Data Processing Agreement.
This agreement governs Linox's processing of personal data on behalf of the Company under UK GDPR, the Data Protection Act 2018, and applicable data protection laws.
// last updated 29 may 2026 · contact hello@linox.co.uk
This Data Processing Agreement ("Agreement" or "DPA") forms part of the agreement for services between the Company and Linox Ltd under Linox's Terms of Service, order form, or master services agreement (the "Principal Agreement"), between:
Linox Ltd, a company registered in England and Wales under company number 12796381, with its registered office at Lytchett House 13 Freeland Park, Wareham Road, Poole, England, BH16 6FA (referred to as "Linox" or the "Processor"); and
the Company using Linox's Services (referred to as the "Company" or the "Controller"), which is to be understood as any business or organisation using the Services, regardless of its legal form.
This Agreement governs the specific requirements of Data Protection Laws to the extent that the Company's use of the Services involves the Processing of Personal Data subject to Data Protection Laws. It is complementary to Linox's Privacy Policy, which is the primary reference for Linox's data protection practices and measures.
Acceptance and incorporation. This Agreement is incorporated into and forms part of the Principal Agreement. The Company is not required to sign this Agreement. By accepting the Principal Agreement, or by accessing or using the Services, the Company agrees to and is bound by this Agreement. Where an individual accepts this Agreement or the Principal Agreement on behalf of the Company, that individual represents that they have authority to bind the Company. This Agreement takes effect on the earlier of the Company's acceptance of the Principal Agreement or its first use of the Services (the "Effective Date"). Linox may update this Agreement from time to time in accordance with the Principal Agreement and its Privacy Policy; the version published on this page is the version in force, and the Company's continued use of the Services constitutes acceptance of the updated version.
The term of this Agreement shall follow the term of the Principal Agreement. Terms not defined herein shall have the meaning set out in the Principal Agreement.
Background
A) The Company acts as a Data Controller (the "Controller").
B) The Company wishes to subcontract certain Services (as defined below), which involve the Processing of Personal Data, to Linox Ltd, acting as a Data Processor (the "Processor").
C) The Parties seek to implement a data processing agreement that complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, to the extent applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) and other applicable data protection laws.
D) The Parties wish to lay down their rights and obligations.
It is agreed as follows.
1 · Definitions and Interpretation
Unless otherwise defined herein, capitalised terms used in this Agreement shall have the following meaning:
- "Agreement" means this Data Processing Agreement and all Annexes;
- "Company Personal Data" means any Personal Data relating to the Company, or the Company's customers, employees, visitors, or other individuals, that is Processed by the Processor on behalf of the Controller in connection with the Principal Agreement, as further described in Annex 1;
- "Contracted Processor" means a Subprocessor;
- "Data Protection Laws" means all laws applicable to the Processing of Company Personal Data under this Agreement, including the UK GDPR, the Data Protection Act 2018 ("DPA 2018"), the Privacy and Electronic Communications Regulations 2003 where applicable, and, to the extent applicable to a Party, the EU GDPR and the data protection or privacy laws of any other country;
- "UK GDPR" has the meaning given in section 3(10) (as supplemented by section 205(4)) of the DPA 2018;
- "EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016;
- "UK" means the United Kingdom;
- "Restricted Transfer" means a transfer of Company Personal Data to a country, territory, or international organisation that is not the subject of UK adequacy regulations under section 17A of the DPA 2018 (or, for Personal Data subject to the EU GDPR, an adequacy decision under Article 45 EU GDPR);
- "Data Transfer" means: (a) a transfer of Company Personal Data from the Controller to the Processor or a Contracted Processor; or (b) an onward transfer of Company Personal Data from the Processor to a Subprocessor, or between two establishments of a Subprocessor;
- "Services" means the Darkfield AI vision platform and related services provided by the Processor, comprising the Processing of video and image data from the Company's cameras to generate events, detections, alerts, analytics, and reports, and, where enabled by the Company, in-memory redaction or anonymisation, as further described in Annex 1 and on the Processor's website;
- "Subprocessor" means any person appointed by or on behalf of the Processor to Process Personal Data on behalf of the Controller in connection with this Agreement;
- "Transfer Mechanism" means the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or any other lawful transfer mechanism provided for under the Data Protection Laws.
