Last updated 5 September 2026

Data Processing Agreement

Version 1.0. This agreement forms part of the Terms of Service and applies to every customer. A countersigned copy is available on request from privacy@throughlineop.co.uk.

1. Parties and roles

This agreement is between the customer (the “Controller”) and Throughline Ltd, company number 13063175, registered office C E M E Innovation Centre, Marsh Way, Rainham, England, RM13 8EU(the “Processor”, “we”).

For personal data the Controller places in its workspace — its customers’ and suppliers’ business contacts, delivery addresses, the names on purchase orders — the Controller determines the purposes and means of processing, and we process it only on the Controller’s instructions. For the Controller’s own account data (who has a login and how they use the service) we are the controller, and the Privacy Policy applies.

2. Subject matter, duration, nature and purpose

Subject matter: the personal data contained in purchase orders, sales orders, customer and supplier records, dispatch and invoice documents and related operational records that the Controller uploads, connects or creates in ThroughlineOps.

Nature and purpose: storing, reading, extracting, matching, transmitting to the warehouses, sales channels and accounting systems the Controller connects, and reporting on that data, in order to provide the service described in the Terms.

Duration: the term of the Controller’s agreement with us, plus the export period after termination stated in the Terms, after which the data is deleted.

Categories of data subject: the Controller’s customers’ and suppliers’ staff, delivery recipients, and the Controller’s own users. Categories of data: names, business email addresses and telephone numbers, delivery addresses, order references and the commercial content of orders and invoices. We do not require, and the service is not designed for, special-category data.

3. Our obligations as Processor

We will:

  1. process personal data only on the Controller’s documented instructions, which include the Terms, the configuration the Controller sets in the service, and the connections the Controller makes — unless UK law requires otherwise, in which case we will tell the Controller before processing where the law permits;
  2. ensure that people authorised to process the data are bound by confidentiality;
  3. implement the technical and organisational measures in section 6;
  4. engage sub-processors only under section 5;
  5. taking into account the nature of the processing, assist the Controller with data-subject requests — the service lets the Controller find, export and delete a data subject’s records itself, and we will help where it cannot;
  6. assist the Controller with its security, breach-notification and impact-assessment obligations, taking into account the information available to us;
  7. at the end of the service, delete the personal data after the export period in the Terms, unless UK law requires us to keep it;
  8. make available the information necessary to demonstrate compliance, and allow for and contribute to audits under section 8.

4. Personal data breach

We will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller’s data, with the information we have at the time and updates as we learn more. Notification goes to the workspace owners’ and billing contact’s email addresses.

5. Sub-processors

The Controller gives general authorisation for the sub-processors listed on the sub-processor page, which at the date of this version are: Supabase, Vercel, Resend, Google (Gemini API).

We will give at least 14 days’ notice by email before a new sub-processor processes the Controller’s personal data. The Controller may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, the Controller may terminate the affected service without penalty for the remainder of the term. We impose data-protection obligations on each sub-processor equivalent to those in this agreement and remain responsible for their performance.

The sales channels, warehouses and accounting systems the Controller connects are the Controller’s own providers, receive data on the Controller’s instruction under the Controller’s agreements with them, and are not our sub-processors.

6. Security measures

The measures we apply are described on the security page and include: isolation of each Controller’s data by row-level security enforced at the database on every table; encryption in transit; encryption of integration credentials with a server-held key; verification of inbound webhooks; role-based permissions enforced on the server and at the database; an audit log that no user of the application can edit; and a per-workspace switch to prevent any content being sent to the AI provider. Encryption at rest is provided by our database provider. We will not reduce the overall level of protection during the term.

7. International transfers

The Controller’s data rests in AWS eu-west-2 (London, United Kingdom). Where a sub-processor is outside the UK, transfer relies on the UK extension to the EU–US Data Privacy Framework or on standard contractual clauses in that sub-processor’s terms, as stated on the sub-processor page. We will not transfer the Controller’s personal data to a country without adequate protection or an appropriate safeguard.

8. Audit

On reasonable written notice, no more than once a year unless a breach or a regulator requires it, we will answer the Controller’s reasonable security questionnaire and provide evidence of the measures in section 6, including walking a reviewer through the relevant source and database policies. Where that does not resolve a reasonable concern, we will allow an audit by the Controller or an independent auditor bound by confidentiality, at the Controller’s cost, scoped to the Controller’s data and conducted so as not to affect other customers.

9. Liability and precedence

Liability under this agreement is subject to the limitations in the Terms. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails. This agreement is governed by the law of England and Wales.