Legal Centre

Data Processing Agreement and Subprocessor List

COLLABOR TECHNOLOGIES LTD, company number 16888312, registered in England and Wales

Last edited 1 September 2026

Download PDF

1. Parties and application

This DPA is between COLLABOR TECHNOLOGIES LTD, a company registered in England and Wales under company number 16888312, with registered office at Egerton Mill, 25–27 Egerton Street, Chester, United Kingdom, CH1 3ND (“Collabor”), and the Brand, Agency or other organisation identified as the customer under the Main Agreement (“Customer”). This DPA applies only to the extent that Collabor processes Customer Personal Data as a Processor on the Customer’s behalf. It is incorporated into the Brand Platform Agreement, subscription, order form or other agreement governing the Customer’s use of Collabor (the “Main Agreement”) and takes effect when the Main Agreement takes effect. If the Customer is an Agency processing personal data for a Brand or another client, the Customer warrants that it is authorised to appoint Collabor as a subprocessor and to give the instructions contained in this DPA. The Customer remains responsible for its obligations to the relevant controller. This DPA does not require a separate signature where it is validly incorporated into an electronically accepted Main Agreement. If the parties sign a customer-specific version, that version prevails to the extent expressly stated.

2. Definitions

In this DPA: “Applicable Data Protection Law” means privacy and data-protection law applying to the Processing, including the UK GDPR, the Data Protection Act 2018, applicable provisions introduced or amended by the Data (Use and Access) Act 2025, the EU GDPR where applicable, and legally binding replacement or implementing legislation. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process” and “Processing” have the meanings given by Applicable Data Protection Law. “Customer Personal Data” means Personal Data Processed by Collabor on the Customer’s documented instructions in providing the Processor Services. It does not include information for which Collabor determines the purposes and essential means of Processing as an independent Controller. “Processor Services” means the campaign, collaboration, messaging, file-sharing, workflow, reporting and related platform functionality described in the Main Agreement and Schedule 1. “Restricted Transfer” means a transfer of Personal Data requiring an adequacy decision, approved safeguard, transfer mechanism or equivalent protection under Applicable Data Protection Law. “Subprocessor” means a third party appointed by or for Collabor to Process Customer Personal Data on Collabor’s behalf in delivering the Processor Services.

3. Roles and scope

For Customer Personal Data, the Customer is the Controller and Collabor is the Processor. Where the Customer is itself a Processor, Collabor is its Subprocessor. Each party must comply with the obligations applying to its role. The Customer determines the lawfulness, purposes and essential means of Processing Customer Personal Data. Collabor Processes that data only to provide, secure and support the Processor Services and as otherwise instructed in accordance with this DPA. Collabor may act as an independent Controller for separate activities including account administration, platform security, fraud prevention, legal compliance, tax and accounting, payment administration, sanctions screening, enforcing platform rules, handling disputes and legal claims, maintaining the Creator Discovery service, and developing aggregated or effectively de-identified service insights. Those activities are governed by Collabor’s Privacy Notice and are outside this DPA. Payment providers, social platforms, identity-verification services and other third parties may act as independent Controllers for some or all of their activities. Their independent Processing is not converted into subprocessing merely because the service is connected to Collabor.

4. Customer instructions

The Main Agreement, the Customer’s permitted use of the Processor Services, configuration choices, campaign actions and documented support requests constitute the Customer’s instructions to Collabor. Collabor must Process Customer Personal Data only on documented instructions from the Customer, including regarding Restricted Transfers, unless law binding on Collabor requires otherwise. Where legally permitted, Collabor will notify the Customer before Processing required by law. Collabor will inform the Customer without undue delay if it reasonably believes an instruction infringes Applicable Data Protection Law. Collabor may suspend the affected Processing until the parties agree a lawful instruction. Collabor is not required to provide legal advice. The Customer must ensure that its instructions are lawful, proportionate and within the Processor Services. The Customer must not instruct Collabor to Process Personal Data that the Customer lacks authority or a lawful basis to use.

