Menu

Data processing agreement

Updated 26 September 2026, 2 minute read

This agreement applies when your firm uses Denby to hold personal data about your clients. Your firm is the controller and decides what data goes in; Denby is the processor and handles it only to run the service, keeps it secure, uses listed sub-processors, helps with requests and deletes it when you ask.

The processor is Telezoid, Calicut, Kerala, India, trading as Denby.

This data processing agreement (“DPA”) forms part of Denby’s terms of service and applies to personal data your firm (“the controller”) puts into Denby (“the processor”). It takes effect when you accept the terms. If you need a signed copy, email legal@denby.app.

Scope

  • Subject matter: hosting and processing client data so your firm can run client portals.
  • Duration: as long as your firm’s account exists, plus the 30-day deletion period.
  • Categories of data subjects: your staff, and your clients’ contacts.
  • Types of personal data: names, email addresses, phone numbers, files and their contents, messages, approvals with the approver’s typed name, IP address and browser, invoices and form responses.
  • Special category data: Denby is not designed for health or other special category data. If you upload it, you are responsible for having a lawful basis and appropriate safeguards.

Our obligations

  1. Instructions. We process personal data only to provide the service, as configured by you, and on your documented instructions, unless the law requires otherwise; if so, we will tell you unless the law forbids it.
  2. Confidentiality. Everyone at Denby with access to customer data is bound by confidentiality, and access is limited to what their work requires.
  3. Security. We apply the technical and organisational measures described on our security page: encryption in transit and at rest, separation of each firm’s data in code and in the database, least-privilege access, audit logging and malware checks on uploads.
  4. Sub-processors. You authorise the sub-processors on our sub-processor list. We will email firm owners at least 30 days before adding or replacing one; you may object on reasonable grounds and, if we can’t address the objection, cancel with a pro-rata refund of prepaid fees. We impose data protection terms on each sub-processor at least as protective as these.
  5. Assistance. We help you respond to requests from data subjects, mostly through the product: you can find, export, correct and delete a client’s data yourself. We also help with data protection impact assessments where reasonable.
  6. Breaches. We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
  7. Deletion and return. You can export all of your data at any time. When you delete your firm, we erase its personal data within 30 days, except where the law requires us to keep it.
  8. Audits. We make available the information needed to show we comply with this DPA. Where that isn’t enough, you may audit us once a year with 30 days’ notice, at your cost, in a way that protects other customers’ data.

International transfers

Denby stores customer data in the United States (see the sub-processor list for each provider’s location). Where personal data moves outside the country it is protected in, and the law requires a transfer mechanism, the standard contractual clauses (or the equivalent for your country) apply between you and Denby, and between Denby and its sub-processors.

Your obligations

You confirm you have a lawful basis for the personal data you put into Denby, that you have given your clients the information the law requires, and that your instructions to us comply with the law.