Data Processing Addendum
Version: 2.1
Last Updated: 28/09/2026
This Data Processing Addendum ("DPA") forms part of either: (a) the applicable Terms of Service for the Services, or (b) any written master services agreement, SaaS agreement or other governing agreement between the Parties (in each case, the "Agreement").
This DPA applies where Watchers App Limited (the "Company" or "Processor") processes Personal Data on behalf of the Client (the "Controller") in connection with the provision of the Services.
1. Definitions
1.1 "UK GDPR" means the UK General Data Protection Regulation as incorporated into the law of the United Kingdom by the Data Protection Act 2018.
1.2 "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018 and, to the extent applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) and any other applicable data protection laws.
1.3 "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given to them in the UK GDPR.
1.4 "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller in connection with the Services.
1.5 "Sub-processor List" means the current list of Sub-processors published by the Processor at https://watchers.io/legal/sub-processors (or such successor URL as the Processor may notify), as updated from time to time in accordance with Section 5.
2. Roles of the Parties
2.1 The Client acts as the Controller of the Personal Data processed in connection with the Services.
2.2 The Company acts as the Processor and shall process Personal Data only on the documented instructions of the Controller, unless required to do otherwise by applicable law. The Agreement (including any schedules and order forms) and any written instructions issued by the Controller constitute the Controller's documented instructions.
3. Subject Matter and Duration
3.1 The subject matter of the processing is the provision of the SaaS Services described in the Agreement.
3.2 The processing shall continue for the term of the Agreement and until the Personal Data is deleted or returned in accordance with Section 7.
3.3 The nature and purpose of the processing includes: hosting of chat and engagement services; transmission, storage, moderation and display of user communications; analytics and engagement tracking; and technical support and system administration.
3.4 The categories of Data Subjects are: the Client's end users; and the Client's administrators and employees.
3.5 The categories of Personal Data may include: username or pseudonym; user ID; IP address; device information; chat content and metadata; interaction data (polls, reactions, engagement metrics); and moderation data (reports, bans, flags).
3.6 The Controller confirms that it does not intentionally provide Special Category Data to the Processor unless otherwise agreed in writing. The Processor has no obligation to identify or monitor for Special Category Data within the Personal Data provided by the Controller.
4. Obligations of the Processor
The Processor shall:
4.1 process the Personal Data only on the documented instructions of the Controller;
4.2 ensure that persons authorised to process the Personal Data are subject to appropriate obligations of confidentiality;
4.3 implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate: pseudonymisation and encryption of Personal Data; measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident; a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures; access control mechanisms; encryption in transit; a secure hosting environment; regular backups; and logical separation of customer data;
4.4 notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under the Agreement, providing, to the extent available, information on: the nature of the breach; the categories and approximate number of Data Subjects concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach;
4.5 taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in responding to requests from Data Subjects exercising their rights;
4.6 assist the Controller in ensuring compliance with Articles 32 to 36 UK GDPR, taking into account the nature of the processing and the information available to the Processor;
4.7 immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable Data Protection Legislation;
4.8 where the Processor receives a request directly from a Data Subject relating to Personal Data processed under the Agreement, promptly forward such request to the Controller and not respond to it except on the documented instructions of the Controller, unless required to do so by applicable law.
5. Sub-processors
5.1 The Controller hereby grants the Processor a general written authorisation to engage Sub-processors for the provision of the Services (including cloud hosting, content delivery, communications, moderation, artificial intelligence and support providers). The Controller acknowledges and approves the Sub-processors listed in the Sub-processor List as at the date of the Agreement.
5.2 The Processor shall ensure that each Sub-processor is bound by written contractual obligations providing at least the same level of data protection as set out in this DPA, and in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
5.3 The Processor remains fully liable to the Controller for the performance of the obligations of its Sub-processors.
5.4 The Processor shall give notice of any intended addition or replacement of a Sub-processor solely by publishing an updated version of the Sub-processor List at https://watchers.io/legal/sub-processors, with an updated version number and "Last Updated" date. The Processor is not required to send individual notices to the Controller. The Controller is responsible for reviewing the Sub-processor List at regular intervals, and the Parties agree that publication in accordance with this Section 5.4 constitutes valid and sufficient notice to the Controller for the purposes of Article 28(2) UK GDPR.
5.5 The Controller may object to the engagement of a new or replacement Sub-processor on reasonable and documented data protection grounds by giving written notice to the Processor within fourteen (14) days of the publication of the updated Sub-processor List. If the Controller does not object within that period, the Controller shall be deemed to have approved the new or replacement Sub-processor.
5.6 Where the Controller objects in accordance with Section 5.5, the Parties shall discuss the objection in good faith. If the Processor is unable to accommodate the objection within a reasonable period, the Controller may, as its sole and exclusive remedy, terminate the part of the Services that cannot be provided without the relevant Sub-processor, by giving written notice to the Processor. Any such termination shall not give rise to any refund or liability on the part of the Processor, save as required by applicable law.
5.7 The Processor may remove a Sub-processor from the Sub-processor List at any time without notice where that Sub-processor is no longer used to process Personal Data.
6. International Transfers
6.1 The Processor shall not transfer Personal Data outside the United Kingdom (and, where applicable, the European Economic Area) unless: (a) the transfer is to a country recognised as providing an adequate level of protection under applicable Data Protection Legislation; or (b) appropriate safeguards are in place in accordance with the UK GDPR, including the UK International Data Transfer Addendum or the UK-approved Standard Contractual Clauses, where required. The countries in which Sub-processors process Personal Data are set out in the Sub-processor List.
6.2 The Parties agree that the UK International Data Transfer Addendum, or the applicable UK-approved Standard Contractual Clauses, shall be deemed incorporated by reference into this DPA to the extent required for any such transfer.
7. Deletion and Return of Data
7.1 Upon termination or expiry of the Agreement, the Processor shall, at the choice of the Controller, delete the Personal Data or return it to the Controller, unless applicable law requires continued retention. Upon written request, the Processor shall provide written confirmation of deletion.
7.2 The Processor may retain backup copies of Personal Data for a limited period in accordance with its standard backup policies, after which such data shall be securely deleted.
8. Audit
8.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
8.2 Any audit shall be: conducted on reasonable prior notice; during normal business hours; no more than once during the term of the Agreement; and at the Controller's expense. This limitation shall not apply where an audit is required by a competent supervisory authority.
9. Liability
9.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
10. Order of Precedence
10.1 In the event of any conflict between this DPA and the Agreement, this DPA shall prevail in respect of data protection matters.
11. Survival
11.1 The provisions of this DPA shall survive termination or expiry of the Agreement to the extent necessary to give effect to the rights and obligations relating to the Processing of Personal Data.
12. Amendments to this DPA
12.1 The Processor may update this DPA from time to time to reflect changes in applicable Data Protection Legislation, regulatory guidance or the Services. The current version is published at https://watchers.io/legal/dpa with an updated version number and "Last Updated" date. Updates to the Sub-processor List are governed by Section 5 and do not constitute amendments to this DPA.
By entering into the Agreement, the Parties agree to be bound by this DPA without further signature.
Contact
Watchers App Limited
4 Hill Street, London, England, W1J 5NE