← Ida

Data Processing Agreement

Version 2026-07-17

Version: 27 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement governing the customer's use of Ida (the "Agreement") between Ida Solutions & Partners Ltd, a company registered in England and Wales ("Ida", "Processor", "we", "us"), and the customer identified in the Agreement ("Customer", "Controller", "you").

This DPA applies where Ida processes Personal Data on behalf of Customer in providing the Service.

Data protection enquiries may be sent to data@runida.com.

1. Definitions

Customer Data means data submitted to, stored in, or accessed by the Service on Customer's behalf, including data accessed from systems Customer connects to the Service.

Customer Personal Data means Personal Data contained in Customer Data.

Data Protection Law means the UK GDPR and Data Protection Act 2018, in each case as amended from time to time, and the EU GDPR where applicable to the relevant processing.

Sub-processor means a third party engaged by Ida to process Customer Personal Data on Customer's behalf.

"Controller", "Processor", "Personal Data", "Processing", "Personal Data Breach" and "Data Subject" have the meanings given in applicable Data Protection Law.

2. Roles and scope

2.1 Customer is the Controller of Customer Personal Data and Ida processes Customer Personal Data as a Processor on Customer's behalf.

2.2 Customer determines the purposes of the processing. Ida will process Customer Personal Data only to provide and support the Service in accordance with the Agreement, this DPA and Customer's documented instructions.

2.3 Ida may separately process limited Personal Data as an independent Controller, including account, billing, security and business-contact information. Such processing is governed by Ida's Privacy Notice and not this DPA.

2.4 Customer is responsible for ensuring that it has all rights, notices, lawful bases and authorisations required to provide Customer Personal Data to Ida and instruct Ida to process it.

3. Customer instructions

3.1 Customer instructs Ida to process Customer Personal Data as necessary to provide the Service, including through Customer's configuration of the Service, authorised integrations and actions taken by its authorised users.

3.2 Ida will process Customer Personal Data only on Customer's documented instructions unless required to do otherwise by applicable law. Where permitted by law, Ida will inform Customer before carrying out processing required by law.

3.3 Ida will promptly inform Customer if, in Ida's opinion, an instruction infringes applicable Data Protection Law.

3.4 Ida will not use Customer Personal Data to train or fine-tune general-purpose machine-learning models and will not permit its Sub-processors to use Customer Personal Data for that purpose.

4. Confidentiality and security

4.1 Ida will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

4.2 Ida will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

4.3 The technical and organisational measures currently applicable to the Service are described in Annex II.

4.4 Ida may update those measures from time to time provided that the overall level of protection of Customer Personal Data is not materially reduced.

5. Sub-processors

5.1 Customer gives Ida general written authorisation to engage Sub-processors in connection with the Service.

5.2 Ida maintains its current list of Sub-processors at runida.com/legal/sub_processors.

5.3 Ida will give Customer at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data or an existing Sub-processor is replaced.

5.4 Customer may object to a new Sub-processor during that notice period on reasonable grounds relating to data protection. Ida will work with Customer in good faith to address the objection. If the parties cannot reasonably resolve it, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of any applicable prepaid fees.

5.5 Ida will enter into a written agreement with each Sub-processor imposing data-protection obligations appropriate to the processing and consistent with the requirements applicable to Ida under this DPA.

5.6 Ida remains responsible to Customer for the performance of its Sub-processors' data-protection obligations.

6. Data Subject requests

6.1 Taking into account the nature of the processing, Ida will provide reasonable assistance to enable Customer to respond to requests from Data Subjects exercising their rights under applicable Data Protection Law.

6.2 If Ida receives a request directly from a Data Subject relating to Customer Personal Data, Ida will, where legally permitted, refer the request to Customer or notify Customer without responding substantively unless instructed to do so by Customer.

7. Assistance and Personal Data Breaches

7.1 Taking into account the nature of the processing and information available to Ida, Ida will provide reasonable assistance to Customer with its obligations relating to:

  • security of processing;
  • Personal Data Breaches;
  • data protection impact assessments; and
  • consultation with supervisory authorities where required.

7.2 Ida will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.3 Ida will provide information concerning the Personal Data Breach that is reasonably available to Ida and reasonably required for Customer to comply with its obligations under applicable Data Protection Law, and may provide that information in phases as further information becomes available.

8. International transfers

8.1 Ida may process Customer Personal Data, or permit its Sub-processors to process Customer Personal Data, outside the United Kingdom or European Economic Area where necessary to provide the Service.

8.2 Where such processing constitutes a restricted international transfer under applicable Data Protection Law, Ida will ensure that the transfer is covered by a valid transfer mechanism.

8.3 For transfers subject to the EU GDPR, this may include an applicable adequacy decision or the European Commission's Standard Contractual Clauses.