5. Customer responsibilities

The Customer is responsible for: ● providing all privacy notices and obtaining any permissions, consents or other lawful basis required for Customer Personal Data; ● ensuring its collection, use, disclosure and instructions comply with Applicable Data Protection Law and the Main Agreement; ● configuring access permissions appropriately and ensuring authorised users protect their credentials; ● responding to Data Subjects and regulators where the Customer is responsible as Controller; ● avoiding unnecessary special-category, criminal-offence or children’s data; and ● providing accurate contact details for security, privacy and subprocessor-change notices. The Customer must not upload special-category data, criminal-offence data or information about children unless the Processing is necessary, lawful, within the Processor Services and expressly approved by Collabor in writing with any additional safeguards Collabor reasonably requires.

6. Confidentiality and personnel

Collabor will ensure that persons authorised to Process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and receive proportionate privacy and security instruction. Collabor will limit access to personnel and contractors who need it for the Processor Services, support, security, incident response or other documented instructions, applying role-based or otherwise appropriate access controls.

7. Security

Taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of Processing, as well as the risk to individuals, Collabor will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current measures are described in Schedule 2. Collabor may update them where the overall level of protection is not materially reduced. No security measure can eliminate every risk, and this clause does not create a warranty that a security incident will never occur.

8. Personal Data Breaches

Collabor will notify the Customer without undue delay and, where feasible, within 48 hours after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. An initial notice may be provided in stages as information becomes available. The notice will, to the extent reasonably known, describe: ● the nature of the breach and affected data or Data Subjects; ● the likely consequences; ● measures taken or proposed to contain, investigate and remediate it; and ● a contact route for follow-up information. Collabor will take reasonable steps to contain and remediate the breach and provide information reasonably required for the Customer’s assessment and legally required notifications. Collabor’s notice is not an admission of fault or liability. The Customer is responsible for notifying regulators, Data Subjects or other parties unless Applicable Data Protection Law requires Collabor to do so directly. The parties will coordinate communications where reasonably practicable.

9. Data Subject requests

Taking account of the nature of the Processing, Collabor will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests to exercise Data Subject rights. If Collabor receives a request relating solely to Customer Personal Data, it will forward the request to the Customer without undue delay unless prohibited by law. Collabor will not respond substantively except on the Customer’s instructions or where legally required. The Customer remains responsible for determining whether and how to respond. Collabor may require sufficient information to authenticate the Customer, locate the relevant data and prevent unauthorised disclosure.

10. Regulatory assistance

Taking account of the nature of Processing and information available to Collabor, Collabor will provide reasonable assistance with the Customer’s obligations concerning security, breach assessment, data-protection impact assessments, prior consultation and regulator enquiries. If assistance materially exceeds the ordinary Processor Services, Collabor may charge reasonable fees agreed in advance, unless the assistance is required because Collabor breached this DPA.

11. Subprocessors

The Customer gives Collabor general written authorisation to appoint the Affiliates and third-party Subprocessors identified in the current Subprocessor Register described in Schedule 3. Collabor will require each Subprocessor by written agreement to protect Customer Personal Data to a standard materially equivalent to the applicable obligations in this DPA, including confidentiality, security, deletion and Restricted Transfer requirements. Collabor remains responsible to the Customer for a Subprocessor’s performance of the data-protection obligations subcontracted to it, subject to the liability provisions of the Main Agreement and mandatory law.

11.1 New and replacement Subprocessors

Collabor will give at least 30 days’ advance notice of a proposed new or replacement Subprocessor that will Process Customer Personal Data, ordinarily through the Customer’s account, a designated contact address or the Help Centre. Where an urgent change is reasonably necessary for security, continuity or legal compliance, Collabor may give notice as soon as reasonably practicable. The Customer may object within 15 days after notice, solely on reasonable and documented data-protection grounds. The parties will work in good faith to resolve the objection, including by considering commercially reasonable safeguards or an alternative configuration. If no reasonable resolution is available, Collabor may elect not to appoint the Subprocessor for that Customer or either party may terminate the affected Processor Service on written notice. Termination does not affect accrued rights, payment obligations or unaffected services.

12. International transfers

Collabor will not make a Restricted Transfer of Customer Personal Data unless the transfer is permitted by an applicable adequacy decision, binding corporate rules, approved contractual clauses, an applicable statutory exception or another lawful transfer mechanism. For transfers governed by the UK GDPR, the parties will use the current UK International Data Transfer Agreement or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, as appropriate, together with any required data protection test or transfer risk assessment and supplementary measures. For transfers governed by the EU GDPR, the applicable modules of the European Commission Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914 will apply where required, together with any required transfer impact assessment and supplementary measures. The relevant approved transfer clauses are incorporated by reference to the extent legally permitted and required for a Restricted Transfer. If mandatory transfer clauses conflict with this DPA, the mandatory clauses prevail for the affected transfer. Collabor will provide reasonable information about relevant transfer locations and safeguards through the Subprocessor Register or on request, subject to appropriate confidentiality and security restrictions.

