Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Master Services Agreement

This Master Services Agreement (“Agreement”) governs the provision of services by GDPRLocal Ltd (“GDPRLocal”, “we”, “us”) to the organisation identified in the Customer’s account profile (“Customer”, “you”).

1. Structure and Application

1.1 Contract Structure. This Agreement consists of:

  • the Customer’s account profile and any Service Activation Records generated upon Service activation;
  • the Data Processing Agreement;
  • the Service Schedules
  • the Rate Card; and
  • this Master Services Agreement,
  • in each case as amended from time to time in accordance with their terms. Together, the above documents and the Customer’s acceptance of the Terms during account registration form a single binding agreement between the parties.

1.2 Order of Precedence. If there is any conflict between the documents, the following order of precedence applies:

  1. Service Activation Record
  2. Data Processing Agreement
  3. Service Schedules
  4. Rate Card
  5. Master Services Agreement

The Standard Contractual Clauses incorporated by reference into the Data Processing Agreement shall prevail over all other documents in matters they expressly cover.

1.3 Incorporation by reference; updates to Inclusions.

(a) Static Header. This Master Services Agreement (the “MSA Header”), once accepted by the Customer at Company Registration, is the Customer’s static umbrella agreement and shall not be amended unilaterally by GDPRLocal during the term.

(b) Linked Inclusions. The MSA Header incorporates by reference the following documents (each an “Inclusion”), as published by GDPRLocal from time to time at https://gdprlocal.com/terms:

(i) the Data Processing Agreement;

(ii) the Service Schedules; and

(iii) the Rate Card.

A snapshot of the then-current Inclusions (identified by version ID) is captured for evidentiary purposes at Company Registration and at each Service activation event, in accordance with clause 4.

(c) Updates by GDPRLocal. GDPRLocal may update an Inclusion from time to time, provided that:

(i) GDPRLocal gives the Customer not less than thirty (30) days’ prior written notice of any material change (the “Update Notice”), sent to the Customer Contact identified in the Customer’s account profile;

(ii) the Update Notice identifies the affected Inclusion, summarises the change, and specifies the proposed effective date and new version ID;

(iii) non-material updates (including formatting corrections, clarifications that do not alter substantive rights or obligations, and changes mandated by law) may be made without prior notice, but shall be recorded in GDPRLocal’s Inclusion Change Log (manual log maintained per D17).

(d) Customer rights on a material update. Where the Customer reasonably objects to a material update notified under clause 1.3(c), the Customer may, before the proposed effective date:

(i) accept the update by continuing to use the affected Service after the effective date;

(ii) terminate the affected Service for convenience on notice expiring on or before the proposed effective date, without further charge or penalty notwithstanding any minimum-term restriction in the relevant Service Schedule; or

(iii) request that GDPRLocal continue to deliver the affected Service under the prior version of the Inclusion (which GDPRLocal may accept or decline at its discretion; where declined, the Customer’s right under (ii) applies).

Where the Customer does not respond before the proposed effective date, the update is deemed accepted.

(e) Effective Date. Subject to clause 1.3(d), an updated Inclusion takes effect on the date specified in the Update Notice and becomes the current version for purposes of any subsequent Service activation. Active Services for which the Customer has validly exercised the right under clause 1.3(d)(iii) continue under the prior version of the Inclusion until the next renewal or termination.

(f) Fees on Rate Card updates. For the avoidance of doubt, updates to the Rate Card do not affect the subscription fees applicable to Services already activated under a prior Rate Card; those fees are governed by the relevant Service Activation Record and the CPI adjustment in clause 5.3.

2. Customer Identity

The Customer is the legal entity that creates an Account and accepts these Terms. Where the Customer acts in the capacity of a Controller, Processor, or other defined role under Data Protection Laws, references to that role in any Service Schedule or in the Data Processing Agreement shall be construed as references to the Customer acting in that capacity.

3. Term

3.1 Acceptance and Effective Date. The Customer accepts these Master Terms by creating a GDPRLocal account and confirming acceptance via the GDPRLocal portal (the “Acceptance Date”). These Master Terms become legally effective and binding on the date the Customer first activates a Service (the “Effective Date”), through the GDPRLocal portal or by written confirmation accepted by GDPRLocal.

3.2 Operative from Acceptance. The following clauses operate from the Acceptance Date and apply during any period between the Acceptance Date and the Effective Date (the “Pre-Activation Period”): clause 6.1 (Customer responsibilities), clause 7 (Confidentiality), clause 8 (Intellectual Property), clause 17 (Entire Agreement), and clause 18 (Governing Law and Jurisdiction).

