Data Processing Agreement for Priceguide
Between:
Priceguide Ltd (“Processor” or “Priceguide“) Company number 15375622 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom
and the customer identified in the underlying Order Form or Subscription Agreement (“Controller” or “Customer“).
Effective date: the date of acceptance of the Priceguide Terms of Service or signature of an Order Form, whichever is earlier.
This Data Processing Agreement (the “DPA“) forms part of and is subject to the agreement between the parties for use of the Priceguide platform (the “Agreement“). In the event of any conflict between this DPA and the Agreement, this DPA shall prevail on matters of data protection.
1. Definitions
Capitalised terms not defined in this DPA shall have the meaning given in the Agreement or in the UK GDPR / EU GDPR, as the context requires.
- “Applicable Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), the Privacy and Electronic Communications Regulations, and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively the “CCPA“), in each case to the extent applicable to the processing of Customer Personal Data.
- “Customer Personal Data” means personal data that Priceguide processes on behalf of the Customer in connection with the provision of the Services.
- “Data Subject”, “Personal Data”, “Processing”, “Controller”, “Processor”, and “Sub-processor” shall have the meanings given in the UK GDPR.
- “Restricted Transfer” means a transfer of Personal Data from the United Kingdom or the European Economic Area to a country that has not been the subject of an adequacy decision.
- “Service Data” means aggregated, de-identified, or anonymised data derived from the Customer’s use of the Services that does not identify the Customer or any Data Subject.
- “Services” means the Priceguide platform and any related services provided under the Agreement.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission in Decision 2021/914 of 4 June 2021.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner.
- “UK IDTA” means the UK International Data Transfer Agreement issued by the UK Information Commissioner.
2. Roles and scope
2.1 The parties acknowledge that, with respect to Customer Personal Data:
- the Customer is the Controller; and
- Priceguide is the Processor acting on the Customer’s documented instructions.
2.2 Each party shall comply with its obligations under Applicable Data Protection Law.
2.3 This DPA shall apply for the duration of the Agreement and any period thereafter during which Priceguide retains Customer Personal Data.
2.4 The subject matter, nature, purpose, duration of processing, types of personal data, and categories of data subjects are set out in Annex 1.
3. Customer instructions
3.1 Priceguide shall process Customer Personal Data only:
(a) as necessary to provide the Services;
(b) in accordance with the Agreement and this DPA;
(c) on the documented instructions of the Customer; and
(d) as required by applicable law, in which case Priceguide shall (unless legally prohibited) inform the Customer before processing.
3.2 The Agreement, this DPA, and the Customer’s use of the Services constitute the Customer’s complete and final documented instructions to Priceguide. Any additional instructions shall require written agreement and may incur additional fees.
3.3 Priceguide shall inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Priceguide shall not be required to comply with any instruction that, in its reasonable opinion, would so infringe.
4. Confidentiality and personnel
4.1 Priceguide shall ensure that personnel authorised to process Customer Personal Data:
(a) are bound by written confidentiality obligations or are subject to appropriate statutory duties of confidentiality;
(b) have received guidance on data protection and information security appropriate to their role; and
(c) access Customer Personal Data only on a need-to-know basis under role-based access controls.
5. Security
5.1 Priceguide shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risks to the rights and freedoms of natural persons.
5.2 The measures are described in Annex 2 (Technical and Organisational Measures).
5.3 Priceguide may update its security measures from time to time, provided that the level of protection is not materially decreased.
6. Sub-processors
6.1 The Customer provides general written authorisation for Priceguide to engage Sub-processors, subject to this Section.
6.2 The current list of Sub-processors is published at priceguide.ai/sub-processor-list and reproduced in Annex 3.
6.3 Priceguide:
(a) shall enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those in this DPA, which may take the form of accepting the Sub-processor’s published data processing terms; and
(b) shall remain liable to the Customer for the acts and omissions of its Sub-processors as if they were its own.
