Skippr AI

Trust & compliance

Data Processing Agreement

Last updated: July 23, 2026

This Data Processing Agreement ("DPA") supplements the agreement for the provision of Skippr's services (the "Agreement") entered into by and between Skippr Limited ("Skippr") and the client entity that is a party to the Agreement ("Client") (together, the "Parties"). In providing the services under the Agreement, Skippr processes Personal Data on behalf of the Client, with the Client acting as Controller and Skippr acting as Processor. This DPA sets out the terms governing that processing and is intended to ensure compliance with applicable Data Protection Laws. This DPA incorporates the terms of the Agreement, and any capitalised terms used but not defined in this DPA have the meanings set forth in the Agreement.

This DPA takes effect automatically upon acceptance of the Agreement and requires no signature. If the Parties have separately executed a data processing agreement, the executed agreement prevails over this DPA.

1. Definitions

  • "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the UK GDPR.
  • "Data Protection Laws" means the UK GDPR and the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679) where applicable, and any other data protection and privacy legislation applicable to the Processing.
  • "UK GDPR" means the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) as it forms part of the law of England and Wales, Scotland, and Northern Ireland.
  • "Supervisory Authority" means the competent data protection authority (in the UK, the Information Commissioner's Office (ICO)).
  • "Sub-processor" means any third party engaged by Skippr to process Personal Data on behalf of the Client.

2. Details of Processing

The subject matter, duration, nature, and purpose of the Processing, and the types of Personal Data and categories of Data Subjects, are set out in Appendix 1.

3. Skippr's Obligations

Skippr shall:

3.1. Process Personal Data only on the documented written instructions of the Client (including as set out in this DPA and the Agreement), including with regard to transfers of Personal Data to a third country, unless required to do so by law. Where Skippr is required by applicable law to process Personal Data other than on the Client's documented instructions, Skippr shall inform the Client of that legal requirement before Processing, unless that law prohibits such notification on important grounds of public interest. Skippr shall immediately inform the Client if, in Skippr's opinion, an instruction infringes Data Protection Laws.

3.2. Ensure that all personnel authorised to process the Personal Data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3. Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Appendix 2.

3.4. Taking into account the nature of the Processing, assist the Client by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Client's obligation to respond to requests for exercising Data Subjects' rights (including access, rectification, and erasure). The Client instructs Skippr to honour data subject requests received directly from Data Subjects (such as the Client's end users); Skippr will notify the Client of such requests.

3.5. Assist the Client in ensuring compliance with its obligations regarding security of processing, notification of a Personal Data Breach to the Supervisory Authority, communication of a Personal Data Breach to Data Subjects, data protection impact assessments, and prior consultation with the Supervisory Authority, taking into account the nature of the Processing and the information available to Skippr.

3.6. Notify the Client without undue delay after becoming aware of a Personal Data Breach and take necessary and reasonable remedial steps. Such notification is not an acknowledgement of fault or liability.

3.7. At the Client's choice, delete or return all Personal Data to the Client after the end of the provision of services relating to Processing, and delete existing copies, unless applicable law requires storage of the Personal Data. Skippr shall also delete Personal Data on the Client's reasonable written request.

3.8. Make available to the Client all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, as set out in Clause 5 (Audit).

3.9. Not process Personal Data for its own purposes, including product research, service improvement, or model training, other than as necessary to provide the services under the Agreement. Skippr may use aggregated, de-identified data that does not identify the Client or any Data Subject to improve its services.

3.10. Nothing in this DPA prevents Skippr from processing personal data as an independent controller for the limited purposes of securing its services, preventing fraud and abuse, and complying with legal obligations, as described in Skippr's Privacy Policy.

4. Sub-processors

4.1. The Client provides general written authorisation for Skippr to engage Sub-processors to support the delivery of the services. Skippr's current list of Sub-processors, including their purposes and locations of Processing, is published at https://skippr.ai/subprocessors.

4.2. Skippr shall give at least 10 days' notice of the addition or replacement of any Sub-processor by updating the list at https://skippr.ai/subprocessors. Clients may subscribe on that page to receive notice of changes by email; it is the Client's responsibility to subscribe or to check the list. The Client may object within 10 days of the notice on reasonable grounds relating to data protection. If the Parties cannot resolve the objection in good faith, the Client may suspend or terminate the affected services.

