MazeByte

Legal

Data Processing Agreement

Last updated: 1 March 2026

Parties

This Data Processing Agreement (“DPA”) is entered into between:

Controller:
The customer entity that has agreed to MazeByte's Terms and Conditions (the “Controller” or “Customer”)

Processor:
MazeByte Ltd
124 City Road
London, EC1V 2NX
United Kingdom
Company number: 16860301
(the “Processor” or “MazeByte”)

This DPA forms part of and is incorporated into the Terms and Conditions agreed between the parties (the “Principal Agreement”). In the event of conflict between this DPA and the Principal Agreement, this DPA shall prevail in respect of data protection matters.

1. Definitions

TermMeaning
“Applicable Data Protection Law”All data protection and privacy laws applicable to the processing of Personal Data under this DPA, including (as applicable): the UK GDPR and Data Protection Act 2018; the EU GDPR (Regulation 2016/679); the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA); and any other applicable national or regional data protection legislation
“UK GDPR”The UK General Data Protection Regulation as defined in the Data Protection Act 2018
“EU GDPR”Regulation (EU) 2016/679 of the European Parliament and of the Council
“Personal Data”Any information relating to an identified or identifiable natural person contained within Customer Data processed by MazeByte under the Principal Agreement
“Processing”Any operation or set of operations performed on Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, or deletion
“Controller”The party that determines the purposes and means of the Processing of Personal Data
“Processor”The party that processes Personal Data on behalf of the Controller
“Sub-processor”Any third party engaged by MazeByte to process Personal Data on behalf of the Controller
“Data Subject”The natural person to whom Personal Data relates
“Personal Data Breach”A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data
“Standard Contractual Clauses” or “SCCs”The standard contractual clauses for the transfer of personal data to third countries as approved by the European Commission or the UK equivalent (IDTA)
“IDTA”International Data Transfer Agreement as approved by the UK Information Commissioner
“Services”The MazeByte platform and related services provided under the Principal Agreement

2. Roles and Scope

2.1 Roles

The parties acknowledge and agree that:

  • The Customer is the Controller of any Personal Data contained within Customer Data uploaded to or processed through the Services
  • MazeByte is the Processor of that Personal Data, acting only on the documented instructions of the Controller
  • Where MazeByte processes Personal Data for its own purposes (for example, account data and usage data as described in the Privacy Policy), MazeByte acts as a Controller in its own right and such processing is governed by the Privacy Policy, not this DPA

2.2 Subject Matter

This DPA governs the processing of Personal Data by MazeByte as Processor on behalf of the Customer as Controller, in connection with the provision of the Services.

2.3 Nature, Purpose, and Duration of Processing

ElementDetail
Nature of processingAutomated processing, including ingestion, transformation, analysis, schema generation, and pipeline construction
Purpose of processingTo provide the Services: autonomous exploration of Customer Data, insight proposal, and generation of analytics-ready ETL pipelines
Categories of Personal DataAs determined and uploaded by the Controller; may include any category of personal data contained within Customer Data
Categories of Data SubjectsAs determined by the Controller; may include the Controller's customers, employees, partners, or end users
Duration of processingFor the term of the Principal Agreement, plus the deletion period set out in Section 9

2.4 Controller Obligations

The Controller warrants and represents that:

  • It has a lawful basis under Applicable Data Protection Law for all Personal Data uploaded to or processed through the Services
  • It has provided all necessary notices to, and obtained all necessary consents from, Data Subjects as required by Applicable Data Protection Law
  • It has the right to transfer Personal Data to MazeByte for processing under this DPA
  • Its instructions to MazeByte will at all times comply with Applicable Data Protection Law

MazeByte shall not be liable for any failure by the Controller to comply with its obligations as Controller.

3. MazeByte's Processing Obligations

3.1 Instructions

MazeByte shall process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. The Principal Agreement and this DPA constitute the Controller's complete and documented instructions as of the date of this DPA. The Controller may issue further instructions in writing during the term; MazeByte will confirm whether it is able to comply with any additional instructions within a reasonable timeframe.

Where MazeByte is required by applicable law to process Personal Data beyond the Controller's instructions, MazeByte shall inform the Controller of that requirement before processing, unless the law prohibits such notification.

3.2 Purpose Limitation

MazeByte shall process Personal Data solely for the purposes of providing the Services as described in the Principal Agreement. MazeByte shall not:

  • Use Personal Data to train, develop, or improve its AI models or any other product or service
  • Use Personal Data for its own commercial purposes
  • Sell, rent, or otherwise transfer Personal Data to any third party
  • Process Personal Data for any purpose not expressly authorised by the Controller

3.3 Confidentiality

MazeByte shall ensure that all personnel authorised to process Personal Data are subject to appropriate obligations of confidentiality, whether by contract or professional obligation, and shall not permit any person to process Personal Data who is not bound by such obligations.

