Version 1.0 - 22 September 2026. This is our first published version of this DPA, and it will be revised following legal review.
This Data Processing Agreement ("DPA") forms part of the agreement between IVY HQ Ltd, trading as ivee (company number 15104292, registered office Arquen House, 4-6 Spicer Street, St. Albans, England, AL3 4PQ) ("ivee", "we") and the organisation using the ivee app ("you", "your organisation"). It applies wherever ivee processes personal data on your behalf as a data processor, with your organisation as data controller, in connection with the ivee app.
1. Subject matter, duration and purpose
ivee processes personal data solely to provide and improve the ivee app for your organisation, for as long as your organisation holds an active ivee account. This DPA applies for that same period.
2. Categories of data and data subjects
Personal data processed under this DPA is limited to: the text your users draft when using ivee to improve a prompt; the app or website domain (not full URL) they were working in; their account email address; and usage data such as character counts, response times and how a rewrite was used. Data subjects are the individual users at your organisation who use the ivee app.
3. Processing on instructions
ivee will process personal data only on your documented instructions, including as set out in this DPA and our App Terms, unless required to do otherwise by UK law.
4. Confidentiality
ivee ensures that anyone it authorises to process personal data under this DPA is subject to a duty of confidentiality.
5. Security measures
ivee maintains the following technical and organisational measures:
Encryption - at rest (AES-256) and in transit (TLS on all connections).
Network isolation - databases held in private subnets with no public access.
Access control - restricted to authorised ivee staff on a need-to-know basis.
Backups - daily, encrypted, retained 30 days, held in the same UK region.
Credential scanning - prompt text is scanned for credentials or API keys before storage, with any matches excluded from storage.
All data ivee stores directly is held in AWS, UK (London).
6. Sub-processors
You authorise ivee to use the following sub-processors in connection with the ivee app: Anthropic (United States) for generating prompt rewrites, and Amazon Web Services (United Kingdom) for hosting and data storage. Where personal data is transferred to Anthropic in the United States, this is safeguarded under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
ivee will give at least 30 days' notice before adding or replacing a sub-processor for the ivee app, and you may object on reasonable grounds within that period; if unresolved, ivee's remedy is to cease using that sub-processor for your account rather than terminate the underlying agreement, unless otherwise agreed.
7. Assistance with data subject rights
ivee will provide reasonable assistance to help your organisation respond to requests from data subjects to exercise their rights under UK GDPR (such as access, rectification or erasure).
8. Assistance with security and breach obligations
ivee will assist your organisation in meeting its obligations relating to the security of processing, and will notify you without undue delay on becoming aware of a personal data breach affecting your data.
9. Deletion or return of data
On termination of your ivee account, ivee will delete your organisation's personal data within 60 days, consistent with ivee's standard data retention practice, save where UK law requires it to be retained for longer.
10. Demonstrating compliance
This DPA, ivee's published data & security policy, and the sub-processor list at ivee.jobs/legal/subprocessors together set out the information needed to demonstrate ivee's compliance with this DPA. Further documentation (such as security certifications) will be made available as and when it exists.
11. Governing law
This DPA is governed by the laws of England and Wales.
