Harrowden Foods: documents logo

Harrowden Foods - Data Processing Agreement (signed)

Documentexecuted

Harrowden Foods: documents logo Harrowden Foods: documents · dpa · executed · 2025-12-12

Executed DPA effective 12 Dec 2025 between Harrowden Foods (Controller) and BB-Demo (Processor). It sets processing scope, security, sub-processor, transfer, breach, deletion and audit terms. It states no availability, response time or price figures.

What it says

What this says

Current to 11 Oct 26

Executed DPA effective 12 Dec 2025 between Harrowden Foods (Controller) and BB-Demo (Processor). It sets processing scope, security, sub-processor, transfer, breach, deletion and audit terms. It states no availability, response time or price figures.

What it is: an executed data processing agreement under UK GDPR. It sits alongside the master services agreement and any order form, and "Where this DPA and another contract document conflict on the handling of personal data, this DPA prevails."

Commits: BB-Demo processes data only on documented instructions, keeps processing inside the Controller's own Snowflake account, and notifies breaches "without undue delay". On exit it will return or delete data and remove the brain's indexes.

Unusual: no fixed breach notification window, no fixed deletion period ("within a reasonable period"), and general authorisation for sub-processors with a reasonable objection period. Transfers outside the United Kingdom need an appropriate safeguard and notice.

Not settled: the document gives no price, service levels, term or renewal date. The Harrowden signatory is shown only as "Authorised signatory", so the evidence does not show who signed for the customer.

AI · claude-sonnet-5-5 · 11 Oct 2026

As found in this document

Current to 9 Oct 26
  • Date signed12 Dec 2025Source: object_read:doc_009_006
  • Date start12 Dec 2025Source: object_read:doc_009_006
  • Processing instructionsThe Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructionsThe Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructions · Source: object_read:doc_009_006
  • Data locationprocessing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environmentprocessing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environment · Source: object_read:doc_009_006
  • Breach notificationwithout undue delay after becoming aware of a personal data breachwithout undue delay after becoming aware of a personal data breach · Source: object_read:doc_009_006
  • International transfersnot outside the United Kingdom unless covered by an appropriate safeguard and the Controller has been toldnot outside the United Kingdom unless covered by an appropriate safeguard and the Controller has been told · Source: object_read:doc_009_006
  • Return and deletionreturn or delete Controller Data at the Controller's choice within a reasonable period, unless the law requires retentionreturn or delete Controller Data at the Controller's choice within a reasonable period, unless the law requires retention · Source: object_read:doc_009_006
  • Auditon reasonable notice, during business hours and subject to sensible confidentiality and scope limitson reasonable notice, during business hours and subject to sensible confidentiality and scope limits · Source: object_read:doc_009_006

The document

Body

Harrowden Foods - Data Processing Agreement (signed)

Status: Executed

Effective date: 12 Dec 2025

Parties

This Data Processing Agreement (the "DPA") is made between:

  • Harrowden Foods, a food manufacturer with its headquarters in Leicester, United Kingdom (the "Controller"); and
  • BB-Demo, a data business based in London, United Kingdom (the "Processor").

The DPA sits alongside the master services agreement and any order form agreed between the parties. Where this DPA and another contract document conflict on the handling of personal data, this DPA prevails.

Background

The Controller intends to use the BB-Demo company brain, an AI-queryable layer over its business systems, so that its commercial insights and customer service teams can see retailer accounts, service-level complaints and orders together. The brain is built and run inside the Controller's own Snowflake account. In doing so the Processor may handle personal data on behalf of the Controller. This DPA sets out how that data is handled.

Part A: Definitions

Read the whole document (6,895 characters)

Terms such as "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Controller Data" means personal data processed by the Processor on behalf of the Controller under this DPA. "Services" means the implementation and subscription services described in the order form.

Part B: Scope and roles

  • The Controller is the controller of the Controller Data and the Processor is its processor.
  • The Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructions, including those given through configuration of the brain.
  • If the Processor believes an instruction infringes data protection law, it will tell the Controller promptly.

