Last updated: July 22, 2026
Data Processing Agreement
The data-processing addendum applicable when ALLM processes personal data for a business Customer.
1. Roles and instructions
The Customer is the controller and ALLM is the processor under Article 28 GDPR, except where ALLM acts as an independent controller for its own Customer relationship, billing, service security and public website. The Customer warrants a lawful basis and required notices for Customer Data it provides.
ALLM processes Customer Data only on documented Customer instructions to provide, secure and maintain the Service, unless law requires otherwise. ALLM will notify the Customer if an instruction appears unlawful unless prohibited from doing so.
2. Subject matter and processing
Subject matter: ALLM platform, API, authentication, support, logging and related security. Duration: the order term plus return and deletion periods. Nature: collection, consultation, organisation, hosting, technical transmission, limited operational analysis and deletion. Purpose: providing the Service and lawful Customer instructions.
Data subjects may include Customer Users, staff, customers, prospects and other persons whose data is entered by the Customer. Data may include identity, contact details, professional identifiers, technical data and Customer-submitted content. The Customer must not submit special-category data without necessity, a lawful basis and appropriate safeguards.
3. Confidentiality and security
ALLM ensures authorised persons are subject to confidentiality obligations and uses measures appropriate to risk, including least-privilege access management, encryption in transit, authentication, logging, backups, development and incident-management procedures, and proportionate testing and reviews. Security also depends on Customer settings, access management and submitted content.
4. Subprocessors and transfers
The Customer authorises use of necessary subprocessors, including Vercel for hosting and deployment, Supabase for authentication and database, Stripe for payment, and PostHog for consent-based public-site analytics. ALLM imposes materially equivalent data-protection obligations and will provide reasonable advance notice of material additions or replacements. The Customer may raise a reasoned objection; if no solution is possible, it may terminate the affected service without penalty before the change takes effect.
For transfers outside the EEA, ALLM uses a GDPR-recognised transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, with supplementary measures where necessary.
5. Assistance and incidents
Taking account of processing nature, ALLM reasonably assists the Customer with data-subject requests. It notifies the Customer without undue delay after becoming aware of a Customer Data breach and provides available information necessary for the Customer’s obligations. It also reasonably assists with DPIAs and prior consultation where required.
6. Audits, return and deletion
Once every twelve (12) months, or following a material incident, the Customer may request proportionate information or an audit with thirty (30) days’ notice during business hours. Recent third-party audit reports may satisfy the request; the Customer bears reasonable extraordinary costs. On termination and Customer instruction, ALLM returns available Customer Data in a standard format or deletes it unless retention is legally required. Backups are purged through their technical cycles and protected until overwritten.
7. Precedence
Where there is a conflict concerning Customer Data processing, this DPA prevails over the Terms of Service. Mandatory legal obligations remain unaffected.