Matainable Data Processing Agreement

Data Processing Agreement

Effective Date: [INSERT DATE]

Last Updated: [INSERT DATE]

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions ("Agreement") between:

The Customer (the entity agreeing to the Terms and Conditions) acting as the data Controller; and

Matainable Ltd, a company registered in England and Wales (Company Registration Number: 16543039) with its registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, acting as the data Processor.

This DPA applies where and to the extent that Matainable processes Personal Data on behalf of the Customer in the course of providing the Platform and Services under the Agreement. This DPA is incorporated into the Agreement by reference and applies automatically wherever a controller-processor relationship exists between the parties.

1. Definitions

In this DPA, unless the context requires otherwise:

  • "Data Protection Laws" means the UK General Data Protection Regulation (UK GDPR) as incorporated into UK law by the Data Protection Act 2018, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), and any applicable national implementing legislation, in each case as amended, replaced, or superseded from time to time.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing", and "Supervisory Authority" have the meanings given to them in the Data Protection Laws.
  • "Customer Data" means any Personal Data that is processed by Matainable on behalf of the Customer in connection with the Platform and Services.
  • "Sub-Processor" means any third party engaged by Matainable to process Customer Data on behalf of the Customer.
  • "SCCs" means the Standard Contractual Clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Decision 2021/914) and/or the UK International Data Transfer Agreement or UK Addendum to the EU SCCs, as applicable.

Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.

2. Scope and Roles

2.1 The Customer is the Controller of Customer Data. Matainable is the Processor of Customer Data.

2.2 This DPA applies to the processing of Customer Data as described in Annex 1 (Details of Processing) of this DPA.

2.3 For the avoidance of doubt, Matainable acts as a Controller in its own right in respect of Account Data, Usage Data, and other data that Matainable collects and processes for its own purposes, as described in the Privacy Policy. This DPA does not apply to such processing.

3. Processor Obligations

3.1 Matainable shall:

  • (a) process Customer Data only on the documented instructions of the Customer, unless required to do so by applicable law, in which case Matainable shall (to the extent permitted by law) inform the Customer of that legal requirement before processing;
  • (b) ensure that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • (c) implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the Data Protection Laws, including the measures described in Annex 2 (Security Measures) of this DPA;
  • (d) not engage another processor (Sub-Processor) without the prior general written authorisation of the Customer, subject to Section 6 of this DPA;
  • (e) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising Data Subjects' rights under Chapter III of the Data Protection Laws;
  • (f) assist the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the Data Protection Laws, taking into account the nature of processing and the information available to Matainable;
  • (g) at the choice of the Customer, delete or return all Customer Data to the Customer after the end of the provision of Services, and delete existing copies unless applicable law requires storage of the Personal Data, subject to Section 9 of this DPA;
  • (h) make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the Data Protection Laws, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, subject to Section 8 of this DPA.

3.2 Matainable shall immediately inform the Customer if, in its opinion, an instruction from the Customer infringes the Data Protection Laws.

4. Customer Obligations

4.1 The Customer shall:

  • (a) comply with its obligations as a Controller under the Data Protection Laws, including ensuring it has a lawful basis for the processing of Personal Data and for instructing Matainable to process Customer Data in accordance with this DPA;
  • (b) provide all necessary privacy notices to Data Subjects whose Personal Data is processed through the Platform, and obtain any necessary consents where required;
  • (c) ensure that its instructions to Matainable regarding the processing of Customer Data comply with the Data Protection Laws;
  • (d) be solely responsible for the accuracy, quality, and legality of Customer Data and the means by which the Customer acquired the Customer Data.

5. Personal Data Breach Notification

5.1 Matainable shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data.

5.2 Such notification shall include, to the extent reasonably available at the time of notification:

  • (a) a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • (b) the name and contact details of the point of contact from whom more information can be obtained;
  • (c) a description of the likely consequences of the Personal Data Breach;
  • (d) a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

5.3 Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.

5.4 Matainable shall cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

5.5 Matainable's notification of or response to a Personal Data Breach under this Section 5 shall not be construed as an acknowledgement by Matainable of any fault or liability with respect to the Personal Data Breach.

6. Sub-Processors

6.1 General Authorisation. The Customer provides a general written authorisation for Matainable to engage Sub-Processors to process Customer Data, subject to the requirements of this Section 6.

6.2 Current Sub-Processors. The Customer acknowledges and agrees to the engagement of the Sub-Processors listed at matainable.com/legal/sub-processors as at the date the Customer enters into the Agreement.

6.3 Notification of Changes. Matainable shall notify the Customer of any intended changes concerning the addition or replacement of Sub-Processors at least 14 days in advance by updating the sub-processor list at the URL above and notifying the Customer by email. The Customer may subscribe to change notifications by contacting admin@matainable.com.

