For business customers

Data Processing Addendum

Interim notice

Our legal registration details are being finalised alongside our public launch. If you have questions about how we handle your data in the meantime, please contact us. The substantive terms below reflect our current practice; specific registration details will be updated shortly.

Data Processing Addendum

Last updated: 05 August 2026


Note for AuthorsLab: This DPA is designed for enterprise or publisher customers who sign a separate commercial agreement with AuthorsLab and require a formal data processing addendum under UK GDPR / EU GDPR. It is not presented to ordinary subscribers. For standard subscribers, the Privacy Policy governs data processing.


DATA PROCESSING ADDENDUM

This Data Processing Addendum ("DPA") is entered into between:

[Legal entity — confirming with co-founder], a company registered in England and Wales (company number [Pending]), with registered address at [Pending] ("AuthorsLab" / "Processor")

and

[Legal entity — confirming with co-founder], a company registered in England and Wales (company number [Pending]), with registered address at [Pending] ("Customer" / "Controller")

(each a "Party", together the "Parties").

This DPA supplements and forms part of the agreement between the Parties for access to the AuthorsLab platform ("Main Agreement"). In the event of conflict between this DPA and the Main Agreement, this DPA takes precedence in respect of data protection matters.


PART ONE - PRELIMINARY

1. Definitions

In this DPA, the following terms have the meanings given below. Capitalised terms not defined here have the meanings given in the Main Agreement.

1.1 "Applicable Data Protection Law" means:

  • (a) UK GDPR and the Data Protection Act 2018, as applicable in the United Kingdom; and/or
  • (b) EU GDPR (Regulation (EU) 2016/679), as applicable in any member state of the European Economic Area;

in each case as amended or replaced from time to time.

1.2 "Controller" has the meaning given in Applicable Data Protection Law - in the context of this DPA, the Customer.

1.3 "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.

1.4 "EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

1.5 "Personal Data" has the meaning given in Applicable Data Protection Law.

1.6 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

1.7 "Process" / "Processing" has the meaning given in Applicable Data Protection Law.

1.8 "Processor" has the meaning given in Applicable Data Protection Law - in the context of this DPA, AuthorsLab.

1.9 "Restricted Transfer" means a transfer of Personal Data from the UK to a third country, or from the EEA to a third country, in circumstances where the transfer is subject to restrictions under Applicable Data Protection Law.

1.10 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of Personal Data to third countries annexed to European Commission Implementing Decision (EU) 2021/914.

1.11 "Sub-processor" means any processor engaged by AuthorsLab to carry out Processing activities on behalf of the Customer.

1.12 "UK GDPR" means the retained EU law version of Regulation (EU) 2016/679, as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018.

1.13 "UK IDTA" means the International Data Transfer Agreement issued by the Information Commissioner's Office under section 119A of the Data Protection Act 2018.


2. Relationship of the parties and subject matter

2.1 The Parties acknowledge that, in relation to the Processing of Personal Data described in Schedule 1 (Processing Details), the Customer is the Controller and AuthorsLab is the Processor.

2.2 AuthorsLab shall Process Personal Data only as necessary to perform its obligations under the Main Agreement and only in accordance with the Customer's documented instructions, except where required to do so by applicable law (in which case AuthorsLab shall, where permitted by law, notify the Customer before such Processing).

2.3 If AuthorsLab reasonably believes that an instruction given by the Customer would cause it to breach Applicable Data Protection Law, it shall notify the Customer promptly.


PART TWO - PROCESSOR OBLIGATIONS

3. Confidentiality and personnel

3.1 AuthorsLab shall ensure that persons authorised to Process Personal Data on its behalf are subject to appropriate confidentiality obligations.

3.2 AuthorsLab shall ensure that access to Personal Data is limited to those personnel who need it to perform AuthorsLab's obligations under the Main Agreement.


4. Security

4.1 AuthorsLab shall implement and maintain appropriate technical and organisational measures to protect Personal Data against a Personal Data Breach, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks of varying likelihood and severity.

4.2 Such measures shall include, as a minimum:

  • (a) encryption of Personal Data in transit using TLS/HTTPS;
  • (b) encryption of Personal Data at rest;
  • (c) appropriate access controls and authentication mechanisms;
  • (d) regular testing and evaluation of the effectiveness of security measures.

4.3 AuthorsLab shall provide the Customer, on request, with sufficient information to demonstrate compliance with this clause 4, including completing reasonable security questionnaires.


