Legal

Data processing agreement.

Version 1.0, 18 August 2026. Published in full, including the current sub-processor list.

This is the standard Data Processing Agreement (“DPA”) that applies to all customers of Archivers.ai. It sets out how we process personal data on your behalf, the security measures we maintain, and the sub-processors we use. Institutional customers who require a countersigned copy for their records, or who need to discuss specific terms as part of a procurement process, can contact us at hello@archivers.ai.

Parties

Broadhurst Digital Limited (trading as “Archivers”)
A company registered in England and Wales, company number 12503471
Registered office: 18 St Nicholas Place, Derby, DE1 3GD
Email: hello@archivers.ai · Phone: 01332 460 205
(“Data Processor”)

The Customer
Name: ___________________________
Registered address: ___________________________
Contact email: ___________________________
(“Data Controller”)

Effective Date: ___________________________

1. Background

1.1 This DPA forms part of the contract between the Data Controller and the Data Processor for the provision of AI-powered archive cataloguing services (the “Services”), as set out in the applicable subscription terms, Statement of Work, or Service Agreement (the “Main Agreement”).

1.2 This DPA reflects the parties’ agreement on the processing of Personal Data in accordance with the requirements of Data Protection Legislation (as defined below).

1.3 In the event of any conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to data processing matters.

2. Definitions

“Data Protection Legislation” means:

  • The UK General Data Protection Regulation (UK GDPR) as retained in UK law under the European Union (Withdrawal) Act 2018;
  • The Data Protection Act 2018 (DPA 2018); and
  • Any successor or replacement legislation to the above.

“Personal Data”, “Data Subject”, “Processing”, “Controller”, and “Processor” have the meanings given in the Data Protection Legislation.

“Sub-processor” means any third party appointed by the Data Processor to process Personal Data on behalf of the Data Controller.

3. Scope and roles

3.1 Nature of Processing: the Data Processor will process Personal Data on behalf of the Data Controller solely for the purpose of providing the Services, which include:

  • Ingestion and storage of archive materials uploaded by the Data Controller;
  • AI-assisted metadata generation, classification, OCR, image analysis, audio transcription, and video description;
  • Storage of user account information and usage logs;
  • Provision of access to processed data via the Archivers application.

3.2 Types of Personal Data: the Personal Data processed may include:

  • Data Controller account holder data: names, email addresses, organisational affiliation;
  • Archive materials: documents, images, audio, video, and other files uploaded by the Data Controller, which may contain personal data of Data Subjects (e.g., names, photographs, correspondence, biographical information);
  • Metadata: AI-generated and manually-entered descriptions, classifications, and provenance notes relating to archive materials.

3.3 Categories of Data Subjects: Data Subjects may include:

  • Employees or representatives of the Data Controller (account holders);
  • Individuals depicted or referenced in archive materials (e.g., donors, subjects of archival records, historical figures, living persons).

3.4 Duration of Processing: the Data Processor will process Personal Data for the duration of the Main Agreement and for the retention period specified in Section 7 below.

4. Data Processor obligations

4.1 Lawful Processing: the Data Processor shall:

  • Process Personal Data only on documented instructions from the Data Controller, unless required to do so by law (in which case the Data Processor shall notify the Data Controller before processing, unless prohibited by law);
  • Ensure that persons authorised to process Personal Data are subject to a duty of confidentiality;
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 5);
  • Not engage Sub-processors without prior written authorisation from the Data Controller (see Section 6);
  • Assist the Data Controller in responding to Data Subject requests under Data Protection Legislation (see Section 8);
  • Assist the Data Controller in ensuring compliance with security, breach notification, and data protection impact assessment obligations;
  • Delete or return all Personal Data to the Data Controller at the end of the Services, unless required by law to retain it (see Section 7);
  • Make available to the Data Controller all information necessary to demonstrate compliance with this DPA and Data Protection Legislation.

4.2 No Onward Transfer: the Data Processor shall not transfer Personal Data outside the United Kingdom or European Economic Area without the prior written consent of the Data Controller and without ensuring appropriate safeguards are in place (e.g., Standard Contractual Clauses, adequacy decisions).

5. Security measures

5.1 The Data Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including:

Technical Measures:

  • Encryption of data in transit (HTTPS/TLS);
  • Encryption of data at rest (database and file storage encryption);
  • Secure password hashing (bcrypt/Argon2);
  • HTTP-only, secure cookies for session management;
  • Regular security patching and dependency updates;
  • Access controls and authentication mechanisms.

Organisational Measures:

  • Access to Personal Data limited to authorised personnel on a need-to-know basis;
  • Confidentiality obligations imposed on all personnel with access to Personal Data;
  • Regular security training for personnel;
  • Incident response and breach notification procedures.

5.2 The Data Processor shall regularly review and update these measures to ensure they remain appropriate.

6. Sub-processors

6.1 Current Sub-processors: the Data Controller authorises the Data Processor to engage the following Sub-processors. This is the current list; we will update this page when the list changes.

Sub-processor Location Purpose
Vercel Inc. USA / EU Application hosting and file storage
Neon Inc. United Kingdom (AWS eu-west-2, London) PostgreSQL database hosting
Google Cloud EU processing AI model processing via Google Vertex AI
Mistral AI France / EU AI model processing (document classification, OCR, image analysis, audio transcription)
Resend USA Transactional email delivery
Stripe USA / EU Payment processing
Twilio USA SMS two-factor verification
Cloudflare Global CDN and cookieless analytics

6.2 Sub-processor Obligations: the Data Processor shall:

  • Enter into written agreements with each Sub-processor imposing data protection obligations equivalent to those in this DPA;
  • Remain fully liable to the Data Controller for the performance of Sub-processors’ obligations.

6.3 New Sub-processors: the Data Processor shall notify the Data Controller at least 30 days in advance of engaging any new Sub-processor. The Data Controller may object to the new Sub-processor on reasonable data protection grounds within 14 days of notification. If the Data Controller objects and the parties cannot agree on an alternative, the Data Controller may terminate the affected Services.

6.4 Sub-processor List: the up-to-date list of Sub-processors is maintained on this page (archivers.ai/dpa/).

7. Data retention and deletion

7.1 Retention Period: the Data Processor shall retain Personal Data for the duration of the Main Agreement and:

  • For Free tier (Community) accounts: 28 days from upload (automatic deletion);
  • For Paid tier accounts (Starter, Professional, Institution, Enterprise): indefinitely while the subscription is active;
  • After account deletion or termination: Personal Data will be deleted within 30 days, except where retention is required by law (e.g., tax, accounting obligations requiring retention for up to 7 years).

7.2 Return or Deletion: upon termination of the Main Agreement or upon request by the Data Controller, the Data Processor shall (at the Data Controller’s choice):

  • Return all Personal Data to the Data Controller in a structured, commonly used, machine-readable format; and/or
  • Securely delete all Personal Data and provide written confirmation of deletion,

unless the Data Processor is required by law to retain certain Personal Data (in which case the Data Processor shall notify the Data Controller).

8. Data Subject rights

8.1 The Data Processor shall, at the Data Controller’s cost, provide reasonable assistance to the Data Controller in responding to requests from Data Subjects exercising their rights under Data Protection Legislation, including:

  • Right of access (Article 15 UK GDPR);
  • Right to rectification (Article 16);
  • Right to erasure (Article 17);
  • Right to restriction of processing (Article 18);
  • Right to data portability (Article 20);
  • Right to object (Article 21).

8.2 If the Data Processor receives a request directly from a Data Subject, the Data Processor shall promptly notify the Data Controller and shall not respond to the request without the Data Controller’s prior written consent.

9. Data breach notification

9.1 The Data Processor shall notify the Data Controller without undue delay (and in any event within 24 hours) upon becoming aware of a Personal Data breach affecting the Data Controller’s Personal Data.

9.2 The notification shall include (to the extent known):

  • Description of the nature of the breach (e.g., categories and approximate number of Data Subjects and Personal Data records affected);
  • Contact details of the Data Processor’s data protection officer or other contact point;
  • Likely consequences of the breach;
  • Measures taken or proposed to address the breach and mitigate its effects.

9.3 The Data Processor shall cooperate with the Data Controller and provide reasonable assistance in investigating and remediating the breach.

10. Audits and inspections

10.1 The Data Processor shall allow the Data Controller (or an independent third-party auditor appointed by the Data Controller) to conduct audits and inspections to verify compliance with this DPA, subject to:

  • Reasonable advance notice (at least 14 days);
  • Confidentiality obligations binding the auditor;
  • Audits conducted no more than once per year (unless required by a supervisory authority or in response to a suspected breach);
  • Audits conducted during normal business hours and in a manner that does not unreasonably disrupt the Data Processor’s operations.

10.2 The Data Controller shall bear the costs of such audits, except where the audit reveals material non-compliance by the Data Processor, in which case the Data Processor shall bear the costs.

11. Liability and indemnity

11.1 Each party’s liability under this DPA shall be subject to the limitations of liability set out in the Main Agreement, except to the extent that Data Protection Legislation imposes non-excludable liability.

11.2 The Data Processor shall indemnify the Data Controller against fines, penalties, compensation claims, and reasonable legal costs arising from the Data Processor’s breach of this DPA or Data Protection Legislation, except to the extent caused by the Data Controller’s instructions or acts/omissions.

12. Term and termination

12.1 This DPA shall commence on the Effective Date and shall continue for the duration of the Main Agreement.

12.2 This DPA may be terminated:

  • By either party if the other party materially breaches this DPA and fails to remedy the breach within 30 days of written notice;
  • Automatically upon termination of the Main Agreement;
  • By the Data Controller if the Data Controller objects to a new Sub-processor and the parties cannot agree on an alternative (Section 6.3).

12.3 Upon termination, the provisions of Sections 7 (Data Retention and Deletion), 11 (Liability and Indemnity), and any other provisions necessary for the interpretation or enforcement of this DPA shall survive.

13. Governing law and jurisdiction

13.1 This DPA shall be governed by and construed in accordance with the laws of England and Wales.

13.2 Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

14. Amendments

14.1 This DPA may be amended only by written agreement signed by both parties, except that the Data Processor may update the list of Sub-processors in accordance with Section 6.3.

14.2 If Data Protection Legislation is amended or replaced, the parties agree to negotiate in good faith any necessary amendments to this DPA to ensure continued compliance.

Signatures

Where a countersigned copy is required, the parties sign below. For self-service subscriptions, this DPA applies as published and is incorporated into the Main Agreement without signature.

Data Controller:

Signed: ___________________________
Name: ___________________________
Title: ___________________________
Date: ___________________________

Data Processor:

Signed: ___________________________
Name: ___________________________
Title: Director, Broadhurst Digital Limited
Date: ___________________________


Broadhurst Digital Limited (trading as Archivers)
Registered in England and Wales, company number 12503471
Registered office: 18 St Nicholas Place, Derby, DE1 3GD
VAT registration number: GB355920584
Email: hello@archivers.ai · Phone: 01332 460 205 · Website: archivers.ai

This Data Processing Agreement was last updated: 18 August 2026 (v1.0).

Need a countersigned copy?

Tell us the signing entity and we will return a signed DPA for your records.