Data Processing Addendum
This Data Processing Addendum ("DPA") sets out the data-protection terms that apply when Skyie Global InfoTech Ltd processes personal data on behalf of a customer in the course of providing its products and services. It is published as a template; for a signed copy, or to incorporate it into your agreement, please contact us at [email protected].
Last updated 25 August 2026
About this addendum
This DPA applies where a customer (the "Customer") uses a Skyie Global product or service under a written agreement (the "Agreement") and, in doing so, Skyie Global InfoTech Ltd ("Skyie Global", "we", "us") processes personal data on the Customer's behalf. In that situation the Customer is the controller and Skyie Global is the processor. This DPA does not apply to our public marketing website, where we act as a controller in our own right — that processing is described in our Privacy Notice. Where this DPA is incorporated into an Agreement, it forms part of that Agreement; in the event of conflict on data-protection matters, this DPA prevails. This published version is a template and takes legal effect once it is executed by, or otherwise agreed between, the parties.
Definitions
"Data Protection Laws" means all laws relating to data protection and privacy that apply to the processing under the Agreement, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). The terms "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given to them in the UK GDPR. "Sub-processor" means any third party engaged by Skyie Global to process personal data on the Customer's behalf. "UK GDPR" means the retained EU General Data Protection Regulation as it forms part of UK law.
Roles and scope of processing
The parties acknowledge that, for personal data processed under the Agreement, the Customer is the controller and Skyie Global is the processor. The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are determined by the Customer's use of the relevant product and are set out in the Agreement and any order documentation, together with the Annex described below. Skyie Global processes personal data only for the purpose of providing and supporting the product and as otherwise instructed by the Customer in accordance with this DPA.
Skyie Global's obligations as processor
Skyie Global shall: (a) process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we will inform the Customer first, unless the law prohibits this); (b) ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality; (c) implement the technical and organisational measures described below; (d) respect the conditions for engaging sub-processors set out in this DPA; (e) taking into account the nature of the processing, assist the Customer by appropriate measures, insofar as possible, to respond to requests from data subjects exercising their rights; (f) assist the Customer in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 of the UK GDPR), taking into account the information available to us; (g) at the Customer's choice, delete or return all personal data after the end of the provision of the services, and delete existing copies unless storage is required by law; and (h) make available to the Customer the information necessary to demonstrate compliance with Article 28 of the UK GDPR and allow for and contribute to audits as described below.
Confidentiality
Skyie Global shall treat all personal data processed on the Customer's behalf as confidential. We ensure that our personnel who have access to personal data are subject to binding confidentiality obligations and are made aware of the confidential nature of the data and of their responsibilities under this DPA. Access to personal data is limited to those personnel who need it to provide the services.
Security measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Skyie Global implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR. These measures include, as appropriate: encryption of personal data in transit and, where appropriate, at rest; measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems; access controls and the principle of least privilege; logging and monitoring; secure software-development practices; and a process for regularly testing, assessing and evaluating the effectiveness of these measures. A summary of our current measures is available on request.
Sub-processors
The Customer provides a general authorisation for Skyie Global to engage sub-processors to process personal data, subject to the conditions in this section. We maintain a list of the sub-processors used to deliver our products and make it available to the Customer. We impose on each sub-processor data-protection obligations that are no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. We remain liable to the Customer for the performance of each sub-processor's obligations. Where we intend to add or replace a sub-processor, we will give the Customer reasonable prior notice and the opportunity to object on reasonable, data-protection grounds; if an objection cannot be resolved, the Customer may, as its remedy, terminate the affected service in accordance with the Agreement.
International transfers
Skyie Global will not transfer personal data processed under the Agreement to a country outside the United Kingdom without ensuring that an appropriate safeguard under Article 46 of the UK GDPR is in place — for example, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or reliance on UK adequacy regulations — or that another lawful basis for the transfer applies. We will process personal data only on the Customer's documented instructions in relation to such transfers.
Assistance, data-subject requests and breaches
Taking into account the nature of the processing and the information available to us, Skyie Global will provide reasonable assistance to the Customer in meeting its obligations under Data Protection Laws, including responding to data-subject requests and carrying out data protection impact assessments and prior consultations. If we become aware of a personal data breach affecting personal data processed on the Customer's behalf, we will notify the Customer without undue delay and provide the information reasonably available to us to help the Customer meet its own breach-notification obligations.
Return or deletion of data
On termination or expiry of the Agreement, and at the Customer's choice, Skyie Global will return the personal data to the Customer or delete it, and will delete existing copies, unless and to the extent that we are required by law to retain it. Where retention is required by law, we will protect the personal data and limit any further processing to the purpose and period required by that law.
Audits and information
Skyie Global will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To minimise disruption, audits will be conducted on reasonable prior notice, during business hours, no more than once a year (unless required by a supervisory authority or following a personal data breach), subject to appropriate confidentiality undertakings; we may satisfy an audit request by providing relevant certifications, reports or summaries of our controls where these reasonably address the Customer's request.
Liability, governing law and contact
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Agreement. If there is any conflict between this DPA and the Agreement on data-protection matters, this DPA prevails. To request a signed copy of this DPA, to discuss its terms, or for any data-protection enquiry relating to our products, contact us at [email protected] or write to Skyie Global InfoTech Ltd, Unit 37B, Alpha House, 100 Borough High Street, London, SE1 1LB, United Kingdom.
This notice is provided for transparency about how Skyie Global InfoTech Ltd handles your information and forms part of how we meet our obligations under UK data protection and consumer law. It is kept up to date and reviewed periodically. If anything here is unclear or you would like more detail, please contact us at [email protected].