3.3 No Service Obligations Pre-Activation. During the Pre-Activation Period, no Service is in effect, no fees are payable, and neither party has any obligation to provide or pay for Services. Either party may withdraw from these Master Terms before the Effective Date by written notice to the other.

This Agreement will continue indefinitely until terminated in accordance with clause 12. The Customer may hold an open GDPRLocal account without any Services being active.

Any service-specific minimum term set out in the relevant Service Schedule applies in addition to this clause and prevails over it for the duration of the relevant Service. Termination of this Agreement will result in closure of the Customer’s GDPRLocal account and termination of any active Services in accordance with the applicable Service Schedules.

4. Activation of Services

This MSA and the associated Service Schedules define the services available (“the Services”).

4.1 Optional, on-demand activation. All services are deemed optional and may be activated at any time by the Customer through the GDPRLocal platform, or by written request from the Customer and written confirmation from GDPRLocal (email sufficient). No separate agreement or amendment is required for Service activation. Each activation constitutes confirmation that the Customer wishes to receive the relevant Service and agrees to the applicable Service Schedule and associated fees.

4.2 Service Activation Record. When a Service is activated, GDPRLocal creates a Service Activation Record, the system-stored event record of the activation. The Service Activation Record sits alongside this Agreement; it is not part of the Agreement or any Service Schedule. A Service may be activated by either (a) in-portal acceptance via the GDPRLocal platform, or (b) written agreement between the parties (email sufficient). The Service Activation Record captures: the Service activated; the Service Start Date (date and time of activation); the activation method; the scope choices and other values supplied by the Customer at activation (including, where applicable, the values that populate the relevant Service Schedule’s Statement of Work); the applicable fee from the Rate Card current at activation; and the initial Term and renewal terms per the relevant Service Schedule. On every activation, GDPRLocal will send the Customer Contact a Service Activation Record email containing: (i) confirmation of the activation event; (ii) a copy of the Master Services Agreement as it stood at the moment of activation (the “at-the-time MSA”), with the relevant Service Schedule’s Statement of Work populated with the Customer’s activation values where applicable; and (iii) links to the live Inclusions at GDPRLocal’s hosted URLs. The Service Activation Record email forms part of the Service Activation Record and provides the Customer with a complete, version-stamped record of the contract terms in force at activation. Each activated Service will be governed by the applicable Service Schedule. Electronic records maintained by GDPRLocal relating to Service activations constitute conclusive evidence of activation of the relevant Service.

4.3 Records split. Information about the Customer (legal entity, registered address, primary billing details, account administrators, Customer Contact) is captured at account creation and maintained by the Customer in its account profile. The Service Activation Record records only the per-activation event data set out in clause 4.2 and does not re-capture account-level information. The Customer may update its account profile at any time via the GDPRLocal portal or by written notice to GDPRLocal.

4.4 Concurrence of statutory roles. Where the Customer activates more than one Service that creates a regulatory role conflict (for example, the Article 27 / Article 14 Representative role and the Data Protection Officer role for the same Customer), the parties shall document in writing how the conflict is managed, including assigning different individuals within GDPRLocal’s organisation (or an affiliate’s organisation, as applicable) to each role.

5. Fees, Billing, Ad-Hoc Work and Overage

5.1 Billing Commencement. Fees for subscription services commence on the date the relevant service is activated (the “Service Start Date”) unless stated otherwise. Billable additional services and overage may arise from usage, requests, or escalation following activation.

5.2 Subscription Fees and Billing Cadence. Where services are provided on a subscription basis, the applicable subscription fees are recorded in the relevant Service Activation Record at the time of activation and reflect the Rate Card current at that date. The Customer may elect monthly or annual billing at activation. Annual billing may be offered with a discount, applied at invoicing. The Rate Card lists standard (non-discounted) subscription fees. All fees are exclusive of VAT and any other applicable taxes. Subscription fees are non-refundable.

5.3 Annual Fee Adjustment (CPI). GDPRLocal may increase the subscription fees and any recurring fees on each anniversary of the Service Start Date. Any increase will be linked to the percentage increase in the Consumer Prices Index (CPI) published by the UK Office for National Statistics over the preceding twelve (12) months, capped at a maximum increase of five per cent (5%) in any twelve-month period. GDPRLocal will provide the Customer with at least thirty (30) days’ written notice of any such increase.

5.4 Included Services: Advisory and Oversight. For services provided on an ongoing basis, including DPO Services and AI Governance (AIGo) Services, the subscription fee includes reasonable ongoing advisory support and reasonable oversight activities, in each case proportionate to the nature, scale, risk profile and level of activity of the Customer, as determined by GDPRLocal acting reasonably and in good faith. These services are not provided on an unlimited basis and do not include responsibility for operational decision-making or execution.

