Data Processing Addendum
Last updated: 29 July 2026
This Data Processing Addendum ("DPA") forms part of the DeepSeer Terms of Service (the "Agreement") entered into between the entity or person agreeing to the Agreement ("Customer") and DeepSeer Ltd, a company registered in England and Wales (Company No. 12647524) with its registered office at 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom ("DeepSeer").
This DPA applies automatically, without the need for a separate signature, wherever DeepSeer processes Personal Data on Customer's behalf in connection with the Services. By using the Services, Customer agrees to this DPA. If Customer requires a separately executed data processing agreement with bespoke terms, for example as part of an enterprise contract, contact legal@deepseer.ai.
In the event of any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.
1. Definitions
- "Applicable Data Protection Laws" means the UK GDPR and the Data Protection Act 2018, as amended, extended or re-enacted.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in Applicable Data Protection Laws.
- "Customer Personal Data" means Personal Data processed by DeepSeer on behalf of Customer under the Agreement, as further described in Annex 1.
- "Services" means the DeepSeer LLM Intelligence service as described in the Agreement.
- "Subprocessor" means any third party engaged by DeepSeer to process Customer Personal Data in connection with the Services, as listed on DeepSeer's subprocessor list.
- "UK Extension" means the UK Extension to the EU-US Data Privacy Framework.
- "UK Transfer Instruments" means the ICO's International Data Transfer Agreement (IDTA), version A1.0, and the ICO's International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, version B1.0, together with the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 to the extent that Addendum applies them, or any UK-approved replacement.
2. Scope and Roles
2.1 This DPA applies to DeepSeer's processing of Customer Personal Data in connection with the provision of the Services.
2.2 For the purposes of Applicable Data Protection Laws, Customer is the Controller and DeepSeer is the Processor in respect of Customer Personal Data.
2.3 The subject matter, duration, nature and purpose of processing, and the categories of Data Subjects and Personal Data, are set out in Annex 1.
3. Processor Obligations
3.1 Instructions. DeepSeer shall process Customer Personal Data only on documented instructions from Customer, including those set out in the Agreement and this DPA, unless required to do otherwise by law, in which case DeepSeer shall, where legally permitted, inform Customer of that legal requirement before processing.
3.2 Limits on instructions. Customer's instructions must not require DeepSeer to process Personal Data relating to any individual other than (a) Customer's Authorized Users and (b) Customer's own personnel in their professional capacity, as described in Annex 1 and as restricted by the acceptable use provisions of the Agreement. An instruction requiring processing outside those limits is not a documented instruction for the purposes of Section 3.1, and DeepSeer may decline to act on it. In accordance with Article 28(3) of the UK GDPR, DeepSeer shall inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
3.3 Confidentiality. DeepSeer shall ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
3.4 Security. DeepSeer shall implement the technical and organisational measures set out in Annex 2, designed to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR.
3.5 Sub-processing. Customer provides DeepSeer with general authorisation to engage the Subprocessors listed on DeepSeer's subprocessor list. DeepSeer will post any intended addition or replacement of a Subprocessor to that page at least thirty (30) days in advance, giving Customer the opportunity to object on reasonable data-protection grounds by contacting legal@deepseer.ai. Where Customer objects and the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the terminated portion of the subscription term. DeepSeer shall impose data protection obligations on each Subprocessor that are no less protective than those in this DPA.
3.6 Data Subject Rights. Taking into account the nature of the processing, DeepSeer shall provide reasonable assistance to Customer, by appropriate technical and organisational measures, to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws. Where DeepSeer receives such a request directly it shall promptly forward it to Customer, and shall not respond substantively except on Customer's instruction or as required by law.
3.7 Assistance. DeepSeer shall provide reasonable assistance to Customer with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner) taking into account the nature of processing and the information available to DeepSeer.
3.8 Personal Data Breach. DeepSeer shall notify Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data, and shall provide reasonably requested information to assist Customer in meeting its own notification obligations.
3.9 Deletion or Return. On termination or expiry of the Agreement, DeepSeer shall, at Customer's election, delete or return all Customer Personal Data, and delete existing copies, within thirty (30) days, unless retention is required by law.
3.10 Audits. DeepSeer shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA. DeepSeer may satisfy this obligation by providing a current third-party audit report or certification, such as SOC 2 Type II or ISO/IEC 27001, together with responses to reasonable written questions. Where such a report is not available, or where Customer can demonstrate that it is insufficient to address a specific and identified concern, DeepSeer shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable prior notice, confidentiality, Customer bearing its own costs, and no more than once per year, save where required by the Information Commissioner or following a Personal Data Breach.
3.11 No training on Customer Personal Data. DeepSeer shall not use Customer Personal Data, or any content submitted by Customer to the Services, to train, fine-tune, develop or improve any artificial intelligence or machine learning model, whether DeepSeer's own or a third party's.
