This Data Processing Agreement ("DPA") forms part of the Terms of Service between Clearpath Labs Ltd - trading as SnapAddress - and the customer. It applies automatically to every account from the moment you create an account or use the Service; no signature is needed.
For the personal data contained in the address-lookup queries you submit, you are the controller and we are your processor. This DPA is the written processing contract that UK GDPR Article 28 requires for that processing.
1. Parties and roles
- Processor: Clearpath Labs Ltd (company no. 17145150, registered office 35 Floyer Close, Richmond, England, TW10 6HS), trading as SnapAddress ("we", "us").
- Controller: the customer (the account holder) ("you").
2. Subject-matter, nature and purpose of the processing
Processing of UK address-lookup queries you submit, to provide the Service: postcode and address autocomplete and validation against our own licensed copy of Royal Mail PAF data.
3. Duration
This DPA applies for the term of your account.
4. Types of personal data and categories of data subject
- Personal data: postcodes and partial address data contained in your lookup queries. (Your own account and billing data is covered by the Privacy Policy, where we act as controller, not by this DPA.)
- Data subjects: your end users - the people whose addresses are looked up through your application.
We do not store the addresses returned to your end users. We log the postcode queried for billing and abuse prevention; retention periods are set out in the Privacy Policy.
5. Our obligations as processor (Article 28(3))
We will:
- (a) process the personal data only on your documented instructions (including for international transfers), unless we are required to process it by law - in which case we will inform you before processing, unless the law prohibits it;
- (b) ensure that the people authorised to process the personal data are under a duty of confidentiality;
- (c) implement the technical and organisational security measures required by Article 32;
- (d) engage sub-processors only under the conditions in clause 6;
- (e) assist you, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights;
- (f) assist you with your security, breach-notification, data protection impact assessment and prior-consultation obligations, taking into account the nature of the processing and the information available to us;
- (g) at your choice, delete or return all personal data at the end of the provision of the Service, and delete existing copies unless we are required by law to retain them (for example, tax records and Royal Mail PAF audit records, which we hold in non-identifying form); and
- (h) make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
6. Sub-processors
You give general authorisation for us to use the sub-processors listed below. We will give you notice by email of any intended addition or replacement, giving you the opportunity to object. Where we engage a sub-processor, we impose data-protection obligations equivalent to those in this DPA, and we remain liable to you for its performance.
- Supabase - authentication and database hosting (EU region).
- Stripe - payment processing (US).
- Vercel - website and API hosting (UK/London function region).
- AWS (Amazon Web Services) - address-lookup API infrastructure (UK/London region).
- Resend - transactional and lifecycle email (US).
- Sentry - error monitoring and diagnostics (EU region).
Royal Mail is not a sub-processor: it is the licensor and source of the PAF data. We query our own licensed copy of PAF and do not send your lookup queries to Royal Mail.
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and will provide the information you need to meet your own notification obligations (including the 72-hour window for notifying the ICO).
8. International transfers
Where a sub-processor processes personal data outside the UK/EEA (currently Stripe and Resend, both in the US), we rely on the UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) where the sub-processor is certified under it, and otherwise on the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) in that sub-processor's data processing agreement.
Contact
Questions about this DPA? Email snapaddress@clearpathlabs.co.uk.