The terms "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data", and "Supervisory Authority" shall have the same meaning as in the Data Protection Laws, and their cognate terms shall be construed accordingly.
2 · Processing of Company Personal Data
2.1 The Processor shall comply with all applicable Data Protection Laws in the Processing of Company Personal Data.
2.2 The Processor shall not Process Company Personal Data other than on the Controller's documented instructions, including as set out in this Agreement and Annex 1, unless Processing is required by laws to which the Processor is subject, in which case the Processor shall (to the extent permitted by law) inform the Controller of that legal requirement before Processing.
The Controller instructs the Processor to Process Company Personal Data to:
- 2.3 provide the Services and related technical support;
- 2.4 comply with legal obligations or resolve disputes;
- 2.5 maintain, secure, and improve the security, privacy, confidentiality, and functionality of the Services, including model quality assurance and per-scene retraining as described in the Principal Agreement;
- 2.6 carry out internal reporting, financial reporting, and similar internal administrative tasks.
2.7 The Controller is responsible for: (a) establishing and maintaining a lawful basis for the Processing; (b) providing all required notices and transparency information to Data Subjects, including in respect of CCTV or video surveillance and any automated processing; (c) determining camera placement, retention periods, and configuration; and (d) carrying out any required Data Protection Impact Assessment. The Controller shall not instruct the Processing of Special Category Data, or data relating to criminal convictions and offences, unless it has first ensured that an applicable condition under Article 9 or Article 10 UK GDPR (and the DPA 2018) is met and has notified the Processor.
2.8 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws.
3 · Processor Personnel
The Processor shall take reasonable steps to ensure the reliability of any employee, agent, or contractor of any Contracted Processor who may have access to Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement and to comply with Data Protection Laws, and ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
4 · Security
4.1 In accordance with Article 32(1) of the UK GDPR, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons. The measures implemented by the Processor are described in Annex 2.
4.2 In assessing the appropriate level of security, the Processor shall take account in particular of the risks presented by Processing, in particular from a Personal Data Breach.
5 · Subprocessing
5.1 The Controller grants the Processor general authorisation to engage Subprocessors to Process Company Personal Data, subject to this section 5. The current list of Subprocessors is set out in Annex 3.
5.2 The Processor shall inform the Controller of any intended addition or replacement of a Subprocessor in accordance with the notification process in its Privacy Policy, thereby giving the Controller the opportunity to object. If the Controller has a reasonable, data-protection-related objection to a new Subprocessor, the Parties shall work together in good faith to resolve it; if it cannot be resolved, the Controller may suspend or terminate the affected part of the Services.
5.3 The Processor shall ensure that each Subprocessor is subject to a written agreement no less protective of Company Personal Data than this Agreement, to the extent applicable to the nature of the services provided by that Subprocessor. The Processor shall remain liable to the Controller for the performance of each Subprocessor's obligations.
5.4 The Controller authorises the Processor to disclose and transfer Company Personal Data to any company within the Processor's corporate group for the purposes of providing the Services, subject to the protections of this Agreement.
6 · Data Subject Rights
6.1 Taking into account the nature of the Processing, the Processor shall reasonably assist the Controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Controller's obligations to respond to requests by Data Subjects exercising their rights under the Data Protection Laws.
The Processor shall:
- 6.2 promptly notify the Controller if the Processor receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
- 6.3 ensure that it does not respond to that request except on the documented instructions of the Controller, or as required by laws to which the Processor is subject, in which case the Processor shall (to the extent permitted by law) inform the Controller of that legal requirement before responding.
7 · Personal Data Breach
7.1 The Processor shall manage any Personal Data Breach in compliance with applicable Data Protection Laws and its internal Personal Data Breach procedures. In the event of a Personal Data Breach affecting Company Personal Data, the Processor shall notify the Controller without undue delay after becoming aware of it, providing sufficient information to enable the Controller to meet its obligations under the Data Protection Laws, including any obligation to notify the Supervisory Authority (in the UK, the Information Commissioner's Office) within 72 hours and to inform affected Data Subjects.
7.2 The Processor shall co-operate with the Controller and take such reasonable commercial steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
7.3 Each Party shall bear the costs of investigation, remediation, and mitigation, and of any fines, penalties, or damages imposed by a competent regulator or court, to the extent the Personal Data Breach is caused by, or arises from, that Party's breach of its obligations under this Agreement.
