Legal

Data Processing Agreement

Always On  ·  alwayson.plangrowdo.com  ·  Version 1.2  ·  July 2026

Parties to This Agreement

Processor Plan Grow Do Ltd t/a Plan Grow Do, registered in England and Wales (Co. No. 12458083). Registered office: Vincent Works, Brough, Sheffield S33 9HG. Operator of the Always On platform (alwayson.plangrowdo.com). Contact: info@plangrowdo.com
Controller The business entity ('Tenant') that subscribes to the Always On platform under a service agreement with Plan Grow Do Ltd. By activating an Always On workspace, the Tenant accepts this DPA.
This Data Processing Agreement forms part of the service agreement between Plan Grow Do Ltd and the Tenant. It is legally binding and sets out the terms under which Plan Grow Do Ltd processes personal data on the Tenant's behalf, as required by UK GDPR Article 28.

Contents

  1. Definitions
  2. Scope and Subject Matter
  3. Controller's Obligations
  4. Processor's Obligations
  5. Security Measures
  6. Sub-Processors
  7. Mailbox Connection and Email Sync
  8. AI Agents and Automated Processing
  9. Special Category Data
  10. Data Subject Rights
  11. Personal Data Breaches
  12. Data Protection Impact Assessments
  13. International Transfers
  14. Return and Deletion of Data
  15. Audit Rights
  16. Liability
  17. Term and Termination
  18. Governing Law
  19. Schedule 1: Processing Details

1 Definitions

In this Agreement, the following terms have the meanings set out below:

2 Scope and Subject Matter

This DPA applies to all personal data that Plan Grow Do Ltd processes on behalf of the Tenant in connection with operating the Platform. Full details of those processing activities are set out in Schedule 1.

Plan Grow Do Ltd acts as a Data Processor in relation to all personal data entered into the Platform by or on behalf of the Tenant. The Tenant remains the Data Controller and is responsible for ensuring its use of the Platform complies with applicable data protection law.

2.1 Plan Grow Do Ltd as an Independent Controller

This DPA applies only where Plan Grow Do Ltd acts as a processor on the Tenant's behalf. For certain activities Plan Grow Do Ltd acts as an independent data controller in its own right, including:

Processing carried out by Plan Grow Do Ltd in its capacity as an independent controller is governed by Plan Grow Do Ltd's own Privacy Notice, not this DPA.

3 Controller's Obligations

The Tenant (Controller) agrees to:

4 Processor's Obligations

Plan Grow Do Ltd agrees to:

4.1 Process only on documented instructions

Process personal data only on the documented instructions of the Controller, including in relation to international transfers, unless required to do so by law (in which case Plan Grow Do Ltd will inform the Controller before processing, unless prohibited by law).

4.2 Confidentiality

Ensure that all persons authorised to access personal data within the Platform are subject to appropriate confidentiality obligations.

4.3 Implement security measures

Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Section 5.

4.4 Sub-processor restrictions

Not engage sub-processors without the general authorisation of the Controller, subject to Section 6 of this DPA.

4.5 Assist the Controller

Assist the Controller, by appropriate technical and organisational measures, in fulfilling obligations to respond to data subject rights requests and to comply with UK GDPR Articles 32–36 (security, breach notification, DPIAs).

4.6 Deletion or return

At the choice of the Controller, delete or return all personal data on termination of services, unless applicable law requires retention, as further detailed in Section 14.

4.7 Audit cooperation

Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and cooperate with audits as set out in Section 15.

5 Security Measures

Plan Grow Do Ltd implements the following technical and organisational measures to protect personal data processed within the Platform:

5.1 Technical measures

5.2 Organisational measures

Note: Plan Grow Do Ltd reviews and updates these security measures periodically. The measures in place aim to provide a level of protection appropriate to the risks presented by the nature of the data processed.

6 Sub-Processors

The Tenant gives general authorisation to Plan Grow Do Ltd to engage the sub-processors listed below. Plan Grow Do Ltd will give the Tenant reasonable advance notice of any intended change to this list (additions or replacements) and the Tenant may object within a reasonable period.

Plan Grow Do Ltd ensures all sub-processors are bound by written data processing agreements providing at least equivalent data protection obligations to those in this DPA.