4.3. Skippr shall impose on each Sub-processor, by written agreement, data protection obligations no less protective than those in this DPA, and shall remain fully liable to the Client for the performance of each Sub-processor's obligations.

5. Audit

5.1. Skippr maintains a SOC 2 Type I report and an ISO/IEC 27001 certificate, each available to the Client on request. The Parties agree that provision of these reports and certificates, together with reasonable supporting documentation, shall satisfy the Client's audit and information rights in the first instance.

5.2. Where the materials in Clause 5.1 are reasonably insufficient, the Client (or an independent auditor mandated by it and not a competitor of Skippr) may audit Skippr's compliance with this DPA, no more than once in any 12-month period, on reasonable prior written notice, during normal business hours, at the Client's cost, and in a manner that is not unreasonably disruptive.

6. Client's Obligations

The Client warrants that it has a valid lawful basis for the Processing of all Personal Data it instructs Skippr to carry out and that it has complied with its obligations under Data Protection Laws, including providing any required notices to, and obtaining any required permissions from, Data Subjects. The services are not intended for the processing of special categories of personal data (Article 9 UK GDPR) or criminal-offence data, and the Client shall not use the services for workflows designed to collect such data.

7. International Transfers

Skippr shall not transfer Personal Data across borders unless appropriate safeguards are in place as required under applicable Data Protection Laws, such as: (a) adequacy decisions or regulations; (b) a recognised Data Privacy Framework certification, where the recipient is certified; or (c) the EU Standard Contractual Clauses and/or the UK International Data Transfer Agreement (IDTA) or UK Addendum, as applicable. The locations of Processing by Sub-processors are set out in the Sub-processor list at https://skippr.ai/subprocessors, and the Client's authorisation under Clause 4 extends to the transfers it entails, subject to such safeguards.

8. Term and Termination

This DPA — including its confidentiality, security, breach-notification, assistance, audit, international-transfer, and Sub-processor obligations — remains in force for so long as Skippr or any Sub-processor processes or retains Personal Data on behalf of the Client, notwithstanding termination or expiry of the Agreement. Personal Data retained to comply with applicable law shall remain protected under this DPA and be processed solely for that purpose.

9. Governing Law and Jurisdiction

This DPA and any dispute or claim arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction.

This DPA is effective without signature, as set out above. Where a Party requests execution, the Parties may sign below:

For the Client: Signature:   Full name:   Title:   Date:

For Skippr: Signature:   Full name:   Title:   Date:


Appendix 1: Details of the Processing

Subject matter of Processing — Provision of the Skippr platform and AI agent services under the Agreement.

Duration of Processing — The term of the Agreement.

Nature and purpose of Processing — Capturing, transcribing, analysing, and responding to user sessions in order to provide, secure, and support the services, including generating live AI agent assistance and related analytics for the Client.

Types of Personal Data — Audio; on-screen content; transcripts; identifiers the Client chooses to submit (such as name, email address, or user ID); usage data and technical data (such as IP address and device/browser information).

Categories of Data Subjects — The Client's end users and personnel who interact with the services.

Appendix 2: Technical and Organisational Security Measures

  • Certifications: Skippr maintains a SOC 2 Type I report and ISO/IEC 27001 certification, and operates an information security management system (ISMS) in line with ISO/IEC 27001.
  • Encryption: Personal Data is encrypted in transit (TLS) and at rest.
  • Access control: Logical tenant isolation; role-based access controls, including database row-level security; access on a least-privilege, need-to-know basis.
  • Confidentiality: Personnel are bound by confidentiality commitments and receive security training.
  • Data minimisation controls: Best-effort client-side masking of recognised credential and payment fields before capture, and Client-controlled exclusion of designated on-screen elements.
  • AI providers: Sub-processors providing AI services are contractually barred from using Client Personal Data to train their models.
  • Availability: Regular backups and recovery procedures.
  • Deletion: Personal Data is deleted or returned in accordance with Clause 3.7 and on request.