ENTERPRISE · DATA PROCESSING
Data Processing Addendum
Draft for procurement/legal adaptation. Version 1.0, 23 August 2026. This is a product-supplied starting point, not legal advice. A signed customer DPA or master agreement prevails.
This Addendum applies where GMBF Ventures Ltd, trading as SnagSort, processes Customer Personal Data on behalf of a customer.
1. Roles
The Customer is controller, or a processor acting on another controller’s instructions, for Customer Personal Data placed in SnagSort. GMBF Ventures Ltd acts as processor for that data except for limited independent controller activities such as billing, service security, legal records and website enquiries.
2. Instructions and purpose
GMBF Ventures Ltd will process Customer Personal Data only on documented Customer instructions, including the customer agreement, configured project access and documented support instructions, unless law requires otherwise.
3. Confidentiality
Persons authorised to process Customer Personal Data will be subject to appropriate confidentiality obligations.
4. Security
GMBF Ventures Ltd will implement technical and organisational measures appropriate to risk. Current product controls include private project photo storage, scoped project/external access, time-limited signed links, revocable guest access and server-side authorisation.
5. Subprocessors
The Customer authorises subprocessors reasonably necessary to operate SnagSort, subject to appropriate data-protection terms. Current subprocessor information will be made available to enterprise customers. GMBF Ventures Ltd remains responsible for its processor obligations as required by law.
6. AI-assisted drafting
Where an authorised Customer user invokes AI-assisted drafting, selected notes, project context and selected photographs required for that draft may be sent to the configured AI API provider. GMBF Ventures Ltd will not intentionally opt Customer Personal Data into an AI provider’s model-training/data-sharing programme without explicit written Customer authorisation.
7. International transfers
Where a transfer outside the UK requires safeguards, GMBF Ventures Ltd will use an applicable lawful transfer mechanism and required supplementary measures.
8. Data-subject requests
Taking account of the nature of processing, GMBF Ventures Ltd will provide reasonable assistance to enable the Customer to respond to applicable data-subject rights requests.
9. Personal-data breaches
GMBF Ventures Ltd will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide reasonably available information required for assessment and notification.
10. DPIAs and consultation
Taking account of the nature of processing and information available, GMBF Ventures Ltd will provide reasonable assistance with DPIAs and prior consultation where required.
11. Return and deletion
At the Customer’s choice and subject to the agreed service terms, GMBF Ventures Ltd will return/export and/or delete Customer Personal Data after the relevant services end, except where retention is required by law or limited technical backup cycles apply.
12. Audit information
GMBF Ventures Ltd will make available information reasonably necessary to demonstrate compliance and support proportionate assessments subject to reasonable notice, confidentiality, security and cost arrangements.
13. Precedence
A signed customer agreement or negotiated DPA prevails over this published draft to the extent of conflict.
