What it says
What this says
Current to 11 Oct 26Executed DPA effective 12 Dec 2025 between Harrowden Foods (Controller) and BB-Demo (Processor). It sets processing scope, security, sub-processor, transfer, breach, deletion and audit terms. It states no availability, response time or price figures.
What it is: an executed data processing agreement under UK GDPR. It sits alongside the master services agreement and any order form, and "Where this DPA and another contract document conflict on the handling of personal data, this DPA prevails."
Commits: BB-Demo processes data only on documented instructions, keeps processing inside the Controller's own Snowflake account, and notifies breaches "without undue delay". On exit it will return or delete data and remove the brain's indexes.
Unusual: no fixed breach notification window, no fixed deletion period ("within a reasonable period"), and general authorisation for sub-processors with a reasonable objection period. Transfers outside the United Kingdom need an appropriate safeguard and notice.
Not settled: the document gives no price, service levels, term or renewal date. The Harrowden signatory is shown only as "Authorised signatory", so the evidence does not show who signed for the customer.
As found in this document
Current to 9 Oct 26- Date signed12 Dec 2025Source: object_read:doc_009_006
- Date start12 Dec 2025Source: object_read:doc_009_006
- Processing instructionsThe Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructionsThe Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructions · Source: object_read:doc_009_006
- Data locationprocessing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environmentprocessing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environment · Source: object_read:doc_009_006
- Breach notificationwithout undue delay after becoming aware of a personal data breachwithout undue delay after becoming aware of a personal data breach · Source: object_read:doc_009_006
- International transfersnot outside the United Kingdom unless covered by an appropriate safeguard and the Controller has been toldnot outside the United Kingdom unless covered by an appropriate safeguard and the Controller has been told · Source: object_read:doc_009_006
- Return and deletionreturn or delete Controller Data at the Controller's choice within a reasonable period, unless the law requires retentionreturn or delete Controller Data at the Controller's choice within a reasonable period, unless the law requires retention · Source: object_read:doc_009_006
- Auditon reasonable notice, during business hours and subject to sensible confidentiality and scope limitson reasonable notice, during business hours and subject to sensible confidentiality and scope limits · Source: object_read:doc_009_006
The document
Body
Harrowden Foods - Data Processing Agreement (signed)
Status: Executed
Effective date: 12 Dec 2025
Parties
This Data Processing Agreement (the "DPA") is made between:
- Harrowden Foods, a food manufacturer with its headquarters in Leicester, United Kingdom (the "Controller"); and
- BB-Demo, a data business based in London, United Kingdom (the "Processor").
The DPA sits alongside the master services agreement and any order form agreed between the parties. Where this DPA and another contract document conflict on the handling of personal data, this DPA prevails.
Background
The Controller intends to use the BB-Demo company brain, an AI-queryable layer over its business systems, so that its commercial insights and customer service teams can see retailer accounts, service-level complaints and orders together. The brain is built and run inside the Controller's own Snowflake account. In doing so the Processor may handle personal data on behalf of the Controller. This DPA sets out how that data is handled.
Part A: Definitions
Read the whole document (6,895 characters)
Terms such as "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Controller Data" means personal data processed by the Processor on behalf of the Controller under this DPA. "Services" means the implementation and subscription services described in the order form.
Part B: Scope and roles
- The Controller is the controller of the Controller Data and the Processor is its processor.
- The Processor processes Controller Data only to deliver the Services and only on the Controller's documented instructions, including those given through configuration of the brain.
- If the Processor believes an instruction infringes data protection law, it will tell the Controller promptly.
Part C: Processing details
| Item | Description |
|---|---|
| Subject matter | Delivery of the BB-Demo company brain to the Controller |
| Duration | The term of the agreement, plus the return or deletion period in Part J |
| Nature of processing | Indexing, storing, searching and summarising data from connected systems, and answering questions put by the Controller's users |
| Purpose | Giving the Controller's teams a single view of retailer accounts, orders and service complaints |
| Categories of data subjects | The Controller's employees and contractors; contacts at retailers, suppliers and other business partners |
| Types of personal data | Business contact details, job titles, call and email content, support and complaint records, user account and usage data |
| Special category data | None is intended to be processed. The Controller will not connect sources that hold it without agreeing this in writing first |
Part D: Processor obligations
The Processor will:
- process Controller Data only as instructed under Part B;
- ensure that everyone authorised to process Controller Data is bound by a duty of confidentiality;
- apply the security measures in Part F;
- assist the Controller, taking account of the nature of the processing, in responding to requests from data subjects;
- assist the Controller with security, breach notification, impact assessments and consultation with a supervisory authority; and
- make available the information needed to show compliance with this DPA.
Part E: Controller obligations
The Controller confirms that it has a lawful basis for the processing it instructs, that it has given any required notices to data subjects, and that its instructions comply with data protection law. The Controller chooses which systems are connected to the brain and is responsible for the access rights of its own users.
Part F: Security
The Processor will maintain appropriate technical and organisational measures to protect Controller Data, including:
- processing inside the Controller's own Snowflake account, so that Controller Data is not copied into a shared BB-Demo environment;
- access controls limited to named staff with a need to know;
- encryption of data in transit and at rest;
- logging of administrative access to the brain; and
- regular review of the measures in light of risk and of changes to the Services.
Part G: Sub-processors
The Controller gives general authorisation for the Processor to use sub-processors where needed to deliver the Services. The Processor will keep an up-to-date list available to the Controller, will give notice of any intended addition or replacement, and will allow the Controller a reasonable period to object. The Processor remains responsible for the acts of its sub-processors and will bind them to terms no less protective than this DPA.
Part H: International transfers
The Processor will not transfer Controller Data outside the United Kingdom unless the transfer is covered by an appropriate safeguard under data protection law and the Controller has been told. Dedicated data residency is available as an add-on under an order form.
Part I: Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Data. The notice will describe, as far as known, the nature of the breach, the data and data subjects concerned, the likely consequences and the steps taken or proposed. The Processor will cooperate with the Controller's investigation and any notification the Controller must make.
Part J: Return and deletion
On expiry or termination of the Services, the Processor will, at the Controller's choice, return or delete Controller Data and remove the brain's indexes from the Controller's environment within a reasonable period, unless the law requires retention. The Controller keeps ownership of its Snowflake account and all data in it throughout.
Part K: Audit
The Processor will allow and contribute to audits, including inspections, by the Controller or an auditor it appoints, on reasonable notice, during business hours and subject to sensible confidentiality and scope limits. The Processor will answer security questionnaires from the Controller in good faith.
Part L: Liability and governing law
Liability under this DPA is subject to the limits in the master services agreement. This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.
Relationship contacts
| Role | Name |
|---|---|
| BB-Demo account owner | Lewis Kerr |
| BB-Demo customer success manager | Amara Obi |
Signatures
Signed by the authorised representatives of the parties on 12 Dec 2025.
| For Harrowden Foods | For BB-Demo | |
|---|---|---|
| Name | Authorised signatory | Lewis Kerr |
| Title | Authorised signatory of the Controller | Account Executive |
| Date | 12 Dec 2025 | 12 Dec 2025 |
| Signature | Signed | Signed |
Unusual terms
Current to 9 Oct 26- No fixed breach notification window
- No fixed deletion period
- General authorisation for sub-processors