Axiom Data Processing Agreement
Last updated 17 September 2026
This agreement sets out the terms on which LinkRide Technologies LTD (company number SC872736, registered office 2/3, 48 West George Street, Glasgow, United Kingdom, G2 1BP), operating as Axiom, processes personal data on behalf of a client organisation. It forms part of the Axiom Terms of Service and applies automatically wherever Axiom processes personal data for you.
It is required by Article 28 of the UK GDPR. In it, “you” and “Controller” mean the client organisation; “we”, “us” and “Processor” mean Axiom. “UK Data Protection Law” means the UK GDPR and the Data Protection Act 2018. Other terms — personal data, processing, data subject, personal data breach, supervisory authority — carry the meanings given in that law.
1. Roles
You are the controller of the personal data you upload to Axiom or that Axiom processes for you. We are your processor in respect of it. You determine the purposes and means; we act on your instructions.
We are a separate controller for the limited data we hold to run our own business — your account, your staff’s sign-in details, and billing records. That is covered by the Axiom privacy notice, not by this agreement.
2. The processing, described
Article 28(3) requires this to be set out, so it is:
- Subject matter: provision of the Axiom client data portal.
- Duration: for as long as your account is open, plus the retention periods in clause 9.
- Nature and purpose: storing, organising, structuring, analysing and displaying data you upload; generating dashboards, exports and reports from it; staff review of a report before it is sent to you; and sending you service emails.
- Types of personal data: whatever your uploaded files contain. Axiom does not prescribe a schema, so this is determined by you. Special category and criminal offence data must not be uploaded without our prior written agreement (see the Terms of Service).
- Categories of data subject: determined by you — typically your customers, staff, members or suppliers.
3. Our obligations
These are the obligations Article 28(3) requires of a processor. We:
- Process only on your documented instructions, including on transfers outside the UK, unless required otherwise by law — in which case we will tell you before processing, unless that law forbids it. Your use of the portal, and this agreement, are your instructions. We will tell you if we believe an instruction breaches UK Data Protection Law.
- Ensure confidentiality: everyone we authorise to process your data is under a binding duty of confidence, and access is limited to those who need it to do their job.
- Apply Article 32 security measures: as set out in clause 6.
- Respect the sub-processor conditions in Articles 28(2) and 28(4): see clause 7.
- Assist you with data subject rights: taking account of the nature of the processing, we will help you respond to requests to access, correct, delete, restrict, port or object. If a data subject contacts us directly about your data, we will not respond substantively — we will refer them to you and tell you promptly.
- Assist you with Articles 32 to 36: security, breach notification, and data protection impact assessments, taking account of what we know and the resources available to us.
- Delete or return your data at the end of the service, as set out in clause 9.
- Demonstrate compliance: make available the information you reasonably need to show we meet these obligations, and allow audits as set out in clause 8.
4. Your obligations
You confirm that you have a lawful basis for the processing you instruct, that you have given whatever privacy information the law requires to the people whose data you upload, and that your instructions do not require us to breach UK Data Protection Law. You are responsible for the accuracy and relevance of what you upload, and for not uploading more personal data than you need.
5. Personal data breaches
We will tell you without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting your data. That leaves you time inside your own 72-hour deadline to the ICO.
We will give you the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — providing what we have immediately and the rest as we establish it, rather than waiting until the picture is complete.
We will not notify a supervisory authority or a data subject about your data on your own behalf unless you ask us to, or the law requires us to.
6. Security measures
Taking account of the state of the art, the costs, and the risks to the people concerned, we apply measures appropriate to that risk. Currently:
- Separation between clientsenforced in the application layer, where every data access carries the organisation it is for, backed by an automated test suite whose purpose is to assert that one client cannot reach another’s data.
- Access control: invitation-only accounts, roles that distinguish who may upload from who may only read, sessions that expire, and passwords hashed with argon2 and never stored or transmitted in readable form.
- Rate limiting on sign-in, so credentials cannot be guessed at volume.
- Encryption in transit (TLS) and at rest, provided by our hosting platform.
- Upload handling: size limits, content-type checking, parsing inside error boundaries, and server-side re-encoding of uploaded images rather than serving the bytes we received.
- Audit logging of uploads, plan changes, report approvals and profile edits.
- Backups sufficient to restore the service, held under the same protections as the live data.
We may change these measures, but not in a way that materially reduces the protection given to your data.
7. Sub-processors
You give general authorisation for us to engage sub-processors. Each one is bound by written terms no less protective than these, and we remain fully liable to you for their performance. Our current sub-processors are:
- Google Cloud Platform (Google Cloud EMEA Limited) — hosting, database, and file storage. Processing in the UK and EU.
- Resend (Plus Five Five, Inc.) — delivery of service and report emails. Processing in the US.
We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any fees paid in advance.
8. Audits
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by you or an auditor you appoint.
In practice, and to keep this workable for both of us: we will answer a reasonable security questionnaire, and where that leaves a question unanswered you may audit on 30 days’ notice, no more than once a year unless a breach or a regulator requires otherwise, during working hours, without unreasonable disruption, and subject to confidentiality. Your auditor may not be a competitor of ours. You bear your own costs; we bear ours unless the audit reveals a material breach by us, in which case we bear both.
9. Return and deletion
You can export your data yourself at any time while your account is open. On termination you have 30 days to do so, after which offboarding permanently deletes the organisation and all of its data. We will confirm deletion in writing if you ask.
We retain only what the law requires us to retain — invoicing records for six years after the relevant tax year — and it stays subject to this agreement for as long as we hold it. Backups are overwritten on their normal cycle rather than surgically edited; anything still in a backup is protected by these terms until the cycle clears it.
10. International transfers
Your data is stored in the UK and EU. Where a sub-processor processes personal data outside the UK — currently Resend, in the US — the transfer is made under an adequacy decision where one applies, or otherwise under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
We will not transfer your data outside the UK other than as described here without telling you first.
11. Liability and precedence
The liability provisions in the Axiom Terms of Service apply to this agreement. Where this agreement and those terms conflict on a matter of data protection, this agreement takes precedence; on everything else, those terms do.
12. Governing law
This agreement is governed by the law of Scotland, and the Scottish courts have exclusive jurisdiction.
Contact
Data protection queries and requests under this agreement: support@linkride.co.uk. LinkRide Technologies LTD, 2/3, 48 West George Street, Glasgow, United Kingdom, G2 1BP.
If you need this executed as a signed document for your own records, ask and we will sign a copy.