6.4 Notice of changes. Priceguide shall give the Customer at least thirty (30) days’ notice of new or replacement Sub-processors by updating the published list and notifying customers via email or in-product announcement. The Customer may object on reasonable data protection grounds within fifteen (15) days of such notice. If the parties cannot resolve the objection within a reasonable time, the Customer may terminate the affected portion of the Services on written notice and shall be entitled to a pro-rata refund of any prepaid fees attributable to the unused portion of the Services so terminated.
7. International transfers
7.1 The Customer authorises Priceguide to transfer Customer Personal Data outside the United Kingdom and the European Economic Area to the countries identified in Annex 3.
7.2 Where a Restricted Transfer occurs, the parties shall rely on the following mechanisms in order of preference:
(a) an adequacy decision applicable to the recipient country or organisation (including the EU-US Data Privacy Framework and UK Extension where the recipient is certified);
(b) the EU Standard Contractual Clauses (Module 2: Controller to Processor and Module 3: Processor to Processor), which are hereby incorporated into this DPA by reference;
(c) the UK Addendum to the EU SCCs, or the UK IDTA, for transfers from the United Kingdom; and
(d) any other lawful transfer mechanism subsequently adopted.
7.3 For the SCCs incorporated by reference, in respect of transfers from the European Economic Area:
- The data exporter is the Customer (or, where Priceguide is the exporter, Priceguide itself).
- The data importer is Priceguide (or the relevant Sub-processor).
- Clause 7 (docking): applicable.
- Clause 9 (sub-processing): Option 2 (general written authorisation), with thirty (30) days’ prior notice.
- Clause 11 (redress): the optional independent dispute resolution language is not selected.
- Clause 17 (governing law): Irish law.
- Clause 18 (jurisdiction): the courts of Ireland.
- Annex I, II, and III are populated by Annexes 1, 2, and 3 of this DPA.
7.4 For the UK Addendum, in respect of transfers from the United Kingdom:
- Table 1 is populated by the parties’ details.
- Table 2: the EU SCCs identified in 7.2(b) above shall apply with the modifications in the Addendum, save that the governing law shall be the law of England and Wales and the courts of England and Wales shall have exclusive jurisdiction.
- Table 3 is populated by Annexes 1, 2, and 3.
- Table 4: neither party may end the Addendum.
8. Data subject rights
8.1 Priceguide shall, taking into account the nature of the processing, provide reasonable assistance to the Customer through appropriate technical and organisational measures, insofar as possible, to enable the Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Law.
8.2 If Priceguide receives a request directly from a data subject, Priceguide shall (unless legally prohibited) promptly forward the request to the Customer and shall not respond substantively except to confirm receipt and to direct the data subject to the Customer.
8.3 Customers may directly access, export, correct, and delete data through the Priceguide product. Where this is not technically possible, Priceguide shall provide reasonable assistance on request.
9. Personal Data Breach
9.1 Priceguide shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 The notification shall, to the extent then known, include:
(a) the nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects and records concerned;
(b) the likely consequences of the Personal Data Breach;
(c) the measures taken or proposed to address the Personal Data Breach and to mitigate its possible adverse effects; and
(d) the name and contact details of a contact point for further information.
9.3 Priceguide shall provide reasonable assistance to the Customer in fulfilling the Customer’s notification obligations to supervisory authorities and data subjects.
9.4 Notification of a Personal Data Breach shall not constitute an acknowledgement of fault or liability.
10. Data protection impact assessments and prior consultation
10.1 Priceguide shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Articles 35 and 36 of the UK GDPR or EU GDPR, taking into account the nature of the processing and information available to Priceguide.