5. Sub-processing

5.1 The Customer provides general authorisation to AuthorsLab to engage Sub-processors. AuthorsLab's current Sub-processors are listed at authorslab.ai/legal/subprocessors ("Sub-processor List").

5.2 AuthorsLab shall give the Customer at least 30 days' prior written notice before adding or replacing a Sub-processor, by updating the Sub-processor List and notifying the Customer at the email address on their account.

5.3 The Customer may object to a new Sub-processor within 14 days of receiving such notice, providing written reasons for the objection. If the Parties are unable to resolve the objection within a further 14 days, the Customer may terminate the Main Agreement on written notice, and AuthorsLab shall refund any pre-paid fees for the unexpired portion of the subscription term.

5.4 AuthorsLab shall impose data protection obligations on each Sub-processor equivalent to those set out in this DPA.

5.5 AuthorsLab remains fully liable to the Customer for the acts and omissions of its Sub-processors.


6. Data subject rights

6.1 AuthorsLab shall, taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures to fulfil the Customer's obligations to respond to Data Subject rights requests under Applicable Data Protection Law.

6.2 If AuthorsLab receives a request directly from a Data Subject in connection with Customer Personal Data, AuthorsLab shall promptly forward it to the Customer without responding to it directly (unless the Customer has authorised AuthorsLab to respond).


7. Data protection impact assessments and prior consultation

To the extent required by Applicable Data Protection Law, AuthorsLab shall provide the Customer with reasonable assistance with data protection impact assessments and with prior consultation with supervisory authorities, where such assessments or consultations relate to Personal Data Processed by AuthorsLab on behalf of the Customer.


8. Personal Data Breaches

8.1 AuthorsLab shall notify the Customer without undue delay - and in any event within 72 hours of becoming aware - of a Personal Data Breach affecting Customer Personal Data.

8.2 The notification shall, to the extent available at the time, include:

  • (a) a description of the nature of the breach, including the categories and approximate number of Data Subjects and Personal Data records concerned;
  • (b) the name and contact details of AuthorsLab's data protection contact;
  • (c) a description of the likely consequences of the breach;
  • (d) a description of the measures taken or proposed to address the breach.

8.3 AuthorsLab shall cooperate with the Customer and take reasonable steps to mitigate the effects of and remediate the breach.


9. Deletion and return of data

9.1 On termination of the Main Agreement, or on the Customer's written request, AuthorsLab shall, at the Customer's election:

  • (a) securely delete all Customer Personal Data in its possession; or
  • (b) return all Customer Personal Data to the Customer in a portable format

within 30 days, and certify in writing that it has done so.

9.2 AuthorsLab may retain Customer Personal Data to the extent required by applicable law, provided that it ensures the confidentiality of that data and does not use it for any other purpose.


10. Audits and inspections

10.1 AuthorsLab shall make available to the Customer such information as is reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or a mandated auditor.

10.2 The Customer shall give AuthorsLab at least 30 days' prior written notice of an audit, and audits shall be conducted during normal business hours, no more than once per calendar year, and in a manner that minimises disruption to AuthorsLab's operations.

10.3 The Customer shall bear the cost of any audit unless the audit reveals a material breach of this DPA by AuthorsLab, in which case AuthorsLab shall bear its reasonable costs.


PART THREE - INTERNATIONAL TRANSFERS

11. Restricted transfers

11.1 AuthorsLab shall not carry out a Restricted Transfer of Customer Personal Data without ensuring that an appropriate transfer mechanism is in place.

11.2 For transfers from the UK to third countries:

The Parties agree that the UK IDTA (or such other transfer mechanism as the ICO may approve) shall apply to any Restricted Transfer of UK Personal Data. The UK IDTA is hereby incorporated into and forms part of this DPA, with the relevant details set out in Schedule 2.

11.3 For transfers from the EEA to third countries:

The Parties agree that the SCCs (Module 2: Controller-to-Processor) shall apply to any Restricted Transfer of EEA Personal Data, with the relevant details set out in Schedule 2.

11.4 In respect of Restricted Transfers to AuthorsLab's Sub-processors, AuthorsLab shall ensure that appropriate transfer mechanisms are in place, as described in clause 5.4.


