Effective Date: 1st February 2025
Last Updated: 24/07/2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Principal Agreement") between Steleo Publishing Limited ("Data Processor" or "Processor") and the customer ("Data Controller" or "Controller") accessing or using BundleCreator.co services.
1.1 Terms used in this DPA have the meanings set forth in the GDPR. "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
1.2 "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller pursuant to or in connection with the Principal Agreement.
1.3 "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
2.1 Processor's Role: The parties acknowledge and agree that with regard to the processing of Personal Data, the Controller is the data controller, the Processor is the data processor, and that the Processor will engage subprocessors pursuant to the requirements set forth in Section 5 below.
2.2 Controller's Instructions: The Processor shall:
2.3 Purpose Limitation: The Processor shall process Personal Data solely for the purpose of providing the BundleCreator.co services as described in the Principal Agreement and not for any other purpose.
3.1 Security Measures: The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
3.2 Specific Security Measures: Without limiting the generality of Section 3.1, the Processor has implemented and will maintain the following security measures:
4.1 Confidentiality Obligation: The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 Access Limitation: The Processor shall ensure that access to Personal Data is limited to those personnel who require such access to perform the Processor's obligations under the Principal Agreement.
5.1 General Authorisation: The Controller provides general authorisation for the Processor to engage subprocessors to assist with the provision of services.
5.2 Current Subprocessors: The Controller acknowledges and agrees that the Processor currently uses the following subprocessors:
5.3 New Subprocessors: The Processor shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors via email at least 14 days in advance, thereby giving the Controller the opportunity to object to such changes.
5.4 Subprocessor Obligations: Where the Processor engages a subprocessor, the Processor shall:
6.1 Assistance with Requests: The Processor shall, to the extent legally permitted, promptly notify the Controller if the Processor receives a request from a Data Subject to exercise rights under the GDPR ("Data Subject Request").
6.2 Controller's Responsibility: The Controller shall be responsible for responding to Data Subject Requests. The Processor shall provide reasonable assistance to the Controller in responding to such requests, to the extent the Processor is legally permitted to do so and the response to such Data Subject Request is required under the GDPR.
7.1 Notification Requirement: The Processor shall notify the Controller without undue delay upon becoming aware of a Data Breach affecting Personal Data, providing the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Data Breach under the GDPR.
7.2 Breach Details: Such notification shall at a minimum:
7.3 Cooperation: The Processor shall cooperate with the Controller and take reasonable commercial steps as directed by the Controller to assist in the investigation, mitigation and remediation of each Data Breach.
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with supervising authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other data protection law.
9.1 End of Processing: Upon termination of the Principal Agreement, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.
9.2 Certification: Upon request, the Processor shall provide written certification to the Controller that it has fully complied with this section.
10.1 Right to Audit: The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
10.2 Audit Conditions: Any audit shall be conducted:
11.1 Transfer Mechanism: The Processor shall not transfer Personal Data outside the European Economic Area unless:
11.2 Standard Contractual Clauses: For transfers to subprocessors in countries without an adequacy decision, the parties agree to execute the European Commission's Standard Contractual Clauses for the transfer of personal data to processors established in third countries.
12.1 Liability Cap: Each party's liability arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Principal Agreement.
12.2 Indemnification: Each party shall indemnify the other party for any losses, damages and liabilities incurred by the indemnified party in connection with any Data Breach caused by the indemnifying party's breach of its obligations under this DPA or the GDPR.
13.1 Amendments: This DPA may only be amended with the written consent of both parties.
13.2 Governing Law: This DPA shall be governed by and construed in accordance with the laws of England and Wales.
13.3 Severability: If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
13.4 Order of Precedence: In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the processing of Personal Data.
For matters relating to this DPA, please contact:
Data Protection Officer
Steleo Publishing Limited
Email: privacy@bundlecreator.co
Address: 167-169 Great Portland Street, London W1W 5PJ
Nature and Purpose of Processing:
The Processor will process Personal Data as necessary to provide the BundleCreator.co services pursuant to the Principal Agreement, including:
Categories of Data Subjects:
Categories of Personal Data:
Duration of Processing:
Personal Data will be processed for the duration of the Principal Agreement, subject to the data retention periods specified in the Data Retention Policy.
Last updated: 24/07/2026
Version: 1.0