Sub-Processor Service Data Location Transfer Safeguard
Supabase Inc. Database and file storage (PostgreSQL). Primary store for all contact records, communication history, and platform data. EU, Ireland (eu-west-1) EU-based; adequacy applies. Supabase DPA in place.
Vercel Inc. Application hosting and edge delivery. Serves the Always On platform to users. EU-primary edge network Standard Contractual Clauses (SCCs). Vercel DPA in place.
Resend Inc. Transactional email. Sends platform invitations, notifications, and system emails. EU region SCCs. Resend DPA in place.
Anthropic PBC (Claude API) AI processing. Powers the Sally, Dan, and Caroline AI agents. Contact record data and communication context are sent to the Claude API to generate responses, qualifications, and recommendations. Under Anthropic's Commercial Terms of Service (which apply to API access), customer inputs and outputs are not used to train Anthropic's models by default. United States (Anthropic infrastructure; no EU data residency option on the standard API) SCCs (EU Standard Contractual Clauses) plus a UK International Data Transfer Addendum, incorporated into Anthropic's Commercial Terms of Service.
Google LLC (Gmail API) / Google Workspace Gmail email sync. Where a Tenant user connects their Gmail account, the Gmail API is used to sync emails to and from contacts. Only emails matching existing contact records are synced. Google infrastructure SCCs / IDTA. Google Cloud DPA in place. Enabled only where user authorises via OAuth.
Microsoft Corporation Outlook / Microsoft 365 email sync (Microsoft Graph API). Where a Tenant user connects their Outlook account, Microsoft Graph is used to sync emails to and from contacts. Only emails matching existing contact records are synced. Microsoft infrastructure SCCs / IDTA. Microsoft Online Services DPA in place. Enabled only where user authorises via OAuth.
Meta Platforms Ireland Ltd WhatsApp Cloud API. Enables WhatsApp messages from contacts to be received, stored, and responded to within the Platform where the Tenant has enabled this feature. Meta infrastructure (EU routing where available) SCCs. Meta Business Terms and DPA in place. Enabled only where activated by the Tenant.

7 Mailbox Connection and Email Sync

The Platform allows individual users to connect their Gmail or Microsoft Outlook mailbox. When Email Sync is enabled, the following applies:

7.1 What is processed

Once a user connects their mailbox, the Platform accesses and processes the following data:

The Platform does not process email attachments or access emails unrelated to contacts with existing records in the Platform. Historical emails are not bulk-imported; only emails sent or received after connection is established are synced, unless a specific historical sync is configured.

7.2 Authorisation

Mailbox connections are only established where the individual user explicitly authorises access via OAuth. Plan Grow Do Ltd does not connect mailboxes without user authorisation. Users can disconnect their mailbox at any time from their profile settings, which immediately revokes access and stops further syncing.

7.3 Disconnection and token deletion

When a user disconnects their mailbox, the Platform immediately revokes the OAuth token and deletes it from storage. No further email syncing takes place after disconnection. Emails already synced and stored against contact records remain, unless deleted by a Tenant manager.

Users may also revoke access directly via their Google Account permissions page or Microsoft My Apps portal at any time.

Gmail: Always On's use of Gmail data complies with the Google API Services User Data Policy, including the Limited Use requirements. Email data is used solely to display communications against contact records and is not used to train AI models or shared with third parties.

Microsoft: Always On's use of Microsoft account data complies with the Microsoft API Terms of Use. Access is limited to email read and send permissions; calendar, contacts, files, and other Microsoft data are not accessed.

8 AI Agents and Automated Processing

8.1 Role of the AI agents

The Always On platform includes three AI agents (Sally, Dan, and Caroline) powered by Anthropic's Claude models. These agents assist with inbound contact handling, sales qualification, daily pipeline management, and market intelligence. When an AI agent processes a contact interaction, relevant contact record data and communication context are sent to the Claude API to generate a response, qualification score, recommendation, or suggested action.

8.2 AI outputs are advisory only

All outputs produced by the AI agents, including qualifications, scores, draft responses, recommendations, and suggested next actions, are advisory and assistive only. They are tools to support the Tenant's team, not decisions in themselves.

The Tenant remains responsible for reviewing, approving, and acting on any AI-generated output before it is relied upon or communicated to a contact. Plan Grow Do Ltd does not accept responsibility for decisions taken by the Tenant on the basis of AI-generated outputs without appropriate review.

8.3 No solely automated decisions

The Platform does not make solely automated decisions that produce legal effects or similarly significant effects on individuals within the meaning of UK GDPR Article 22. Human review is always part of the process.

8.4 AI data handling

9 Special Category Data

The Always On platform is designed for B2B sales management and is not intended for the processing of Special Category Data or criminal offence data.

The Tenant must not intentionally submit Special Category Data into the Platform unless it has:

Plan Grow Do Ltd recognises that Special Category Data may occasionally appear incidentally in free-text fields (for example in emails, WhatsApp messages, or form submissions) without having been intentionally submitted. In those cases, Plan Grow Do Ltd will process such data only as necessary to provide the Platform and in accordance with this DPA and the Tenant's instructions.

Note: If the Tenant becomes aware that Special Category Data has been submitted into the Platform outside of the circumstances described above, it should contact info@plangrowdo.com promptly so that appropriate steps can be taken.

10 Data Subject Rights

Plan Grow Do Ltd will assist the Controller in fulfilling its obligations to respond to data subject rights requests under UK GDPR, including requests relating to:

Where a data subject contacts Plan Grow Do Ltd directly regarding their rights, Plan Grow Do Ltd will promptly refer the request to the Controller. The Controller is responsible for determining how to respond.

