Skip to content

Data Processing Agreement how we handle data on your behalf

The Article 28 terms that govern SimpleKPI's processing of personal data for customers. Version August 2026, effective 6 August 2026.

This Data Processing Agreement ("DPA") forms part of the SimpleKPI Terms of Service (the "Agreement") between:

SimpleKPI Ltd, a company registered in England under company number 6191007, whose registered office is at 86-90 Paul Street, London, EC2A 4NE, United Kingdom ("SimpleKPI", "we", "us"), and

the Client identified in the Agreement ("Client", "you").

It applies whenever SimpleKPI processes Personal Data on the Client's behalf in the course of providing the Services.

This DPA replaces any previous data processing agreement between the parties with effect from the effective date.

Where this DPA conflicts with the Agreement, this DPA prevails in respect of the processing of Personal Data.

1. Definitions

Terms not defined here carry the meaning given in the Agreement, the Privacy Notice, or Applicable Data Protection Law.

  • "Applicable Data Protection Law" means, as applicable to the processing: the UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679 (the "EU GDPR"); and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.
  • "Client Data" has the meaning given in the Agreement.
  • "Client Personal Data" means Personal Data contained within Client Data, and User account and usage data, processed by SimpleKPI on the Client's behalf.
  • "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processor" and "processing" carry the meanings given in Applicable Data Protection Law.
  • "Services" means the SimpleKPI Services as defined in the Agreement.
  • "Sub-processor" means any third party engaged by SimpleKPI to process Client Personal Data.
  • "Third Country Transfer" means a transfer of Client Personal Data to a country or international organisation outside the United Kingdom or the European Economic Area, whether or not that destination is the subject of an adequacy decision.
  • "Transfer Mechanism" means the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

2. Roles of the parties

2.1 In respect of Client Personal Data, the Client is the Controller and SimpleKPI is the Processor.

2.2 SimpleKPI acts as an independent Controller in respect of billing data, public Website data, and its own business records, as described in the Privacy Notice. This DPA does not govern that processing. For the avoidance of doubt, User account data and usage data generated within the Services are Client Personal Data and are governed by this DPA.

2.3 The Client warrants that it has a lawful basis for the processing it instructs, that it has provided any notice and obtained any consent required from Data Subjects, and that its instructions will not put SimpleKPI in breach of Applicable Data Protection Law.

3. Scope and instructions

3.1 SimpleKPI will process Client Personal Data only on documented instructions from the Client, including in respect of any Third Country Transfer, unless required to do otherwise by United Kingdom, European Union or European Union Member State law to which SimpleKPI is subject. Where so required, SimpleKPI will inform the Client before processing unless that law prohibits it on important grounds of public interest.

3.2 The Agreement, this DPA, its Annexes, and the Client's use and configuration of the Services constitute the Client's documented instructions. The particulars of the processing are set out in Annex I.

3.3 SimpleKPI will immediately inform the Client if, in its opinion, an instruction infringes Applicable Data Protection Law.

3.4 SimpleKPI will access, use or modify Client Personal Data only in the circumstances set out in Section 3.2 of the Agreement: to deliver the Services effectively, to resolve service or technical issues, and where required by law in compliance with legal obligations relating to compelled disclosure.

3.5 SimpleKPI does not use Client Personal Data to train artificial intelligence or machine learning models, and will not configure the Services in a way that permits a Sub-processor to do so. Where AI Features are used, model inference is performed within Microsoft Azure AI Foundry. As at the effective date, SimpleKPI's contractual terms with Microsoft provide that data processed through Azure AI Foundry is not used to train Microsoft's models, and that Microsoft may retain interaction data for up to 30 days solely for abuse and misuse monitoring under its own terms, after which it is deleted. SimpleKPI will notify the Client under clause 6.4 if those terms materially change.

3.6 Government and law enforcement requests. If SimpleKPI receives a legally binding request from a public authority for disclosure of Client Personal Data, it will, unless legally prohibited: notify the Client without undue delay and before disclosure; provide the minimum amount of data reasonably necessary to respond; and challenge the request where there are reasonable grounds to consider it unlawful. Where notification is prohibited, SimpleKPI will use reasonable efforts to obtain a waiver of the prohibition and will keep a record of the request for the Client where lawful to do so.

4. Confidentiality

SimpleKPI will ensure that persons authorised to process Client Personal Data are subject to an appropriate duty of confidentiality, are granted access only to the extent necessary for their role under role-based access control, and receive appropriate data protection guidance.