11. Audits
11.1 Priceguide shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA.
11.2 The Customer may, no more than once per twelve (12) month period (and additionally following a confirmed Personal Data Breach affecting the Customer’s data, or a material change in Priceguide’s security posture), exercise audit rights as follows:
(a) Priceguide shall make available, on written request, its current security documentation, security questionnaire responses (including its CAIQ-Lite), and Sub-processor compliance evidence; and
(b) where the foregoing is reasonably insufficient to demonstrate compliance with this DPA, the Customer or an independent third-party auditor (other than an auditor that is a competitor of Priceguide) bound by confidentiality obligations may conduct an audit of Priceguide’s relevant systems and processes during normal business hours, on at least thirty (30) days’ written notice. Audits may take the form of remote review of systems and documentation or, where reasonably necessary, on-site review.
11.3 Audits shall be conducted in a manner that does not unreasonably interfere with Priceguide’s business operations and shall not access the data of other customers. Each party shall bear its own costs of the audit, save that the Customer shall reimburse Priceguide’s reasonable costs where the audit reveals no material non-compliance.
12. Return and deletion
12.1 On termination or expiry of the Agreement, Priceguide shall, at the Customer’s election:
(a) delete all Customer Personal Data; or
(b) return all Customer Personal Data and then delete it.
12.2 The Customer may export its data through the product at any time during the term and for thirty (30) days after termination.
12.3 Priceguide shall complete deletion within ninety (90) days of termination, except where applicable law requires retention. Backups containing Customer Personal Data are deleted in accordance with the backup rotation schedule (up to 35 days).
12.4 On the Customer’s written request, Priceguide shall provide written confirmation of deletion.
13. CCPA terms
13.1 To the extent Priceguide processes personal information of California residents on behalf of the Customer, Priceguide acts as a “Service Provider” under the CCPA.
13.2 Priceguide shall not:
(a) sell or share Customer Personal Data;
(b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes set out in the Agreement and this DPA;
(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or
(d) combine Customer Personal Data with personal information received from any other source, except as permitted by the CCPA Regulations.
13.3 Priceguide certifies that it understands and shall comply with the restrictions in this Section 13. Priceguide shall promptly notify the Customer if it makes a determination that it can no longer meet its obligations under the CCPA.
14. Service Data
14.1 The Customer acknowledges and agrees that Priceguide may collect, generate, and use Service Data for the purposes of:
(a) operating, securing, maintaining, improving, and developing the Services;
(b) producing aggregate analytics and benchmarks; and
(c) supporting the Customer and other customers in their use of the Services.
14.2 Service Data shall not include any data from which the Customer or any Data Subject can be identified, whether alone or in combination with other information reasonably available to Priceguide. Priceguide shall ensure that Service Data is rendered anonymous in a manner that prevents re-identification.
14.3 Service Data is not Customer Personal Data and the obligations in this DPA relating to Customer Personal Data shall not apply to Service Data.
15. Liability
15.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, save that:
(a) nothing in this DPA or the Agreement shall limit either party’s liability for matters that cannot be limited under Applicable Data Protection Law; and
(b) the parties may agree in writing in an Order Form to a separate liability cap applicable to data protection matters.
16. General
16.1 Order of precedence. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail on data protection matters. In the event of a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum shall prevail.
16.2 Severability. If any provision is held unenforceable, the remainder of this DPA shall continue in effect.
16.3 Governing law. This DPA is governed by the laws of England and Wales, save that the SCCs and UK Addendum are governed by the law specified in those instruments.
16.4 Updates. Priceguide may update this DPA from time to time to reflect changes in law or its services, with at least thirty (30) days’ notice for material changes that adversely affect the Customer.
Annex 1 — Description of processing
Subject matter and duration
Provision of the Priceguide platform during the term of the Agreement and any post-termination retention period set out in Section 12.
Nature and purpose of processing
Hosting, storing, transmitting, and analysing data submitted through the Priceguide estimator and customer dashboard, in order to:
- generate price estimates for end users;
- deliver lead information to the Customer;
- provide reporting, analytics, and product features to the Customer; and
- maintain, secure, and improve the platform.
Categories of data subjects
- The Customer’s authorised users (employees, contractors).