Plan Grow Do Ltd provides tools within the Platform to enable the Controller to export, rectify, and delete personal data to support data subject requests.

11 Personal Data Breaches

Plan Grow Do Ltd will notify the Controller without undue delay and, where feasible, within 24 hours of becoming aware of a personal data breach affecting data processed under this DPA.

Where not all information is available within 24 hours, Plan Grow Do Ltd will provide an initial notification with the information available at that time, followed by further updates in phases as the investigation progresses. Initial notification will include, where known:

Plan Grow Do Ltd will cooperate with the Controller throughout the investigation and provide reasonable assistance where the Controller is required to notify the ICO or affected data subjects.

To report a suspected breach: info@plangrowdo.com

12 Data Protection Impact Assessments

Where the Controller is required to conduct a Data Protection Impact Assessment (DPIA) in connection with processing on the Platform, Plan Grow Do Ltd will provide reasonable assistance, including:

13 International Transfers

All primary data storage is within the EU (Ireland). Where personal data is transferred to or processed by sub-processors outside the UK or EU, including Anthropic (Claude API), Google (Gmail API), Microsoft (Microsoft Graph), and Meta, Plan Grow Do Ltd ensures appropriate safeguards are in place:

Details of transfer mechanisms for each sub-processor are available on request from info@plangrowdo.com.

14 Return and Deletion of Data

On termination of the service agreement, Plan Grow Do Ltd will, at the Controller's written election within 30 days of termination:

Where no election is made within 30 days of termination, Plan Grow Do Ltd will securely delete active production data by default.

14.1 Backups

The Platform maintains automated backups of all tenant data. Deletion from active production systems will be completed within the timeframe above, but backup copies may remain until they are overwritten or expire under Plan Grow Do Ltd's standard backup retention cycle.

Backup data is held solely for disaster recovery purposes and will not be accessed, used, or restored for any other purpose. If a backup containing deleted customer data is restored following a disaster recovery event, the previously deleted data will be re-deleted promptly following restoration.

The Controller is responsible for exporting any data it requires before termination. Data export functionality is available within the Platform at any time during the active subscription.

15 Audit Rights

The Controller has the right to audit Plan Grow Do Ltd's compliance with this DPA. Plan Grow Do Ltd will first respond to audit requests by providing relevant documentation (such as security policies, sub-processor agreements, and breach records) within a reasonable timeframe.

Where a physical audit or inspection is required, this will be agreed in advance, conducted at the Controller's cost, with no less than 30 days' written notice, and no more than once per calendar year, unless a personal data breach has occurred.

The Controller agrees not to request information that would compromise the security of other tenants' data or Plan Grow Do Ltd's commercially confidential information.

16 Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the main service agreement between the Tenant and Plan Grow Do Ltd.

Where Plan Grow Do Ltd has processed personal data in breach of this DPA or UK GDPR and this has caused damage to the Controller or a data subject, Plan Grow Do Ltd accepts liability to the extent it is responsible for the breach.

Where the Controller has given inaccurate or unlawful instructions that caused a breach, the Controller bears responsibility to the extent of those instructions.

17 Term and Termination

This DPA comes into effect when the Tenant activates their Always On workspace and accepts the service terms. It remains in force for the duration of the service agreement between the parties.

This DPA terminates automatically on termination or expiry of the service agreement, subject to any continuing obligations under Section 14 (return and deletion of data).

18 Governing Law

This DPA is governed by and construed in accordance with the laws of England and Wales. Any disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.

S1 Schedule 1: Processing Details

This Schedule sets out the details of the processing carried out by Plan Grow Do Ltd on behalf of the Controller, as required by UK GDPR Article 28(3).

Subject matter

The provision of the Always On B2B sales management platform, including AI-assisted contact qualification, pipeline management, email and WhatsApp communication sync, and sales analytics.

Duration

For the duration of the service agreement, plus any post-termination period required to fulfil obligations under Section 14.

Nature and purpose of processing

NaturePurpose
Storage and retrievalHolding contact, prospect, and communication records within the Platform
AI analysis and generationQualifying contacts, generating responses and recommendations via the Sally, Dan, and Caroline AI agents (advisory outputs only; see Section 8)
Email synchronisationSyncing emails between a user's connected Gmail or Outlook mailbox and contact records where the user has authorised Email Sync
Form handlingReceiving and storing web form enquiries submitted by contacts via Tenant-embedded forms
WhatsApp messagingReceiving, storing, and responding to WhatsApp messages from contacts where the Tenant has enabled this feature
Reporting and analyticsGenerating pipeline reports, activity metrics, and sales dashboards for the Tenant

Types of personal data

Categories of data subjects

Tenant responsibility: The Tenant is responsible for ensuring that all personal data entered into the Platform has been obtained lawfully and that appropriate notices have been given to data subjects. The Platform is not designed for Special Category Data and the Tenant should not submit such data without satisfying the requirements of Section 9.