Data processing agreement

Last updated 4 October 2026.

About this agreement

This Data Processing Agreement ("DPA") forms part of the contract between Oshy Labs Ltd (company number 16883720, registered office 100 St Pier Court, 549 Green Street, London E13 9GU) ("Processor", "we") and the business customer that has agreed to our Terms of Service ("Controller", "you") for Broker Lead Lab. It applies whenever we process personal data on your behalf as part of the service. If there is a conflict between this DPA and the Terms of Service on data protection matters, this DPA takes priority.

1. Roles and scope

1.1 You are the controller of the personal data contained in the lead records and files you upload to Broker Lead Lab. We are the processor. This DPA does not apply to personal data we process as controller, such as your user account details or our own sales outreach data, which are covered by our Privacy Notice instead.

1.2 Subject matter, duration, nature and purpose: providing the Broker Lead Lab service as described in the Terms of Service, producing source to outcome reports and controlled tests for you, for the duration of your subscription or Pilot and any period afterwards during which we hold your data before deletion.

1.3 Categories of data subjects: your prospective sellers and enquirers whose details appear in uploaded files or records, and your own agents and staff named in uploaded records.

1.4 Categories of personal data. Lead records: CRM reference, dates, lead source, campaign, agent name, postcode district or zip code, status, outcome, and commission or cost figures; names, email addresses and phone numbers are automatically detected and discarded on import and are not knowingly retained in lead records. Raw CSV files: whatever columns your CRM exported, which may include lead names, email addresses, phone numbers and property addresses, held in private storage for the retention period set on your organisation (30 days by default, or shorter if you choose) and then deleted.

2. Processor obligations (UK GDPR Article 28(3))

2.1 Instructions. We will only process personal data on your documented instructions, including about transfers to a third country, unless we are required to do otherwise by law, in which case we will tell you before processing (unless the law prohibits this). Your use of the service as designed, and its settings, are your documented instructions.

2.2 Infringing instructions. If, in our opinion, an instruction you give us infringes the UK GDPR, the Data Protection Act 2018 or any other applicable data protection law, we will tell you immediately and may suspend performance of that instruction until the issue is resolved between us.

2.3 Confidentiality. We ensure that anyone we authorise to process personal data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

2.4 Security. We take the technical and organisational security measures required by Article 32 UK GDPR, appropriate to the risk, including those listed in Annex 3, and we will not reduce them during this DPA.

2.5 Sub-processors. You give us general authorisation to use the sub-processors in clause 6. We will give you at least 30 days' notice on the changelog before adding or replacing a sub-processor, and you may object on reasonable data protection grounds during that period and, if we cannot resolve the objection, end the agreement. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for a sub-processor's performance.

2.6 Assisting with data subject rights. Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects exercising their rights under UK GDPR Chapter III, including through the export and deletion functions in the product.

2.7 Assisting with security, breach notice, DPIAs and consultation. Taking into account the nature of processing and the information available to us, we will assist you in complying with your obligations under Articles 32 to 36 UK GDPR, including by: notifying you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data; providing information reasonably needed for your own breach assessment and notification duties; and providing reasonable assistance with data protection impact assessments and, where a DPIA indicates a high risk that cannot be mitigated, with any related consultation with the Information Commission.

2.8 Deletion or return. At your choice, and in any event at the end of the Pilot or subscription, we will delete or return all personal data we process on your behalf, and delete existing copies, unless we are required by law to keep it. You can export your data for 30 days after the end; deleting an organisation removes every row and file and leaves only a record that the deletion happened, with row counts.

2.9 Audits and information. We will make available to you the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and subject to reasonable confidentiality and scheduling arrangements, no more than once a year unless required by a regulator. Given the scale of our business, we may first satisfy this obligation by providing a current security and compliance summary, and offering a call or questionnaire response, before agreeing to an on-site audit.

3. Sub-processor flow-down (UK GDPR Article 28(4))

Where we engage a sub-processor to carry out specific processing on your behalf, we impose on that sub-processor, by contract, the same data protection obligations that apply to us under this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets UK GDPR requirements. If a sub-processor fails to meet its data protection obligations, we remain fully liable to you for that sub-processor's performance.

4. International transfers

Where processing under this DPA involves a transfer of personal data outside the UK, the transfer mechanism annex (Annex 1) applies.

5. US state privacy law

To the extent any personal data we process on your behalf is subject to US state privacy law, the US state law service provider annex (Annex 2) applies in addition to the terms above.

6. Sub-processors

We currently use the following sub-processors. We will update this table, and give you notice under clause 2.5, before adding or replacing a sub-processor.

