This Data Processing Agreement ("DPA") forms part of the agreement entered into between the Client and Mondra pursuant to which Mondra has agreed to provide services to the Client ("Master Agreement"), and governs the processing of personal data by Mondra, pursuant to the Master Agreement.
1. Definitions and Interpretation
1.1Unless otherwise defined in this DPA, capitalised terms and expressions used in this DPA shall have the meanings set out below:
Authorised Users means those employees, agents and contractors of the Client who are authorised by the Client to access the Services, pursuant to the Master Agreement;
Client means the entity which has entered into a Master Agreement with Mondra;
Client Personal Data means any Personal Data Processed by Mondra on behalf of the Client pursuant to or in connection with the Master Agreement;
Data Protection Laws means all applicable data protection and privacy legislation in force from time to time which is applicable to a Party, including the UK GDPR; the EU GDPR; the Data Protection Act 2018; the Privacy and Electronic Communications Directive 2002/58/EC (as updated by Directive 2009/136/EC), the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended, and the Data (Use and Access) Act 2025;
DPA means this Data Processing Agreement;
EEA means the European Economic Area;
EU GDPR means EU General Data Protection Regulation ((EU) 2016/679);
Mondra means a company incorporated and registered in England and Wales with company number 12485878 whose registered office is at c/o DMH Stallard LLP, Fetter Yard, Barnards Inn, 86 Fetter Lane, London, England, EC4A 1EN;
Party means a party to this DPA, being either the Client or Mondra (and "Parties" shall be interpreted accordingly);
Services means the services that Mondra provides to the Client pursuant to the Master Agreement;
Subprocessor means any person appointed by or on behalf of Mondra to process Client Personal Data in connection with the Master Agreement;
UK means the United Kingdom of Great Britain and Northern Ireland; and
UK GDPR has the meaning given in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.
1.2The terms "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as given in the UK GDPR and the EU GDPR (as applicable), and their cognate terms shall be construed accordingly.
This DPA forms part of, and is incorporated into, the Master Agreement.
1.3In this DPA: (i) a reference to writing or written includes email; and words importing the singular include the plural and vice versa.
1.4In the case of conflict or ambiguity between any of the provisions of this DPA and the provisions of the Master Agreement, the provisions of this DPA will prevail.
2. Compliance
2.1Each Party shall, in respect of Client Personal Data, comply with the obligations imposed on it under the Data Protection Laws.
3. Roles
3.1The Parties acknowledge that their respective roles under Data Protection Laws in relation to the Processing of Personal Data shall be determined by the factual circumstances of such Processing. Without prejudice to the generality of the foregoing, the Parties agree that Mondra shall act as independent Controller in respect of the following categories of Personal Data:
- (a) Personal Data of Authorised Users collected by Mondra through the administration, security and management of its platform and websites (including, without limitation, technical and operational data, usernames and passwords); and
- (b) Personal Data of the Client and its personnel to the extent Processed by Mondra for the purposes of establishing, managing and administering the contractual relationship between the Parties.
3.2Where Mondra Processes Personal Data in its capacity as an independent Controller pursuant to clause 3.1 above, it shall Process such Personal Data in accordance with its privacy policy (as updated from time to time and made available to the Client upon request) and in compliance with all applicable Data Protection Laws.
3.3To the extent that Client Personal Data is Processed by Mondra on the Client's behalf and in accordance with the Client's instructions, through the provision of the Services, the Parties agree that the Client shall be the Controller of such Client Personal Data, and Mondra shall be the Processor and in such case, Mondra shall act as a Processor in accordance with the terms of this DPA.
4. Scope
4.1In the course of providing the Services under the Master Agreement, Mondra may gain access to and process Client Personal Data. Unless the Master Agreement expressly states otherwise, where Mondra processes Client Personal Data pursuant to the Master Agreement, the terms of this DPA shall automatically apply.
4.2The remainder of this DPA sets out the terms of Processing and the obligations of the Parties in respect of Personal Data Processed by Mondra in its capacity as a Processor on behalf of the Client.
5. Client Obligations
5.1The Client shall, in respect of Personal Data Processed by Mondra on its behalf:
- (a) ensure that it has a lawful basis for the Processing of such Personal Data and that all necessary notices have been given to, and (where required) all necessary consents have been obtained from, the relevant Data Subjects;
- (b) ensure that the Personal Data provided to Mondra is accurate, complete and up to date to the extent necessary for the purposes of Processing;
- (c) ensure that its instructions to Mondra in respect of such Personal Data comply with all applicable Data Protection Laws; and
- (d) be solely responsible for the accuracy, quality, and legality of the Personal Data and the means by which it is obtained.
