Data processing agreement.
1. Do you need one?
Probably not, and it is worth saying so before the rest of this page.
If you are a student using Obiter for your own studies — which is almost everyone — you do not need a DPA with us and we could not sensibly sign one with you. In that relationship we are the controller of your personal data: we decide what is collected and why. Your rights are set out in our Privacy Policy and our GDPR rights page, and a processing agreement would add nothing to them.
A DPA matters when you are the controller and we are processing personal data on your instructions. That happens where an organisation puts Obiter in front of its own people:
- a university, law school or department buying access for its students;
- a firm or chambers providing Obiter to trainees or pupils;
- any organisation holding the account and deciding who uses it.
In those arrangements the organisation decides whose data goes in and why, so the organisation is the controller and Article 28 of the UK GDPR requires a written contract between us. That is what this page is for.
2. How to get one
Email privacy@obiter.site with your organisation's name, the account it relates to, and who should sign. We will send our standard DPA back, normally within 5 working days.
There is no charge, and you do not need to be on a particular plan.
If your organisation has its own DPA it would rather use, send it. We will read it properly and tell you what we can and cannot accept. What we will not do is sign a document without reading it — a processor that agrees to everything is not offering you any protection.
3. What our standard DPA covers
Everything Article 28(3) requires, namely:
- the subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects;
- that we process only on your documented instructions, including for transfers;
- confidentiality commitments from everyone we authorise to process the data;
- the security measures we take under Article 32 — described on our security page;
- the terms on which we engage sub-processors, and your right to be told before a new one is added;
- our help with data subject requests, and with your obligations under Articles 32 to 36;
- deletion or return of the data when the service ends;
- the information and audit rights Article 28(3)(h) gives you;
- the UK International Data Transfer Addendum, where a sub-processor is outside the UK.
Our current sub-processors, what each one does and where it is, are published at /sub-processors. That list is not held back for contract negotiations — you can read it before you talk to us.
4. Which parts we will not vary
Said up front so nobody spends three weeks discovering it:
- Sub-processors. We will give you notice and a right to object, but we cannot give any single customer a veto over infrastructure the whole service depends on.
- On-site audits. We are a small team. We will answer security questionnaires, provide documentation and support a remote audit. We cannot host physical inspections.
- Data location. Our database and file storage are in London and stay there. AI features involve a transfer to the United States under the UK IDTA; that is inherent to the feature, and an organisation that cannot accept it should disable AI features for its users rather than have us promise otherwise.
- Uncapped liability. We will discuss the cap. We will not agree that it does not exist.
5. Who you are contracting with
Obiter Technologies Ltd, a company registered in England and Wales (number 17329055), whose registered office is at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
We are not required to appoint a Data Protection Officer under Article 37, and we have not appointed one. Data protection questions go to privacy@obiter.site and reach a person, not a queue.