5. Security

5.1 Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, SimpleKPI implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures are described in Annex II.

5.2 SimpleKPI maintains a process for regularly testing, assessing and evaluating the effectiveness of those measures, and for restoring availability of and access to Client Personal Data in a timely manner following a physical or technical incident.

5.3 SimpleKPI may change a security measure provided the change does not materially reduce the overall level of security.

6. Sub-processors

6.1 The Client grants SimpleKPI general authorisation to engage Sub-processors, subject to this clause.

6.2 The Sub-processors authorised at the effective date are listed in Annex III.

6.3 SimpleKPI will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Client for the performance of that Sub-processor's obligations. On the Client's written request, SimpleKPI will provide a copy of the relevant Sub-processor agreement, with commercial terms redacted.

6.4 SimpleKPI will inform the Client of any intended addition or replacement of a Sub-processor at least 30 days in advance, by email to the Account owner and by in-app notice. This obligation applies to every addition and replacement, not only those SimpleKPI considers material.

6.5 The Client may object to a proposed Sub-processor on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If it cannot be resolved, the Client may terminate the affected Services on written notice. Fees already paid are dealt with under Section 4 and Section 10.1 of the Agreement.

7. International transfers

7.1 Some Sub-processors process Client Personal Data outside the UK and the EEA, including in the United States.

7.2 SimpleKPI will not make a Third Country Transfer unless it has ensured that one of the following applies:

  • the destination is covered by an adequacy decision under Applicable Data Protection Law, including the UK-US Data Bridge or the EU-US Data Privacy Framework where the recipient is and remains certified under it; or
  • an appropriate Transfer Mechanism is in place, completed as set out in Annex IV; or
  • another safeguard or derogation permitted by Applicable Data Protection Law applies.

7.3 Where a recipient's certification under an adequacy decision lapses or is withdrawn, SimpleKPI will put an appropriate Transfer Mechanism in place without undue delay.

7.4 Where a Transfer Mechanism applies and conflicts with this DPA, the Transfer Mechanism prevails.

8. Assistance with Data Subject rights and compliance

8.1 The Services provide the Client with tools to access, correct, export and delete Client Personal Data directly, including spreadsheet export and the Developer API. Those tools remain available to the Client during the term and throughout the deletion window in clause 11.3.

8.2 If a Data Subject contacts SimpleKPI directly in respect of Client Personal Data, SimpleKPI will not respond substantively but will, without undue delay, direct them to the Client and inform the Client.

8.3 Taking into account the nature of the processing, SimpleKPI will provide reasonable assistance to the Client, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Client's obligation to respond to Data Subject requests under Chapter III of the UK GDPR and EU GDPR, where the Client cannot reasonably do so using the tools in clause 8.1.

8.4 Taking into account the nature of processing and the information available to it, SimpleKPI will provide reasonable assistance to the Client in ensuring compliance with its obligations under Articles 32 to 36, including security of processing (Article 32), notification of a Personal Data Breach to a supervisory authority (Article 33), communication of a Personal Data Breach to Data Subjects (Article 34), data protection impact assessments (Article 35), and prior consultation (Article 36).

8.5 SimpleKPI may charge a reasonable fee for assistance under clauses 8.3 and 8.4 where a request is manifestly unfounded, excessive or repetitive.

9. Personal Data Breach

9.1 SimpleKPI will notify the Client without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Client Personal Data.

9.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and any information provided to SimpleKPI by its Sub-processors. Where the information cannot be provided at once it will be provided in phases without undue delay, and SimpleKPI will keep the Client informed as the investigation progresses.

9.3 SimpleKPI will take reasonable steps to contain and remediate the breach, will document the facts, effects and remedial action, and will make that documentation available to the Client on request.

9.4 SimpleKPI will not make a public statement identifying the Client without the Client's prior written consent unless required by law.

9.5 Notification under this clause is not an admission of fault or liability.

10. Information and audit

10.1 SimpleKPI will make available to the Client all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and EU GDPR, and will allow for and contribute to audits, including inspections, conducted by the Client or by another auditor mandated by the Client.

10.2 SimpleKPI will satisfy clause 10.1 in the first instance by providing its published security documentation, this DPA, and the certifications and audit reports of its infrastructure Sub-processors. SimpleKPI's hosting is provided by Microsoft Azure, which maintains ISO 27001 certification.

