Effective date: 26/01/2026
Version: 1.0
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Silkworm Systems Ltd (“Processor”) and the user of the Silkworm platform (“Controller”).
This DPA applies where the Processor processes personal data on behalf of the Controller in the course of providing the Service.
Terms used but not defined in this DPA have the meanings given in:
“Personal Data”, “Processing”, “Controller”, and “Processor” have the meanings given in UK GDPR.
The Processor processes Personal Data solely on the documented instructions of the Controller, as necessary to provide the Service.
Processing activities may include:
Processing is limited to:
May include:
May include:
Processing may include:
The Controller confirms it has a lawful basis to process and disclose such data.
The Processor shall:
5.1 Process Personal Data only on documented instructions from the Controller, unless required by law.
5.2 Ensure that persons authorised to process Personal Data:
5.3 Implement appropriate technical and organisational measures to protect Personal Data against:
5.4 Not use Personal Data to train general-purpose or cross-customer models.
5.5 Not access Personal Data except:
6.1 The Controller authorises the Processor to engage sub-processors as necessary to provide the Service, including:
6.2 The Processor shall:
6.3 A current list of sub-processors shall be made available upon request.
7.1 Personal Data is hosted and processed on servers located in the European Economic Area.
7.2 Where international transfers are required:
The Processor implements measures including, as appropriate:
Further details may be provided upon reasonable request.
9.1 The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach.
9.2 The notification shall include, where available:
The Processor shall:
Assistance will be provided insofar as reasonably possible given the nature of the Service.
11.1 Upon termination of the Service, the Processor shall:
11.2 Backup data will be deleted in accordance with normal retention cycles.
12.1 The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.
12.2 On-site audits are limited to:
Liability under this DPA is subject to the limitations set out in the Terms of Service.
In the event of conflict:
This DPA is governed by the laws of England and Wales.