8.4 For transfers subject to the UK GDPR, this may include applicable UK adequacy regulations, the UK International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses together with the applicable UK International Data Transfer Addendum.

8.5 Ida will conduct any transfer assessment required by applicable Data Protection Law and implement supplementary measures where required.

8.6 The locations and applicable transfer arrangements for Ida's Sub-processors are identified in Ida's published Sub-processor information.

9. Audit and compliance information

9.1 Ida will make available to Customer information reasonably necessary to demonstrate compliance with the processor obligations applicable under Data Protection Law.

9.2 Where that information is insufficient for Customer's reasonable regulatory requirements, Ida will allow for and contribute to reasonable audits or inspections conducted by Customer or an auditor appointed by Customer.

9.3 Unless required by a supervisory authority or reasonably necessary following a Personal Data Breach or material compliance concern, audits may be conducted no more than once in any 12-month period, on reasonable prior notice, during normal business hours, subject to appropriate confidentiality obligations and in a manner designed to minimise disruption.

10. Return and deletion

10.1 During the term, Customer may export Customer Data using functionality made available through the Service.

10.2 Following termination or expiry of the Agreement, Ida will, at Customer's choice, return or delete Customer Personal Data and delete existing copies, unless applicable law requires Ida to retain particular Personal Data.

10.3 Unless Customer instructs Ida otherwise, Customer Data will remain available for export for up to 30 days following termination and will then be deleted from active systems.

10.4 Customer Personal Data contained in backups may remain until those backups expire in accordance with Ida's ordinary backup-retention schedule. Until deletion, such data will remain protected and will not be processed except as required for backup restoration, security or legal obligations.

10.5 Where applicable law requires Ida to retain Customer Personal Data, Ida will isolate and protect that Personal Data from further processing except to the extent required by law.

11. General

11.1 If this DPA conflicts with the Agreement on matters concerning the processing of Customer Personal Data, this DPA prevails.

11.2 Any applicable Standard Contractual Clauses, UK Addendum or IDTA prevail over this DPA to the extent of any conflict concerning an international transfer governed by those terms.

11.3 Except where an applicable international-transfer mechanism requires otherwise, this DPA is governed by the governing law and jurisdiction specified in the Agreement.

Annex I — Details of Processing

Subject matter

Processing of Customer Personal Data in connection with the provision of the Ida Service.

Duration

For the term of the Agreement and any limited retention period described in this DPA.

Nature and purpose

Hosting, storage, indexing, retrieval, analysis and AI-assisted processing of Customer Data; generation of outputs; interaction with systems authorised by Customer; and other processing necessary to provide, secure and support the Service.

Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer's authorised users and personnel;
  • Customer's clients and prospective clients;
  • suppliers, contractors and professional advisers;
  • contacts contained in Customer's business systems, documents or correspondence; and
  • other individuals whose Personal Data Customer makes available to the Service.

Types of Personal Data

Depending on Customer's use of the Service, Customer Personal Data may include:

  • names and business contact information;
  • employment, company and role information;
  • communications and correspondence;
  • documents, files and their metadata;
  • information contained in systems connected by Customer;
  • financial and transaction-related business information;
  • conversations and instructions provided to the Service; and
  • data generated or derived by the Service from Customer Data, including embeddings, memories and structured entity information.

The Service is not intended to require Special Category Personal Data for normal use. Such information may nevertheless be processed where it is contained in Customer Data supplied or made accessible by Customer.

Frequency

As required during Customer's use of the Service.

Controller rights and obligations

As set out in the Agreement and this DPA.

Annex II — Technical and Organisational Measures

Ida currently maintains technical and organisational measures including:

Access and tenant isolation

  • database-enforced tenant isolation;
  • role-based and least-privilege access controls; and
  • separation of administrative and application privileges.

Authentication and encryption

  • authenticated access to the Service;
  • TLS encryption for data in transit;
  • encryption at rest through Ida's infrastructure providers; and
  • encryption of stored connector credentials and OAuth tokens using AES-256-GCM with encryption keys stored separately from the database.

Data minimisation

  • technical measures designed to limit the Customer Data retained by Ida to that required for the Service; and
  • deletion of applicable stored integration data and derived data when integrations are disconnected or Customer Data is erased, subject to applicable retention requirements.

Logging and accountability

  • recording of material system actions, approvals and execution events with attribution where applicable;
  • application and error logs restricted to technical and identifier data, excluding the content of Customer Data; and
  • monitoring of service availability with automated alerting on faults.

Retention and deletion

  • technical processes supporting organisation deletion, user deletion, export and Data Subject erasure; and
  • encrypted backups subject to a defined retention and deletion cycle.

Ida may update these measures in accordance with section 4.4.

© 2026 IDAHELLO@IDASOLUTIONS.CO.UK
PRIVACYTERMSDATA PROCESSINGSUB-PROCESSORS
MADE IN THE UK