PART FOUR - CONTROLLER OBLIGATIONS

12. Customer obligations

12.1 The Customer warrants that:

  • (a) it has a lawful basis for the Processing activities described in Schedule 1 and has complied with all applicable notice and transparency requirements;
  • (b) it is authorised to provide AuthorsLab with any Personal Data it provides under the Main Agreement;
  • (c) its instructions to AuthorsLab will comply with Applicable Data Protection Law.

12.2 The Customer is responsible for ensuring that the Personal Data it provides to AuthorsLab is accurate, adequate, relevant, and limited to what is necessary for the purposes described in Schedule 1.


PART FIVE - GENERAL

13. Liability

13.1 Each Party's liability under this DPA is subject to any limitations set out in the Main Agreement, except to the extent that applicable law prohibits any limitation on liability in respect of data protection obligations.

13.2 If a Data Subject brings a claim against either Party in respect of Processing governed by this DPA, the Parties shall cooperate in good faith to allocate liability between them in accordance with their respective responsibilities.


14. Term

This DPA shall commence on the date the Main Agreement becomes effective and shall continue until the Main Agreement terminates or expires, at which point this DPA shall terminate automatically (subject to clause 9 on post-termination data obligations).


15. Governing law

This DPA is governed by the law of England and Wales. The Parties submit to the exclusive jurisdiction of the courts of England and Wales, without prejudice to any mandatory data protection supervision rights of EU supervisory authorities.


16. Entire agreement

This DPA, together with the Main Agreement and its schedules, constitutes the entire agreement of the Parties with respect to the Processing of Personal Data.


SCHEDULE 1 - PROCESSING DETAILS

Nature and purpose of Processing

AuthorsLab processes Customer Personal Data for the purpose of providing the Services described in the Main Agreement, including storing manuscript content, facilitating AI editorial workflows, and providing access to publishing and marketing surfaces where the Customer has been granted access by an author user.

Duration of Processing

For the term of the Main Agreement, and as described in clause 9 of this DPA.

Types of Personal Data

CategoryDetails
Account dataNames, email addresses of users within the Customer's organisation or associated with the Customer's account
Manuscript contentText, metadata, and version history of manuscripts associated with the Customer's account
AI conversation historyTranscripts of interactions between users and AI personas
AI-generated outputsEditorial notes, cover images, marketing materials

Categories of Data Subjects

Authors, editors, and other individuals whose Personal Data is processed through the platform in connection with the Customer's use of the Services.

Special categories of data

The Parties do not anticipate that special category Personal Data (as defined in Article 9 of UK/EU GDPR) will routinely be processed under this DPA. If the Customer wishes to process special category data, it must notify AuthorsLab in writing and obtain AuthorsLab's prior agreement.


SCHEDULE 2 - INTERNATIONAL TRANSFER DETAILS

UK IDTA (clause 11.2)

FieldDetails
ExporterCustomer (as detailed in the Main Agreement)
ImporterAuthorsLab Ltd (and, as applicable, Sub-processors listed on the Sub-processor List)
Transfer mechanismUK International Data Transfer Agreement (UK IDTA)
Table 1 (Parties)As set out in the body of this DPA
Table 2 (Transfer details)Processing as described in Schedule 1
Table 3 (Technical and organisational measures)As described in clause 4 of this DPA
Table 4 (Ending the IDTA)Either Party may end the UK IDTA if the ICO issues a revised Addendum that the other Party does not accept

EU SCCs (clause 11.3)

FieldDetails
ModuleModule 2 (Controller-to-Processor)
Clause 7 (docking clause)Not applicable
Clause 9 (sub-processors)Option 2 (general written authorisation) with 30-day notice period
Clause 11 (redress)Optional language not included
Clause 17 (governing law of SCCs)Laws of Ireland
Clause 18 (jurisdiction)Courts of Ireland
Annex I.A (list of parties)As set out in the body of this DPA
Annex I.B (description of transfer)As described in Schedule 1 of this DPA
Annex I.C (supervisory authority)ICO (for UK transfers); Data Protection Commission of Ireland (for EU transfers)
Annex II (technical and organisational measures)As described in clause 4 of this DPA

EXECUTION

This DPA is agreed and entered into by the duly authorised representatives of each Party.

For and on behalf of [Legal entity — confirming with co-founder]

Signature: ___________________________

Name: ___________________________

Title: ___________________________

Date: ___________________________

For and on behalf of [Legal entity — confirming with co-founder]

Signature: ___________________________

Name: ___________________________

Title: ___________________________

Date: ___________________________