Last updated: 28/03/2026
Version: 1.0
TL;DR
- This DPA applies when Codemix processes personal data for customers.
- The customer is the controller and Codemix is the processor, unless the parties agree otherwise.
- Codemix processes personal data only to provide the service and on documented instructions.
- Codemix uses appropriate security measures and will help customers meet certain data protection obligations.
- Codemix may use subprocessors subject to appropriate safeguards.
Overview
This Data Processing Agreement ("DPA") forms part of the agreement between the customer and Codemix Ltd governing the customer’s use of Codemix.
This DPA applies where Codemix processes personal data on behalf of the customer as a processor under applicable data protection law.
1. Definitions
In this DPA:
- Customer means the entity that has entered into the agreement for use of Codemix.
- Codemix means Codemix Ltd.
- Data Protection Law means applicable laws relating to privacy, data protection, and processing of personal data, including UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.
- Personal Data means personal data processed by Codemix on behalf of the Customer in connection with the Service.
- Service means the Codemix platform and related services.
2. Roles of the Parties
The parties acknowledge that, for the processing of Personal Data under this DPA:
- the Customer is the controller; and
- Codemix is the processor,
unless otherwise expressly agreed in writing.
3. Scope and Nature of Processing
Codemix will process Personal Data only for the purpose of providing, supporting, securing, and improving the Service in accordance with the main agreement and the Customer’s documented instructions.
The nature of processing may include collection, storage, organisation, retrieval, consultation, analysis, transmission, transformation, generation of outputs, deletion, and other processing necessary to provide the Service.
The categories of data subjects and Personal Data processed under this DPA depend on the Customer’s use of the Service and may include users, employees, contractors, customers, and other individuals whose data the Customer chooses to submit.
4. Customer Instructions
Codemix will process Personal Data only on documented instructions from the Customer, unless otherwise required by law. The agreement, applicable configuration of the Service, and the Customer’s use of the Service constitute the Customer’s documented instructions.
If Codemix believes an instruction infringes Data Protection Law, Codemix may inform the Customer.
5. Confidentiality
Codemix will ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
6. Security Measures
Codemix will implement appropriate technical and organisational measures designed to protect Personal Data, taking into account the nature of the processing and the risks involved.
Such measures may include access controls, authentication measures, logging, encryption in transit where appropriate, environment segregation, backup practices, and organisational security controls.
7. Subprocessors
The Customer authorises Codemix to use subprocessors to provide the Service.
Codemix will impose data protection obligations on subprocessors that are substantially similar to those set out in this DPA. Codemix will remain responsible for the performance of its subprocessors to the extent required by law.
A current subprocessor list may be made available on request or via the Codemix website.
8. International Transfers
Where Codemix or its subprocessors transfer Personal Data internationally, Codemix will implement appropriate safeguards where required by Data Protection Law.
9. Assistance to Customer
Taking into account the nature of the processing and the information available to Codemix, Codemix will provide reasonable assistance to the Customer with:
- responding to requests from data subjects;
- conducting data protection impact assessments, where required;
- consulting with regulators, where required; and
- demonstrating compliance with applicable processor obligations.
Codemix may charge reasonable costs for assistance beyond what is required by law or beyond standard support commitments.
10. Personal Data Breach Notification
If Codemix becomes aware of a Personal Data Breach affecting Personal Data processed under this DPA, Codemix will notify the Customer without undue delay and provide available information reasonably necessary to help the Customer meet any reporting or notification obligations.
11. Deletion and Return of Data
Upon termination or expiry of the Service, Codemix will delete or return Personal Data in accordance with the agreement and applicable law, unless retention is required by law or necessary for legitimate backup, security, audit, fraud prevention, billing, or compliance purposes.
12. Audits and Information
Codemix will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by applicable law, and subject to reasonable confidentiality, security, and operational safeguards, Codemix may permit audits or provide audit materials at reasonable intervals.
13. Liability
Each party’s liability under this DPA is subject to the liability limitations and exclusions in the main agreement, to the extent permitted by applicable law.
14. Order of Precedence
If there is a conflict between this DPA and the main agreement with respect to the processing of Personal Data, this DPA will prevail to the extent of that conflict.
15. Version History
- v1.0 — Initial release (28/03/2026)