Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "you") and Pubblish Limited ("Pubblish", "we") when you use Pubblish to process personal data about other people. It sets out how Pubblish processes that personal data on your behalf, in line with Article 28 of the UK GDPR.
This DPA only applies where you upload personal data about third parties — for example authors, contributors, editors, illustrators, agents, or other individuals connected to your titles. For personal data about you and your account, our Privacy Policy applies.
1. Roles
You are the data controller for the third-party personal data you upload. Pubblish is the data processor. We process that data only to provide the Pubblish service to you, and only on your instructions.
Your use of the Pubblish platform — the data you enter, the features you use, the settings you configure — constitutes your documented instructions to us. If you need to give us additional instructions, contact us at [email protected].
2. Subject Matter, Duration, Nature, and Purpose
Subject matter: Processing of personal data that you upload to Pubblish as part of operating your publishing workflow.
Duration: For as long as your Pubblish account is active, plus the deletion period set out in Section 9 of this DPA.
Nature and purpose: Storage, organisation, retrieval, display, and limited automated processing (such as generating contributor lists, formatting output files, and sending email through your account) — all for the purpose of providing the Pubblish service to you.
3. Categories of Personal Data and Data Subjects
Categories of data typically processed include: names, professional contact details, biographical information, professional credits, and roles (for example, author, editor, illustrator, translator). You may upload other categories of personal data through free-text fields and file attachments.
Categories of data subjects typically include: authors, contributors, illustrators, editors, translators, agents, and other individuals professionally connected to your titles.
You should not upload special category personal data (for example, data about health, ethnicity, or political views) unless you have a lawful basis to do so.
4. Our Obligations as Processor
We will:
- Process personal data only on your documented instructions, including in relation to transfers outside the UK, unless required to do otherwise by law (in which case we will inform you first, where legally permitted)
- Ensure that the people who process personal data on our behalf are bound by confidentiality
- Implement appropriate technical and organisational security measures, as described in Section 5
- Engage sub-processors only on the terms set out in Section 6
- Assist you, taking into account the nature of the processing, in responding to requests from data subjects who exercise their rights under data protection law
- Assist you in meeting your obligations relating to security, breach notification, data protection impact assessments, and prior consultation with the ICO
- At the end of the service, delete or return personal data as set out in Section 9
- Make available to you the information needed to demonstrate compliance with this DPA
5. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- TLS encryption for all data in transit
- Encryption at rest for the database and stored assets
- Strict tenant isolation: each customer's data lives in a separate PostgreSQL schema
- Hashed passwords using current best-practice algorithms
- Role-based access controls
- Regular security patching and dependency updates
- Restricted, audited administrative access
These measures may change over time to reflect evolving risk and best practice. We will not materially reduce the level of protection.
6. Sub-Processors
You authorise us to engage sub-processors to help us provide the Pubblish service. Our current sub-processors are:
- Render — cloud hosting and database infrastructure
- Cloudflare — DNS, asset storage, email routing, and custom domain proxying
- Postmark — transactional email delivery
- Sentry — error monitoring; configured not to send account details, though an error report can include fragments of the data being processed when a fault occurs
- Anthropic — AI-assisted content suggestions, only where you choose to use those features
We have written contracts with each sub-processor requiring them to protect personal data to a standard at least equivalent to this DPA.
If we add or replace a sub-processor in a way that affects how third-party personal data is processed, we will give you at least 30 days' notice by email or through the service. If you object on reasonable data protection grounds, you may terminate the affected service.
7. International Transfers
Some sub-processors are based outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place — typically the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework.
8. Personal Data Breaches
If we discover a personal data breach affecting your data, we will notify you without undue delay — and in any event within 72 hours of becoming aware of it — providing the information you need to meet your own breach notification obligations.
9. Return or Deletion of Data
When your Pubblish account ends — through cancellation, termination, or otherwise — we will:
- Retain your workspace in a read-only state for 90 days, during which your data remains available for export in a structured machine-readable format
- After that, permanently delete personal data from our production systems
- Retain a single export snapshot in secure off-platform storage for a further 90 days, after which it is permanently deleted
- Allow residual copies in disaster-recovery backups — full-database backups held off-platform on a rolling basis of around 30 days — to be overwritten in the normal backup rotation
We will not retain personal data beyond what is needed to comply with legal obligations (for example, tax records).
10. Audits
We will make available, on request, the information reasonably needed to demonstrate compliance with this DPA — for example, our security measures, sub-processor list, and breach history.
Given the multi-tenant nature of the platform, we do not permit on-site audits or direct inspection of our systems. If your specific regulatory requirements need more than the information we provide, contact us at [email protected].
11. Data Subject Requests
If we receive a request directly from one of your data subjects, we will tell them to contact you and will not respond to the substance of the request ourselves. We will forward the request to you promptly.
We will help you respond to data subject requests, taking into account the nature of the processing and the information we hold.
12. General
This DPA forms part of your agreement with Pubblish and is governed by the laws of England and Wales. If there is any conflict between this DPA and the Terms of Service in relation to the processing of third-party personal data, this DPA prevails. Otherwise, the Terms of Service prevail.
13. Contact
For any questions about this DPA, contact us at: