DATA PROCESSING TERMS
Processor terms apply only where the processing role actually requires them.
Controlled-proving revision: 11 September 2026
1. Scope
These terms supplement the B2B Service Terms only for personal data that a customer controls and that Levqor processes on the customer's documented instructions as processor. They do not recast Levqor as processor for its own prospect research, marketing, fraud/security, billing, legal or business-administration purposes, where Levqor may be an independent controller.
2. Instructions
Levqor processes in-scope processor data only on documented lawful instructions necessary to perform the agreed service, including instructions in the Order Form and configured customer actions. Levqor will inform the customer where an instruction appears unlawful unless prohibited from doing so and may refuse an instruction that would breach law or the security/anti-abuse controls.
3. Customer obligations
The customer is responsible for its lawful basis, notices, data minimisation, accuracy and instructions for controller data supplied to Levqor, and for ensuring it has the rights required to provide that data and require the instructed processing.
4. Confidentiality and security
Levqor limits access to in-scope data to authorised personnel/providers who need it for the service and applies proportionate technical and organisational controls. The current evidence-bounded security posture is described at Trust & Security; this DPA does not create unsupported certification or numeric SLA promises.
5. Subprocessors
Levqor may use subprocessors necessary for the instructed service, subject to appropriate data-protection obligations. The applicable provider set depends on the actual feature/engagement and is reverified before external release. Levqor remains responsible for its processor obligations and will provide material subprocessor information through the current provider/legal route where required.
6. International transfers
Where processor data is transferred outside the UK, Levqor applies an appropriate UK transfer mechanism and supplementary safeguards where required, based on the actual provider/destination. Historic references to EU SCCs or another mechanism do not override the mechanism legally required for the live transfer.
7. Assistance
Taking account of the nature of processing and information available to it, Levqor will provide reasonable assistance with data-subject requests, security/breach obligations, DPIAs and regulator consultation where those duties relate to in-scope processor data. The customer remains responsible for its controller decisions and statutory deadlines.
8. Personal-data breach
Levqor will notify the customer without undue delay after becoming aware of a personal-data breach affecting in-scope processor data and provide available information reasonably required for the customer's assessment, subject to secure investigation and evolving facts.
9. Return/deletion
At the end of the relevant processor service, Levqor will delete or return in-scope processor data as required by the agreed instruction, except to the extent law requires retention or the data has become part of a separate lawful controller record (for example minimal billing, fraud/security, legal-defence or suppression evidence). Any retained data remains protected and purpose-limited.
10. Audit information
Levqor will make reasonably necessary information available to demonstrate compliance with these processor obligations and permit proportionate audit/inspection arrangements where legally required, subject to confidentiality, security, other customers' rights and reasonable scope/frequency controls.
11. Order Form particulars
Where these terms apply, the Order Form or data-processing schedule should identify the subject matter, duration, nature/purpose, categories of personal data, data subjects and any specific instructions. First Three prospect research performed for Levqor's own defined B2B purposes is not silently converted into processor activity merely by using the service.
12. Release status
These are role-dependent data-processing terms for the bounded controlled-proving implementation. They are not represented as externally solicitor-reviewed. The Owner has accepted proceeding in the bounded proving stage without paid external solicitor review; external professional review may be reconsidered before materially broader rollout or a material change in role allocation, data model or risk profile. Any engagement-specific processor relationship still requires the relevant Order Form or schedule particulars. See the Privacy Policy and Business Contact Privacy Notice.