5.5 Billable Additional Services and Tasks. Additional fees may apply where services requested or required (a) fall outside the scope of the applicable service description; or (b) are within scope but, in aggregate, exceed the baseline level of activity reasonably included within the subscription fee. Examples include (without limitation): unusually high volumes of data subject requests; sustained or repeated emergency incidents; extended regulatory investigations or remediation activity; complex documentation or framework rebuilds; large-scale training, enablement, or assurance programmes. Where qualifying additional services are required, a Task will be opened and the Customer notified. Customer Task approval is required before billable work commences. Tasks are Fixed Cost or Open-Ended, and may be closed on request by the Customer.

5.6 Hourly Rates and Rate Card. Additional services, ad-hoc work, and overage are billed at GDPRLocal’s then-current rates, as set out in the applicable Rate Card. The Rate Card forms part of this Agreement and is incorporated by reference. GDPRLocal may update the Rate Card on at least thirty (30) days’ written notice; updated rates apply prospectively only.

5.7 Approval and Authorisation. Email confirmation from an authorised Customer contact constitutes valid approval for billable additional services. Where emergency or urgent work is pre-approved and later determined to be billable, GDPRLocal will provide reasonable transparency as to the basis of the charges.

5.8 Transparency and Good Faith. GDPRLocal will act reasonably and in good faith when determining whether additional fees apply. The Customer agrees to act reasonably and in good faith when requesting services, responding to requests for information, and engaging with GDPRLocal in a timely manner.

5.9 Failure to Cooperate. Where the Customer becomes unresponsive or fails to provide information reasonably required for the delivery of services, GDPRLocal may determine the scope, prioritisation, and sequencing of services to be performed during the relevant service period using its reasonable professional judgement. Any services performed by GDPRLocal in such circumstances shall be deemed duly performed and delivered, and the fees for that period shall remain due in full and non-refundable.

6. Customer Responsibilities

6.1 General. The Customer is responsible for: (a) ensuring the accuracy and completeness of information provided to GDPRLocal; (b) decisions made and actions taken based on advice provided; and (c) implementing operational, technical, and organisational measures required for compliance. GDPRLocal is not responsible for delays, failures, or non-compliance caused by inaccurate information, failure to cooperate, or failure to implement recommendations.

6.2 Customer Contact. The Customer shall designate a named contact (the “Customer Contact”) responsible for issuing instructions to GDPRLocal under this Agreement and any active Service Schedule. The Customer Contact’s details are captured in the Customer’s account profile at registration and may be updated by the Customer at any time via the GDPRLocal portal or by written notice to GDPRLocal.

6.3 Lawful instructions. If the Customer’s instructions would, in GDPRLocal’s reasonable opinion, require GDPRLocal (or any affiliate appointed to perform a Service) to act in violation of applicable law or in a manner disproportionate to the scope of the relevant Service, GDPRLocal may decline such instructions and shall promptly notify the Customer.

6.4 Account security and identity verification. Each individual user accessing the GDPRLocal platform on behalf of the Customer is responsible for safeguarding their access credentials and for activity carried out under their account. The Customer shall ensure that its users do not share credentials and shall procure that any suspected unauthorised access is notified to GDPRLocal promptly. GDPRLocal may verify the identity of any user, or their affiliation with the Customer, at any time.

6.5 Use Restrictions. The Customer shall not, and shall procure that its users do not, use the GDPRLocal platform, the portal, or the website to: (a) break any applicable law, regulation, or contractual obligation; (b) impersonate any person or misrepresent affiliation with any organisation; (c) scrape, harvest, or otherwise extract data by automated means without GDPRLocal’s prior written permission; (d) reverse engineer, decompile, or attempt to derive the source code of any part of the platform or GDPRLocal’s software; (e) introduce malware, viruses, or any code designed to disrupt, damage, or gain unauthorised access to GDPRLocal’s systems; (f) probe, scan, or test the vulnerability of GDPRLocal’s systems, or breach or circumvent any security or authentication measures; (g) send spam, phishing, or other unsolicited communications via GDPRLocal’s systems; (h) harass, abuse, or threaten other users or GDPRLocal’s staff; (i) upload, transmit, or distribute any content that is unlawful, infringing, defamatory, obscene, or otherwise objectionable; (j) use the platform to compete with GDPRLocal or to build a substantially similar service; (k) resell, sublicense, or commercially exploit access except as expressly permitted under this Agreement; or (l) interfere with the proper functioning of the platform, including by overloading or flooding GDPRLocal’s infrastructure. GDPRLocal may investigate suspected breaches and cooperate with law enforcement.

