Data Processing Addendum

This Data Processing Addendum forms part of our Terms of Service and sets out how we process personal data on your behalf when you use ascend LLM.

Last Updated: August 6, 2026

1. Definitions

"UK GDPR" means the UK General Data Protection Regulation as incorporated into UK law, read with the Data Protection Act 2018. "EU GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor" and "data subject" have the meanings given in those laws. "Customer Personal Data" means personal data contained in Customer Data (as defined in the Terms of Service) that we process on your behalf to provide the Service. "Data protection law" means the UK GDPR, the EU GDPR where applicable, and any other privacy law applicable to the processing under this DPA.

2. Roles and scope

You are the controller of Customer Personal Data (or a processor acting on behalf of your own clients), and we act as your processor (or sub-processor). Annex 1 describes the subject matter, duration, nature and purposes of the processing, the categories of data subjects and the types of personal data. Each party will comply with its own obligations under applicable data protection law. Where you act as a processor for your own clients, you warrant that the instructions you give us are authorised by the relevant controller and that you have made the disclosures and obtained the permissions needed for us to process the data as described.

3. Processing on your instructions

We process Customer Personal Data only on your documented instructions, which consist of the Terms of Service and this DPA, your configuration of the Service, and your use of its features, unless we are required to process otherwise by law (in which case we will inform you before processing, unless the law prohibits it). We will inform you if we believe an instruction infringes data protection law, and we may pause the affected processing until the issue is resolved.

4. Confidentiality

We ensure that every person we authorise to process Customer Personal Data, including our staff and contractors, is bound by contractual or statutory confidentiality obligations.

5. Security

We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. The current measures are described in Annex 2. We will assist you, to a reasonable extent and taking into account the information available to us, in meeting your own security obligations under data protection law.

6. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex 3. We will notify you by email or in the app at least 30 days before we add or replace a sub-processor. You may object in writing within that period on reasonable data-protection grounds. If we cannot offer a solution, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period. We impose on every sub-processor data protection obligations materially equivalent to this DPA, and we remain responsible for their performance.

7. Data subject requests

Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights, such as access, rectification, erasure or portability. If a data subject contacts us directly about data processed on your behalf, we will forward the request to you without undue delay and will not respond on the merits, except where required by law.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include the information reasonably available to us, such as the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We may provide information in phases as it becomes available and will not delay the initial notice solely because every detail is not yet known. We will cooperate with you and provide reasonable assistance for your own notification obligations to the ICO or another competent authority.

9. Impact assessments

We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to the Service and taking into account the information available to us.

10. International transfers

We host Customer Personal Data in the United Kingdom or the European Economic Area. Where a sub-processor processes Customer Personal Data outside the UK or the EEA, we ensure a lawful transfer mechanism, such as UK adequacy regulations, an adequacy decision of the European Commission, the UK International Data Transfer Addendum, or the Standard Contractual Clauses, together with supplementary measures where needed. Details for each provider are set out in Annex 3.

11. Audits and information

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, including responses to reasonable written security questionnaires. You may audit our compliance with this DPA no more than once every 12 months, on at least 30 days written notice, during business hours, without disrupting our operations, at your own cost, under confidentiality, and without access to data of other customers. The frequency and notice limits do not apply where an audit is reasonably required following a suspected or confirmed personal data breach, credible evidence of material non-compliance, or a request from a competent supervisory authority. In those cases, you will give the notice that is reasonable in the circumstances. Where possible, we will first satisfy audit requests with documentation and third-party attestations. If an audit reveals material non-compliance, we will remediate it without undue delay.

12. Return and deletion of data

When the processing ends, at your choice we will return Customer Personal Data to you and delete existing copies, or delete it, unless we are required by law to keep it. You can make that choice in writing during your subscription or within 30 days after termination. During that period, we will on request make a reasonable export available as described in the Terms of Service. If you give no instruction, you instruct us to delete the data. We complete deletion within 90 days after termination, except for backup copies that are overwritten in the normal backup cycle and data we must retain by law, which remains protected under this DPA until deleted. On written request, we will confirm deletion.

13. Liability

The exclusions and limitations of liability in the Terms of Service apply to this DPA to the maximum extent permitted by law, and the combined liability under the Terms and this DPA is subject to a single aggregate cap. These contractual limits apply only between you and us. They do not limit the rights of data subjects, the powers of supervisory authorities, or any liability that applicable data protection law does not permit the parties to exclude or limit.

14. Term, precedence and changes

This DPA applies for as long as we process Customer Personal Data under the Terms of Service. For data-protection subject matter, this DPA prevails over the Terms. We may update this DPA following the change mechanics of the Terms. Changes needed to comply with data protection law may take effect on shorter notice, and we will inform you of them.

Annex 1: Details of processing

Subject matter: provision of the ascend LLM platform, the optional features selected by the Customer, and related managed services and support. Duration: the term of your subscription plus the return and deletion period described in Section 12. Raw log files you upload for AI crawler analytics are retained for up to 30 days after processing. Nature and purposes: hosting, storage, analysis, reporting, connected web analytics, AI crawler and referral analytics, shared or embedded reports, AI-assisted features you request, support, security and service improvement as instructed through your use of the Service. Categories of data subjects: your users and staff; your clients and viewers of shared or embedded reports; website visitors or leads whose personal data is included in a connected analytics source or a log source you provide; and individuals whose personal data appears in public sources analysed by the Service. Categories of personal data: identification and contact details such as names and email addresses, business and professional details, aggregated traffic, session and conversion data, page URLs and referrers, viewer activity, technical request and log data included in sources you provide, and content data contained in those sources. Special categories: none intended. You agree not to submit special category data to the Service.

Annex 2: Technical and organisational measures

Our measures include: hosting with reputable providers in the UK or the EEA; encryption of data in transit using TLS; encryption of data at rest; access controls based on least privilege and role-based permissions; multi-factor authentication for administrative access; logging and monitoring of production systems; separation of production and non-production environments; regular backups with defined retention; personnel confidentiality commitments and security training; due diligence on sub-processors; documented incident response procedures; and secure development practices, including code review and dependency updates.

Annex 3: Sub-processors

We engage the following categories of sub-processors to provide the Service: - cloud hosting and database infrastructure (UK or EEA regions); - email delivery and customer communications; - payment processing and invoicing; - product analytics and error monitoring; - customer support and ticketing; - third-party AI model providers used to generate optional AI-assisted outputs. A current, named list of sub-processors, the purpose of each and their processing regions is available on request from hello@ascendllm.co.uk. Changes are notified as described in Section 6 of this DPA.

Contact

Questions about this DPA, or requests to sign a counter-signed copy, should be sent to: Serendipity Int Ltd (trading as ascend LLM) Causeway House, 13 The Causeway, Teddington, TW11 0JR, United Kingdom Email: hello@ascendllm.co.uk Website: https://ascendllm.co.uk
Back to home