14 Day Free Trial on All Plans

Data Processing Agreement

Made pursuant to Article 28 of the UK GDPR

Version 1.0  |  Effective from 10/08/2026
Processor: 91D Ltd, trading as FoundationsAI. Registered in England & Wales, company no. 12768586.
Registered office: Unit 13E, 92 Burton Road, Sheffield, S3 8BX
ICO registration: ZA890593
Data protection contact: Daniel Sagar, Data Protection Lead - [email protected] - 01590 439000

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between 91D Ltd trading as FoundationsAI ("we", "us", "the Processor") and the customer identified in the Order ("you", "the Controller"). It applies automatically from the moment you accept those Terms and requires no separate signature to take effect.

If your organisation requires a countersigned copy for its own records, or a version completed with your company details, contact us at [email protected] and we will provide one.

Background

A. We provide you with access to, and configuration, integration and support services in respect of, a customer relationship management platform (the "Services"), under the agreement between us for those Services (the "Principal Agreement").

B. In performing the Services we process personal data on your behalf. You are the controller and we are a processor in respect of that personal data.

C. This DPA sets out the terms on which we process that personal data, and is entered into to satisfy Article 28(3) of the UK GDPR.

D. This DPA is incorporated into and forms part of the Principal Agreement.

1. Definitions and interpretation

1.1 In this DPA:

Data Protection Laws - the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and all other applicable laws relating to the processing of personal data and privacy, each as amended or replaced from time to time.

UK GDPR - the retained EU law version of Regulation (EU) 2016/679 as defined in section 3(10) of the Data Protection Act 2018.

Controller Personal Data - personal data processed by us on your behalf under the Principal Agreement, as described in Annex 1.

Personal Data Breach - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Controller Personal Data.

Sub-processor - any third party engaged by us to process Controller Personal Data, as listed in Annex 3.

Platform Provider - HighLevel Inc. (also trading as LeadConnector), the provider of the underlying CRM platform through which the Services are delivered.

Restricted Transfer - a transfer of Controller Personal Data to a country outside the United Kingdom which is not the subject of UK adequacy regulations.

Transfer Mechanism - the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or any other lawful transfer mechanism under Article 46 UK GDPR.

1.2 The terms "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the UK GDPR.

1.3 Where this DPA conflicts with the Principal Agreement, this DPA prevails in respect of the processing of Controller Personal Data.

2. Scope and roles

2.1 In respect of Controller Personal Data, you are the controller and we are a processor.

2.2 Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject. You are responsible for satisfying yourself that Annex 1 accurately describes your intended use of the Services, and for notifying us in advance of any material change to it.

2.3 You are responsible for determining the lawful basis for the processing, for issuing privacy information to data subjects, and for obtaining and maintaining any consents required under Data Protection Laws - including consents required for electronic marketing under the Privacy and Electronic Communications Regulations 2003.

2.4 We do not use Controller Personal Data for our own purposes, and do not sell, licence or otherwise disclose it to any third party except as permitted by this DPA or required by law.

2.5 We act as a controller in respect of personal data we process for our own business purposes, such as your account and billing contact details and our own marketing. That processing is described in our Privacy Policy and is not governed by this DPA.

2.6 Nothing in this DPA relieves you of your own obligations under Data Protection Laws.

2.7 You must not use the Services to process special category data under Article 9 UK GDPR, criminal offence data under Article 10, or personal data relating to children, without first notifying us in accordance with Annex 1. We do not routinely monitor the content of Controller Personal Data and rely on the description in Annex 1 in determining the measures we apply. Where we become aware that such data is being processed without prior notification, we may require you to remove it, and may suspend the affected Services if you do not do so within a reasonable period. We are not responsible for any failure to apply additional safeguards to data whose nature has not been disclosed to us.

3. Our obligations as processor

3.1 We shall process Controller Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law. Where we are required by law to process otherwise, we shall inform you of that legal requirement before processing, unless the law prohibits it.

3.2 The Principal Agreement, this DPA, and any configuration, workflow, automation or support request you submit through our agreed channels, together constitute your documented instructions.

