Data Processing Agreement
Version 1.0 — Last updated: July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between ALLME GROUP LIMITED, a company registered in England and Wales (company number 17155873) (“allme.life”, “we”, “us”), and the customer using the allme.life service (“Customer”, “you”). It sets out how we process personal data on your behalf when providing the allme.life service (the “Service”).
1. Definitions
- “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation 2016/679), and any other applicable data protection legislation.
- “Customer Data” means personal data you (or your family members) submit to the Service: emails, documents, calendar events, notes, tasks, contacts, messages, and content derived from connected accounts.
- “Sub-processor” means a third party engaged by us to process Customer Data.
- “Controller”, “processor”, “processing”, “personal data”, and “personal data breach” have the meanings given in the Data Protection Laws.
2. Roles of the Parties
For Customer Data, you are the controller and we are the processor: we process Customer Data only on your documented instructions, as expressed through your use of the Service and this DPA. For limited operational data — account registration details, billing information, service telemetry, and website analytics — we act as an independent controller, as described in our Privacy Policy.
3. Nature and Purpose of Processing
We process Customer Data solely to deliver the Service: secure storage, synchronisation of connected accounts, search, organisation, and — where you enable them — AI-assisted features such as summarisation, categorisation, and drafting. Much of the Customer Data in the Service is protected by end-to-end encryption, meaning we process it only in encrypted form and cannot read it. Where AI features require access to content, processing occurs inside short, time-limited decryption windows that you have authorised, followed by deletion of the decrypted copy; each such access is recorded in an audit receipt available to you.
Duration: for the term of your use of the Service, plus the deletion period in Section 11. Data subjects: you, your family members, and individuals appearing in your content (e.g. email correspondents). Categories of data: the content you store or connect, which may include contact details, correspondence, documents, financial and health-related documents, and other categories you choose to store.
4. Processor Obligations
We will:
- process Customer Data only on your documented instructions, unless required otherwise by law (in which case we will inform you unless legally prohibited);
- ensure persons authorised to process Customer Data are bound by confidentiality obligations;
- implement and maintain the technical and organisational measures described in Section 7;
- respect the conditions in Sections 5 for engaging Sub-processors;
- assist you in responding to data-subject requests and in meeting your obligations under Data Protection Laws (Section 8);
- delete or return Customer Data at the end of the engagement (Section 11); and
- make available information necessary to demonstrate compliance with this DPA (Section 10).
5. Sub-processors
You provide general authorisation for the Sub-processors listed in our Trust Center, which we keep current. We will give you at least 30 days' notice before engaging a new Sub-processor (by updating the Trust Center and, for material changes, by email). You may object on reasonable data-protection grounds; if we cannot address your objection, you may terminate the affected part of the Service. We impose data-protection obligations on every Sub-processor that are no less protective than this DPA, and we remain fully liable for their performance.
Current Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (SES) | Transactional email delivery | EU (Ireland) |
| Hetzner Online GmbH | Server and GPU hosting | Germany |
| Contabo GmbH | Server hosting | Germany |
6. Data Location and International Transfers
Customer Data is stored and processed in the United Kingdom and the European Union. Where any transfer of personal data outside the UK/EEA occurs (for example, email-delivery metadata, or data you choose to sync from US-based connected accounts such as Google or Microsoft), it is protected by appropriate safeguards — the providers' Standard Contractual Clauses and, for UK transfers, the ICO's International Data Transfer Agreement or UK Addendum, as applicable.
7. Security Measures
We implement technical and organisational measures appropriate to the risk, including:
- End-to-end encryption of protected Customer Data with user-held keys (zero-knowledge architecture) — we cannot decrypt this data;
- Encryption in transit (TLS 1.2+) and at rest using modern authenticated encryption (ChaCha20-Poly1305) with per-user key isolation;
- Secure Remote Password (SRP-6a) authentication — passwords are never transmitted to or stored by our servers;
- Time-limited, receipted decryption windows for user-authorised AI processing, followed by deletion of decrypted copies;
- Least-privilege, individually credentialled staff access; key-based server access only (password authentication disabled), with automated brute-force protection;
- Two-layer firewalling and network segregation via encrypted private mesh — internal data services are not exposed to the internet;
- Code review, automated CI checks, and secret scanning on all changes;
- Audit receipts recording AI access to protected Customer Data.
A fuller description of our controls, and an honest statement of our certification status (we do not currently hold SOC 2 or ISO 27001 certificates — our programme is aligned to these frameworks with certification on our roadmap), is published at our Trust Center.
8. Assistance to Controller
Taking into account the nature of processing, we will assist you with appropriate technical and organisational measures in fulfilling data-subject requests (access, rectification, erasure, portability, restriction, objection), and in your obligations regarding security, breach notification, and data protection impact assessments. In practice, the Service gives you direct self-service tools for most data-subject rights, including export and deletion.
9. Personal Data Breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, providing sufficient information for you to meet your own notification obligations, and will cooperate with you in investigating and mitigating the breach.
10. Audits
On written request (no more than once per year, unless following a breach or required by a supervisory authority), we will make available the information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable security questionnaires and our published control documentation. As we do not yet hold third-party audit certifications, we do not provide SOC 2 or ISO 27001 reports; when such reports exist, providing them will satisfy audit requests. Where the above is insufficient, we will allow audits by you or your appointed auditor, at your cost, on reasonable notice, subject to confidentiality and without access to other customers' data.
11. Deletion or Return of Data
Upon termination of the Service, or on your request, we will delete or return Customer Data within 30 days, unless retention is required by law. Data in encrypted backups is overwritten in the ordinary backup rotation cycle and remains protected by encryption until destroyed. Because protected Customer Data is end-to-end encrypted with keys you hold, deletion of your keys independently renders that data unreadable.
12. Analytics and Operational Data
We collect limited, self-hosted operational telemetry (service health, error rates, anonymised usage counts) as an independent controller, retained for up to 14 months in aggregate form. This data is never used to train third-party AI models, never sold, and never used for behavioural advertising. Our website analytics are cookie-free and anonymised, as described in our Privacy Policy.
13. De-identified Data
We may create and use aggregated or de-identified data (which is no longer personal data) to improve the Service, provided we maintain it in de-identified form and do not attempt re-identification.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this DPA limits either party's liability for matters that cannot be limited under applicable law.
15. Survival and Amendments
This DPA survives for as long as we process Customer Data. We may update this DPA to reflect changes in law or the Service; material changes will be notified via email or a prominent notice, and the current version is always published at this address.
16. Governing Law
This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, except where Data Protection Laws require otherwise.
17. Contact
Data protection contact: privacy@allme.life
Security: security@allme.life
Company: ALLME GROUP LIMITED, registered in England and Wales, company number 17155873.
You may lodge a complaint with the Information Commissioner's Office at ico.org.uk.