3.4 Data Minimisation

MazeByte shall process only the Personal Data that is necessary for the provision of the Services and shall take reasonable steps to ensure that irrelevant or excessive Personal Data is not retained beyond operational necessity.

4. Security

4.1 Technical and Organisational Measures

MazeByte shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account:

  • The state of the art and costs of implementation
  • The nature, scope, context, and purposes of processing
  • The risk to the rights and freedoms of natural persons

MazeByte's current technical and organisational measures include, at a minimum:

MeasureDescription
Encryption in transitTLS 1.2 or higher for all data transmitted to and from the platform
Encryption at restEncryption of stored Personal Data using industry-standard algorithms
Access controlsRole-based access controls; principle of least privilege applied to all internal access
AuthenticationMulti-factor authentication required for administrative access
Network securityFirewalls, intrusion detection, and network segmentation
Vulnerability managementRegular security assessments and penetration testing
Incident responseDocumented procedures for detecting, responding to, and notifying Personal Data Breaches
Backup and recoveryRegular backups with tested restoration procedures
Vendor securitySecurity assessments of Sub-processors prior to engagement

4.2 Updates to Security Measures

MazeByte may update its technical and organisational measures from time to time, provided that any updates do not materially reduce the level of protection afforded to Personal Data. MazeByte will inform the Controller of any material changes to its security measures on request.

4.3 Controller Access to Security Information

MazeByte shall, on reasonable written request and no more than once per calendar year (unless a security incident has occurred), provide the Controller with sufficient information to demonstrate compliance with this Section 4, which may take the form of a summary of security practices, third-party audit reports, or certifications, subject to confidentiality obligations.

5. Sub-processors

5.1 Authorisation

The Controller provides general authorisation to MazeByte to engage Sub-processors for the provision of the Services, subject to the conditions set out in this Section 5.

5.2 Current Sub-processors

MazeByte's current Sub-processors involved in the processing of Personal Data are set out below. MazeByte will maintain an up-to-date list of Sub-processors at mazebyte.com/sub-processors or available on request.

Sub-processorPurposeLocation
Auth0 (Okta)Identity and authentication managementUSA (SCCs/IDTA in place)
Cloud infrastructure providerHosting, storage, and computeUK / EEA
Email service providerTransactional email deliveryTBC

5.3 Changes to Sub-processors

MazeByte shall give the Controller no less than 14 days' prior written noticeof any intended addition or replacement of a Sub-processor. Notice will be provided by email to the address registered to the Controller's account or by update to the Sub-processor list at the URL above.

If the Controller objects to a new or replacement Sub-processor on reasonable data protection grounds, the Controller must notify MazeByte in writing within 14 days of receiving notice. The parties shall work in good faith to resolve the objection. If the objection cannot be resolved and MazeByte proceeds with the Sub-processor engagement, the Controller may terminate the affected Services on written notice without liability for early termination fees.

5.4 Sub-processor Obligations

MazeByte shall, by written contract, impose on each Sub-processor data protection obligations equivalent to those imposed on MazeByte under this DPA. MazeByte remains fully liable to the Controller for the performance of each Sub-processor's obligations to the extent that the Sub-processor fails to fulfil its data protection obligations.

6. Data Subject Rights

6.1 Assistance

MazeByte shall, taking into account the nature of the processing, provide reasonable assistance to the Controller to fulfil its obligations to respond to Data Subject requests to exercise their rights under Applicable Data Protection Law, including rights of:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection

6.2 Requests Received Directly

Where MazeByte receives a request directly from a Data Subject in connection with Personal Data processed under this DPA, MazeByte shall:

  • Promptly notify the Controller of the request (and in any event within 3 business days)
  • Not respond to the request other than to acknowledge receipt, unless instructed by the Controller or required by law
  • Provide the Controller with reasonable assistance to respond to the request within the applicable statutory timeframe

6.3 Costs

MazeByte may charge the Controller reasonable costs incurred in providing assistance under this Section 6 where requests are unusually complex or numerous.

7. Data Protection Impact Assessments and Prior Consultation

Where required by Applicable Data Protection Law, MazeByte shall provide reasonable assistance to the Controller in carrying out data protection impact assessments (DPIAs) and in consulting with supervisory authorities, to the extent that such assistance relates to the processing carried out by MazeByte under this DPA and the information available to MazeByte.

