Second Marking · Data Processing Agreement
Second MarkingPeer Skills Ltd
Data Processing Agreement
UK GDPR / EU GDPR · Article 28
Version 1.0 · [effective date]
Ref: PA-DPA-1.0

Data Processing Agreement

This Data Processing Agreement (“DPA”) governs the Processing of Personal Data by Peer Skills Ltd in the course of providing the Second Marking independent assessment service. It forms part of, and is incorporated into, the Services Agreement between the parties.

The Processor
Peer Skills Ltd
A company registered in England & Wales, No. 14970813
Registered office: [registered office address]
Contact: greg@peerlab.ai (“Peer”, “we”, “us”)
The Controller
[Client legal name]
Company No. [number]
Registered office: [address]
Contact: [data protection contact] (“you”, the “Client”)

Each a “party” and together the “parties”. This DPA takes effect on the date the Services Agreement is signed, or the date stated above if earlier.

1Definitions and interpretation

  1. Data Protection Law means all laws applicable to the Processing of Personal Data under this DPA, including the UK GDPR and the Data Protection Act 2018, and — where the Client or the relevant data subjects are in the EEA — Regulation (EU) 2016/679 (EU GDPR), in each case as amended or replaced.
  2. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data and Supervisory Authority have the meanings given in Data Protection Law.
  3. Assurance Data means the Personal Data described in Annex I that we Process on your behalf to deliver the Services — principally the recorded or transcribed conversations you submit and the assessment records produced from them.
  4. Services means the Second Marking independent human assessment service, including blind human marking, human-vs-AI agreement analysis, and the reliability reporting described in the Services Agreement.
  5. Sub-processor means any third party engaged by us to Process Assurance Data.
  6. Standard Contractual Clauses / SCCs means the clauses adopted by the European Commission (Decision 2021/914) and, for UK transfers, the UK Addendum / International Data Transfer Agreement (IDTA) issued by the Information Commissioner.
  7. In the event of conflict, the order of precedence is: (a) the SCCs; (b) this DPA; (c) the Services Agreement.

2Roles and scope of processing

  1. For the Assurance Data, you are the Controller (or a processor acting on behalf of your own client) and we are your Processor. Where you are yourself a processor, you warrant that you have the authority and instructions of the underlying controller to engage us as a sub-processor on these terms.
  2. The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I. We Process Assurance Data only to provide the Services and for no other purpose.
  3. We will Process Assurance Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law — in which case we will (unless the law prohibits it) inform you before Processing. This DPA and the Services Agreement are your complete and final documented instructions; any additional instruction must be agreed in writing.
  4. We will immediately inform you if, in our opinion, an instruction infringes Data Protection Law, without obligation to act on an instruction we reasonably consider unlawful.
  5. We will never use Assurance Data to train, fine-tune, evaluate or improve any machine-learning model, to benchmark or profile any other client, to build any cross-client dataset or library, or for any purpose of our own.

3Confidentiality

  1. We will keep Assurance Data confidential and ensure that every person authorised to Process it — including every assessor on the panel — is bound by a written obligation of confidentiality and has received appropriate data-protection guidance.
  2. Access is granted on a strict need-to-know, least-privilege basis and withdrawn promptly when no longer required. Assessors work through an anonymised interface and cannot export raw material.

4Security of processing

  1. Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risk to Data Subjects, we will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex II (Article 32).
  2. In particular, and as a defining feature of the Services, any automated sanitisation or anonymisation of Assurance Data is performed on models hosted within our own infrastructure. Assurance Data is not transmitted to any third-party artificial-intelligence service for Processing, and no third-party AI provider retains, or is permitted to train on, Assurance Data.
  3. Each Client’s Assurance Data is logically isolated from that of every other Client, with separate storage and separate export. Data is encrypted in transit and at rest.
  4. We may update the measures in Annex II from time to time provided the level of protection is not materially reduced.

5Sub-processors

  1. You grant a general written authorisation for us to engage Sub-processors to Process Assurance Data. Our current Sub-processors are listed in Annex III.
  2. We will impose on each Sub-processor, by written contract, data-protection obligations materially equivalent to those in this DPA, and we remain fully liable to you for any Sub-processor’s acts and omissions as if they were our own.
  3. We will give you at least thirty (30) days’ prior notice of any intended addition or replacement of a Sub-processor. You may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, you may suspend or terminate the affected Services without penalty.

6Assistance with data-subject rights

  1. Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data-Subject rights (access, rectification, erasure, restriction, portability and objection).
  2. If we receive such a request directly, we will not respond to it ourselves (save to acknowledge and redirect) but will notify you without undue delay and pass it on, since the key re-identifying a code to a named individual is held by you and not by us.

7Personal Data Breach

  1. We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Assurance Data.
  2. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a point of contact. Where the information cannot all be provided at once, it may be provided in phases without further undue delay.
  3. We will assist you in meeting your own obligations to notify the Supervisory Authority and affected Data Subjects (Articles 33–34), and will not make any public statement identifying you in connection with a breach without your prior written consent, except where required by law.

8Data protection impact assessments

  1. Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with any data-protection impact assessment and any prior consultation with a Supervisory Authority that you are required to carry out under Articles 35–36.