4. International Transfers
4.1 Adequacy. Where a transfer of Customer Personal Data outside the United Kingdom is to a recipient covered by a UK adequacy regulation, including a recipient that maintains a current and active self-certification to the UK Extension, DeepSeer may rely on that adequacy, and shall maintain the safeguards in Section 4.2 as a fallback for every such transfer.
4.2 Contractual safeguards. Where adequacy is not available, transfers of Customer Personal Data outside the United Kingdom, including to Subprocessors located in the United States as listed on DeepSeer's subprocessor list, are subject to the applicable UK Transfer Instrument, incorporated into this DPA by reference and deemed executed between the parties from the date Customer accepts this DPA.
4.3 Transfer particulars. For the purposes of the UK Transfer Instruments: Customer is the data exporter and DeepSeer the data importer, and in respect of onward transfers to Subprocessors DeepSeer is the exporter; the parties' details are those given in the Agreement; Annex 1 sets out the details of the transfer and Annex 2 the technical and organisational security measures; and neither party may terminate the relevant instrument on the ground that the ICO has issued a revised approved version.
4.4 DeepSeer shall ensure that any Subprocessor located outside the United Kingdom is bound by transfer safeguards equivalent to those in this Section 4, and shall carry out and document a transfer risk assessment for each transfer relying on contractual safeguards.
5. Subprocessor List
DeepSeer maintains an up-to-date list of Subprocessors, including their identity, location and the transfer mechanism relied on for each, at deepseer.ai/subprocessors. That page is the authoritative source and is updated independently of this DPA; DeepSeer will notify changes to it in accordance with Section 3.5.
6. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement, save that nothing in this DPA or the Agreement limits either party's liability to a Data Subject under the UK Transfer Instruments.
7. Term
This DPA takes effect when Customer accepts the Agreement and remains in effect until the Agreement terminates or expires, notwithstanding completion of the actions in Section 3.9.
8. Governing Law and Precedence
8.1 This DPA is governed by the laws of England and Wales, save that Section 4 (International Transfers) shall be governed as set out in the UK Transfer Instruments themselves where applicable.
8.2 In the event of conflict between this DPA and the Agreement in relation to the processing of personal data, this DPA prevails; in all other respects the Agreement prevails.
Annex 1 - Details of Processing
Also constitutes the details of the transfer for the purposes of the UK Transfer Instruments.
Subject matter. Provision of the DeepSeer LLM Intelligence service: analysis of how Customer's brand, products, leadership and strategy are represented across third-party large language models.
Duration. For the term of the Agreement, plus thirty (30) days for deletion or return of Customer Personal Data thereafter.
Nature and purpose of processing. Collection, storage and analysis of Customer-submitted brand and stakeholder-persona content in order to query third-party large language model Subprocessors and generate reports; hosting of Customer account data to provide login and administration of the Services.
Categories of Data Subjects
- Customer's Authorized Users: employees or contractors with access to the Services.
- Customer's own personnel, in their professional capacity, where Customer elects to analyse how they are represented in large language model outputs. Customer is the Controller in respect of such individuals and is responsible for informing them and for establishing its own lawful basis.
Personas. Stakeholder personas used in the Services, for example "the sceptical institutional investor" or "a sector regulator", are analytical archetypes constructed by Customer for the purposes of the Services. They are not profiles of identified or identifiable natural persons, and Customer is prohibited under the Agreement from using the Services to analyse individuals other than those described above.
Categories of Personal Data
- Authorized User account data: name, business email address, login credentials, IP address and usage logs.
- Billing contact details.
- Where Customer elects to analyse the representation of its own personnel: name, job title, employer, and the content of large language model outputs concerning that individual.
Special category data. DeepSeer does not seek, and the Services are not designed to process, special category personal data within the meaning of Article 9 UK GDPR. Large language model outputs concerning a named individual may nonetheless contain assertions falling within Article 9, for example concerning political opinions, health or religious belief, which DeepSeer neither solicits nor uses for any purpose beyond delivering the output to Customer. Customer is responsible for its own lawful basis in respect of such content, and may request deletion or suppression at any time.
Frequency of transfer. Continuous, for the duration of the Services.
Competent supervisory authority. The Information Commissioner's Office.
Annex 2 - Technical and Organisational Security Measures
Also constitutes the security measures for the purposes of the UK Transfer Instruments.
DeepSeer implements and maintains the following measures:
- Encryption of Customer Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Role-based access controls, with multi-factor authentication on administrative accounts.
- Logging and monitoring of access to systems processing Customer Personal Data.
- Confidentiality undertakings and data protection training for personnel with access to Customer Personal Data.
- Vulnerability management and regular security patching.
- Regular backups and a documented disaster recovery process.
- A documented security incident response plan.
- Due diligence and contractual data protection obligations imposed on Subprocessors.
- Pseudonymisation or de-identification of Personal Data where compatible with the purpose of processing.
- Hosting and storage of Customer Personal Data at rest in the United Kingdom (London region).