Legal

Data Processing Agreement

Last updated: 27 July 2026

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable account or order form ("Customer") and CXDATA LTD ("Refyner", "we", "us"), a company registered in England & Wales under company number 15100231, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. It applies automatically to all customers using the Service and is incorporated into, and forms part of, the Terms of Service. No signature is required.

1. Roles of the parties

The Customer is the controller and Refyner is the processor in respect of personal data processed in connection with the Service, as those terms are used in the UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law"). Where the Customer is itself a processor for a third party, Refyner acts as a sub-processor and the Customer confirms it has the necessary authority.

2. Subject matter, duration, nature and purpose

3. Categories of data subjects and personal data

Categories of data subjects: the Customer's own customers, prospects and subscribers, and the Customer's personnel who use the Service.

The Customer must not include special category data or children's data in a dataflow scope without agreeing appropriate additional measures with us in writing.

4. Processing on documented instructions

Refyner processes personal data only on the Customer's documented instructions – the Terms of Service, this DPA, the Customer's configuration of the Service, and any further written instruction we accept – and for no other purpose. We will inform the Customer if, in our opinion, an instruction infringes Data Protection Law. If we are required by law to process personal data otherwise, we will notify the Customer in advance unless legally prohibited.

5. Confidentiality

Access to personal data is limited to personnel who need it to deliver or support the Service. All such personnel are bound by written confidentiality obligations that survive the end of their engagement, receive data protection and security training, and are subject to least-privilege access controls.

6. Security measures

Refyner implements appropriate technical and organisational measures under Article 32, described in more detail on our Trust & Security page. These include encryption in transit (TLS 1.2+) and at rest (AES-256), a least-privilege Snowflake role scoped by the Customer and revocable at any time, control-plane-only storage of configuration and metadata, role-based access control with multi-factor authentication on all accounts, daily Azure-managed backups with point-in-time restore, and hosting on Microsoft Azure (East US 2).

7. Sub-processors

The Customer gives general authorisation for Refyner to engage the sub-processors listed below. Each is engaged under a written contract imposing data protection obligations no less protective than this DPA, and Refyner remains liable for their performance.

We will give the Customer at least 30 days' notice of any new or replacement sub-processor by updating this page. The Customer may object on reasonable data protection grounds within that period by writing to privacy@refyner.com; if we cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty for the unused balance of any prepaid fees. Self-hosted deployments do not use Refyner-operated sub-processors for Customer data.

8. Assistance to the Customer

Taking into account the nature of the processing, Refyner will provide reasonable assistance with responding to data subject requests for access, rectification, erasure, restriction, portability or objection – including through the Service's own export and deletion functions – and with the Customer's obligations under Articles 32 to 36, covering security of processing, breach notification, data protection impact assessments and prior consultation. If we receive a request directly from a data subject relating to Customer data, we will refer it to the Customer rather than respond ourselves, unless legally required otherwise.

9. Personal data breach

Refyner will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to us at the time – the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses and cooperate with the Customer's own notification obligations.

10. International transfers

The Refyner control plane is hosted on Microsoft Azure in the United States (Azure East US 2). The configuration and metadata described in Section 3, together with account and support data, are therefore stored in the United States. The Customer’s warehouse data stays in the Snowflake account and region the Customer controls, and is not transferred by Refyner. Transfers of personal data outside the UK or EEA are safeguarded by the UK International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or an applicable adequacy decision – including the UK Extension to the EU–US Data Privacy Framework where the recipient is certified. A UK region (Azure UK South) is on our roadmap; where the Customer requires processing in a single region today, Refyner Self-Hosted deploys the entire control plane inside the Customer’s own cloud.

11. Deletion or return of personal data

On termination or expiry of the Customer’s subscription, Refyner will make Customer data available for export for 30 days and will then delete or return the personal data it holds, including from backups in line with our backup cycle, unless retention is required by law – for example billing records, which we keep for six years. Earlier deletion is available on written request. Warehouse data remains in the Customer's own Snowflake account throughout and is unaffected. Written confirmation of deletion is available on request.

12. Audits

Refyner will make available the information necessary to demonstrate compliance with this DPA. Audit rights are satisfied primarily through documentation – our security pack, certifications, penetration test summaries and this DPA. Where the Customer reasonably requires more, an audit may be conducted on at least 30 days' written notice, no more than once a year except following a personal data breach, during business hours, subject to confidentiality, and without disrupting the Service or other customers' data.

13. Applicable data protection law

This DPA is drafted against UK GDPR and applies on that basis worldwide. Where the processing is also subject to another regime, the terms below apply automatically, with no country-specific addendum or additional signature required.

14. General

In the event of conflict, this DPA prevails over the Terms of Service on matters of data protection, and a signed order form or bespoke DPA prevails over this DPA. This DPA is governed by the laws of England & Wales.

15. Contact

CXDATA LTD, 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ · privacy@refyner.com.