3.3 We shall immediately inform you if, in our opinion, an instruction infringes Data Protection Laws.

3.4 We shall ensure that persons authorised to process Controller Personal Data - whether our employees, contractors or the personnel of a Sub-processor - are subject to a binding duty of confidentiality, have received appropriate data protection training, and are granted access only to the extent necessary to perform their role.

3.5 We shall maintain a written record of processing carried out on your behalf in accordance with Article 30(2) UK GDPR.

3.6 We shall, taking into account the nature of the processing and the information available to us, assist you in ensuring compliance with your obligations under Articles 32 to 36 UK GDPR.

3.7 We shall notify you without undue delay if we become unable to meet our obligations under this DPA, and you may suspend the transfer of Controller Personal Data or terminate the affected Services if the matter is not resolved within a reasonable period.

4. Security

4.1 We shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR. The measures in place are described in Annex 2.

4.2 You acknowledge that a substantial part of the measures in Annex 2 are those of the Platform Provider. We shall use reasonable endeavours to ensure the Platform Provider maintains a standard of security consistent with Annex 2, and shall notify you of any material adverse change of which we become aware.

4.3 We may update Annex 2 from time to time provided the updated measures do not materially reduce the overall level of security.

4.4 You are responsible for the security of your own environment, including the management of user accounts and access rights you control, the security of devices used to access the Services, the strength of credentials, and the prompt deactivation of accounts belonging to leavers.

5. Sub-processors

5.1 You grant us general authorisation to engage Sub-processors for the purposes of delivering the Services. Those authorised at the date of this version are listed in Annex 3.

5.2 We shall give you at least 14 days' notice of the addition or replacement of a Sub-processor, by updating Annex 3 and notifying you by email to your registered account contact. You may object on reasonable data protection grounds within 14 days of that notice.

5.3 Where you object, we shall discuss a resolution with you in good faith. If none is reached within 30 days, you may terminate the affected Services on written notice without penalty, and we shall refund any fees paid in advance in respect of the period after termination.

5.4 We shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, including in respect of confidentiality, security, international transfers, and deletion of data on termination.

5.5 We remain fully liable to you for the performance of each Sub-processor's obligations.

5.6 The Platform Provider maintains its own list of sub-processors, published at gohighlevel.com/sub-processors, which may change from time to time and which you may review at any time.

6. International transfers

6.1 You acknowledge and expressly instruct that delivery of the Services requires Controller Personal Data to be transferred to and processed outside the United Kingdom, as follows:

(a) Platform hosting. The Platform Provider hosts the platform in the United States and does not currently offer a UK or EEA hosting region. Support and service personnel of the Platform Provider's affiliate in India may also access Controller Personal Data for support purposes.

(b) Support and fulfilment. We engage third-party support and fulfilment providers, identified in Annex 3, which are established in the United States and whose personnel are located in a number of countries outside the United Kingdom. Those personnel may access Controller Personal Data solely to the extent necessary to perform support and fulfilment tasks requested by you or by us on your behalf. We maintain a current register of those providers and the countries in which their personnel are located, available to you on request.

6.2 We shall not make a Restricted Transfer unless a valid Transfer Mechanism is in place for it. The transfers in clause 6.1(a) are made under the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, incorporated into our contract with the Platform Provider. The transfers in clause 6.1(b) are made under a Transfer Mechanism incorporated into our contract with each provider concerned.

6.3 We shall, on request, provide you with reasonable information to enable you to carry out a transfer risk assessment.

6.4 If a Transfer Mechanism relied on ceases to be valid, we shall work with you in good faith to implement an alternative. If no lawful alternative is available, you may terminate the affected Services on written notice without penalty.

If you have a data residency requirement. The platform is hosted in the United States and no UK or EEA hosting option is available. If your organisation requires personal data to remain within the UK or EEA, raise this with us before your account goes live.

7. Data subject rights

7.1 Taking into account the nature of the processing, we shall assist you by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III UK GDPR.

7.2 We shall notify you without undue delay, and in any event within 3 business days, if we receive a request directly from a data subject relating to Controller Personal Data. We shall not respond to that request ourselves except on your documented instruction or as required by law.

7.3 Some categories of data are exportable by you on a self-service basis; others require our assistance. The current position is set out in Annex 2, Part C.

