Effective Date: [INSERT DATE]
Last Updated: [INSERT DATE]
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions ("Agreement") between:
The Customer (the entity agreeing to the Terms and Conditions) acting as the data Controller; and
Matainable Ltd, a company registered in England and Wales (Company Registration Number: 16543039) with its registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, acting as the data Processor.
This DPA applies where and to the extent that Matainable processes Personal Data on behalf of the Customer in the course of providing the Platform and Services under the Agreement. This DPA is incorporated into the Agreement by reference and applies automatically wherever a controller-processor relationship exists between the parties.
In this DPA, unless the context requires otherwise:
Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.
2.1 The Customer is the Controller of Customer Data. Matainable is the Processor of Customer Data.
2.2 This DPA applies to the processing of Customer Data as described in Annex 1 (Details of Processing) of this DPA.
2.3 For the avoidance of doubt, Matainable acts as a Controller in its own right in respect of Account Data, Usage Data, and other data that Matainable collects and processes for its own purposes, as described in the Privacy Policy. This DPA does not apply to such processing.
3.1 Matainable shall:
3.2 Matainable shall immediately inform the Customer if, in its opinion, an instruction from the Customer infringes the Data Protection Laws.
4.1 The Customer shall:
5.1 Matainable shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data.
5.2 Such notification shall include, to the extent reasonably available at the time of notification:
5.3 Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.
5.4 Matainable shall cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
5.5 Matainable's notification of or response to a Personal Data Breach under this Section 5 shall not be construed as an acknowledgement by Matainable of any fault or liability with respect to the Personal Data Breach.
6.1 General Authorisation. The Customer provides a general written authorisation for Matainable to engage Sub-Processors to process Customer Data, subject to the requirements of this Section 6.
6.2 Current Sub-Processors. The Customer acknowledges and agrees to the engagement of the Sub-Processors listed at matainable.com/legal/sub-processors as at the date the Customer enters into the Agreement.
6.3 Notification of Changes. Matainable shall notify the Customer of any intended changes concerning the addition or replacement of Sub-Processors at least 14 days in advance by updating the sub-processor list at the URL above and notifying the Customer by email. The Customer may subscribe to change notifications by contacting admin@matainable.com.
6.4 Objection Right. If the Customer has a reasonable objection to a new or replacement Sub-Processor, the Customer shall notify Matainable in writing within 14 days of receiving notice, setting out the specific grounds for the objection. The parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached within 30 days, the Customer may terminate the affected Services (and only those Services) by written notice, and Matainable shall provide a pro-rata refund of any prepaid Fees for the terminated Services covering the period after the effective date of termination.
6.5 Sub-Processor Obligations. Where Matainable engages a Sub-Processor, Matainable shall:
7.1 Matainable shall not transfer Customer Data outside the United Kingdom or the European Economic Area unless appropriate safeguards are in place in accordance with Chapter V of the Data Protection Laws.
7.2 Where Customer Data is transferred to a Sub-Processor in a country that has not been recognised as providing an adequate level of data protection, Matainable shall ensure that the transfer is made subject to appropriate safeguards, which may include:
7.3 Where Matainable relies on SCCs as a transfer mechanism, and those SCCs are amended, replaced, or superseded by the European Commission or the UK ICO, Matainable shall adopt the updated clauses within a reasonable timeframe.
7.4 Matainable shall conduct Transfer Impact Assessments where required and shall make the results available to the Customer on request.
8.1 Matainable shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and the obligations set out in Article 28 of the Data Protection Laws.
8.2 The Customer (or its appointed third-party auditor, provided such auditor is not a competitor of Matainable and is bound by appropriate confidentiality obligations) may conduct an audit of Matainable's processing of Customer Data, subject to the following conditions:
8.3 Where Matainable holds current certifications, audit reports, or assessments from independent third-party auditors (such as SOC 2, ISO 27001, or penetration test reports), Matainable may provide these to the Customer in lieu of permitting a physical audit, provided they are reasonably sufficient to demonstrate compliance.
9.1 Upon termination or expiry of the Agreement, Matainable shall, at the Customer's election:
9.2 Customer Data will be made available for export for a period of 30 days following termination, consistent with the Agreement. After this period, Matainable shall delete all remaining Customer Data within 30 days, unless applicable law requires further retention.
