Data Processing Agreement
Effective date: 15 June 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between equate ltd (“equate”, “Processor”) and the customer using the equate Service (“Controller”). It sets out the terms on which equate processes personal data on behalf of the Controller in connection with the Service.
This DPA applies where the Controller uploads or otherwise provides personal data to equate as part of using the Service, for example data contained within supplier invoices, booking records, or related documents.
1. Definitions
In this DPA, “personal data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given to them in the UK GDPR and the Data Protection Act 2018.
2. Roles of the parties
The Controller determines the purposes and means of processing personal data uploaded to the Service. equate processes that personal data only on the instructions of the Controller and only for the purpose of providing the Service. equate is the Processor for that data.
equate is the Controller for personal data about the Controller’s users (such as names and email addresses used for account management). This is governed by the Privacy Policy.
3. Subject matter and nature of processing
equate processes personal data for the following purposes on behalf of the Controller:
- extraction of structured data from supplier invoice documents;
- matching extracted data against the Controller’s booking records;
- storage and retrieval of processed invoices and results;
- workflow management, review queues, and audit logging;
- transmission of results to the Controller’s connected systems as configured by the Controller.
The types of personal data processed may include names, reference numbers, contact details, and financial information relating to the Controller’s customers, suppliers, and staff, as contained in uploaded documents. The Controller is responsible for informing affected data subjects about this processing.
4. Instructions
equate will process personal data only on the documented instructions of the Controller, including those set out in the Controller’s use of the Service (for example, pipeline configurations and integration settings). equate will inform the Controller promptly if, in its opinion, any instruction infringes applicable data protection law.
5. Confidentiality
equate will ensure that all personnel authorised to process personal data are bound by an appropriate duty of confidentiality.
6. Security
equate will implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and accidental loss, destruction, or damage. These measures include AES-256 encryption at rest, TLS 1.3 in transit, access controls, and audit logging.
7. Sub-processors
The Controller authorises equate to engage sub-processors to provide the Service. equate will make an up-to-date list of its sub-processors available to the Controller on request, and will notify the Controller of any intended addition or replacement of a sub-processor, giving the Controller an opportunity to object. equate remains responsible to the Controller for the performance of its sub-processors.
8. Data subject rights
equate will, to the extent possible, assist the Controller in responding to data subject rights requests (access, rectification, erasure, restriction, portability, and objection) relating to personal data processed under this DPA.
9. Security incidents
equate will notify the Controller without undue delay (and no later than 72 hours where feasible) after becoming aware of a personal data breach affecting the Controller’s data. The notification will include the information reasonably available at that time to help the Controller meet its own notification obligations.
10. Data protection impact assessments
equate will provide reasonable assistance to the Controller in carrying out data protection impact assessments and prior consultations where required.
11. Return and deletion
On termination of the agreement, equate will, at the Controller’s choice, delete or return all personal data processed under this DPA and delete existing copies, unless applicable law requires retention.
12. Audit and information
equate will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. equate will allow for and contribute to audits conducted by the Controller or an auditor appointed by the Controller, provided that the Controller gives reasonable notice, the audit is conducted during business hours, and the Controller bears the cost.
13. International transfers
Where personal data is transferred to a sub-processor in a country outside the UK or EEA, equate will ensure that an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement (IDTA) or standard contractual clauses.
14. Governing law
This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.
15. Contact
For questions about this DPA, please contact us at hello@equatetravel.ai or write to us at 167–169 Great Portland Street, London, England, W1W 5PF.