7.4 Assistance under this clause is provided at no charge for requests of routine scope. Where a request requires materially more than 4 hours of our time, we may charge at our then-current professional services rate, having first notified you and obtained your approval.

8. Personal data breaches

8.1 We shall notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Controller Personal Data.

8.2 That notification shall, to the extent known at the time, describe:

(a) the nature of the breach, including the categories and approximate number of data subjects and records concerned;

(b) the likely consequences of the breach;

(c) the measures taken or proposed to address the breach and mitigate its effects; and

(d) the name and contact details of a point of contact at FoundationsAI.

8.3 Where the information is not available at the time of notification, we shall provide it in phases without undue further delay.

8.4 We shall not notify a supervisory authority or any data subject of a Personal Data Breach affecting Controller Personal Data without your prior written consent, unless required to do so by law. Notification to the Information Commissioner's Office under Article 33 UK GDPR is your responsibility as controller.

8.5 We shall co-operate with you and take such reasonable steps as you direct to assist in the investigation, mitigation and remediation of the breach.

9. Data protection impact assessments

9.1 We shall provide reasonable assistance with any data protection impact assessment and any prior consultation with the Information Commissioner's Office, in each case relating solely to the processing of Controller Personal Data under this DPA, and taking into account the nature of the processing and the information available to us.

10. Return and deletion of data

10.1 On termination or expiry of the Principal Agreement we shall, at your election, return or delete Controller Personal Data.

10.2 You must notify your election in writing before termination takes effect. Where you elect return, we shall provide the exportable data in the formats described in Annex 2, Part C within 30 days.

10.3 Where you elect deletion, or fail to make an election within 30 days of termination, we shall delete Controller Personal Data, and procure its deletion by our Sub-processors, within 90 days of termination, and shall certify deletion in writing on request.

10.4 We may retain Controller Personal Data to the extent required by law, or where held in routine backup media which cannot reasonably be isolated, provided that such data remains subject to this DPA and is deleted in accordance with the applicable backup cycle.

10.5 We strongly recommend you export your data before termination takes effect. Access to the platform ceases on termination.

11. Audit and information

11.1 We shall make available to you all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.

11.2 We shall allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits shall be:

(a) on at least 30 days' prior written notice, save where an audit follows a Personal Data Breach or a regulator's direction, in which case reasonable notice applies;

(b) no more than once in any 12-month period, save as set out in (a);

(c) conducted during normal business hours and in a manner that does not unreasonably disrupt our business; and

(d) subject to the auditor entering into reasonable confidentiality undertakings.

11.3 We may satisfy an audit request by providing the Platform Provider's then-current independent audit reports and certifications, including its SOC 2 Type II report, together with our own responses to a reasonable security questionnaire, where these adequately address the scope of the audit.

11.4 Each party bears its own costs of an audit, save that where an audit requires materially more than 8 hours of our time we may charge at our then-current professional services rate.

12. Liability

12.1 The limitations and exclusions of liability in the Principal Agreement apply to this DPA, save to the extent that Data Protection Laws prohibit their application.

12.2 Nothing in this DPA limits either party's liability to a data subject or to a supervisory authority, or excludes liability which cannot lawfully be excluded.

12.3 Where one party has paid compensation for damage caused by processing, it may claim back from the other the part of that compensation corresponding to the other's share of responsibility, in accordance with Article 82(5) UK GDPR.

13. Term, changes and termination

13.1 This DPA takes effect when you accept the Principal Agreement and continues for so long as we process Controller Personal Data.

13.2 We may amend this DPA where necessary to reflect a change in law, in the Services, or in our security or sub-processing arrangements. Where an amendment materially reduces your rights or our obligations, we shall give you at least 30 days' notice by email to your registered account contact before it takes effect, and you may terminate the affected Services without penalty before that date if the amendment is unacceptable to you.

13.3 Changes to Annex 2 are governed by clause 4.3 and changes to Annex 3 by clause 5.2.

13.4 Every version of this DPA carries a version number and effective date. Previous versions are available on request.

13.5 Clauses 10, 11 and 12 survive termination.

14. General

14.1 If any provision is held invalid or unenforceable, the remainder continues in full force.

14.2 A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this DPA.

14.3 This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Annex 1 - Description of the processing

Subject matter. Provision, configuration, integration and support of a customer relationship management platform, including marketing and communications functionality.

