ENTERPRISE · DATA PROCESSING

Data Processing Addendum

Draft for procurement/legal adaptation. Version 1.0, 23 August 2026. This is a product-supplied starting point, not legal advice. A signed customer DPA or master agreement prevails.

This Addendum applies where GMBF Ventures Ltd, trading as SnagSort, processes Customer Personal Data on behalf of a customer.

1. Roles

The Customer is controller, or a processor acting on another controller’s instructions, for Customer Personal Data placed in SnagSort. GMBF Ventures Ltd acts as processor for that data except for limited independent controller activities such as billing, service security, legal records and website enquiries.

2. Instructions and purpose

GMBF Ventures Ltd will process Customer Personal Data only on documented Customer instructions, including the customer agreement, configured project access and documented support instructions, unless law requires otherwise.

3. Confidentiality

Persons authorised to process Customer Personal Data will be subject to appropriate confidentiality obligations.

4. Security

GMBF Ventures Ltd will implement technical and organisational measures appropriate to risk. Current product controls include private project photo storage, scoped project/external access, time-limited signed links, revocable guest access and server-side authorisation.

5. Subprocessors

The Customer authorises subprocessors reasonably necessary to operate SnagSort, subject to appropriate data-protection terms. Current subprocessor information will be made available to enterprise customers. GMBF Ventures Ltd remains responsible for its processor obligations as required by law.

6. AI-assisted drafting

Where an authorised Customer user invokes AI-assisted drafting, selected notes, project context and selected photographs required for that draft may be sent to the configured AI API provider. GMBF Ventures Ltd will not intentionally opt Customer Personal Data into an AI provider’s model-training/data-sharing programme without explicit written Customer authorisation.

7. International transfers

Where a transfer outside the UK requires safeguards, GMBF Ventures Ltd will use an applicable lawful transfer mechanism and required supplementary measures.

8. Data-subject requests

Taking account of the nature of processing, GMBF Ventures Ltd will provide reasonable assistance to enable the Customer to respond to applicable data-subject rights requests.

9. Personal-data breaches

GMBF Ventures Ltd will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide reasonably available information required for assessment and notification.

10. DPIAs and consultation

Taking account of the nature of processing and information available, GMBF Ventures Ltd will provide reasonable assistance with DPIAs and prior consultation where required.

11. Return and deletion

At the Customer’s choice and subject to the agreed service terms, GMBF Ventures Ltd will return/export and/or delete Customer Personal Data after the relevant services end, except where retention is required by law or limited technical backup cycles apply.

12. Audit information

GMBF Ventures Ltd will make available information reasonably necessary to demonstrate compliance and support proportionate assessments subject to reasonable notice, confidentiality, security and cost arrangements.

13. Precedence

A signed customer agreement or negotiated DPA prevails over this published draft to the extent of conflict.