- End users of the Customer’s website who submit estimate requests (typically homeowners or property owners).
Categories of personal data
- Account data: name, work email, role, company name.
- Lead data submitted by end users: name, email address, telephone number, postal address or postcode/ZIP, project details, IP address, browser metadata, timestamps.
- Usage and log data associated with use of the Services.
Special categories of data
None intended. The Customer is responsible for not configuring estimators to collect special category data.
Frequency of processing
Continuous for the duration of the Agreement.
Retention
As set out in Section 9 of the Privacy Policy and Section 12 of this DPA. Default retention for estimator submissions is 24 months unless the Customer configures otherwise.
Annex 2 — Technical and organisational measures
Priceguide implements the following measures, which may be updated from time to time provided that the level of protection is not materially decreased.
1. Access control
Multi-factor authentication is required for administrative access to production systems. Role-based access control is implemented on a least-privilege basis. Access rights for production systems are reviewed quarterly. Identity is centrally managed via Auth0.
2. Encryption
TLS 1.2 or higher is used for all data in transit. AES-256 (or provider equivalent) encryption is applied to data at rest in databases, storage, and backups managed by our hosting providers. Application secrets are stored in an encrypted secret store.
3. Network security
Cloudflare provides web application firewall and DDoS protection on customer-facing endpoints. Vercel provides managed edge infrastructure. Production, staging, and corporate environments are logically separated.
4. Application security
Priceguide follows a peer code review process: changes to production code are reviewed by an engineer other than the author before merging. Static analysis runs on pull requests. Dependency scanning is in use. Patching of dependencies follows a risk-based approach, with critical vulnerabilities addressed in priority where a patch is available.
5. Logging and monitoring
Application and infrastructure logs are captured and retained in accordance with the retention policies of our hosting providers (Vercel, Cloudflare), typically up to twelve (12) months. Authentication events and administrative actions are logged.
6. Backups and resilience
Automated database backups with point-in-time recovery are in place. Backup retention is up to thirty-five (35) days. Backups are encrypted at rest. Critical platform components are hosted on the multi-region infrastructure of Vercel and Cloudflare.
7. Incident response
A documented Incident Response Plan defines roles, severity classification, communication paths, and notification timelines. Customer notification of confirmed Personal Data Breaches is provided without undue delay and in any event within forty-eight (48) hours of awareness, in accordance with Section 9.
8. Personnel
Personnel and contractors with production access are bound by written confidentiality obligations. Identity verification and role-appropriate reference checks are conducted prior to granting production access. Access is revoked promptly on departure or contract end.
9. Sub-processor management
Pre-engagement review of Sub-processors includes assessment of their certifications and data protection terms. Sub-processors are engaged under written data protection terms (which may take the form of the Sub-processor’s published data processing addendum). Active Sub-processors are reviewed annually.
10. Physical security
Production data is hosted in third-party data centres operated by Vercel, AWS (via Vercel), and Cloudflare, which maintain SOC 2 Type II, ISO 27001, and equivalent certifications. Priceguide does not operate physical data centre infrastructure.
11. Data minimisation
Data sent to AI providers is minimised. Personally identifying fields (name, email, telephone, full address) are not sent to AI/LLM endpoints. Only the minimum data required for each operation is processed.
12. Endpoint security
Personnel devices used to access production systems are protected with full-disk encryption and screen lock. Production access requires multi-factor authentication.
Annex 3 — Sub-processors
The current list of Sub-processors is published at priceguide.ai/sub-processor-list and reproduced in our Sub-processor List document, which forms part of this DPA. Priceguide shall give at least thirty (30) days’ notice of changes as set out in Section 6.
Acceptance
This DPA is accepted by the Customer’s acceptance of the Agreement or execution of an Order Form referencing the Priceguide Terms of Service. No signature is required for entry into force.
For a counter-signed copy, please contact [email protected].
Have Any Questions?
We’d love to hear from you.