8. Personal Data Breaches

8.1 Notification

MazeByte shall notify the Controller of a Personal Data Breach without undue delay and, where feasible, within 48 hoursof becoming aware of it. Notification shall be made to the email address registered to the Controller's account.

8.2 Content of Notification

MazeByte's breach notification shall include, to the extent then known:

  • A description of the nature of the Personal Data Breach, including categories and approximate number of Data Subjects and records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its effects
  • Contact details of MazeByte's data protection point of contact

When not all information is available at the time of initial notification, MazeByte shall provide it in phases as it becomes available.

8.3 Controller Responsibility for Regulatory Notification

The Controller is responsible for determining whether to notify the relevant supervisory authority and affected Data Subjects of any Personal Data Breach, in accordance with its obligations under Applicable Data Protection Law. MazeByte shall provide reasonable assistance to the Controller in making any such notifications.

8.4 No Admission

Nothing in this Section 8 shall be construed as an admission of fault or liability by MazeByte in connection with any Personal Data Breach.

9. Deletion and Return of Personal Data

9.1 On Termination

Upon expiry or termination of the Principal Agreement, MazeByte shall, at the Controller's election:

  • Delete all Personal Data processed under this DPA; or
  • Return all Personal Data to the Controller in a structured, machine-readable format

MazeByte shall complete deletion or return within 30 days of the termination date and shall provide written confirmation on request.

9.2 Retention Exceptions

MazeByte may retain Personal Data beyond the period set out in Section 9.1 only to the extent required by applicable law. Any such retained Personal Data shall remain subject to this DPA and shall be deleted as soon as the legal retention obligation ceases to apply.

9.3 Backup Copies

MazeByte shall ensure that Personal Data in backup systems is deleted or overwritten within its standard backup rotation cycle following the termination of the Principal Agreement.

10. Audits and Inspections

10.1 Audit Rights

MazeByte shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, subject to:

  • Reasonable prior written notice of no less than 30 days
  • Audits being conducted during normal business hours and in a manner that minimises disruption to MazeByte's operations
  • A limit of one audit per calendar year, unless a Personal Data Breach has occurred or a supervisory authority has identified a compliance concern
  • The auditor being subject to confidentiality obligations acceptable to MazeByte
  • The Controller bearing the reasonable costs of the audit

10.2 Third-Party Certifications

Where MazeByte holds relevant third-party security certifications or audit reports (such as ISO 27001 or SOC 2), MazeByte may provide these to the Controller in lieu of or in addition to a bespoke audit, at MazeByte's discretion.

11. International Transfers

11.1 Transfers by MazeByte

MazeByte shall not transfer Personal Data outside the UK or European Economic Area without ensuring that an appropriate transfer mechanism is in place, including:

  • An adequacy decision issued by the UK Secretary of State or European Commission (as applicable)
  • Standard Contractual Clauses (EU SCCs) or an International Data Transfer Agreement (UK IDTA), with any required supplementary measures
  • Any other transfer mechanism recognised under Applicable Data Protection Law

11.2 Current Transfer Mechanisms

Where MazeByte transfers Personal Data to Sub-processors located outside the UK or EEA (including the USA), it does so under Standard Contractual Clauses or UK IDTAs as applicable, supplemented by appropriate technical and organisational measures. Details are available on request.

11.3 Controller Transfers

Where the Controller transfers Personal Data to MazeByte from outside the UK or EEA, the Controller is responsible for ensuring a valid transfer mechanism is in place for that transfer. MazeByte will execute any required SCCs or IDTA addenda on request.

12. Data Protection Officer and Contact

MazeByte's designated data protection contact for matters arising under this DPA is:

Data Protection Contact
MazeByte Ltd
124 City Road, London, EC1V 2NX
[email protected]

The Controller shall designate a contact point for data protection matters and notify MazeByte of any changes to that contact.

13. Liability and Indemnity

13.1 Mutual Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement, to the fullest extent permitted by Applicable Data Protection Law.

13.2 Processor Liability

MazeByte shall be liable to the Controller for damage caused by processing that does not comply with this DPA or Applicable Data Protection Law, where MazeByte has not complied with its obligations specifically directed to processors under Applicable Data Protection Law.

13.3 Controller Indemnity

The Controller shall indemnify and hold harmless MazeByte against any claims, penalties, fines, costs, or liabilities (including reasonable legal fees) arising from:

  • The Controller's failure to comply with its obligations as Controller under Applicable Data Protection Law
  • Processing carried out by MazeByte in accordance with the Controller's documented instructions that results in a violation of Applicable Data Protection Law
  • Personal Data uploaded by the Controller that was obtained or is being processed in violation of Applicable Data Protection Law

13.4 Regulatory Fines

Where a supervisory authority imposes a fine or penalty on MazeByte that arises wholly or substantially from the Controller's failure to fulfil its Controller obligations under Applicable Data Protection Law, the Controller shall reimburse MazeByte for that fine or penalty in full.