7. Confidentiality

Each party will keep confidential all non-public information received from the other that is marked or reasonably understood to be confidential (“Confidential Information”). Confidential Information may be used only to perform obligations or exercise rights under this Agreement.

A party may disclose Confidential Information where required by law or regulation, subject to notice where legally permitted.

Where GDPRLocal (or any affiliate appointed to perform a Service) is appointed in a statutory role (including as Data Protection Officer or as a representative under Article 27 GDPR or Article 14 Swiss FADP), additional confidentiality and statutory secrecy obligations apply as set out in the relevant Service Schedule.

8. Intellectual Property

All intellectual property rights in GDPRLocal’s materials, templates, methodologies, documentation, tools, know-how, and platforms remain owned by GDPRLocal. The Customer is granted a non-exclusive, non-transferable licence to use deliverables provided under the Services solely for the Customer’s internal compliance purposes.

9. No Legal Advice; No Guarantees

GDPRLocal provides compliance support and advisory services and does not provide legal advice or legal representation. GDPRLocal does not guarantee regulatory outcomes, the absence of enforcement action, or full compliance.

The GDPRLocal portal is provided on an “as available” basis. GDPRLocal aims to keep the portal available but does not guarantee uninterrupted access, and may suspend, withdraw, or change any part of the portal without notice. This does not affect any specific service-level commitments set out in a Service Schedule.

10. Limitation of Liability

Nothing in this Agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot be limited by law. Subject to the above, GDPRLocal’s total aggregate liability is limited to the fees paid by the Customer in the twelve (12) months preceding the event giving rise to the claim. GDPRLocal will not be liable for any indirect or consequential loss.

This clause sets the baseline. Specific Services (including Article 27 Representative Services and DPO Services) carry additional liability and indemnity provisions in the relevant Service Schedule that operate as supplements to this clause.

11. Indemnities

Each party will indemnify the other against third-party claims arising from its breach of this Agreement or applicable law. Specific indemnity provisions applicable to particular Services are set out in the relevant Service Schedule and extend, where applicable, to GDPRLocal’s affiliates appointed to perform the relevant Service.

12. Suspension and Termination

12.1 Suspension. GDPRLocal may suspend Services on written notice where undisputed fees remain unpaid for more than fourteen (14) days after the due date.

12.2 Termination for Cause. Either party may terminate this Agreement or any Service Schedule with immediate effect on material breach (with 30-day cure where remediable), insolvency, or cessation of business. GDPRLocal may additionally terminate immediately where continued provision of Services would create material legal or regulatory risk.

12.3 Termination for Convenience. Either party may terminate this Agreement or any individual Service Schedule for convenience on not less than thirty (30) days’ prior written notice, except that termination for convenience is not available during the initial minimum term of any Service, and longer notice periods set out in any Service Schedule prevail.

12.4 Service-specific resignation rights. Where GDPRLocal (or any affiliate) is appointed in a statutory role, additional rights of immediate resignation may apply as set out in the relevant Service Schedule.

12.5 User Access. GDPRLocal may suspend or terminate an individual user’s access to the GDPRLocal portal, with or without notice, where: (a) the user breaches this Agreement or any other agreement with GDPRLocal; (b) GDPRLocal reasonably suspects fraudulent, abusive, or unlawful activity; (c) GDPRLocal is required to do so by law, regulator, or court order; or (d) the user’s access is no longer required (including where the user ceases to be associated with the Customer). Suspension or termination of an individual user’s access is a discrete operational action that does not, of itself, affect this Agreement or any Service Schedule and does not affect any rights or obligations arising before that event.

13. Effect of Termination

On termination: all outstanding fees become immediately due; licences granted continue for internal compliance use (subject to misuse exceptions); personal data is handled in accordance with the Data Processing Agreement; and service-specific consequences of termination apply as set out in the relevant Service Schedule.

14. Force Majeure

Neither party will be liable for failure or delay caused by events beyond its reasonable control.

15. Assignment and Subcontracting

GDPRLocal may assign this Agreement to an affiliate or successor in connection with a corporate reorganisation, merger, acquisition, or sale of assets. GDPRLocal may use affiliates or subcontractors to deliver Services and remains responsible for their performance.

16. Notices

Notices must be in writing and may be sent by email to the addresses most recently notified by the parties.

17. Entire Agreement

This Agreement constitutes the entire agreement between the parties and supersedes all prior discussions or agreements relating to its subject matter.

18. Governing Law and Jurisdiction

This Agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.