Data Processing Agreement
Last updated: 8 September 2026.
This Data Processing Agreement (DPA) forms part of the PricingLens Terms of Service between the customer (the Controller) and Universal Global Services (UK corporate entity, EU/UK VAT via Ireland OSS, the Processor). TODO(S8): confirm exact legal entity name, company registration number and registered office address with the Chairman before public launch.
1. Scope
This DPA applies to personal data processed by PricingLens on behalf of the Controller, including account data and the product/competitor pricing data submitted by the Controller for pricing audits and monitoring. To the extent the Controller is a business customer, the Processor acts as a data processor; where the Controller is an individual consumer, the Privacy Policy applies instead.
2. Processing instructions
The Processor processes personal data only on documented instructions from the Controller, unless required otherwise by law. The subject matter is the provision of automated pricing audit and competitor price monitoring, including crawling public pricing pages that the Controller has submitted and analyzing them with our LLM gateway to produce reports and alerts. PricingLens does not set the Controller's prices automatically.
3. Sub-processors
The Processor uses sub-processors including Stripe (payments and tax), hosting and LLM infrastructure providers. The Processor remains responsible for its sub-processors and will inform the Controller of material changes through the Service. The Processor does not sell personal data.
4. Security
The Processor implements appropriate technical and organisational measures including tenant isolation using per-tenant row-level security, encryption in transit, access controls, secret scanning, backups and monitoring.
5. Data subject rights and assistance
The Processor will assist the Controller in responding to data subject requests and in complying with obligations under applicable data protection law. Contact [email protected] for assistance.
6. Breach notification
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
7. International transfers
To the extent personal data is transferred outside the UK or EEA, transfers are protected by UK or EU Standard Contractual Clauses or an equivalent lawful transfer mechanism.
8. Retention and deletion
The Processor retains Controller data while the account is active and for as long as needed to provide the Service and meet legal obligations. On termination the Controller may export or request deletion of personal data through the self-serve GDPR export/delete flow in settings or by writing to [email protected].
9. Contact
[email protected] · Support: [email protected]
See also: Privacy Policy · Terms of Service · Refund Policy · Cookie Policy