Data Processing Agreement

1. Parties and roles

This Data Processing Agreement ("DPA") is between Mostly Tiny Ltd, a company registered in England and Wales (company number 17282011, registered office Studio M, Hackney Depot, 5 Sheep Lane, London E8 4QS, United Kingdom), as processor, and the business customer that uses a Mostly Tiny product, as controller. It applies to the personal data we process on the customer's behalf to provide MostlyQR, MostlyPDF, MostlyRender, MostlyPrivacy and the Mostly Tiny account and organisation features. Terms such as "personal data", "processing" and "sub-processor" have their meaning in the UK GDPR and the EU GDPR.

Last updated: 2026-10-01.

2. When this DPA applies

This DPA forms part of our Terms of Service for every business customer, with no separate signature. It applies only where we act as the customer's processor. Where we decide why and how data is processed — for example your own account and billing details — we are a controller, and our Privacy Policy applies.

3. Subject-matter, duration, nature and purpose

We process personal data only to provide the product the customer uses, as described in the product annexes below, for as long as the customer uses it and for the deletion period in "Deletion or return". We do not use it for our own purposes, sell it or combine it with other customers' data.

4. Instructions

We process the personal data only on the customer's documented instructions, given through its settings and use of the product, this DPA and our Terms — including for transfers outside the UK and EEA — unless the law requires otherwise, in which case we tell the customer first unless the law forbids it. We tell the customer if, in our opinion, an instruction breaks data-protection law.

5. Confidentiality

Everyone we authorise to process the personal data is bound by confidentiality, and access is limited to the people who need it to run, support and secure the service.

6. Security

We take appropriate technical and organisational measures to protect the personal data, including: encryption in transit (TLS) and at rest (Google Cloud); least-privilege access for staff and authenticated, per-account access for customers; hashing or truncating identifiers where the product does not need them in full; data hosted in Google Cloud europe-west2 (London); and logging and monitoring of access to production systems.

7. Sub-processors

The customer gives general written authorisation for us to use the sub-processors on our sub-processor list, published at /legal/subprocessors on each product's website. We impose on each sub-processor data-protection obligations equivalent to those in this DPA, and we remain responsible to the customer for them.

We will tell customers of any intended addition or replacement of a sub-processor at least 30 days before it takes effect, by email and on the sub-processor list. The customer may object on reasonable data-protection grounds within that period; if we cannot reasonably accommodate the objection, the customer may end the affected subscription and we will refund any prepaid fees for the unused period.

8. International transfers

We host the personal data in the UK (Google Cloud europe-west2, London). Where a sub-processor processes it outside the UK or EEA, we rely on an adequacy decision (including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified) or on the EU Standard Contractual Clauses with the UK International Data Transfer Addendum.

9. Helping with requests and compliance

Taking into account the nature of the processing, we help the customer respond to data subjects exercising their rights — most of this the customer can do itself in the product — and with its security, breach notification, data-protection impact assessment and prior consultation obligations, using the information available to us.

10. Personal data breaches

We notify the customer without undue delay after becoming aware of a personal data breach affecting its data, with the information we have that it needs to meet its own obligations, and we update it as we learn more.

11. Deletion or return

When the customer deletes data or closes its account, or the service ends, we delete the personal data (the customer can export it first), unless the law requires us to keep it. Copies in backups are deleted as those backups expire.

12. Information and audits

We make available the information reasonably needed to show that we meet Article 28, and allow for and contribute to audits, including inspections, by the customer or an auditor it mandates. We will answer written questions and share documentation first; an on-site audit needs reasonable notice, happens during business hours, at most once a year unless a regulator requires or a breach justifies more, and is at the customer's cost.

13. Liability and precedence

Each party's liability under this DPA is subject to the limits in the business-customer section of our Terms of Service, except where the law does not allow it to be limited. If this DPA and our Terms conflict about personal data processed on the customer's behalf, this DPA wins. It is governed by the laws of England and Wales.

14. EU representative

We are established in the UK. Our representative in the European Union under Article 27 of the EU GDPR is being appointed; we will name it here and in our privacy policies. Until then, contact us at hello@mostlytiny.io.

15. Annex A — MostlyQR

Data subjects: people who scan the customer's QR codes or open its short links; people who submit its hosted forms.

Personal data: on paid plans, for each scan — the time, the country and region, the type of browser, operating system and device, the browser's preferred language, the referring page, how the scan was routed, an approximate location derived from the IP address and rounded to about 1 km (two decimal places), and a salted one-way hash of the IP address used to count unique scans; the full IP address, the full browser string and the city are not stored. A location the person chooses to share on a hosted page is also rounded to about 1 km. Form submissions: whatever fields the customer puts on its form.

Purpose: redirecting scans, scan analytics, hosted pages and forms, and — only if the customer turns them on — forwarding scan events to the customer's own webhooks or its Meta Conversions API account, which are recipients the customer chooses, not our sub-processors.

Retention: for the life of the customer's account, within its plan's analytics limits, or until the customer deletes the code or form.

16. Annex B — MostlyPrivacy

Data subjects: visitors to the customer's websites who use its consent banner; people who submit a data-subject request through its request form.

Personal data: consent records (the choice made, the time, the page address without its query string, the page language, the approximate country and a keyed hash of the IP address); request-form submissions (the request, a salted hash of the requester's email address used for verification, and the details the requester gives).

Purpose: recording and proving consent; handling data-subject requests for the customer.

Retention: consent records for 13 months on a rolling basis; requests until the customer deletes them or its account.

17. Annex C — MostlyPDF

Data subjects: anyone whose personal data is in a file the customer processes.

Personal data: the contents of the files the customer uploads and the outputs we produce; for the AI assistant, the text of the document and the question.

Purpose: running the tool or assistant the customer chooses. Retention: files and outputs are deleted after processing; AI text is not kept by us after the answer is returned (Anthropic deletes it within 30 days).

18. Annex D — MostlyRender

Data subjects: anyone whose personal data is in the customer's templates, the data it sends to fill them, or the pages it asks us to capture.

Personal data: that template data, the rendered images and PDFs, and screenshots.

Purpose: rendering and delivering outputs to the customer. Retention: rendered outputs are deleted 30 days after they are made on the free plan and 90 days on paid plans; templates until the customer deletes them.

19. Annex E — Mostly Tiny organisations

Data subjects: the members of the customer's organisation.

Personal data: names, work email addresses, roles and group memberships received from the customer's identity provider through SAML single sign-on or SCIM provisioning, and members' sign-in and usage records within the organisation.

Purpose: signing members in, provisioning and removing them, and showing the organisation's usage. Retention: until the member is removed or deprovisioned, or the organisation is deleted.