Data processing agreement
Last updated 27 September 2026.
This is our template data processing agreement for organisation accounts, under Article 28 of UK GDPR. We offer it to every organisation that uses Explain a Paper through a team account, and we will sign it with yours on request: email [email protected] with your organisation's legal name and address and the name of the person signing. It applies alongside our terms and privacy policy.
1. The parties
The controller is the organisation that holds the team account and signs this agreement ("you").
The processor is Digital Tactics Ltd., a private limited company registered in England and Wales, company number 07666910, registered office Ground Floor, 19 New Road, Brighton, East Sussex BN1 1UF, ICO registration Z2807798 ("we"), which provides Explain a Paper.
2. Definitions
"Data protection law" means UK GDPR, the Data Protection Act 2018 and, where it applies to the processing, the EU GDPR. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in data protection law. "Your personal data" means the personal data described in Annex 1 that we process for you.
3. Scope and instructions
We process your personal data only to provide the service described in our terms, which is your documented instruction, and on any further written instructions you give us. If we are required by law to process it otherwise, we will tell you first unless the law forbids it. We will tell you promptly if we believe an instruction breaks data protection law.
You are responsible for having a lawful basis for giving us your personal data and for telling the people it concerns, including the authors of papers you upload. You will not upload data that identifies research participants, or special category data, unless we have agreed it in writing first.
4. Confidentiality
Everyone we authorise to process your personal data is bound by a duty of confidentiality, and only staff who need it to make your films can reach it.
5. Security
We take the technical and organisational measures described in Annex 3, appropriate to the risk, as Article 32 requires, and keep them under review.
6. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex 2. We will tell you at least 30 days before we add or replace one, and you may object on reasonable data protection grounds; if we cannot address the objection, you may end the agreement and the subscription without penalty. We impose data protection terms on each sub-processor that are no less protective than this agreement, and remain responsible to you for its work.
7. International transfers
Where a sub-processor processes your personal data outside the UK, we make sure the transfer is covered by an adequacy regulation, such as the UK Extension to the EU-US Data Privacy Framework where the sub-processor is certified under it, or by the International Data Transfer Agreement or Addendum approved by the Information Commissioner.
8. Helping you meet your obligations
Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights, and we will pass on to you any such request we receive directly. We will give you reasonable help with security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner.
9. Personal data breaches
We will tell you without undue delay after becoming aware of a personal data breach affecting your personal data, with the information you need to meet your own obligations, and will keep you informed as we investigate and contain it.
10. Deletion and return
We delete uploaded papers and working files 90 days after you accept a film, and papers for films never submitted after 7 days. Finished films stay in your account until you delete them or close it. When the agreement ends, we delete your personal data, or return it first if you ask within 30 days, unless the law requires us to keep it. Records of each sale are kept for six years, as UK accounting and tax law requires. Material sent to our language-model provider for a paper that is not flagged confidential or embargoed may be kept by that provider for the limited period set out in Annex 2.
11. Audits and information
We will make available the information you reasonably need to show that this agreement is being met, and allow for and contribute to audits and inspections by you or an auditor you appoint, on reasonable notice, at reasonable times, and under a duty of confidentiality.
12. Duration, liability and law
This agreement lasts as long as we process your personal data for you. Each party's liability under it is subject to the limits in our terms, except where data protection law does not allow a limit. It is governed by the law of England and Wales, and the courts of England and Wales have jurisdiction. If this agreement and our terms conflict on the processing of your personal data, this agreement prevails.
Annex 1: The processing
- Subject matter and purpose
- Making, revising and delivering explainer films of papers your team uploads, and running your team account.
- Nature of the processing
- Storing, reading and summarising papers; drafting scripts with the help of a language model; preparing, reviewing, rendering and delivering films; deleting files when their retention period ends.
- Duration
- For as long as your team account is open, subject to the deletion periods in section 10.
- Categories of data subject
- Authors of the papers you upload and people named or acknowledged in them; your team's members, as far as they appear in the papers, instructions and change requests you give us.
- Types of personal data
- Names, affiliations, roles and contact details that appear in papers; anything else a paper contains; names and instructions in change requests.
- Special category data
- None is expected. Participant data must be removed before upload (section 3).
Annex 2: Sub-processors
- Cloudflare, Inc.: hosting, database, file storage and message queues for the site; protection of forms from automated abuse.
- Resend (Resend Inc.): sending account, order and delivery emails. Mail is sent from the EU; Resend Inc. is US-based.
- Anthropic PBC (Claude, commercial API): helping draft scripts. No use of Customer material for model training. Papers not flagged confidential or under embargo are processed under Anthropic's standard commercial terms, which let it keep inputs and outputs for safety and abuse monitoring for up to 30 days (up to 2 years where its automated systems flag a breach of its usage policy); the Customer's user accepts this when submitting each such paper. Confidential or embargoed papers only under a zero-data-retention arrangement or with a private model on infrastructure we control, and until one is in place they are not processed. Or, at the Customer's request, under the Customer's own Anthropic API key and agreement. Location: United States.
Stripe, which processes payments, acts as a separate controller for payment information and receives no papers.
Annex 3: Security measures
- All traffic to the site is encrypted with TLS, and papers are stored in private storage with no public access.
- Papers are never served back through the site; staff download them only through an access-controlled console that requires multi-factor sign-in.
- Sign-in is by single-use email links that expire after 15 minutes; only hashes of sign-in links and sessions are stored.
- Every staff action on accounts, credits and films is recorded in an audit log.
- Papers are sent to a language model only through its commercial API under no-training terms, never to consumer chat apps. Papers flagged confidential or embargoed go only to a model under zero data retention or to a private model on infrastructure we control, and are marked on every staff screen.
- Database backups are taken regularly and restores are rehearsed.