This DPA forms part of the agreement where ROWSH LTD, trading as Rowsh, processes Customer Personal Data for a business customer. ROWSH LTD is registered in England and Wales under company number 17352462, with registered office at 350 Abbey Hey Lane, Abbey Hey, Manchester, England, M18 8RP. Any customer-specific security, retention, regulated-data, or transfer schedule must be agreed in writing before the relevant processing.
1. Definitions and scope
"Customer Personal Data" means personal data contained in Customer Content that Rowsh processes on the customer's behalf. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 as it amends that framework, and other data-protection law applicable to the processing. Controller, processor, personal data, processing, personal-data breach, and data subject have the meanings given by Data Protection Law.
The customer is controller and Rowsh is processor for Customer Personal Data, except where Rowsh independently determines a purpose described in the Privacy Notice. This DPA applies only to processing needed to provide, secure, support, and improve the contracted Service.
2. Documented instructions
Rowsh will process Customer Personal Data only on documented customer instructions contained in the agreement, configured product use, authorised support requests, and lawful written directions, including instructions relating to transfers. Rowsh will inform the customer if an instruction appears to infringe Data Protection Law. If law requires processing beyond the instructions, Rowsh will notify the customer before processing unless that law prohibits notice.
3. Customer rights and obligations
The customer determines the lawfulness, purposes, means, data categories, data subjects, retention, user permissions, and instructions for its use of Rowsh. The customer must provide required notices, identify lawful bases and any special-category conditions, respond to data subjects, and avoid instructing Rowsh to process data unlawfully. The customer has the rights to issue lawful instructions, receive assistance and compliance information, authorise subprocessors, request return or deletion, and exercise the audit rights below.
4. Processing details
- Subject matter: operation of the modules, administration, integrations, security, support, and related services selected by the customer.
- Duration: the agreement term plus the limited period required for return, deletion, legal duties, dispute preservation, and verified backup rotation.
- Nature and purpose: collection, storage, organisation, retrieval, transmission, display, alteration, export, restriction, deletion, and other processing needed to provide the configured Service.
- Data subjects: workspace users, guests, customer contacts, candidates, form submitters, meeting participants, help-desk requesters, and other people represented in Customer Content.
- Data types: identifiers, account and contact data, employment and candidate data, messages, files, operational records, billing and CRM records, usage events, audit data, and other data the customer chooses to submit.
- Sensitive data: not required for ordinary use and permitted only when the customer has established a lawful, contractually approved basis and necessary safeguards.
5. Confidentiality and security
Rowsh will ensure that people authorised to process Customer Personal Data are bound by confidentiality and access it only as necessary. Rowsh will maintain technical and organisational measures appropriate to the risk, taking account of the state of the art, implementation cost, processing context, and likely impact on people. The Security page describes the safeguards supporting those measures without representing that Rowsh holds a certification or independent audit that is not expressly identified there.
6. Subprocessors
The customer gives general written authorisation for Rowsh to use the subprocessors needed for the contracted configuration. Rowsh will maintain the Subprocessor List, give reasonable advance notice of an intended material addition or replacement, and allow the customer to object on reasonable data-protection grounds before the change takes effect. Where an immediate replacement is reasonably necessary for security, availability, or legal compliance, Rowsh may make the change first and give notice without undue delay. Rowsh will impose written data-protection terms that provide materially equivalent protection and remains responsible for each subprocessor's performance of those obligations.
7. Data-subject and compliance assistance
Taking account of the nature of processing and information available, Rowsh will provide reasonable assistance with data-subject requests, security obligations, personal-data breach notifications, data-protection impact assessments, and regulator consultations. If Rowsh receives a request concerning Customer Personal Data, it will redirect the requester to the customer where lawful and will not independently answer except on the customer's instruction or where law requires.
8. Personal-data breaches
Rowsh will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. Rowsh will provide available information reasonably required for the customer's assessment and notification, take reasonable containment and remediation steps, and provide material updates. Rowsh's notice is not an admission of fault or liability.
9. Return and deletion
On termination or a verified instruction, Rowsh will make supported export paths available and, at the customer's choice, delete or return Customer Personal Data, then delete remaining copies unless applicable law requires storage. Legal preservation, security records, disputes, and data awaiting deletion through backup rotation remain subject to purpose and access limitation and are deleted in accordance with Rowsh's applicable retention schedule. A signed order form may specify a customer-specific return or deletion period.
10. International transfers
Rowsh will not make a restricted transfer of Customer Personal Data without a lawful transfer mechanism. Where no UK adequacy regulation applies, the parties will incorporate the UK International Data Transfer Agreement or UK Addendum to approved standard clauses, as appropriate, and complete the required data-protection test. Customer authorises access from the locations identified in the Subprocessor List or applicable deployment schedule. Operational access from Pakistan by people within ROWSH LTD remains subject to Rowsh's UK GDPR obligations; transfer terms are required where the recipient is a separate organisation.
11. Compliance information and audits
Rowsh will make available information reasonably necessary to demonstrate compliance with Article 28 and allow proportionate audits or inspections by the customer or its mandated independent auditor. The parties will first use current documentation and independent reports, if available. Any further audit must be reasonably scoped, scheduled, confidential, avoid access to other customers' data, and not compromise security. The customer bears its audit costs unless the audit identifies a material breach by Rowsh.
12. Records and regulators
Rowsh will maintain records required of a processor, cooperate with the UK Information Commissioner's Office and other competent supervisory authorities as required, and inform the customer of a legally binding disclosure request where permitted. Nothing in the agreement relieves Rowsh of obligations imposed directly on processors by Data Protection Law.
13. Liability, term, and precedence
This DPA begins with the agreement and continues while Rowsh processes Customer Personal Data. Liability under this DPA is subject to the agreement except to the extent Data Protection Law prohibits that allocation. This DPA prevails over conflicting general Terms only for its subject matter. A signed enterprise agreement, order form, transfer schedule, or data-processing schedule prevails where it expressly says so.