8 · Data Protection Impact Assessment and Prior Consultation
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with the Information Commissioner's Office or other competent Supervisory Authority that the Controller reasonably considers to be required under Article 35 or Article 36 of the UK GDPR (or equivalent provisions of any other Data Protection Law), in each case solely in relation to the Processing of Company Personal Data and taking into account the nature of the Processing and the information available to the Processor.
9 · Deletion or Return of Company Personal Data
9.1 On termination or expiry of the Principal Agreement, or on cessation of any Service involving the Processing of Company Personal Data, the Processor shall, at the Controller's choice, delete or return all Company Personal Data in its possession or control, and delete existing copies, except to the extent that retention is required by laws to which the Processor is subject.
9.2 The Parties acknowledge that in edge (on-premises) deployments, raw video and frames remain within the Company's own environment and are not held by the Processor. For managed cloud deployments, the Processor shall delete Company Personal Data held in the Company's dedicated instance in accordance with this section and its Privacy Policy.
9.3 If the Company requires a copy of its data, it must request it before deletion of its account or instance; requests made after deletion can no longer be fulfilled.
10 · Audit Rights
10.1 Subject to this section 10, the Processor shall make available to the Controller, on request, all information reasonably necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller in relation to the Processing of Company Personal Data.
10.2 The Controller shall not exercise its audit rights more than once per calendar year, except following a Personal Data Breach or where required by an instruction of a regulatory authority. The Controller shall give the Processor at least sixty (60) days' prior written notice of any audit. Audits shall be conducted during the Processor's business hours, shall not unreasonably disrupt the Processor's operations, and shall protect the Personal Data of the Company, the Processor, and other Data Subjects. The Parties shall agree in advance on the date, scope, duration, and security and confidentiality controls applicable to the audit. The Controller acknowledges that the Processor may require the signing of a non-disclosure agreement prior to the audit.
10.3 Information and audit rights of the Controller arise under this section 10 only to the extent that this Agreement does not otherwise give them information and audit rights meeting the relevant requirements of the Data Protection Laws.
11 · Data Transfers
11.1 The Processor shall, where reasonably possible, Process and store Company Personal Data within the UK. The Processor's default position is UK data residency for UK customers.
11.2 The Processor shall not make a Restricted Transfer of Company Personal Data unless an appropriate Transfer Mechanism is in place, or another exemption or derogation under the Data Protection Laws applies. Where a Transfer Mechanism is required, the Parties shall, unless otherwise agreed, rely on the UK IDTA and/or the UK Addendum to the EU Standard Contractual Clauses (and, for Personal Data subject to the EU GDPR, the EU Standard Contractual Clauses), together with any supplementary measures required.
11.3 The Processor is authorised to make such transfers to Subprocessors provided that adequate safeguards are implemented in accordance with this section 11 and the nature of the transfer.
12 · General Terms
Compliance with applicable laws. The Processor will Process Company Personal Data in accordance with this Agreement and the Data Protection Laws applicable to its role as Processor. The Processor is not responsible for complying with Data Protection Laws applicable to the Controller solely by virtue of the Controller's business or industry.
Confidentiality. Each Party must keep confidential any information it receives about the other Party and its business in connection with this Agreement ("Confidential Information"), and must not use or disclose that Confidential Information without the other Party's prior written consent, except to the extent that: (a) disclosure is required by law; or (b) the relevant information is already in the public domain through no fault of that Party.
Notices. All notices and communications given under this Agreement must be in writing and may be sent by email. The Controller shall be notified by email sent to the address associated with its use of the Services under the Principal Agreement. The Processor shall be notified by email sent to: hello@linox.co.uk.
Order of precedence. In the event of any conflict between this Agreement and the Principal Agreement in relation to the Processing of Company Personal Data, this Agreement shall prevail.
Governing law and jurisdiction. This Agreement shall be governed by the laws of England and Wales. The Parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute, claim, or cause of action arising out of or in connection with this Agreement.