6.4 Objection Right. If the Customer has a reasonable objection to a new or replacement Sub-Processor, the Customer shall notify Matainable in writing within 14 days of receiving notice, setting out the specific grounds for the objection. The parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached within 30 days, the Customer may terminate the affected Services (and only those Services) by written notice, and Matainable shall provide a pro-rata refund of any prepaid Fees for the terminated Services covering the period after the effective date of termination.

6.5 Sub-Processor Obligations. Where Matainable engages a Sub-Processor, Matainable shall:

  • (a) impose data protection obligations on the Sub-Processor by way of a written contract that are substantially equivalent to those set out in this DPA;
  • (b) remain fully liable to the Customer for the performance of the Sub-Processor's obligations.

7. International Data Transfers

7.1 Matainable shall not transfer Customer Data outside the United Kingdom or the European Economic Area unless appropriate safeguards are in place in accordance with Chapter V of the Data Protection Laws.

7.2 Where Customer Data is transferred to a Sub-Processor in a country that has not been recognised as providing an adequate level of data protection, Matainable shall ensure that the transfer is made subject to appropriate safeguards, which may include:

  • (a) Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) and/or the UK International Data Transfer Agreement or UK Addendum to the EU SCCs issued by the UK ICO;
  • (b) the EU-US Data Privacy Framework (and UK Extension), where the recipient Sub-Processor is certified;
  • (c) any other transfer mechanism approved under the Data Protection Laws.

7.3 Where Matainable relies on SCCs as a transfer mechanism, and those SCCs are amended, replaced, or superseded by the European Commission or the UK ICO, Matainable shall adopt the updated clauses within a reasonable timeframe.

7.4 Matainable shall conduct Transfer Impact Assessments where required and shall make the results available to the Customer on request.

8. Audits

8.1 Matainable shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and the obligations set out in Article 28 of the Data Protection Laws.

8.2 The Customer (or its appointed third-party auditor, provided such auditor is not a competitor of Matainable and is bound by appropriate confidentiality obligations) may conduct an audit of Matainable's processing of Customer Data, subject to the following conditions:

  • (a) the Customer shall provide at least 30 days' prior written notice of any audit;
  • (b) audits shall be conducted during normal business hours and shall not unreasonably disrupt Matainable's business operations;
  • (c) audits shall be limited to no more than one per calendar year, unless a Personal Data Breach has occurred or a Supervisory Authority requires an additional audit;
  • (d) the Customer shall bear the costs of any audit it initiates, unless the audit reveals a material breach of this DPA by Matainable, in which case Matainable shall bear the reasonable costs of the audit.

8.3 Where Matainable holds current certifications, audit reports, or assessments from independent third-party auditors (such as SOC 2, ISO 27001, or penetration test reports), Matainable may provide these to the Customer in lieu of permitting a physical audit, provided they are reasonably sufficient to demonstrate compliance.

9. Data Return and Deletion

9.1 Upon termination or expiry of the Agreement, Matainable shall, at the Customer's election:

  • (a) return all Customer Data to the Customer in a structured, commonly used, and machine-readable format (such as JSON or CSV); or
  • (b) delete all Customer Data and certify such deletion in writing.

9.2 Customer Data will be made available for export for a period of 30 days following termination, consistent with the Agreement. After this period, Matainable shall delete all remaining Customer Data within 30 days, unless applicable law requires further retention.

9.3 Where Matainable is required by applicable law to retain any Customer Data beyond the deletion date, Matainable shall:

  • (a) inform the Customer of that requirement (to the extent permitted by law);
  • (b) limit its processing of the retained Customer Data to the purpose(s) required by that law;
  • (c) continue to protect the retained Customer Data in accordance with this DPA.

10. Data Subject Requests

10.1 Matainable shall promptly notify the Customer if it receives a request from a Data Subject to exercise any of their rights under the Data Protection Laws in respect of Customer Data, unless prohibited by applicable law from doing so.

10.2 Matainable shall not respond to a Data Subject request directly unless authorised to do so by the Customer, except to direct the Data Subject to the Customer.

10.3 Matainable shall provide reasonable assistance to the Customer in responding to Data Subject requests, taking into account the nature of the processing and the information available to Matainable. Where Matainable incurs material costs in providing such assistance beyond what is reasonably expected, the parties shall agree on reimbursement in advance.

11. Data Protection Impact Assessments

11.1 Matainable shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required under Articles 35 and 36 of the Data Protection Laws, taking into account the nature of the processing and the information available to Matainable.

