Perspective Cloud legal information
Data Processing Agreement
Effective 26 July 2026 · Version 2026-07-26
This Data Processing Agreement (“DPA”) forms part of the Terms when a customer organisation uses Perspective Cloud to process personal data for which it is controller. The customer is “Controller” and Chibuike Chidi-Iwobi is “Processor”.
1. Processing details
Subject matter: provision of the Perspective Cloud service. Duration: the customer’s authorised use plus deletion and backup lifecycle. Nature and purpose: hosting, organising, securing, transmitting, analysing at the customer’s request and supporting forms, sessions, participant responses, reports, AI-assisted features and actions. Data subjects may include organisation members, participants, employees, clients, partners and other invitees. Data may include identity, contact, role, response, interaction, technical and audit information.
2. Documented instructions
We process customer personal data only on documented instructions contained in the agreement, product configuration and authorised support requests, unless UK law requires otherwise. We will inform the Controller of a conflicting instruction or legal requirement where permitted.
3. Confidentiality and security
People authorised to process customer data are bound by confidentiality. We maintain proportionate technical and organisational measures, including access control, organisation isolation, encryption in transit, protected credentials, audit records, backups, dependency maintenance and incident procedures.
4. Subprocessors
The Controller gives general authorisation for the subprocessors published on our Subprocessors page. We impose appropriate data-protection obligations and remain responsible for their processing to the extent required by law. We will provide reasonable notice of a material new subprocessor and consider a documented objection in good faith.
5. Individual rights
Taking account of the processing, we will provide reasonable assistance for access, correction, erasure, restriction, portability and objection requests. The Controller remains responsible for deciding and communicating the response.
6. Security incidents
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting customer data and provide information reasonably available to support assessment and legally required notifications.
7. Compliance assistance
Taking account of the nature of processing and information available, we will reasonably assist with security obligations, breach assessment, data-protection impact assessments and prior consultation.
8. Return and deletion
At the end of the service, we will delete or return customer personal data on request, subject to product functionality, backup lifecycle, legal retention duties and records required to establish or defend rights.
9. Information and audits
We will make information reasonably necessary to demonstrate Article 28 compliance available. Audits should first use current documentation and written enquiries; additional inspections must be proportionate, protect other customers, avoid unreasonable disruption and be subject to confidentiality and reasonable cost arrangements.
10. International transfers
Where customer data is transferred outside the UK without an adequacy regulation, the parties will use a lawful safeguard such as the UK International Data Transfer Agreement or UK Addendum, as applicable.
Contact
Data-protection enquiries: support@perspectivecloud.co.uk.