10.3 Where that information is insufficient, the Client or its mandated auditor may audit on at least 30 days' written notice, during business hours, subject to confidentiality obligations, and conducted so as not to disrupt the Services or affect the data of other clients. SimpleKPI will cooperate in good faith and provide reasonable assistance. Audits are limited to once in any twelve-month period except where required by a supervisory authority or following a Personal Data Breach affecting the Client. Each party bears its own costs.

10.4 A supervisory authority may audit as required by law, without the limits in clause 10.3.

11. Retention, return and deletion

11.1 SimpleKPI retains Client Personal Data for as long as the Client's Account is active and thereafter as set out in this clause. The retention periods below match Section 6 of the Privacy Notice and Section 10.3 of the Agreement.

11.2 At any time during the term, and throughout the deletion window in clause 11.3, the Client may export Client Personal Data using the tools in clause 8.1.

11.3 On termination or expiry the Client may choose, by written notice within 30 days of the end of the Agreement, whether SimpleKPI returns or deletes Client Personal Data. In the absence of a choice, SimpleKPI will delete it. Deletion occurs:

  • for cancelled and expired Accounts, within the six-month period described in Section 10.3 of the Agreement, with a warning notice sent approximately 14 days before deletion;
  • for lapsed Free Trial Accounts, generally within two months of the trial lapsing;
  • on the Client's request for earlier deletion, within one month;
  • where the Client has asked SimpleKPI to keep its data on cancellation, after up to 12 months.

11.4 Client Personal Data may persist in encrypted backups after deletion from live systems. Those backups are retained for a limited period, generally up to 35 days, before secure deletion; during SimpleKPI's platform migration, long-term archival backups of the previous-generation database are retained for up to six months. Where deletion from backups is not immediately possible, SimpleKPI will securely store the data and isolate it from any further processing until deletion is possible. This DPA continues to apply to that data for as long as it is held.

11.5 Ancillary records containing Client Personal Data are retained as follows: AI conversation transcripts for 12 months, deleted immediately if the Account is deleted; spreadsheets uploaded through the AI-assisted import, and the redacted samples retained to improve import quality, for up to 12 months.

11.6 SimpleKPI may retain Client Personal Data where required by law, for the period required, and will continue to protect it under this DPA.

12. Liability and term

12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

12.2 This DPA takes effect on the effective date and continues for as long as SimpleKPI processes Client Personal Data, including data held in archival backups under clause 11.4. Clauses 1, 3.6, 4, 5, 6.3, 7, 9, 10, 11, 12 and 13 survive termination of the Agreement for as long as SimpleKPI holds Client Personal Data.

12.3 SimpleKPI may update this DPA where required to reflect a change in law, in the Services, or in its Sub-processors, provided the update does not materially reduce the protections afforded to the Client. Updates will be notified in accordance with clause 6.4.

13. Governing law

This DPA is governed by the law of England and Wales and subject to the exclusive jurisdiction of its courts, without prejudice to any mandatory provision of Applicable Data Protection Law or to the governing law of any Transfer Mechanism incorporated under clause 7.2.

14. Contact

Data protection enquiries: privacy@simplekpi.com

SimpleKPI Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom

SimpleKPI has not designated a representative in the Union under Article 27.

Annex I: Particulars of processing

Incorporated by clause 3.2. Sections A, B and C correspond to Annex I.A, I.B and I.C of any Transfer Mechanism.

A. Parties

Data exporter (Controller)The Client, as identified in the Agreement
Data importer (Processor)SimpleKPI Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
SimpleKPI data protection contactprivacy@simplekpi.com
Client data protection contactThe Account owner details captured at sign-up, or such other contact as the Client notifies to SimpleKPI in writing

B. Description of processing

Subject matter: provision of the SimpleKPI KPI tracking, dashboard, reporting and analytics Services.

Duration: the term of the Agreement, plus the retention periods in clause 11.

Nature and purpose: hosting, storage, organisation, structuring, retrieval, analysis, visualisation and transmission of Client Data, so that the Client can track, report on and analyse its Key Performance Indicators; and, where the Client uses them, the integration features described below.

Integrations processing Client Personal Data, where the Client authorises them:

  • Google Analytics: accessing the Client's Google Analytics data to display metrics and reports within the Client's SimpleKPI dashboard.
  • Google Sheets: importing data into SimpleKPI, and exporting data from SimpleKPI to a Sheet the Client authorises.
  • Google Search Console: accessing the Client's search performance data to display it as KPIs.
  • Xero: accessing the Client's accounting data to display it as KPIs.
  • Stripe: accessing the Client's Stripe account data to display revenue and subscription KPIs. This is the Client's own Stripe account, and is separate from SimpleKPI's use of Stripe to bill the Client, which is covered in Annex III.
  • Zendesk: accessing the Client's support data to display it as KPIs. This is the Client's own Zendesk account, and is separate from SimpleKPI's use of Zendesk for its own support, which is covered in Annex III.