Duration. The term of the Principal Agreement, plus the retention periods in clause 10.

Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, combination, restriction, erasure and destruction, by automated means.

Purpose of the processing. Managing your customer and prospect relationships; capturing and progressing enquiries; scheduling appointments; sending transactional and marketing communications by email, SMS and WhatsApp; recording and storing communications; reporting and analytics.

Categories of data subject. Your customers and prospective customers; enquirers and website visitors who submit their details; your employees and contractors who use the Services; any other individual whose personal data you choose to store in the platform.

Types of personal data.

Identity - name, job title, business name.

Contact - email address, telephone and mobile number, postal address.

Communications - email, SMS, WhatsApp and web-chat message content; call recordings and transcripts where enabled; notes.

Transactional - enquiry and order history, quotations, invoices, payment status.

Marketing - consent and preference records, engagement and campaign data.

Technical - IP address, device and browser data, cookie and tracking identifiers.

Special category data. The Services may be used to process special category data under Article 9 UK GDPR - including data concerning health, such as allergies, medical conditions or dietary requirements - only where you have told us in advance, we have confirmed the arrangement in writing, and the security measures have been reviewed. Where such data is processed, you remain responsible for identifying both your lawful basis under Article 6 and your condition for processing under Article 9, and for carrying out a data protection impact assessment where one is required under Article 35. We will assist under clause 9.

Criminal offence data. The Services must not be used to process criminal offence data under Article 10 UK GDPR.

Children's data. Where your use of the Services involves personal data relating to children, you must tell us before that data is stored in the platform, so that we can record it in this Annex and confirm the access restrictions and retention settings applied to your account. You remain responsible for identifying your lawful basis, for obtaining parental consent where it is required, and for carrying out a data protection impact assessment where one is required under Article 35. We will assist under clause 9.

Frequency. Continuous, for the duration of the Principal Agreement.

Retention. Controller Personal Data is retained for the duration of the Principal Agreement and deleted in accordance with clause 10. Setting and applying your own retention schedule within the platform is your responsibility as controller.

If your use differs from this description. Annex 1 describes the ordinary use of the Services. If you intend to process categories of data or data subject not listed here, tell us before you do, so that we can confirm the description and review the security measures. On request we will issue a version of this Annex completed for your organisation.

Annex 2 -Technical and organisational measures

Part A - Platform measures (provided by the Platform Provider)

Certification - SOC 2 Type II (Security, Confidentiality, Availability). ISO/IEC 27001:2022 certification stated by the Platform Provider; certificate available on request.

Encryption in transit - TLS 1.2 / 1.3, 2048-bit keys or greater.

Encryption at rest - AES-256, with keys held in a hardened key management service with rotation.

Credentials - passwords stored hashed. Two-factor authentication available and recommended for all users.

Infrastructure - Google Cloud Platform and Amazon Web Services, United States. Multi-availability-zone redundancy.

Backups - daily backups with 7-day retention and point-in-time recovery, maintained for the Platform Provider's disaster recovery purposes. Alerting on backup failure.

Testing - annual third-party penetration testing, automated vulnerability scanning, and a responsible disclosure programme.

Access control - role-based access at agency and sub-account level, described in Part B.

Audit logging - time-stamped logs of create, update and delete actions by user and module, filterable and exportable to CSV. Retention 60 days.

Disclosed limitations. The Platform Provider does not publish a recovery point objective or recovery time objective. Platform backups are maintained for disaster recovery and are not restorable by you on a self-service basis. Audit log retention is 60 days; where a longer audit trail is required, we can configure a periodic export to storage you control.

Part B - Access control

Roles - two roles per sub-account: Admin (full access) and User (restricted by permission set).

Granular permissions - per-module permissions across contacts, conversations, opportunities, workflows, calendars, funnels, payments, integrations, settings and user management. A separate permission governs data export.

Need-to-know restriction - the "Only Assigned Data" setting restricts a User to the contacts, opportunities and appointments assigned to them, supporting data minimisation.