13. Deletion and return

During the term, the Customer may access, export or delete Customer Personal Data using available platform functionality. On termination or expiry of the Processor Services, Collabor will, at the Customer’s choice and subject to a timely written request, return or delete Customer Personal Data unless law requires retention. If the Customer makes no different lawful request, Collabor will delete or render inaccessible Customer Personal Data from active systems within a commercially reasonable period, ordinarily no later than 90 days after termination. Residual copies in backups may remain until overwritten under the ordinary backup cycle, provided they remain protected and are not restored except for continuity, security or legal purposes. Collabor may retain data where required by law or reasonably necessary to establish, exercise or defend legal claims, but will isolate and protect it and Process it only for that purpose. This section does not apply to data Collabor retains as an independent Controller.

14. Records, information and audits

Collabor will maintain information reasonably necessary to demonstrate compliance with the Processor obligations in this DPA and will make relevant information available to the Customer on reasonable request. The Customer should first use current security documentation, questionnaires, certifications or independent audit materials that Collabor makes available. If those materials are insufficient to demonstrate compliance, the Customer may request an audit no more than once in any 12-month period, unless a Personal Data Breach, regulator requirement or reasonable evidence of material non-compliance justifies an additional audit. An audit must be conducted on reasonable written notice, during normal business hours, by the Customer or an independent auditor bound by confidentiality. It must minimise disruption and must not expose another customer’s data, privileged information, trade secrets or security-sensitive details beyond what is reasonably necessary. The Customer bears reasonable audit costs unless the audit identifies a material breach by Collabor. Collabor may satisfy an on-site request through a suitable independent assessment where that provides materially equivalent assurance.

15. Government and third-party demands

Unless prohibited by law, Collabor will notify the Customer of a legally binding demand specifically requiring disclosure of Customer Personal Data. Collabor may challenge an unlawful or disproportionate demand where reasonably appropriate but is not required to pursue litigation. Where notice is prohibited, Collabor will use reasonable efforts to preserve the confidentiality of Customer Personal Data and disclose only the information legally required.

16. Charges

Ordinary compliance with this DPA is included in the Processor Services. Collabor may charge reasonable fees for exceptional, repetitive or Customer-specific assistance, exports, audits or configuration work that materially exceeds the standard service, provided fees are communicated in advance. No fee applies where the work is required to remedy Collabor’s breach.

17. Liability

Each party’s liability arising from this DPA is subject to the exclusions, limitations and remedies in the Main Agreement, except to the extent a limitation is prohibited by Applicable Data Protection Law. Nothing in this DPA limits an individual’s rights or a regulator’s powers.

18. Term and precedence

This DPA remains in force while Collabor Processes Customer Personal Data on the Customer’s behalf. Provisions concerning confidentiality, deletion, audits, liability and Restricted Transfers survive for as long as relevant Customer Personal Data remains in Processing. If this DPA conflicts with the Main Agreement on the protection of Customer Personal Data, this DPA prevails. Mandatory approved transfer clauses prevail over both for the Restricted Transfer they govern.

19. Governing law and jurisdiction

Unless mandatory law or applicable approved transfer clauses require otherwise, this DPA and related non-contractual obligations are governed by the law and jurisdiction specified in the Main Agreement. If the Main Agreement is silent, the laws of England and Wales apply and the courts of England and Wales have exclusive jurisdiction.