Each integration reads only from the account the Client connects, using credentials the Client authorises and can revoke at any time. SimpleKPI does not write back to a connected source except where an integration explicitly offers it, as Google Sheets export does.

Categories of Data Subject, determined by the Client, typically:

  • the Client's Users, being its employees, contractors and other authorised individuals;
  • individuals identified within Client Data uploaded by the Client, which may include employees, customers, suppliers or members.

Categories of Personal Data:

  • User account data: name, business email address, and optionally profile photograph, time zone and language preference;
  • Usage data: authentication events, actions taken in the Services, and IP address;
  • Client Data content: any Personal Data the Client chooses to upload or enter, which SimpleKPI does not control and cannot predict. This may include names, identifiers, and performance or activity measures relating to identifiable individuals;
  • Integration data: Google Analytics and Google Sheets data the Client authorises SimpleKPI to access.

Special category data: the Services are not designed for special category data as defined in Article 9, and the Agreement prohibits uploading Sensitive Information. The Client is responsible for ensuring none is submitted.

Frequency: continuous, for the duration of the Agreement.

C. Competent supervisory authority

The competent supervisory authority is determined by reference to the data exporter, which under this DPA is the Client. It is therefore identified per Client rather than fixed in advance:

  • where the Client is established in an EU Member State, the supervisory authority of that Member State;
  • where the Client is not established in the EU but is subject to the EU GDPR under Article 3(2) and has appointed a representative under Article 27, the supervisory authority of the Member State in which that representative is established;
  • where the Client is not established in the EU, is subject to the EU GDPR under Article 3(2), and has not appointed a representative, the supervisory authority of a Member State in which the Data Subjects whose Personal Data is transferred are located;
  • for transfers made under the UK International Data Transfer Agreement or the UK Addendum, the Information Commissioner's Office.

For the avoidance of doubt, in respect of the processing for which SimpleKPI acts as an independent Controller under clause 2.2, SimpleKPI's supervisory authority under the UK GDPR is the Information Commissioner's Office.

SimpleKPI has no establishment in the Union. It is established in the United Kingdom only.

Annex II: Technical and organisational measures

Incorporated by clause 5.1. Our wider approach is described on the Security page.

AreaMeasure
HostingMicrosoft Azure data centres, with replication and redundancy managed at platform level
EncryptionEncryption in transit (TLS) and at rest
Secrets managementManaged in Azure Key Vault
Access controlRole-based access control; Owner, Admin, Manager, Contributor, Analyst and Viewer roles; internal processes restricting which personnel may access Client Data
AuthenticationPasswordless sign-in by passkey or email one-time passcode, or through Google or Microsoft single sign-on. Enterprise Clients may connect their own SSO identity provider
PaymentsHandled entirely by Stripe, a PCI DSS Level 1 certified provider. Card data does not touch SimpleKPI systems; SimpleKPI stores only Stripe customer and subscription references
Data mappingA maintained mapping of how Client Data flows across the application and support services
BackupsEncrypted backups, generally retained up to 35 days before secure deletion, per clause 11.4
PortabilitySpreadsheet export and Developer API available to the Client, per clause 8.1
Breach responseNotification to the Client without undue delay and within the period in clause 9.1
Vulnerability managementA defined process for identifying, triaging and remediating security vulnerabilities in the application and its dependencies, together with a published channel for reporting suspected vulnerabilities
Testing and evaluationAutomated test runs are executed daily as part of the development and release process
Restoration of availabilityEncrypted backups are held on Azure infrastructure and are periodically restore-tested, to verify that availability of and access to Client Personal Data can be recovered in a timely manner following a physical or technical incident

Annex III: Authorised Sub-processors

Incorporated by clause 6.2. Corresponds to Annex III of any Transfer Mechanism. Changes are notified under clause 6.4.

