Skip to content

Rosebud Solutions

Home · Data Processing Agreement

Data Processing Agreement.

Last update: July 22, 2026

This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between Rosebud Global Ltd (company number 16623472, trading as “Rosebud Solutions”, “we,” “us,” or “our”) and the customer that subscribes to the Service (“you,” the “Customer”). By subscribing, you agree to this DPA in respect of the personal data we process on your behalf.

This DPA reflects the requirements of Article 28 of the UK GDPR and applies where we process Contact Data as your processor. It does not govern data for which we are the controller, which is covered by our Privacy Policy.

1. Definitions

  • “Contact Data” means personal data about your leads, enquirers, prospects, and customers that the Service processes on your behalf.
  • “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Personal Data Breach” have the meanings given in the UK GDPR.
  • “UK GDPR” means the retained EU General Data Protection Regulation as it forms part of UK law, together with the Data Protection Act 2018.
  • “Subprocessor” means any third party engaged by us to process Contact Data.

2. Roles of the Parties

For Contact Data, you are the Controller and we are your Processor. You are responsible for the lawfulness of the Contact Data and for having a valid lawful basis and any necessary consents. We process Contact Data only on your documented instructions, including as set out in this DPA, the Terms, and your configuration of the Service, unless required to do otherwise by law (in which case we will inform you unless legally prohibited).

3. Details of the Processing

Subject matter and duration. Provision of the Rosebud Solutions Service for the duration of your subscription and any agreed export period thereafter.

Nature and purpose. As Processor, and only to provide the Service on your instructions, we:

  • capture enquiries across your active channels — web form, email, SMS, WhatsApp and Instagram — into a single record;
  • score each record against your own qualification rules and route it (continue, escalate to your staff, or apply your not-qualified disposition);
  • book appointments into your calendar and send confirmations, reminders and reschedule messages;
  • run re-engagement sequences to contacts that have gone cold or are due for recall;
  • synchronise the record into your CRM, which remains your system of record; and
  • for attribution clients only, produce a consented first-party outcome signal.

Categories of data subject. Your leads, enquirers, prospects and customers.

Categories of personal data.Contact identifiers, enquiry content and channel, qualification fields and status, appointment and engagement events, and — where you provide it — an expected or actual value. We do not enrich Contact Data with third-party or sourced data as part of the Service. No special category data is required by the Service; you should not submit special category data unless separately agreed.

4. Our Obligations

  • process Contact Data only on your documented instructions;
  • ensure persons authorised to process Contact Data are bound by confidentiality;
  • implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR;
  • respect the conditions in this DPA for engaging Subprocessors;
  • assist you, taking into account the nature of the processing, in responding to Data Subject requests and in meeting your obligations regarding security, breach notification, data protection impact assessments, and prior consultation; and
  • at your choice, delete or return Contact Data at the end of the provision of the Service, as set out in section 9.

5. Subprocessors

You give general authorisation for us to engage Subprocessors to provide the Service, across these categories: hosting and database infrastructure; your CRM and calendar; messaging delivery (email, SMS, WhatsApp and Instagram); AI model providers; payment processing; security and bot detection; and product and website analytics. A named Subprocessor register — provider, purpose, data categories and processing region — is maintained and available to you on request.

We will impose data protection terms on each Subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give you [notice period — to be confirmed] notice of any intended addition or replacement of a Subprocessor, during which you may reasonably object.

6. Data Subject Requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. If we receive such a request directly, we will refer the Data Subject to you and will not respond except on your instructions.

7. Personal Data Breaches

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Contact Data, and will provide information reasonably available to us to help you meet your notification obligations.

8. International Transfers

Where processing of Contact Data involves a transfer outside the United Kingdom, we will ensure an appropriate transfer mechanism is in place (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), together with any supplementary measures required. [Transfer mechanisms and regions to be confirmed alongside the Subprocessor register.]

9. Return and Deletion

On termination or expiry of the Service, we will make Contact Data available to you for export for a period of [export window — to be confirmed], after which we will delete or anonymise Contact Data held within the Service, save where retention is required by law. Data already written into your own CRM is unaffected and remains under your control. Retention periods stated here must match those in the Terms and Privacy Policy.

10. Audits

We will make available to you information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality, and frequency limits to be set out in the final DPA.

11. Relationship to the Terms

This DPA supplements the Terms of Service. In the event of a conflict between this DPA and the Terms in respect of the processing of Contact Data, this DPA prevails. Liability under this DPA is subject to the limitations and exclusions set out in the Terms.

12. Governing Law

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms of Service.

Contact

Rosebud Global Ltd

Company number: 16623472

Email: contact@rosebud.global