Data Processing Agreement

Draft for legal review — not yet in force. Items in [square brackets] need confirming before publication.

Last updated: 3 October 2026 · Version: 2026-10-03-draft3

This agreement forms part of the Terms of Service between Inside & Out Digital Ltd, trading as Audova, a company registered in Scotland under number SC334849, whose registered office is at 38 Inchgarvie Avenue, Burntisland, Fife, KY3 0BU ("Audova", the processor) and the customer ("you", the controller). It applies whenever Audova processes personal data on your behalf, and meets the requirements of Article 28 of the UK GDPR.

1. Details of the processing

Subject matter Providing the Audova email marketing and customer relationship service
Duration For as long as you use the service, and until the data is deleted under clause 9
Nature and purpose Storing, organising and segmenting contact data; recording consent; sending emails and automated journeys; tracking delivery and engagement; reporting
Data subjects Your customers, subscribers and prospects; and the content and activity your team members create in your account (Audova is the controller of your team members' own sign-in, account and security data — see our Privacy Policy)
Personal data Names, email addresses, mobile numbers, dates of birth, postal details, preferences and interests, consent records, venue/location visit and booking data you import, email delivery and engagement events (opens, clicks, bounces, unsubscribes)
Special category data None. You must not upload special category data.

2. Your instructions

Audova processes personal data only on your documented instructions — which are the Terms and your use and configuration of the service — unless the law requires otherwise, in which case we will tell you first unless the law prevents it. We will tell you if we believe an instruction breaks data protection law.

3. Confidentiality

Everyone at Audova who can access your data is bound by confidentiality.

4. Security

We maintain appropriate technical and organisational measures, including:

  • hosting and email sending in the UK (London) — see the sub-processors page;
  • a separate database for each customer account;
  • encryption in transit (TLS) and encrypted database backups;
  • role-based access within your account, with each team member's access limited to the locations you assign;
  • an audit trail of actions taken in your account;
  • automatic suppression of addresses that unsubscribe, bounce or complain;
  • removal of personal data (contact details, names, dates of birth, IP addresses) from error reports before they leave our servers;
  • [staff access controls, multi-factor authentication for administrative access, and regular patching — confirm].

5. Sub-processors

You give general authorisation for Audova to use the sub-processors on our sub-processors page. We will update that page at least [30] days before adding or replacing a sub-processor, and you may object on reasonable data protection grounds; if we cannot accommodate the objection, you may cancel without penalty. We impose data protection terms on each sub-processor that are at least as protective as this agreement, and remain responsible for them.

6. International transfers

Your contacts, campaigns and consent records are stored and sent from the UK. Where a sub-processor outside the UK processes personal data (for example, content you choose to send to our AI provider), we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.

7. Helping you meet your obligations

Taking into account the nature of the processing, we will help you respond to requests from data subjects (Audova includes tools to find, export, correct and erase a contact's data), and assist with security, breach notification, data protection impact assessments and consultation with the ICO.

8. Personal data breaches

We will notify you without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own reporting obligations.

9. Retention and deletion

9.1 While your account is active: detailed email engagement events are kept for [90] days (summary statistics are kept for the life of the account); form submissions for [365] days; consent records for the life of the account, as evidence of consent.

9.2 Please export your data before your paid period ends; after it ends we will provide an export on request. We delete account data within [90] days, unless the law requires us to keep it. Encrypted backups are overwritten within 14 days.

10. Audits

We will make available the information reasonably needed to show compliance with this agreement and allow for audits by you or an auditor you appoint, on reasonable notice, no more than once a year [unless required by a regulator or following a breach], at your cost.

11. Liability and precedence

Liability under this agreement is subject to the limits in the Terms. If this agreement conflicts with the Terms on data protection, this agreement takes priority.