20. Notices and contact

Privacy, DPA and Subprocessor Register requests must be submitted through the relevant privacy or support route in Collabor’s Help Centre. Contractual notices may also be sent to the notice route specified in the Main Agreement. Postal address: COLLABOR TECHNOLOGIES LTD, Egerton Mill, 25–27 Egerton Street, Chester, United Kingdom, CH1 3ND. Schedule 1 — Processing details A. Subject matter and duration Processing Customer Personal Data to provide, secure, maintain and support the Processor Services. Processing continues for the term of the Main Agreement and the deletion or return period described in section 13. B. Nature and purpose Receiving, recording, organising, hosting, storing, retrieving, viewing, transmitting, sharing at the Customer’s direction, securing, backing up, supporting, correcting, exporting, deleting and otherwise Processing Customer Personal Data as necessary to: ● administer the Customer’s organisation, users and access permissions; ● create and manage campaigns, briefs, shortlists, approvals, milestones and deliverables; ● enable authorised messages, uploads and collaboration between the Customer and Creators; ● produce Customer-requested campaign reports, records and exports; ● provide technical support, continuity, security and fraud-prevention functions relating to the Processor Services; and ● follow other lawful documented instructions within the scope of the Main Agreement. C. Categories of Data Subjects Customer personnel, authorised users and representatives; Brand and Agency contacts; Creators, Creator representatives and campaign participants; and individuals whose Personal Data the Customer lawfully includes in campaign materials, communications or files. D. Types of Personal Data Names, usernames, business contact details, organisation and role information; social-profile and professional information; campaign preferences, shortlists, notes and status information; messages and support communications; content, files, briefs, approvals and deliverables; account, access, log, device and usage information; payment status, invoice references and transaction identifiers; and other Personal Data submitted by the Customer within the permitted Processor Services. E. Special-category and children’s data Not intended. The Customer must not provide special-category, criminal-offence or children’s data except as permitted under section 5 and any additional written terms. F. Processing frequency Continuous or as initiated by authorised users during the term, with periodic backups, security monitoring and support Processing. Schedule 2 — Technical and organisational measures Collabor will maintain measures appropriate to the risk, including where relevant: ● access controls based on business need, authentication requirements and account-permission management; ● encryption of Customer Personal Data in transit and, where supported by the relevant service, at rest; ● confidentiality obligations, security awareness and controlled personnel access; ● logging, monitoring and procedures designed to detect suspicious or unauthorised access; ● vulnerability management, security updates and proportionate secure-development practices; ● backup, recovery, service-continuity and incident-response arrangements appropriate to the service; ● supplier due diligence and written data-protection and confidentiality controls; ● data minimisation, retention controls and secure deletion or access restriction; ● procedures for responding to Data Subject requests, security incidents and regulator enquiries; and ● periodic review and improvement of security measures having regard to risk and material service changes. Customer-specific security documentation may be provided on request where reasonably necessary, subject to confidentiality and restrictions required to protect Collabor and its users. Schedule 3 — Subprocessor List and change procedure A. How to obtain the current named list Collabor maintains a controlled Subprocessor Register for the Processor Services. An authorised Brand or Agency customer may request the current register through Collabor’s Help Centre. The register will identify, as applicable, the provider’s legal name, service function, principal Processing location or region, relevant data categories and the transfer mechanism used for a Restricted Transfer. The named register may be supplied under confidentiality restrictions because infrastructure details can be commercially sensitive and security-relevant. Collabor will not withhold information that Applicable Data Protection Law requires the Customer to receive. B. Public service categories Depending on the features used, Collabor may appoint providers in the following categories: ● cloud infrastructure, application hosting, content delivery and network services; ● database, file storage, backup and recovery services; ● transactional email, notifications and business communications; ● application monitoring, logging, security and error diagnostics; ● customer support and service-management tools; ● payment, identity-verification and fraud-prevention infrastructure, but only to the extent the provider acts as Collabor’s Processor for Customer Personal Data; ● analytics or reporting services used solely on Collabor’s instructions for the Processor Services; and ● specialist contractors with controlled access for support, security or service operation. C. Providers acting independently The Subprocessor Register covers only Processing performed on Collabor’s behalf for the Processor Services. A payment provider, social platform, Creator, Brand or other recipient may instead act as an independent Controller. Stripe’s status, for example, depends on the particular payment, identity, fraud and connected-account activity. Independent-Controller activities are governed by the relevant provider’s terms and privacy notice and are outside this DPA. D. Initial and continuing authorisation The Customer authorises the Subprocessors identified in the current register made available under paragraph A and any later Subprocessor appointed in accordance with section 11. Collabor will maintain a version record or other reasonable evidence of material register changes. Regulatory references This DPA has been structured with reference to the ICO guidance on controller–processor contracts, ICO international-transfer guidance, the UK IDTA and Addendum, and the European Commission Standard Contractual Clauses. These materials do not form a substitute for the operative terms above and may be updated by the relevant authority.