Neea Pulse legal
Data Processing Addendum
Processor terms incorporated into the Neea Pulse Terms where a customer provides personal data for us to process on its behalf.
Effective and last updated: 6 October 2026
1. Parties and roles
This addendum forms part of the agreement between NEEA STUDIOS LTD (“Processor”) and the customer (“Controller”). It applies where Processor handles personal data on Controller’s behalf through Neea Pulse. Each party will comply with applicable data-protection law, including UK GDPR and the Data Protection Act 2018.
2. Processing details
The subject is provision of the subscription service. Processing lasts for the subscription plus the deletion and backup period. It may include collection, organisation, storage, retrieval, enrichment, analysis, communication, suppression, export, and deletion. Data may concern customer users, prospects, business contacts, recipients, and correspondents, and may include identity, professional contact, source, targeting, campaign, delivery, reply, objection, and audit information. Customers must not provide special-category or criminal-offence data unless separately agreed in writing.
3. Documented instructions
Processor will process personal data only on Controller’s documented instructions, including the agreement and configured use of the service, unless law requires otherwise. Processor will notify Controller if an instruction appears to infringe applicable data-protection law and may suspend the affected processing.
4. People and security
Processor ensures authorised personnel are bound by confidentiality and applies measures appropriate to risk, including access control, tenant separation, authentication, encryption in transit, backups, logging, vulnerability management, and incident procedures. Controller is responsible for user access, lawful content, exports, and secure configuration.
5. Subprocessors and transfers
Controller gives general authorisation for subprocessors needed for hosting, databases, email delivery, payments, monitoring, support, and verification. Processor remains responsible for imposing materially equivalent data-protection obligations. Processor will provide current subprocessor information on request and reasonable notice of material changes. Restricted international transfers will use an applicable UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard.
6. Assistance
Taking account of the processing and information available, Processor will reasonably assist Controller with data-subject requests, security, breach assessment and notification, impact assessments, and regulator consultation. Controller remains responsible for responding to individuals and determining whether notification is required.
7. Incidents
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller data and provide available information reasonably needed for Controller’s obligations. Notification is not an admission of fault or liability.
8. Return and deletion
On termination, Controller may export available data during the applicable access period. Processor will delete or return personal data at Controller’s choice unless law requires retention. Data may remain temporarily in protected backups and legal, fraud-prevention, audit, or suppression records, where it will remain restricted.
9. Information and audit
Processor will provide information reasonably necessary to demonstrate compliance. No more than once annually, unless following a material incident or regulator request, Controller may request a proportionate audit. Audits require reasonable notice, confidentiality, minimal disruption, use of existing independent reports first, and reimbursement of reasonable costs where the request exceeds standard information.
10. Controller warranties
Controller warrants that it has a lawful basis, provides required transparency, respects marketing objections, issues lawful instructions, and has all rights needed for the data. Controller will not instruct Processor to breach law. Liability under this addendum is subject to the agreement’s lawful limitations.