Last updated: 26 July 2026
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Master Service Agreement between the Client ("Controller") and TH Technology Ltd, trading as "ES Studios" ("Processor," "we," or "us"). It applies where we process personal data on the Client's behalf in the course of providing the Services. In the event of a conflict with the Master Service Agreement on data-protection matters, this DPA prevails.
The Client is the controller of the personal data of its own customers and contacts ("Client Personal Data"). We act as processor, processing Client Personal Data only to provide the Services. Where we determine the purposes and means of processing our own business data (for example, our website analytics or our billing of the Client), we act as a controller under our Privacy Policy, not under this DPA.
"Data Protection Laws" means all applicable laws relating to privacy and the processing of personal data, including the UK GDPR and Data Protection Act 2018, the EU GDPR, the California Consumer Privacy Act as amended by the CPRA, and the Telephone Consumer Protection Act (TCPA) and CAN-SPAM Act. "Personal Data," "processing," "controller," "processor," "data subject," and "personal data breach" have the meanings given in the Data Protection Laws. Under US state laws, the Controller is a "business" and the Processor is a "service provider," and the equivalent terms apply.
We process Client Personal Data only on the Client's documented instructions, including those set out in this DPA and the Master Service Agreement, and as needed to provide the Services, unless required to process by law (in which case we will inform the Client unless the law prohibits it). We will inform the Client if, in our opinion, an instruction infringes Data Protection Laws. We will not "sell" or "share" Client Personal Data, and will not retain, use, or disclose it for any purpose other than providing the Services or as permitted by the Data Protection Laws.
We ensure that personnel authorized to process Client Personal Data are bound by confidentiality obligations and process the data only as instructed.
Taking into account the state of the art and the risks involved, we implement appropriate technical and organizational measures to protect Client Personal Data, including access controls, encryption in transit, use of reputable hosted platforms, and restricting access to those who need it. A summary of measures is at Annex B.
The Client provides general authorization for us to engage sub-processors to deliver the Services. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current sub-processors include:
We will give the Client reasonable notice of any intended addition or replacement of a sub-processor, giving the Client the opportunity to object on reasonable data-protection grounds. If the Client reasonably objects and we cannot accommodate the objection, the Client may terminate the affected Services.
Taking into account the nature of the processing, we will assist the Client by appropriate technical and organizational measures, insofar as possible, to: (a) respond to data-subject requests (access, correction, deletion, portability, objection, and opt-out); (b) ensure security of processing; (c) notify and communicate personal data breaches; and (d) carry out data-protection impact assessments and prior consultations. If we receive a request directly from a data subject, we will not respond ourselves except on the Client's instructions, and will promptly forward it to the Client.
We will notify the Client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Personal Data, and will provide information reasonably available to help the Client meet its own notification obligations.
On termination of the Services, at the Client's choice and written request made within 30 days of the effective date, we will return Client Personal Data (for example, a CSV export of CRM contacts and pipeline) or delete it, and delete existing copies, unless retention is required by law. Data used solely for a one-time review-reactivation campaign is deleted on cancellation unless an export is requested. We may retain anonymized, aggregated data that no longer identifies any individual.
We maintain records of processing carried out on the Client's behalf and will make available information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, and no more than once per year unless required by a supervisory authority, we will allow and contribute to audits conducted by the Client or an independent auditor bound by confidentiality, in a manner that does not compromise other clients' data.
We are established in the United Kingdom and process data for clients in the United States, so Client Personal Data may be transferred internationally. Where a transfer requires a safeguard under the Data Protection Laws, the parties agree that the appropriate transfer mechanism applies, including the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and the UK Extension to the EU-US Data Privacy Framework where applicable, which are incorporated by reference.
Each party's liability under this DPA is subject to the limitations and exclusions in the Master Service Agreement. This DPA is governed by the same law as the Master Service Agreement (the State of California, USA), except where the Data Protection Laws require a specific supervisory authority or forum, which the parties will respect.
Data-protection contact: [email protected] · TH Technology Ltd t/a ES Studios, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.