Sub-processorServiceLocation of processingContracting entityTransfer basis
SupabaseDatabase, authentication and file storageLondon, UK (eu-west-2)Supabase Pte Ltd (Singapore)Data is stored and processed in London; the contract with the Singapore entity is treated as a restricted transfer covered by the UK Addendum or IDTA in Annex 1
VercelHosting and application functionsLondon, UK (functions); worldwide edge for static assetsVercel Inc (US)Restricted transfer; UK Addendum or IDTA as set out in Annex 1
ResendTransactional and account emailUnited StatesResend Inc (US)Restricted transfer; UK Addendum or IDTA as set out in Annex 1
StripePayment processingUnited States and globalStripe, Inc. and affiliatesRestricted transfer; Stripe's data protection terms with the UK Addendum or IDTA as set out in Annex 1
GoogleOptional sign-inGlobal (as operated by Google)Google LLCRestricted transfer where applicable; Google's standard contractual terms with the UK Addendum or IDTA as set out in Annex 1
PostHogOptional product analytics (no profiles, no autocapture, no lead data)European UnionPostHog Inc / PostHog EUNo restricted transfer where EU hosting is used; UK adequacy for the EU applies
TypesafeOptional decision support ("Jev"), aggregate counts onlyNot switched onTypesafeNot in use. We will not switch it on until its hosting location and transfer basis are confirmed and you have had notice under clause 2.5

7. General

7.1 This DPA is governed by the law of England and Wales, in line with the Terms of Service. 7.2 If any part of this DPA is found unenforceable, the rest continues to apply. 7.3 This DPA ends automatically when the Terms of Service end, except for obligations that by their nature continue, such as confidentiality and deletion or return of data.

Annex 1: International transfer mechanism

This annex applies wherever processing under this DPA involves a restricted transfer of personal data from the UK to a country that does not benefit from UK adequacy regulations.

A1.1 Transfer tool. Where we or a sub-processor transfer personal data outside the UK without the benefit of UK adequacy regulations, we use the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as appropriate, completed with the relevant importer, together with a transfer risk assessment addressing the destination country's laws and practices.

A1.2 No sole reliance on the UK-US data bridge. For transfers to the United States, we do not rely solely on the UK extension to the EU-US Data Privacy Framework (the "UK-US data bridge"), in light of ongoing uncertainty about the independence of the US oversight mechanisms that support it. Where a US importer is not a current, verified participant in the framework, or where we consider the framework alone insufficient, we use the IDTA or UK Addendum as the primary safeguard, supported by a transfer risk assessment.

A1.3 Transfers covered. This includes, at a minimum, the transfer arising from Supabase's contracting entity being based in Singapore (even though data is stored in London), and transfers to Vercel Inc, Resend Inc, Stripe and Google, to the extent each involves processing outside the UK, and to Typesafe if it is switched on.

A1.4 Updates. We will update the safeguards used under this annex if the law changes, including if a UK adequacy decision or data bridge is adopted, replaced or successfully challenged, and will reflect any such change in the sub-processor table in clause 6.

Annex 2: US state privacy law service provider terms

This annex applies to the extent personal data processed under this DPA is subject to US state privacy law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act and the Texas Data Privacy and Security Act.

A2.1 Role. We act as your "service provider" (CCPA/CPRA) and "processor" (Virginia, Colorado, Connecticut and Texas) for personal data we process on your behalf under this DPA, and only for the business purpose of providing Broker Lead Lab to you.

A2.2 Restrictions on use. We will not: sell or share personal data we process on your behalf; retain, use or disclose it for any purpose other than providing the service to you, as instructed in writing, including any commercial purpose other than providing the service; retain, use or disclose it outside our direct business relationship with you; or combine it with personal data we receive from other sources, except as each applicable law permits.

A2.3 Certification. We certify that we understand and will comply with the restrictions in this annex.

A2.4 Assistance. We will provide reasonable assistance to help you respond to consumer or data subject rights requests under applicable US state privacy law, and will notify you if we receive such a request directly, without responding to it ourselves unless you instruct us to.

A2.5 Subcontractors. We will ensure that any subcontractor we use to process personal data on your behalf is bound by written terms that are at least as protective as this annex.

Annex 3: Security measures

  • Row level security in the database on every table, so one organisation's queries cannot return another's rows, verified by an automated probe after every schema change.
  • Encryption in transit (TLS) and at rest by the hosting providers.
  • Name, email and phone columns detected and dropped before storage. Raw files held in a private bucket, downloadable only by members through short lived signed links.
  • Role based access enforced in the database, with owner, manager, analyst and viewer roles.
  • Append only audit log of imports, exports, deletions, role changes and outcome edits.
  • Secrets held in the hosting provider's environment, never in source control. Service credentials never shipped to the browser.
  • A retention job that removes raw files past the customer's retention period.
Data processing agreement · Broker Lead Lab