Data Processing Agreement (DPA)

Bigby.cloud Ltd
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: [email protected]
Company number: 17214602
ICO registration reference: ZC235231
Last updated: 11 September 2026

This DPA sits alongside the Alpha Testing Agreement & Terms of Service and applies when you upload personal data about your own contacts, clients, or employees to our service. In this context, you are the data controller and we are the data processor.

1. What we will do with your data

We will process your personal data only:

  • to provide the cloud storage and office suite service to you,
  • to comply with applicable law, or
  • as you otherwise instruct us in writing.

We will not use your data for any other purpose, including our own commercial benefit.

2. What data and who it is about

Because we are a general-purpose file storage service, we do not know exactly what you will upload. You may upload personal data including, but not limited to:

  • your employees or team members,
  • your customers or clients,
  • your business contacts.

The types of personal data may include names, email addresses, phone numbers, addresses, and any other information contained in the documents you upload.

3. Sub-processors

We use the following sub-processors to deliver the service. They only access data as needed to perform their role.

Sub-processorRoleLocation
OVHHosting infrastructureUK/EU
CloudflareSecurity and CDNGlobal
AWSEmail, backup and auxiliary servicesUK/EU
GrafanaLog collection, metrics collection, and monitoringGlobal
FormspreeWebsite formsGlobal
InfomaniakEmail servicesEU

During the alpha testing period, we may need to add new sub-processor who will access your personal data without notice for evaluation purposes. If we need to add a new sub-processor permanently, we will notify you by email before the alpha testing period ends. Data held in any sub-processor evaluated and ultimately not permanently added to the service will be deleted as early as possible in line with their policies.

After the alpha testing period, if we need to add a new sub-processor who will access your personal data, we will tell you at least 30 days in advance. You can object by terminating your account before the change takes effect.

4. Security

We apply industry-standard security measures appropriate to the risk, including:

  • encryption of data in transit and at rest,
  • access controls and authentication for our users and staff,
  • regular security reviews.

We will keep these measures under review and improve them as the service matures.

5. Data subject rights and breaches

If someone asks us directly to exercise a data subject right over data in your account, we will redirect them to you. We will help you respond to such requests as far as we are reasonably able.

If we become aware of a personal data breach that affects your data, we will tell you without undue delay and no later than 72 hours after we become aware.

6. After termination

When your account ends, we will delete your data (including personal data) within 60 days, unless we are required to keep it by law.

7. Audits

Once per year, you may ask us for information to confirm we are meeting our obligations under this DPA. We will provide a summary or relevant certifications if we have them. If you need a physical audit, we will allow it once per year with reasonable notice, provided it does not disrupt our operations.

8. Changes to this DPA

If UK data protection law changes in a way that requires us to update this DPA, we will notify you and publish an updated version.