6. Processor Obligations
6.1The table below describes the subject matter, duration, nature and purpose of the Processing and the Personal Data categories and Data Subject types in respect of which Mondra may Process the Client Personal Data for the purposes of providing the Services to the Client pursuant to the Master Agreement.
| Subject matter, nature and purpose of Processing | Mondra shall Process the Client Personal Data for the purpose of providing the Services under the Master Agreement. |
| Duration of Processing | The duration of the Master Agreement, or so long as Mondra retains any of the Personal Data related to the Master Agreement in its possession or control. |
| Categories of Personal Data | The Data Subject's name, job title, telephone number(s) and email address, and any other types of Personal Data that may be described in the Master Agreement or otherwise agreed in writing between the parties from time to time. |
| Categories of Data Subjects | Authorised Users. |
6.2Mondra shall comply with all applicable Data Protection Laws in the Processing of Client Personal Data.
6.3Mondra shall not Process Client Personal Data other than on the Client's documented instructions. The Client instructs Mondra to process Client Personal Data as required in order to provide the Services pursuant to the Master Agreement. Mondra will not process the Client Personal Data for any other purpose or in a way that does not comply with this DPA or the Data Protection Laws. Mondra must promptly notify the Client if, in its opinion, the Client's instructions do not comply with Data Protection Laws.
6.4Mondra will maintain the confidentiality of the Client Personal Data and will not disclose the Client Personal Data to third parties unless the Client or this DPA specifically authorises the disclosure, or as required by domestic law, court or regulator.
6.5Mondra will reasonably assist the Client, at the Client's expense, with meeting the Client's compliance obligations under the Data Protection Laws, taking into account the nature of Mondra's processing and the information available to Mondra, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with any relevant regulator under the Data Protection Laws.
6.6Mondra shall:
- (a) promptly notify the Client if it receives a request from a Data Subject under the Data Protection Laws in respect of Client Personal Data; and
- (b) ensure that it does not respond to that request except on the documented instructions of the Client or as required by applicable laws to which Mondra is subject, in which case Mondra shall, to the extent permitted by applicable laws, inform the Client of that legal requirement before responding to the request.
6.7Mondra shall provide reasonable assistance to the Client, at the Client's expense, with any data protection impact assessments, and consultations with Supervisory Authorities or other competent data privacy authorities, which the Client reasonably considers to be required by article 35 or 36 of the EU GDPR or the UK GDPR, as the context requires or equivalent provisions of any other Data Protection Laws, in each case solely in relation to Processing of Client Personal Data by Mondra, and taking into account the nature of the Processing and information available.
6.8Mondra will ensure that all of its employees and other personnel:
- (a) are informed of the confidential nature of the Client Personal Data and are bound by confidentiality obligations and use restrictions in respect of the Client Personal Data; and
- (b) have undertaken appropriate training on the Data Protection Laws relating to handling Personal Data and how it applies to their particular duties.
6.9Mondra shall, in relation to the Client Personal Data, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) of the EU GDPR or the UK GDPR, as the context requires. In assessing the appropriate level of security, Mondra shall take into account, in particular, the risks that are presented by the proposed Processing.
6.10Mondra shall notify the Client without undue delay upon Mondra becoming aware of a Personal Data Breach affecting Client Personal Data, providing the Client with sufficient information to allow the Client to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws. Mondra shall co-operate with the Client and take reasonable commercial steps as are directed by the Client to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
6.11Subject to clause 6.12, on termination of the Master Agreement for any reason, or the expiry of its term, Mondra shall securely delete or destroy or, if directed in writing by the Client, return and not retain, all or any of the Personal Data related to this DPA or the Master Agreement in its possession or control.
6.12If any law, regulation, or government or regulatory body requires Mondra to retain any documents or materials or Client Personal Data that Mondra would otherwise be required to return or destroy, it will notify the Client in writing of that retention requirement, giving details of the documents, materials or Client Personal Data that it must retain, the legal basis for retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.
6.13Mondra will keep detailed, accurate and up-to-date written records regarding any processing of the Client Personal Data. Mondra shall provide the Client with copies of such documentation as the Client may reasonably request in order to audit Mondra's compliance with this DPA.