12. Confidentiality

12.1 Matainable shall ensure that any person it authorises to process Customer Data (including its employees, agents, and Sub-Processors) shall be subject to a duty of confidentiality (whether contractual or statutory) with respect to that Customer Data.

12.2 Matainable shall ensure that access to Customer Data is limited to those personnel who need access to perform their duties in connection with the Services.

13. Term and Termination

13.1 This DPA shall take effect on the date the Customer enters into the Agreement and shall continue in force for as long as Matainable processes Customer Data on behalf of the Customer.

13.2 Termination or expiry of this DPA shall not discharge the parties from the obligations set out in Sections 5 (Breach Notification), 9 (Data Return and Deletion), and 12 (Confidentiality), which shall survive termination.

14. Liability

14.1 Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, except that the aggregate liability cap in the Agreement does not apply to claims arising from either party's breach of its obligations under the Data Protection Laws or this DPA, as set out in Section 13.4A of the Agreement.

14.2 Nothing in this DPA limits either party's liability to Data Subjects under Article 82 of the Data Protection Laws.

15. Governing Law

15.1 This DPA shall be governed by and construed in accordance with the laws of England and Wales, consistent with the Agreement.

15.2 Where the SCCs apply, the governing law of the SCCs shall be as specified in those clauses.

16. Changes to This DPA

16.1 Matainable may update this DPA from time to time to reflect changes in Data Protection Laws, regulatory guidance, or our processing practices. For material changes, Matainable will provide at least 30 days' prior written notice by email.

16.2 If a change to this DPA materially reduces the level of data protection afforded to Customer Data, the Customer may object within the notice period. If the parties cannot reach agreement, the Customer may terminate the affected Services with a pro-rata refund of prepaid Fees.


Annex 1 — Details of Processing

Subject matterProcessing of Personal Data by Matainable on behalf of the Customer in connection with the provision of the Matainable platform and Services, as described in the Agreement.
DurationFor the term of the Agreement, plus any period of data retention required by the Agreement or applicable law.
Nature and purpose of processingStorage, organisation, retrieval, display, sharing (in accordance with Customer-configured visibility settings), analysis, and deletion of Customer Data to provide the Platform features including: material and product data management, Digital Product Passport creation and hosting, supply chain data management, B2B messaging and RFQs, AI-assisted analysis, and compliance readiness tools.
Categories of Data SubjectsEmployees, contractors, and agents of the Customer; employees, contractors, and agents of the Customer's suppliers and supply chain partners; other individuals whose Personal Data is included in materials, products, or supply chain records uploaded by the Customer.
Types of Personal DataNames and contact details (email, phone, address) of individuals at the Customer and its supply chain; job titles and roles; facility locations; certification holder details; any other Personal Data included by the Customer in material data, product data, Digital Product Passport data, supply chain records, or B2B communications.
Special categories of dataNone expected. The Customer must not upload special category data (as defined in Article 9 of the Data Protection Laws) to the Platform without Matainable's prior written agreement and appropriate safeguards.

Annex 2 — Security Measures

Matainable implements the following technical and organisational measures to protect Customer Data, in accordance with Article 32 of the Data Protection Laws:

Encryption

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS).
  • Passwords are stored using industry-standard one-way hashing algorithms (bcrypt or equivalent).
  • Database infrastructure provided by Xano includes encryption at rest.

Access Control

  • Role-based access controls (RBAC) limit access to Customer Data based on user roles and permissions configured by the Customer.
  • Administrative access to production systems is restricted to authorised Matainable personnel on a need-to-know basis.
  • Authentication via secure token-based sessions (JWT).

Infrastructure Security

  • Primary database and file storage hosted in EU data centres.
  • DDoS protection and web application firewall provided by Cloudflare.
  • Regular security reviews and vulnerability assessments.

Sub-Processor Security

  • All Sub-Processors are evaluated for their security posture before engagement.
  • Data processing agreements with security obligations are in place with all Sub-Processors.

Incident Management

  • Documented incident response procedure including identification, containment, investigation, notification, and remediation.
  • Security logging retained for up to 12 months.

Business Continuity

  • Regular data backups maintained by infrastructure provider (Xano).
  • Disaster recovery procedures in place through cloud infrastructure redundancy.

Personnel

  • All personnel with access to Customer Data are bound by confidentiality obligations.
  • Access is reviewed periodically and revoked upon role change or departure.

Contact

For questions about this DPA, please contact:

Privacy enquiries: admin@matainable.com
Postal address: Matainable Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Company Registration Number: 16543039

Sustainable Materials, Now Attainable
© 2025 Matainable. All rights reserved
Matainable Ltd. CRN: 16543039

3rd Floor, 86-90 Paul Street
London, England
United Kingdom,
EC2A 4NE