9International transfers

  1. We will not transfer Assurance Data to a country outside the UK or EEA without an appropriate transfer mechanism in place — an adequacy decision, or the SCCs / UK IDTA together with any supplementary measures required following a transfer risk assessment.
  2. Where the SCCs apply, they are incorporated into this DPA by reference and completed by the information in Annexes I–III; you are the “data exporter” and we are the “data importer”.
  3. Data residency is scoped per engagement. Where you specify that Assurance Data must be stored and Processed only within a stated region (for example UK-only or EEA-only), that requirement, once confirmed by us in writing, is binding and recorded in Annex I.

10Return and deletion

  1. On expiry or termination of the Services, and at any time on your written request, we will — at your choice — return Assurance Data to you and/or securely delete it, together with existing copies, unless retention of specific data is required by law.
  2. Deletion will be completed within thirty (30) days of your request or of termination, and we will provide a written certificate of deletion on request. Retention periods during the engagement are stated in Annex I and may be fixed by you.
  3. Any Assurance Data retained by law will remain subject to the confidentiality and security obligations of this DPA for as long as it is held.

11Audit and demonstration of compliance

  1. We will make available to you all information reasonably necessary to demonstrate compliance with Article 28, including by completing your security and data-protection questionnaires and sharing our controls documentation and, when available, third-party certifications.
  2. We will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice (normally at least thirty (30) days), no more than once in any twelve-month period unless a Personal Data Breach or Supervisory-Authority requirement makes a further audit necessary, during business hours, and subject to confidentiality and to not compromising the security or confidentiality of other clients’ data.
  3. Certification status. As at the version date of this DPA, Peer does not hold SOC 2 or ISO/IEC 27001 certification. Our controls are aligned to the ISO/IEC 27001 framework and formal certification is on our roadmap. This clause will be updated to reflect certifications as and when they are obtained; nothing in this DPA should be read as asserting a certification we do not hold.

12Controller obligations and warranties

  1. You warrant that: (a) you have a valid lawful basis for the Processing and, where required, have obtained all necessary consents and provided all necessary notices to Data Subjects; (b) your instructions are lawful; and (c) you are entitled to disclose the Assurance Data to us for the purpose of the Services.
  2. You are responsible for the accuracy of the Assurance Data you submit and for holding, and keeping secure, the key that maps any participant code back to an identified individual.

13Liability, term and governing law

  1. Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement, which apply to this DPA as if set out here.
  2. This DPA takes effect on the date stated above and continues for as long as we Process Assurance Data. Clauses that by their nature should survive termination (including confidentiality, deletion, and liability) survive it.
  3. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of its courts, save where Data Protection Law requires otherwise for the protection of Data Subjects.
  4. If any provision is held invalid, the remainder continues in force; the parties will replace the invalid provision with a valid one achieving the same purpose as nearly as possible.
This DPA is a standard template offered by Peer Skills Ltd. Specific engagement details are completed in the Annexes and the accompanying Services Agreement. The parties may agree amendments in writing; where a client requires its own DPA paper, we are glad to review and sign from that instead.
Signed for the Processor · Peer Skills Ltd
Signature
Name & title
Date
Signed for the Controller · the Client
Signature
Name & title
Date
Annex I

Details of the processing

Subject-matterIndependent human assessment (quality assurance) of recorded or transcribed sales conversations and of the AI scores produced from them.
DurationThe term of the Services Agreement, plus any retention period agreed below, after which data is returned and/or deleted per clause 10.
Nature & purposeCollection, storage, organisation, anonymisation/sanitisation, human review and marking, agreement analysis, reporting, and deletion — solely to deliver the Services.
Types of Personal DataRecordings/transcripts of conversations; assessment scores and assessor commentary; participant codes. Names, contact details or other identifiers only to the extent they incidentally occur in a conversation and are not removed by sanitisation. [note any Special Category Data expected — otherwise “none anticipated”]
Categories of Data SubjectsThe individuals being assessed (your personnel or your clients’ personnel); any third parties whose voice or details incidentally appear in a submitted conversation.
Special Category Data[None anticipated / specify]. Sanitisation is applied where sensitive content is a possibility (see FAQ).
FrequencyContinuous / batch, for the duration of the engagement.
Retention[e.g. deleted 30 days after each quarterly report / on request]
Data residency[No restriction / UK-only / EEA-only — as agreed] (clause 9.3).
Annex II

Technical and organisational security measures

The measures we implement and maintain under clause 4 (Article 32). This Annex describes controls in place at the version date and is kept current; it is not a claim of any certification we do not hold (clause 11.3).

Encryption & data handling

Access control

Monitoring & resilience

Organisational

Annex III

Authorised sub-processors

Engaged under clause 5. The current list is maintained by us and provided on request; we give at least 30 days’ notice of changes. Because sanitisation runs on self-hosted models, no third-party artificial-intelligence provider is a Sub-processor of Assurance Data.

Sub-processorPurposeLocation / safeguards
[Cloud hosting provider]Encrypted hosting and storage of the platform and Assurance Data[Region — UK/EEA as configured]; encryption at rest; DPA + SCCs/IDTA where applicable
Additional Sub-processors, if any, are recorded here and notified in advance under clause 5.3. Self-hosted AI models used for sanitisation are operated by Peer and are not third-party Sub-processors.
End of Data Processing Agreement — Second Marking · Peer Skills Ltd (Company No. 14970813). Read alongside the Data & privacy FAQ and the Services Agreement.