6.14The Client acknowledges that Mondra engages various Subprocessors to Process Personal Data in order to provide the Services. The Client provides its general authorisation for Mondra to appoint additional Subprocessors from time to time in relation to the Client Personal Data, provided that:
- (a) Mondra notifies the Client in writing of the identity and role of any proposed new Subprocessor prior to its appointment;
- (b) the Client shall have a period of 30 days from receipt of such notice within which to raise a reasonable objection to the proposed appointment;
- (c) where no objection is received within the 30-day period referred to in clause 6.14(b), the proposed Subprocessor shall be deemed approved by the Client;
- (d) the proposed Subprocessor shall not commence any Processing of Personal Data until the expiry of the 30-day period referred to in clause 6.14(b) without objection, or until any objection raised has been resolved in accordance with clause 6.14(e); and
- (e) if the Client raises a reasonable objection to the appointment of a proposed Subprocessor, the Parties shall discuss and seek to resolve the objection in good faith. Pending resolution, Mondra shall ensure that the proposed Subprocessor does not Process any Personal Data on behalf of the Client. If the Parties are unable to resolve the objection within a reasonable period, the Client shall be entitled to terminate the Master Agreement on written notice to Mondra without liability.
6.15Mondra shall enter into a written contract with each Subprocessor on terms that are no less protective of Personal Data than those set out in this DPA, and which, in particular, impose appropriate technical and organisational measures to safeguard Client Personal Data.
6.16Subject to clause 8.2, Mondra shall remain fully liable to the Client for the acts and omissions of each Subprocessor as if such acts or omissions were those of Mondra itself under this DPA.
7. Transfers of Client Personal Data
7.1Mondra (and any Subprocessor) may only transfer Client Personal Data from the UK or the EEA if:
- (a) the transfer of the Client Personal Data is to a territory which is subject to adequacy regulations under the Data Protection Laws that the territory provides adequate protection for the privacy rights of individuals; or
- (b) Mondra participates in a valid cross-border transfer mechanism under the Data Protection Laws, so that Mondra (and, where appropriate, the Client) can ensure that appropriate safeguards are in place to ensure an adequate level of protection with respect to the privacy rights of individuals as required by Article 46 of the UK GDPR and EU GDPR (as relevant); or
- (c) the transfer otherwise complies with Data Protection Laws.
8. Liability
8.1Nothing in this DPA shall exclude or limit either Party's liability for:
- (a) death or personal injury caused by its negligence;
- (b) fraud or fraudulent misrepresentation; or
- (c) any other liability that cannot be excluded or limited by applicable law.
8.2Subject to clause 8.1, Mondra's total aggregate liability under or in connection with this DPA, whether arising in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be subject to the limitations and exclusions of liability set out in the Master Agreement. In the event that the Master Agreement does not contain limitations or exclusions of liability, Mondra's total aggregate liability under or in connection with this DPA shall not exceed the total fees paid and payable by the Client to Mondra under the Master Agreement in the twelve (12) months immediately preceding the date on which the first event giving rise to the claim occurred.
8.3Subject to clause 8.1, Mondra shall have no liability under or in connection with this DPA for any:
- (a) loss of profits, revenue, business, or anticipated savings;
- (b) loss of goodwill or reputation; or
- (c) indirect or consequential loss or damage,
howsoever arising, whether in contract, tort (including negligence), breach of statutory duty, or otherwise.
8.4The Client shall indemnify Mondra and keep Mondra indemnified against all claims, demands, actions, liabilities, costs, and expenses (including reasonable legal fees) arising from or in connection with any processing carried out by Mondra in accordance with the Client's Processing instructions, save to the extent that such claims, demands, actions, liabilities, costs, or expenses arise directly from Mondra's breach of this DPA or applicable Data Protection Laws.
8.5Each Party shall be solely responsible for any regulatory fines and penalties imposed by a Supervisory Authority directly upon it in respect of that Party's own breach of Data Protection Laws, and no Party shall be required to indemnify the other in respect of any such fine or penalty.
8.6The Client shall not be entitled to recover from Mondra any loss or damage to the extent that the Client has already been compensated for such loss or damage by any other means, including (without limitation) under any applicable insurance policy. For the avoidance of doubt, the Client shall not benefit from double recovery in respect of the same loss.
8.7Any claim by either Party under or in connection with this DPA must be notified to the other Party in writing within a reasonable time of the claimant Party becoming aware of the circumstances giving rise to such claim. Failure to provide such notice within a reasonable time shall not extinguish the claim but may be taken into account in assessing any loss suffered.
9. Term and Termination
9.1This DPA will remain in full force and effect so long as the Master Agreement remains in effect, or Mondra retains any of the Personal Data related to the Master Agreement in its possession or control.
9.2Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Master Agreement in order to protect the Personal Data will remain in full force and effect.
10. Notices
10.1Any notice given to a Party under or in connection with this DPA shall be in writing and shall be given in accordance with the terms of the Master Agreement.
11. Governing Law and Jurisdiction
11.1This DPA is governed by the laws of England and Wales, and any dispute arising in connection with this DPA, which the Parties are not able to resolve amicably, will be submitted to the exclusive jurisdiction of the English Courts.