Our access - our personnel access your account only as necessary to deliver, configure, support and troubleshoot the Services. Access is limited to authorised personnel bound by confidentiality.

Joiners and leavers - you are responsible for requesting the creation, amendment and prompt removal of your own users. We shall action such requests without undue delay.

Review - we will provide a user and permission report on request, and recommend you review access at least every 6 months.

Disclosed limitation. There is no custom role builder; access is configured through the permission settings above. Audit logs record changes to records, not every occasion on which a record is viewed.

Part C - Data export and portability

Available to you on a self-service basis (Admin users):

Contacts, including custom fields and tags - CSV export from the platform.

Companies, transactions and orders - CSV export.

Issued training certificates - CSV export.

Available with our assistance:

Opportunities - CSV or API export.

Conversations (SMS, email and chat message history) - no native self-service export; extracted by us via the platform API on request.

Automation and message send history - not included in the standard contact export; extracted via API on request.

Disclosed limitation. The standard contact export includes only the most recent note, truncated to 255 characters. Conversation history has no native export function; where a subject access request requires message history, we will extract it via the platform API under clause 7. Please factor this into your own subject access request response timescales.

Part D - Our organisational measures

Registration - registered with the Information Commissioner's Office, registration no. ZA890593.

Personnel - the Services are delivered by a small team. Every person with access to Controller Personal Data, including any contractor or assistant engaged by us, is bound by written confidentiality obligations and is briefed on their data protection responsibilities before access is granted. Access is granted on a need-to-know basis and withdrawn promptly when no longer required.

Devices - full-disk encryption on all devices used for business purposes; automatic screen lock; a managed password manager; and two-factor authentication on all business systems, including the platform.

Insurance - professional indemnity, employers' liability, and public and products liability insurance are maintained. Certificates are available on request.

Breach response - personal data breaches are handled in accordance with clause 8. Daniel Sagar, Data Protection Lead, is the named individual responsible for breach assessment and notification.

Annex 3 - Authorised sub-processors

The following Sub-processors are authorised as at the Effective Date.

Part A - Our direct sub-processors

HighLevel Inc. / LeadConnector LLC
Purpose: CRM platform hosting and delivery.
Established: United States. Personnel locations: United States; India.

Extendly LLC
Purpose: white-label technical support.
Established: United States. Personnel locations: various - register available on request.

Growthable LLC
Purpose: white-label support and fulfilment.
Established: United States. Personnel locations: various - register available on request.

Note. Where an integration between the platform and a third-party system is built at your request using an automation platform operated by us, that platform becomes a Sub-processor and will be added to this Annex under clause 5.2 before the integration goes live.

Part B -The Platform Provider's sub-processors

The Platform Provider engages the following categories of sub-processor. The authoritative current list is published at gohighlevel.com/sub-processors.

Infrastructure - Google Cloud, Amazon Web Services. United States.

Communications - Twilio, Mailgun. United States.

Artificial intelligence - OpenAI, BotPress, RetellAI, Synthflow. United States.

Payments - Stripe, Chargebacks911. United States.

Analytics and data - Pendo, ChartMogul, People Data Labs, Mozart Data. United States.

Support and operations - Freshworks, Zapier, Persona Identities. United States.

Affiliates - LeadConnector LLC (United States); HighLevel India, services and support (India).

Disclosure. Your attention is drawn to the engagement of a support affiliate in India, meaning support personnel outside the United Kingdom may access Controller Personal Data, and to the presence of a data enrichment provider on the Platform Provider's list. Both are disclosed so that you can take them into account in your own risk assessment.

91D Ltd trading as FoundationsAI. Registered in England & Wales, company no. 12768586. Registered office: Unit 13E, 92 Burton Road, Sheffield, S3 8BX. ICO registration ZA890593. Data protection enquiries: [email protected]. This DPA should be read alongside our Terms & Conditions, Privacy Policy and Refund Policy.

FoundationsAI

FoundationsAI is based in Lymington, Hampshire. Serving the New Forest and wider UK.

The platform is built for UK service businesses that are serious about follow-up, bookings, and repeat work.

Copyright © 2026. 91D Ltd Trading As FoundationsAI. All Rights Reserved.