Data Processing Agreement

Effective 8 July 2026

This Data Processing Agreement ("DPA") forms part of the Patch14 Terms of Servicebetween you ("Customer") and Granite & Fleur Digital Ltd ("Patch14", company no. 17289418). It applies wherever Patch14 processes personal data on Customer's behalf as part of the service. Terms not defined here have the meaning given to them in UK GDPR.

1. Roles

Customer is the controller of the personal data it submits to Patch14, or is itself processing that data on behalf of its own clients (for example, an MSP acting on behalf of an SME client). Patch14 is a processor, acting only on Customer's documented instructions as set out in this DPA and the underlying agreement. Where Customer is itself a processor for a third-party controller, Customer warrants it is authorised to instruct Patch14 to process that data accordingly.

2. Subject matter and duration

Patch14 processes personal data for the duration of Customer's subscription, for the purpose of providing the service described in the Terms of Service (asset monitoring, vulnerability matching, alerting, and evidence pack generation).

3. Nature and categories of data

4. Patch14's obligations

Patch14 will:

5. Sub-processors

Customer authorises Patch14 to engage the following sub-processors, each engaged directly by Patch14 to provide part of the service:

Patch14 will give Customer at least 30 days' notice before adding a new sub-processor (by email or in-product notice), during which Customer may object on reasonable data protection grounds. Patch14 remains responsible for each sub-processor's performance of its obligations.

6. Customer-configured integrations

Where Customer connects a PSA or RMM integration it controls (Halo PSA, ConnectWise Manage, Autotask, or Lansweeper) using its own credentials with that provider, that provider is not a Patch14 sub-processor under this DPA — Customer is responsible for its own contractual and data protection relationship with that provider. Patch14's role is limited to transmitting data to and from that integration at Customer's direction.

7. International transfers

Customer's core account, client, and asset data is stored in the UK. Where a sub-processor processes personal data outside the UK, Patch14 ensures an appropriate safeguard is in place, such as an applicable UK adequacy regulation or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

8. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.

9. Term

This DPA takes effect when Customer creates a Patch14 account and continues for as long as Patch14 processes personal data on Customer's behalf under the Terms of Service.

Questions about this agreement: privacy@graniteandfleur.com