Data Processing Agreement

How we process data on your behalf.

This Data Processing Agreement (DPA) forms part of your main agreement with Ingenious Pixies Ltd. It explains exactly how we, Pixie (the “Processor”), handle the personal data you (the “Controller” or “Customer”) provide to us when using the Pixie platform and related services.

Our goal is to meet the strict requirements of data protection laws including UK GDPR and EU GDPR. If there is any conflict between this DPA and your main Services agreement, this DPA will generally take priority.

1. Key definitions

TermMeaning
Controller / Customer / YouYour company - the entity that decides why and how personal data is processed.
Processor / Pixie / WeIngenious Pixies Ltd - processes personal data on your behalf as part of providing the Services.
Personal dataAny information relating to an identified or identifiable person that we process for you.
ProcessingAny operation performed on personal data (collecting, storing, using, disclosing, etc.).
Applicable data protection lawAll relevant laws including UK GDPR, Data Protection Act 2018, and EU GDPR.
Personal data breachA security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorised access to personal data.
Sub-processorAny third party (e.g. a cloud hosting provider) that Pixie uses to help process personal data for you.

2. Scope and purpose

This DPA governs how Pixie handles personal data solely for the purpose of delivering the Services. Pixie processes personal data only to:

Processing continues for the term of your main Services agreement until the data is deleted or returned.

3. Types of data we process

We only process personal data necessary to provide the Services. This may include:

Important: The Services are not designed to process sensitive data (health information, political opinions, criminal offence data, etc.). You must not submit this type of data unless agreed specifically and in writing.

4. Your responsibilities as Controller

5. Pixie’s responsibilities as Processor

Pixie will:

6. Personal data breach notification

If a personal data breach occurs, Pixie will:

7. Using sub-processors

8. International data transfers

Pixie will not transfer personal data outside the UK or EEA unless a lawful transfer mechanism is in place, such as:

9. Assistance with data subject requests

10. Audit rights and compliance

11. End of agreement - data return and deletion

Annex 1: Technical and organisational security measures

A. Access control

B. Data protection

C. Infrastructure security

D. Operational security

Last updated: March 2026