Data Processing Agreement
Last updated: 30 July 2026
This Data Processing Agreement (DPA) sets out how Critical Media Ltd processes personal data on behalf of client organisations using Critical 360, in accordance with Article 28 of the UK GDPR. It forms part of our Terms of Service.
1. Parties and roles
This DPA is between the client organisation (the “Controller”) and Critical Media Ltd, company no. 6582022 (the “Processor”, “we”). For personal data processed within the Critical 360 platform, the Controller determines the purposes and means of processing, and we process that data only on the Controller’s documented instructions, including as set out in the Terms of Service and this DPA.
2. Subject matter and duration
The subject matter is the provision of the Critical 360 360°-feedback platform. Processing continues for the duration of the Controller’s subscription and until data is deleted or returned in accordance with section 9.
3. Nature and purpose of processing
We process personal data to host, operate, secure and support the platform so the Controller can run 360° feedback and appraisal cycles — including collecting questionnaire responses, generating benchmarked reports, and sending related notifications.
4. Types of personal data and data subjects
| Categories of personal data | Categories of data subjects |
|---|---|
| Names and email addresses; account role; questionnaire responses and free-text feedback; optional self-declared demographic fields (e.g. age, gender) where the Controller enables them. | The Controller’s administrators, employees or members being reviewed (reviewees), and the reviewers they nominate. |
We do not require special-category data to provide the service. The Controller should not upload special-category data except through fields intended for it, and remains responsible for its lawful basis to do so.
5. Our obligations
We will:
- process personal data only on the Controller’s documented instructions, unless required by law (in which case we’ll inform the Controller where permitted);
- ensure personnel authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (section 8);
- engage sub-processors only in line with section 6;
- taking into account the nature of processing, assist the Controller with data-subject requests and with its obligations on security, breach notification and data-protection impact assessments;
- notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data;
- make available information reasonably necessary to demonstrate compliance, and allow for and contribute to audits (section 7).
6. Sub-processors
The Controller provides general authorisation for us to engage the sub-processors listed below to help deliver the service. Each is bound by data-protection terms no less protective than this DPA. We will give the Controller reasonable notice of any intended addition or replacement of a sub-processor, giving them the opportunity to object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Application hosting and data storage | United Kingdom |
| Cloudflare | DNS, content delivery and security | Global edge (UK-served) |
| Resend | Transactional email delivery | EU / US |
| Stripe | Subscription billing and payments | EU / US |
7. Audit
We will make available information reasonably necessary to demonstrate compliance with Article 28 and, on reasonable prior notice and no more than once per year (unless required by a supervisory authority), allow the Controller or its authorised auditor to review our relevant policies and measures, subject to confidentiality and without compromising the security of other customers.
8. Security measures
Our technical and organisational measures include:
- encryption of data in transit (TLS) and at rest;
- logical isolation of each client organisation’s data (multi-tenant separation);
- role-based access controls and least-privilege access to production systems;
- hosting on Microsoft Azure UK, with the platform’s resilience and backup features;
- secure development practices, dependency management and access logging;
- anonymity safeguards in reporting — feedback is aggregated by peer group, and small groups are combined to protect individual anonymity.
9. Return and deletion
On termination of the subscription, and at the Controller’s choice, we will return or delete the personal data we process on its behalf, and delete existing copies, unless we are required by law to retain them. We will do so within a reasonable period after termination.
10. International transfers
Platform data is hosted in the UK. Where a sub-processor processes personal data outside the UK, such transfers are made under the UK’s adequacy regulations or an appropriate transfer mechanism (Standard Contractual Clauses together with the UK International Data Transfer Addendum).
11. General
This DPA forms part of and is governed by our Terms of Service, including its provisions on liability and governing law (England and Wales). If any provision conflicts with the Terms in respect of data protection, this DPA prevails.
12. Requesting a signed copy
Public-sector and enterprise customers who require a countersigned DPA (or need it aligned to a specific procurement framework) can request one at [email protected].