA
Anthropic AI assistant (chatbot reasoning) USA
Google AI speech-to-text transcription; Google Sheets export (where enabled) USA / Global
Alibaba Cloud (DashScope) AI speech-to-text transcription Outside UK/EEA
OpenAI AI processing (where used) USA
Slack (Salesforce) Chatbot messaging channel USA
Meta (WhatsApp) Chatbot messaging channel USA / Global
Nango Secure third-party integration and token management USA / EU
Microlink Link preview generation USA

This list is kept under review and may be updated in accordance with clause 6.


Contact

For any matter relating to this DPA, contact privacy@padoc.app.

Insight Automate Ltd (trading as Padoc) Suite 5, 5th Floor, City Reach, Greenwich View Place, London, England, E14 9NN