14. Term

This DPA shall remain in force for the duration of the Principal Agreement and shall terminate automatically upon expiry or termination of the Principal Agreement, subject to the survival of obligations relating to deletion of Personal Data (Section 9), confidentiality (Section 3.3), and liability (Section 13), which shall survive termination.

15. General

15.1 Order of Precedence

In the event of conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to data protection matters. In the event of conflict between this DPA and any applicable Standard Contractual Clauses or IDTA, the SCCs or IDTA shall prevail.

15.2 Governing Law

This DPA is governed by the laws of England and Wales. Each party submits to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising under this DPA, except where mandatory provisions of Applicable Data Protection Law require otherwise.

15.3 Severability

If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

15.4 Amendments

MazeByte may update this DPA from time to time to reflect changes in Applicable Data Protection Law or its processing activities. Where changes are material, MazeByte shall provide no less than 30 days' written notice. Continued use of the Services after the effective date constitutes acceptance of the updated DPA. If the Controller does not accept the changes, it may terminate the Principal Agreement before the changes take effect.

15.5 Entire Agreement

This DPA, together with the Principal Agreement and any applicable SCCs or IDTA, constitutes the entire agreement between the parties with respect to the processing of Personal Data under the Principal Agreement.

Annex A: Details of Processing

This Annex forms part of this DPA and sets out the details of processing as required by Applicable Data Protection Law.

ElementDetail
ControllerThe Customer as identified in the Principal Agreement
ProcessorMazeByte Ltd, 124 City Road, London, EC1V 2NX, Company number: 16860301
Subject matterProcessing of Personal Data contained within Customer Data for the provision of the Services
DurationTerm of the Principal Agreement plus deletion period
Nature of processingAutomated ingestion, transformation, schema generation, insight proposal, and pipeline construction
Purpose of processingProvision of autonomous AI data pipeline and insight generation services
Types of Personal DataAs uploaded by the Controller; may include any category of personal data
Categories of Data SubjectsAs determined by the Controller; may include customers, employees, partners, or end users of the Controller
Special category dataThe Controller must not upload special category data (as defined under UK/EU GDPR Article 9) without first notifying MazeByte and agreeing additional safeguards in writing
Frequency of transferContinuous, as determined by the Controller's use of the Services
RetentionFor the term of the Principal Agreement; deleted within 30 days of termination

Annex B: Technical and Organisational Measures

This Annex sets out MazeByte's current technical and organisational security measures as required under Article 28(3)(c) of the UK/EU GDPR.

B.1 Access Control

  • Access to Personal Data is restricted to authorised personnel on a need-to-know basis
  • Role-based access controls are enforced across all systems
  • Administrative access requires multi-factor authentication
  • Access rights are reviewed quarterly and revoked promptly upon change of role or departure

B.2 Data Encryption

  • All Personal Data in transit is encrypted using TLS 1.2 or higher
  • All Personal Data at rest is encrypted using AES-256 or equivalent
  • Encryption keys are managed using industry-standard key management practices

B.3 Network and Infrastructure Security

  • Production systems are isolated behind firewalls and network segmentation
  • Intrusion detection and prevention systems are in place
  • Regular vulnerability scans and penetration tests are conducted
  • Security patches are applied within defined timeframes based on severity

B.4 Incident Detection and Response

  • Security monitoring and alerting is in place across production systems
  • A documented incident response procedure is maintained and tested
  • Personal Data Breaches are escalated and notified in accordance with Section 8 of this DPA

B.5 Availability and Resilience

  • Production systems are deployed with redundancy and failover capability
  • Regular backups are taken and tested for restorability
  • Business continuity and disaster recovery plans are maintained

B.6 Personnel and Organisational Measures

  • All personnel with access to Personal Data are subject to confidentiality obligations
  • Data protection training is provided to relevant personnel
  • A data protection contact is designated (see Section 12)
  • Data protection considerations are integrated into product and engineering processes

B.7 Sub-processor Management

  • Sub-processors are assessed for security compliance prior to engagement
  • Sub-processors are bound by data protection obligations equivalent to those in this DPA
  • Sub-processor access to Personal Data is limited to what is necessary for their specific function

This Data Processing Agreement should be read alongside our Privacy Policy and Terms and Conditions.