Legal & compliance
Data Processing Addendum
The terms on which Epiow Limited processes personal data for organisations, under UK GDPR Article 28.
Last updated: 27 September 2026
1. Scope and roles
These processing terms form part of the Terms of Service at epiow.com/legal/terms. They apply when Epiow Limited processes personal data for an organisation that uses Epiow (the "customer") as its processor under Article 28 of the UK GDPR and, where it applies, the EU GDPR. The customer is the controller. They apply without signature.
2. Subject matter, duration and data
Subject matter and purpose: hosting, storing, processing and displaying data to provide, secure and support the Service. Duration: the customer's subscription and the period until deletion under section 9. Personal data: whatever the customer and its Users put into the workspace, such as staff, pupil, member, client and contact records, including special category data where the customer chooses to add it. Data subjects: the customer's Users, staff, members, pupils, clients and contacts.
3. Instructions
We process personal data only on the customer's documented instructions, which are the Terms of Service, these terms and the customer's use and configuration of the Service, unless the law requires otherwise; in that case we tell the customer first unless the law forbids it. We tell the customer if, in our opinion, an instruction infringes data protection law, and we may decline to follow it.
4. Confidentiality and security
People we authorise to process personal data are bound by confidentiality. We apply technical and organisational measures appropriate to the risk, as Article 32 requires, and may change them as long as the overall level of protection is not reduced.
5. Subprocessors
The customer gives general authorisation for the subprocessors on our subprocessor list (see epiow.com/legal/subprocessors). We inform the customer of an intended addition or replacement before it takes effect, so that it can object. If the customer objects on reasonable data protection grounds and we do not resolve the objection, the customer's remedy is to stop using the affected part of the Service or to end its subscription. Each subprocessor is bound by a written contract with the data protection obligations Article 28(4) requires, and we remain liable for its performance to the extent that Article requires.
6. Assistance
Taking into account the nature of the processing and the information available to us, we assist the customer, mainly through the Service's own features, with requests from data subjects and with its obligations under Articles 32 to 36. Assistance beyond those features is at the customer's reasonable cost.
7. Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach affecting its personal data, with the information Article 33(3) requires as it becomes available. The customer decides whether to notify supervisory authorities and data subjects, and does so where the law requires. A notification is not an admission of fault or liability.
8. Information and audits
We make available the information needed to demonstrate compliance with Article 28, first through written answers to reasonable questionnaires and our existing documentation. If the customer still reasonably needs an audit or inspection, it may carry out one in any 12 months, on at least 30 days' notice, during business hours, through an auditor bound by confidentiality who is not our competitor, without access to other customers' data, and at the customer's cost. These limits do not apply where a supervisory authority requires an audit.
9. Return and deletion
The customer can export its data at any time before closing its workspace and, on request, for a limited period after closure. We then delete the personal data, unless the law requires us to keep it.
10. International transfers
The customer authorises us and our subprocessors to process personal data outside the United Kingdom and the European Economic Area, relying on adequacy regulations or decisions, the International Data Transfer Agreement or Addendum, or the EU standard contractual clauses.
11. Liability and precedence
Liability under these terms is subject to the limits and exclusions in the Terms of Service. On the processing of personal data, these terms prevail over the Terms of Service where the two conflict.
12. Signed copy and requests
A countersigned copy is available on request through the contact page.