9.3 Where Matainable is required by applicable law to retain any Customer Data beyond the deletion date, Matainable shall:
10.1 Matainable shall promptly notify the Customer if it receives a request from a Data Subject to exercise any of their rights under the Data Protection Laws in respect of Customer Data, unless prohibited by applicable law from doing so.
10.2 Matainable shall not respond to a Data Subject request directly unless authorised to do so by the Customer, except to direct the Data Subject to the Customer.
10.3 Matainable shall provide reasonable assistance to the Customer in responding to Data Subject requests, taking into account the nature of the processing and the information available to Matainable. Where Matainable incurs material costs in providing such assistance beyond what is reasonably expected, the parties shall agree on reimbursement in advance.
11.1 Matainable shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required under Articles 35 and 36 of the Data Protection Laws, taking into account the nature of the processing and the information available to Matainable.
12.1 Matainable shall ensure that any person it authorises to process Customer Data (including its employees, agents, and Sub-Processors) shall be subject to a duty of confidentiality (whether contractual or statutory) with respect to that Customer Data.
12.2 Matainable shall ensure that access to Customer Data is limited to those personnel who need access to perform their duties in connection with the Services.
13.1 This DPA shall take effect on the date the Customer enters into the Agreement and shall continue in force for as long as Matainable processes Customer Data on behalf of the Customer.
13.2 Termination or expiry of this DPA shall not discharge the parties from the obligations set out in Sections 5 (Breach Notification), 9 (Data Return and Deletion), and 12 (Confidentiality), which shall survive termination.
14.1 Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, except that the aggregate liability cap in the Agreement does not apply to claims arising from either party's breach of its obligations under the Data Protection Laws or this DPA, as set out in Section 13.4A of the Agreement.
14.2 Nothing in this DPA limits either party's liability to Data Subjects under Article 82 of the Data Protection Laws.
15.1 This DPA shall be governed by and construed in accordance with the laws of England and Wales, consistent with the Agreement.
15.2 Where the SCCs apply, the governing law of the SCCs shall be as specified in those clauses.
16.1 Matainable may update this DPA from time to time to reflect changes in Data Protection Laws, regulatory guidance, or our processing practices. For material changes, Matainable will provide at least 30 days' prior written notice by email.
16.2 If a change to this DPA materially reduces the level of data protection afforded to Customer Data, the Customer may object within the notice period. If the parties cannot reach agreement, the Customer may terminate the affected Services with a pro-rata refund of prepaid Fees.
| Subject matter | Processing of Personal Data by Matainable on behalf of the Customer in connection with the provision of the Matainable platform and Services, as described in the Agreement. |
|---|---|
| Duration | For the term of the Agreement, plus any period of data retention required by the Agreement or applicable law. |
| Nature and purpose of processing | Storage, organisation, retrieval, display, sharing (in accordance with Customer-configured visibility settings), analysis, and deletion of Customer Data to provide the Platform features including: material and product data management, Digital Product Passport creation and hosting, supply chain data management, B2B messaging and RFQs, AI-assisted analysis, and compliance readiness tools. |
| Categories of Data Subjects | Employees, contractors, and agents of the Customer; employees, contractors, and agents of the Customer's suppliers and supply chain partners; other individuals whose Personal Data is included in materials, products, or supply chain records uploaded by the Customer. |
| Types of Personal Data | Names and contact details (email, phone, address) of individuals at the Customer and its supply chain; job titles and roles; facility locations; certification holder details; any other Personal Data included by the Customer in material data, product data, Digital Product Passport data, supply chain records, or B2B communications. |
| Special categories of data | None expected. The Customer must not upload special category data (as defined in Article 9 of the Data Protection Laws) to the Platform without Matainable's prior written agreement and appropriate safeguards. |
Matainable implements the following technical and organisational measures to protect Customer Data, in accordance with Article 32 of the Data Protection Laws:
For questions about this DPA, please contact:
Privacy enquiries: admin@matainable.com
Postal address: Matainable Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Company Registration Number: 16543039
Sustainable Materials, Now Attainable
© 2025 Matainable. All rights reserved
Matainable Ltd. CRN: 16543039
3rd Floor, 86-90 Paul Street
London, England
United Kingdom,
EC2A 4NE