Data Processing Addendum
Last updated: 3 September 2026
This Addendum forms part of the Terms of Service between Matter Due ("Processor") and the Customer ("Controller") and reflects the parties' agreement on the processing of personal data under UK GDPR Article 28.
1. Roles
The Controller determines the purposes and means of processing the personal data it loads into the Service. The Processor processes that data only on the Controller's documented instructions, which are: to provide the Service in accordance with the Terms.
2. Subject-matter and details of processing
| Item | Detail |
|---|---|
| Subject-matter | Provision of deadline tracking and reminder delivery |
| Duration | The term of the subscription, plus the deletion period |
| Nature and purpose | Storage, display, and transmission of reminders |
| Types of personal data | Names, work contact details (email, phone) of the Controller's staff; matter references; deadline details |
| Categories of data subject | The Controller's personnel and caseworkers |
| Special category data | Not intentionally processed; the Controller must not load special category data into free-text fields |
3. Processor obligations
- Process only on documented instructions, including on transfers.
- Ensure persons authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational measures (see Annex — Security page).
- Respect the conditions in section 4 for engaging sub-processors.
- Assist the Controller with data-subject requests and with DPIAs and consultations, taking into account the nature of processing.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- At the Controller's choice, delete or return personal data at the end of the provision of services, and delete existing copies unless storage is required by law.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits.
4. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed on the sub-processors page. The Processor will give notice of intended additions or replacements and the Controller may object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this Addendum.
SMS and WhatsApp are sent through the Controller's own Twilio account; in that respect the Controller engages Twilio directly.
5. International transfers
The Processor will not transfer personal data outside the UK/EEA except with appropriate safeguards (UK IDTA, EU SCCs, or an adequacy decision).
6. Security
Technical and organisational measures are described on the Security page and are incorporated here as the Annex.
7. Liability and precedence
Liability under this Addendum is subject to the limitations in the Terms. If there is a conflict on data protection matters, this Addendum prevails.
8. Signing
A countersigned copy is available on request: privacy@matterdue.com.