Sub-processorContracting entityPurposeProcessing locationTransfer safeguard
Microsoft AzureMicrosoft Ireland Operations Ltd, IrelandApplication hosting, databases, storage, security servicesEuropean Union, West Europe (Netherlands). Data at rest remains in that Azure geography, and the Microsoft EU Data Boundary applies to Customer Data and pseudonymised personal dataCertified under the EU-US Data Privacy Framework and the UK Extension. EU Standard Contractual Clauses and the UK Addendum apply as a fallback
Microsoft Azure AI FoundryMicrosoft Ireland Operations Ltd, IrelandAI Features (model inference). Up to 30-day retention for abuse and misuse monitoring, per clause 3.5Data at rest remains in the Azure geography of the resource. Inference uses a Global Standard deployment, so prompts and responses may be processed in any Azure region worldwide in which the model is deployed. SimpleKPI does not offer a regional residency guarantee for inferenceAs above
CloudflareCloudflare, Inc., United States, and Cloudflare Ltd, United KingdomNetwork security and content deliveryEuropean Union. Cloudflare Regional Services is enabled for the European Union region, so TLS termination and inspection of request content are confined to Cloudflare's EU data centres. Functions operating below the HTTP layer, such as DNS resolution and network-layer DDoS mitigation, remain globalCertified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses with the UK Addendum apply as a fallback
StripeStripe Payments Europe Ltd, Ireland (contracting entity outside the Americas), with processing by Stripe, LLC, United StatesSubscription billing and card processingGlobal by design. Stripe offers no customer-facing option to keep payment data at rest within the EEA onlyStripe, LLC is certified under the EU-US Data Privacy Framework, the UK Extension and the Swiss-US Data Privacy Framework. EU Standard Contractual Clauses and the UK International Data Transfer Addendum apply as a fallback
Amazon Web ServicesAmazon Web Services EMEA SARL, LuxembourgTransactional and service email deliveryEuropean Union, eu-west-1 (Ireland)Certified under the EU-US Data Privacy Framework and the UK Extension. EU Standard Contractual Clauses and the UK Addendum apply under the AWS GDPR Data Processing Addendum
ZendeskZendesk, Inc., United StatesIn-app messaging and support conversationsUnited StatesCertified under the EU-US Data Privacy Framework, the UK Extension and the Swiss-US Data Privacy Framework, and operates Binding Corporate Rules approved by the Irish Data Protection Commission and the UK Information Commissioner's Office
GoogleGoogle Ireland Ltd, Ireland, for Clients in the EEA; Google LLC, United States, for Clients in the UK and as sub-processor to Google Ireland LtdClient-authorised integrations only: displaying the Client's Google Analytics data in the Client's SimpleKPI dashboard, and importing from or exporting to a Google Sheet the Client authorisesGlobal. Data may be processed by Google LLC in the United States as sub-processor to Google Ireland LtdCertified under the EU-US Data Privacy Framework and the UK Extension. EU Standard Contractual Clauses and the UK Addendum apply as a fallback

Scope note on Google. The Google row covers only the Client-authorised Analytics and Sheets integrations described in Section 3.6 of the Privacy Notice. Google Analytics on the public SimpleKPI website is SimpleKPI's own processing as an independent Controller and falls outside this DPA under clause 2.2.

Transfer safeguards and certification status are stated as at the effective date. Data Privacy Framework certifications can lapse; clause 7.3 governs what happens if one does.

Annex IV: Transfer Mechanisms

Applies under clause 7.2.

EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914):

ProvisionSelection
ModuleTwo (Controller to Processor). Module Three (Processor to Processor) where the Client is itself a Processor
Clause 7 (docking)Not included
Clause 9 (sub-processors)Option 2, general written authorisation, with the notice period in clause 6.4. Clause 9(c) copies are provided under clause 6.3
Clause 11 (redress)The optional independent dispute resolution body is not used
Clause 17 (governing law)The law of Ireland
Clause 18 (forum)The courts of Ireland
Annex I.A, I.B and I.CAnnex I, sections A, B and C of this DPA
Annex IIAnnex II of this DPA
Annex IIIAnnex III of this DPA

UK transfers. SimpleKPI uses the UK Addendum (the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018), rather than the standalone UK International Data Transfer Agreement, so that one set of Clauses covers both EEA and UK transfers.

TableCompletion
Table 1 (Parties)Annex I, section A of this DPA
Table 2 (Selected SCCs, Modules and Selected Clauses)The EU Standard Contractual Clauses as elected above
Table 3 (Appendix Information)Annexes I, II and III of this DPA
Table 4 (Ending this Addendum when the Approved Addendum changes)Neither party

The Addendum's Mandatory Clauses govern UK transfers and replace Clauses 17 and 18 of the EU Standard Contractual Clauses for those transfers. The choice of Irish law at Clause 17 above therefore applies to transfers from the EEA, not to transfers from the UK.

Get started with your KPI Software

Get started for free