Skip to main content

Data Processing Agreement

Data Processing Agreement pursuant to Article 28 GDPR

Effective Date: 1st February 2025

Last Updated: 24/07/2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Principal Agreement") between Steleo Publishing Limited ("Data Processor" or "Processor") and the customer ("Data Controller" or "Controller") accessing or using BundleCreator.co services.

1. Definitions

1.1 Terms used in this DPA have the meanings set forth in the GDPR. "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.

1.2 "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller pursuant to or in connection with the Principal Agreement.

1.3 "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

2. Processing of Personal Data

2.1 Processor's Role: The parties acknowledge and agree that with regard to the processing of Personal Data, the Controller is the data controller, the Processor is the data processor, and that the Processor will engage subprocessors pursuant to the requirements set forth in Section 5 below.

2.2 Controller's Instructions: The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation;
  • Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other data protection provisions;
  • Process Personal Data only for the duration of the Principal Agreement, subject to the terms of this DPA.

2.3 Purpose Limitation: The Processor shall process Personal Data solely for the purpose of providing the BundleCreator.co services as described in the Principal Agreement and not for any other purpose.

3. Security of Processing

3.1 Security Measures: The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • The pseudonymisation and encryption of Personal Data;
  • The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
  • A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

3.2 Specific Security Measures: Without limiting the generality of Section 3.1, the Processor has implemented and will maintain the following security measures:

  • AES-256 encryption for all data at rest;
  • TLS 1.3 encryption for all data in transit;
  • Browser-based PDF password protection using QPDF WASM;
  • Access controls with multi-factor authentication;
  • Regular security audits and penetration testing;
  • Comprehensive activity logging and monitoring.

4. Confidentiality

4.1 Confidentiality Obligation: The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2 Access Limitation: The Processor shall ensure that access to Personal Data is limited to those personnel who require such access to perform the Processor's obligations under the Principal Agreement.

5. Subprocessors

5.1 General Authorisation: The Controller provides general authorisation for the Processor to engage subprocessors to assist with the provision of services.

5.2 Current Subprocessors: The Controller acknowledges and agrees that the Processor currently uses the following subprocessors:

  • Cloud Database Provider - PostgreSQL database and file storage infrastructure (United States, SOC 2 Type II and ISO 27001 certified)
  • OAuth 2.0 Authentication Provider - Enterprise authentication services (United States, SOC 2 Type II certified)
  • Vercel Inc. - Hosting services (United States)
  • Payment Processing Provider - PCI DSS Level 1 payment infrastructure (United States, SOC 2 Type II and ISO 27001 certified)

5.3 New Subprocessors: The Processor shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors via email at least 14 days in advance, thereby giving the Controller the opportunity to object to such changes.

5.4 Subprocessor Obligations: Where the Processor engages a subprocessor, the Processor shall:

  • Impose data protection obligations on the subprocessor by way of a contract or other legal act that are no less onerous than those set out in this DPA;
  • Remain fully liable to the Controller for the performance of the subprocessor's obligations.

6. Data Subject Rights

6.1 Assistance with Requests: The Processor shall, to the extent legally permitted, promptly notify the Controller if the Processor receives a request from a Data Subject to exercise rights under the GDPR ("Data Subject Request").

6.2 Controller's Responsibility: The Controller shall be responsible for responding to Data Subject Requests. The Processor shall provide reasonable assistance to the Controller in responding to such requests, to the extent the Processor is legally permitted to do so and the response to such Data Subject Request is required under the GDPR.

7. Data Breach Notification

7.1 Notification Requirement: The Processor shall notify the Controller without undue delay upon becoming aware of a Data Breach affecting Personal Data, providing the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Data Breach under the GDPR.

7.2 Breach Details: Such notification shall at a minimum:

  • Describe the nature of the Data Breach including the categories and approximate number of Data Subjects concerned;
  • Communicate the name and contact details of the Processor's data protection officer or other contact point;
  • Describe the likely consequences of the Data Breach;
  • Describe the measures taken or proposed to address the Data Breach.

7.3 Cooperation: The Processor shall cooperate with the Controller and take reasonable commercial steps as directed by the Controller to assist in the investigation, mitigation and remediation of each Data Breach.

8. Data Protection Impact Assessment and Prior Consultation

The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with supervising authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other data protection law.

9. Deletion or Return of Personal Data

9.1 End of Processing: Upon termination of the Principal Agreement, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.

9.2 Certification: Upon request, the Processor shall provide written certification to the Controller that it has fully complied with this section.

10. Audit Rights

10.1 Right to Audit: The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

10.2 Audit Conditions: Any audit shall be conducted:

  • With reasonable notice of at least 30 days (except in case of suspected breach);
  • During regular business hours;
  • No more than once per year (except in case of suspected breach);
  • Subject to the Processor's reasonable security and confidentiality controls;
  • At the Controller's sole expense.

11. International Transfers

11.1 Transfer Mechanism: The Processor shall not transfer Personal Data outside the European Economic Area unless:

  • The Controller has provided prior written consent;
  • Appropriate safeguards are in place pursuant to Article 46 GDPR;
  • The transfer is based on an adequacy decision pursuant to Article 45 GDPR;
  • The transfer is otherwise lawful under the GDPR.

11.2 Standard Contractual Clauses: For transfers to subprocessors in countries without an adequacy decision, the parties agree to execute the European Commission's Standard Contractual Clauses for the transfer of personal data to processors established in third countries.

12. Liability and Indemnification

12.1 Liability Cap: Each party's liability arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Principal Agreement.

12.2 Indemnification: Each party shall indemnify the other party for any losses, damages and liabilities incurred by the indemnified party in connection with any Data Breach caused by the indemnifying party's breach of its obligations under this DPA or the GDPR.

13. General Terms

13.1 Amendments: This DPA may only be amended with the written consent of both parties.

13.2 Governing Law: This DPA shall be governed by and construed in accordance with the laws of England and Wales.

13.3 Severability: If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

13.4 Order of Precedence: In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the processing of Personal Data.

14. Contact Information

For matters relating to this DPA, please contact:

Data Protection Officer

Steleo Publishing Limited

Email: privacy@bundlecreator.co

Address: 167-169 Great Portland Street, London W1W 5PJ

Annex 1: Processing Details

Nature and Purpose of Processing:

The Processor will process Personal Data as necessary to provide the BundleCreator.co services pursuant to the Principal Agreement, including:

  • Storage and organisation of legal documents
  • Document encryption and decryption
  • Bundle creation and formatting
  • User authentication and access control
  • Activity logging and audit trails

Categories of Data Subjects:

  • Controller's employees and contractors
  • Controller's clients
  • Individuals referenced in legal documents

Categories of Personal Data:

  • Names and contact information
  • Authentication credentials
  • Legal case information
  • Document metadata
  • Activity logs and access records
  • Any personal data contained in uploaded documents

Duration of Processing:

Personal Data will be processed for the duration of the Principal Agreement, subject to the data retention periods specified in the Data Retention Policy.

Last updated: 24/07/2026

Version: 1.0