Legal
Data Processing Agreement and Standard Contractual Clauses
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Provonic (“Makli”, the “Processor”) and the customer (the “Controller”). It applies whenever Makli processes personal data on the customer’s behalf, and incorporates the transfer mechanisms in section 9. A countersigned copy is available on request.
Roles and scope
The customer is the controller of the personal data held in the helpdesk, billing and control-panel systems it connects to Makli, and of any other personal data it instructs Makli to process. Makli is the processor and will process that data only to provide the service and as documented in the Terms, this DPA and the customer’s configuration of the service. The customer’s configuration — which systems are connected and which actions are enabled — constitutes its documented instructions.
Details of the processing
| Subject matter | Automated handling of customer-support tickets and chats and the account actions needed to resolve them. |
|---|---|
| Duration | The term of the customer’s subscription, plus the deletion period in section 11. |
| Nature and purpose | Reading tickets and connected account data; generating replies; performing actions the controller has enabled (for example changing PHP settings, updating DNS, issuing refunds within policy); recording an audit log; preparing drafts for the controller’s staff. |
| Categories of data subjects | The controller’s customers and their end users; the controller’s staff who use Makli. |
| Categories of personal data | Names, email addresses and other contact details; account, service, domain and billing information; the content of tickets, chats and attachments; technical data such as IP addresses and server settings. Special-category data is not sought and is processed only where it appears in ticket content. |
Processor obligations
Makli will:
- process personal data only on the controller’s documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Makli will inform the controller before processing where the law allows;
- tell the controller immediately if, in Makli’s opinion, an instruction infringes data-protection law;
- ensure that people authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in section 7;
- respect the conditions for engaging sub-processors in section 6;
- assist the controller, taking account of the nature of the processing, in responding to data-subject requests and in meeting its obligations on security, breach notification, impact assessments and prior consultation;
- delete or return all personal data at the end of the service as set out in section 11;
- make available the information necessary to demonstrate compliance, and allow for and contribute to audits as set out in section 8.
Controller obligations
The controller is responsible for the lawfulness of the personal data it makes available to Makli, for providing any notices and obtaining any consents required from its own customers and end users, for the instructions it gives — including which actions it enables — and for reviewing Makli’s drafts and audit logs.
Confidentiality of personnel
Makli restricts access to personal data to personnel who need it to provide the service, requires them to keep it confidential, and logs their access.
Sub-processors
The controller gives Makli general authorisation to engage sub-processors for hosting, AI model inference, email delivery and payment processing. Makli maintains a list of current sub-processors and will supply it on request to sam@makli.com. Makli will give the controller at least 30 days’ notice before adding or replacing a sub-processor; the controller may object on reasonable data-protection grounds within that period, and if the parties cannot resolve the objection the controller may terminate the affected service without penalty. Makli imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance.
Security measures
Makli implements and maintains at least the following measures, and will not reduce them during the term:
- Tenant isolation — each customer runs in a fully separate data environment.
- Encryption — personal data is encrypted in transit and at rest.
- Access control — role-based access, least privilege, multi-factor authentication for staff, and access logging.
- Action logging — every action Makli takes and every reply it sends is recorded on the ticket and available to the controller.
- Permission scoping — Makli can only perform actions the controller has explicitly enabled; everything else is returned as a draft.
- No model training — customer personal data is not used to train AI models, and model providers are contractually prohibited from doing so.
- Anonymisation option — the controller may require personal data to be anonymised before it is sent to an AI model.
- Self-hosted option — the Makli agent can be deployed inside the controller’s own infrastructure.
- Independent assurance — regular third-party security audits; findings are remediated on a risk basis.
- Business continuity — backups and tested recovery procedures.
Audits and information
On written request, and no more than once a year unless required by a supervisory authority or following a personal data breach, Makli will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of its most recent third-party audit reports. Where that information is insufficient, the controller or an independent auditor bound by confidentiality may audit Makli’s relevant processing on reasonable notice, during business hours and without unreasonable disruption.
International transfers
Makli is established in the United Kingdom. Where Makli or a sub-processor transfers personal data to a country without an adequacy decision, the parties rely on the following, which are incorporated into this DPA by reference:
- For transfers subject to the UK GDPR: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as issued by the Information Commissioner under s.119A of the Data Protection Act 2018.
- For transfers subject to the EU GDPR: the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the optional docking clause, and with the details of the processing in section 2 and the security measures in section 7 forming the relevant annexes.
Makli will carry out and document transfer risk assessments where required and apply supplementary measures where necessary.
Personal data breaches
Makli will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data, and will provide the information reasonably available to help the controller meet its own notification obligations, including the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed.
Deletion and return
On termination or expiry of the service, Makli will, at the controller’s choice, return the controller’s personal data in a commonly used format or delete it, and will delete existing copies within 90 days unless UK or EU law requires longer retention. Connected third-party systems remain the controller’s own and are unaffected.
Data-subject requests
If Makli receives a request from a data subject relating to personal data it processes for the controller, it will not respond on the merits but will promptly forward the request to the controller and assist as described in section 3.
Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails on matters of data protection. If the Standard Contractual Clauses or UK transfer instruments conflict with this DPA, those instruments prevail.
Governing law
This DPA is governed by the laws of England and Wales, except that the Standard Contractual Clauses and UK transfer instruments are governed as provided within them.
Obtaining a signed copy
Customers who need a countersigned DPA, or executed transfer clauses with their details completed, can request them from sam@makli.com. Provonic, 172 Stamford Street, Manchester, United Kingdom.