Severance. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
Annex 1 · Details of the Processing
| Subject matter | The provision of the Darkfield AI vision platform and related services by the Processor to the Controller under the Principal Agreement. |
|---|---|
| Duration | For the term of the Principal Agreement, plus any period necessary for deletion or return of Company Personal Data under section 9. |
| Nature and purpose | Ingestion of video and image data from the Controller's cameras; computer-vision and vision-language model inference to detect objects, people, vehicles, events, and conditions; generation of events, alerts, analytics, reports, and short evidence clips; model quality assurance and per-scene retraining; and, where enabled by the Controller, in-memory redaction or anonymisation of frames. |
| Data subjects | May include the Controller's employees, contractors, visitors, customers, members of the public, drivers, and any other individuals captured by the Controller's cameras. |
| Types of data | Images and video footage of individuals and their appearance, location, movements, and behaviour; vehicle images and number plates (including, where configured, lookups against vehicle data sources such as the DVLA and DVSA); event and detection metadata; alert and audit records; and Company account and user data (such as names and email addresses of the Controller's administrators). |
| Special category data | The Services are not intended to Process Special Category Data. Depending on the Controller's configuration, footage may nonetheless reveal information capable of constituting Special Category Data. The Controller is responsible for determining whether such Processing occurs and for ensuring an Article 9 UK GDPR condition applies (see section 2.7). |
| Frequency | Continuous, for the duration of the Principal Agreement. |
Processing is carried out under one of the following deployment models, as selected by the Controller:
- Edge (Enterprise): inference runs on the on-site vision-box behind the Controller's firewall; raw video remains on the Controller's network and only events, detections, and short evidence clips are transmitted to the Processor.
- Managed cloud inferencing (SME): video is streamed to a dedicated, network-isolated instance in the UK, managed by the Processor.
- Air-gapped: all Processing occurs on the Controller's or a partner's hardware with no outbound connection to the Processor.
Annex 2 · Technical and Organisational Measures
The Processor implements the following measures, as further described in the Linox Security Whitepaper:
- Encryption: Company Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256.
- Data minimisation: the Services convert video into events and retain events and short evidence clips rather than continuous footage. In edge deployments, raw video does not leave the Controller's network. Where the Controller requires it, in-memory redaction or anonymisation can be applied to frames before any clip is persisted.
- Access control: least-privilege role-based access control, single sign-on, and multi-factor authentication for administrative and remote access to production systems; access provisioned on a documented, approved basis and promptly revoked on role change or departure.
- Network security: network segmentation; camera-scoped gateways that cannot reach the wider Controller network; dedicated, network-isolated instances for managed cloud customers; zero-trust corporate access; endpoint and email threat protection.
- Data residency: UK-based processing and storage for UK customers by default.
- Logging and monitoring: centralised audit logging and continuous monitoring of infrastructure and access events; exportable audit logs.
- Resilience: redundant infrastructure, encrypted backups, disaster recovery and business continuity arrangements, and local edge operation if connectivity to the Processor is interrupted.
- Vulnerability management: vulnerability management procedures and at least annual penetration testing, with prioritised remediation.
- Incident response: a documented Incident Response Plan covering both security and AI-safety events, with breach notification to the Controller without undue delay.
- Personnel security: background checks where lawful, confidentiality obligations, security awareness training, and centrally managed devices.
Annex 3 · Subprocessors
The Controller authorises the following Subprocessors.
| Subprocessor | Purpose / Service | Location |
|---|---|---|
| Google (Google Cloud) | Cloud infrastructure, security, data storage, LLM services, and communication / alert delivery | United Kingdom |
| Amazon Web Services (AWS) | Cloud infrastructure and data storage | United Kingdom |
| Microsoft Azure | Cloud infrastructure, data storage, and LLM services | United Kingdom |
| Vast.ai | GPU rental for model inference | UK / EU |
| Slack | Collaboration: client communication and support-ticket management | United States |
| DVLA | Vehicle data lookups (number-plate and vehicle records) | United Kingdom |
| DVSA | Vehicle data lookups (MOT and vehicle standards records) | United Kingdom |
Anthropic and OpenAI are used by Linox for internal purposes only and do not Process Company Personal Data; they are therefore not Subprocessors under this Agreement.
No signature required. This Agreement does not need to be signed. It is accepted as described in the "Acceptance and incorporation" section above and takes effect from the Effective Date, for as long as the Company uses the Services or the Principal Agreement remains in force.
// © 2026 linox ltd · united kingdom