Part C: Processing details

ItemDescription
Subject matterDelivery of the BB-Demo company brain to the Controller
DurationThe term of the agreement, plus the return or deletion period in Part J
Nature of processingIndexing, storing, searching and summarising data from connected systems, and answering questions put by the Controller's users
PurposeGiving the Controller's teams a single view of retailer accounts, orders and service complaints
Categories of data subjectsThe Controller's employees and contractors; contacts at retailers, suppliers and other business partners
Types of personal dataBusiness contact details, job titles, call and email content, support and complaint records, user account and usage data
Special category dataNone is intended to be processed. The Controller will not connect sources that hold it without agreeing this in writing first

Part D: Processor obligations

The Processor will:

  1. process Controller Data only as instructed under Part B;
  2. ensure that everyone authorised to process Controller Data is bound by a duty of confidentiality;
  3. apply the security measures in Part F;
  4. assist the Controller, taking account of the nature of the processing, in responding to requests from data subjects;
  5. assist the Controller with security, breach notification, impact assessments and consultation with a supervisory authority; and
  6. make available the information needed to show compliance with this DPA.

Part E: Controller obligations

The Controller confirms that it has a lawful basis for the processing it instructs, that it has given any required notices to data subjects, and that its instructions comply with data protection law. The Controller chooses which systems are connected to the brain and is responsible for the access rights of its own users.

Part F: Security

The Processor will maintain appropriate technical and organisational measures to protect Controller Data, including:

  • processing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environment;
  • access controls limited to named staff with a need to know;
  • encryption of data in transit and at rest;
  • logging of administrative access to the brain; and
  • regular review of the measures in light of risk and of changes to the Services.

Part G: Sub-processors

The Controller gives general authorisation for the Processor to use sub-processors where needed to deliver the Services. The Processor will keep an up-to-date list available to the Controller, will give notice of any intended addition or replacement, and will allow the Controller a reasonable period to object. The Processor remains responsible for the acts of its sub-processors and will bind them to terms no less protective than this DPA.

Part H: International transfers

The Processor will not transfer Controller Data outside the United Kingdom unless the transfer is covered by an appropriate safeguard under data protection law and the Controller has been told. Dedicated data residency is available as an add-on under an order form.

Part I: Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Data. The notice will describe, as far as known, the nature of the breach, the data and data subjects concerned, the likely consequences and the steps taken or proposed. The Processor will cooperate with the Controller's investigation and any notification the Controller must make.

Part J: Return and deletion

On expiry or termination of the Services, the Processor will, at the Controller's choice, return or delete Controller Data and remove the brain's indexes from the Controller's environment within a reasonable period, unless the law requires retention. The Controller keeps ownership of its Snowflake account and all data in it throughout.

Part K: Audit

The Processor will allow and contribute to audits, including inspections, by the Controller or an auditor it appoints, on reasonable notice, during business hours and subject to sensible confidentiality and scope limits. The Processor will answer security questionnaires from the Controller in good faith.

Part L: Liability and governing law

Liability under this DPA is subject to the limits in the master services agreement. This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.

Relationship contacts

RoleName
BB-Demo account ownerLewis Kerr
BB-Demo customer success managerAmara Obi

Signatures

Signed by the authorised representatives of the parties on 12 Dec 2025.

For Harrowden FoodsFor BB-Demo
NameAuthorised signatoryLewis Kerr
TitleAuthorised signatory of the ControllerAccount Executive
Date12 Dec 202512 Dec 2025
SignatureSignedSigned
Documentsmade from

Unusual terms

Current to 9 Oct 26
  • No fixed breach notification window
  • No fixed deletion period
  • General authorisation for sub-processors

BB-Demo is a fictional company; every organisation and person here is invented. B-Brain is the tool. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations150
People at customers573
BB-Demo staff48
Calls1,382
Email threads2,122
Support tickets789
Documents850
Deals217
Invoices187
Events49
News items84

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

BB-Demo is a fictional company: every organisation, person and figure here is invented for this demonstration. B-Brain is the tool that reads its data.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

HelpAsk B

Ask B

B-Brain · read-only