Data Processing Agreement

This Data Processing Agreement forms part of our Terms of Service. It sets out how BizHeroFor handles personal data on your behalf when you use our platform to process personal data belonging to your own customers, staff, suppliers, or other third parties.

Version: 1.0
Effective date: 13 August 2026
Last updated: 13 August 2026

1. Parties

1.1 This Data Processing Agreement ("DPA") is entered into between:

  • Semad Ltd, trading as BizHeroFor ("BHF", "we", "us", "the Processor"), a company incorporated in Ireland with its registered office at Unit 5, Portmarnock Town Centre, Co. Dublin, Ireland; and
  • the person or legal entity that has agreed to BHF's Terms of Service and is using the BHF platform ("the Customer", "you", "the Controller").

1.2 This DPA forms part of, and is incorporated into, BHF's Terms of Service. In the event of any conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.

2. Definitions

2.1 In this DPA, the following terms have the following meanings:

  • "Applicable Data Protection Law" means the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK General Data Protection Regulation as defined in section 3 of the Data Protection Act 2018 ("UK GDPR"), the Irish Data Protection Act 2018, and any other laws relating to the protection of personal data that apply to the processing under this DPA.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Sub-processor" and "Supervisory Authority" have the meanings given in the EU GDPR or UK GDPR as applicable.
  • "Customer Personal Data" means Personal Data belonging to the Customer's customers, staff, prospects, suppliers, or other individuals that the Customer causes to be processed through the BHF Service.
  • "Service" means the software-as-a-service platform provided by BHF under its Terms of Service.
  • "Sub-processor" has the meaning given in the EU GDPR and includes any third party engaged by BHF to process Customer Personal Data.

3. Application and roles

3.1 This DPA applies whenever BHF processes Customer Personal Data on the Customer's behalf in connection with the Service.

3.2 The parties acknowledge that, in relation to Customer Personal Data:

  • (a) the Customer is the Controller; and
  • (b) BHF is the Processor acting on the Customer's documented instructions.

3.3 In relation to Personal Data that BHF collects and processes about the Customer itself (for example, the Customer's account holder name, billing details, and login records), BHF acts as Controller. That processing is governed by BHF's Privacy Policy, not this DPA.

3.4 The parties do not intend, by this DPA, to establish any joint controllership relationship under Article 26 GDPR.

4. Details of the processing

4.1 The subject matter, duration, nature and purpose of the processing, the type of Personal Data, and the categories of Data Subjects are set out in Annex 1.

4.2 The Customer's documented instructions to BHF consist of:

  • (a) the configuration of the Customer's account in the Service;
  • (b) the Customer's use of the Service in accordance with its ordinary functionality;
  • (c) any written instructions the Customer sends to BHF's support team at adam@semad.ie; and
  • (d) this DPA and the Terms of Service.

4.3 If BHF believes that a Customer instruction infringes Applicable Data Protection Law, BHF will inform the Customer without undue delay and may refuse to carry out the instruction until it is amended or withdrawn.

5. Processor obligations under Article 28(3)

BHF, as Processor, undertakes the following obligations, which reflect the requirements of Article 28(3) of the EU GDPR and the equivalent provisions of the UK GDPR.

5.1 Documented instructions (Article 28(3)(a))

BHF will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of Customer Personal Data to a third country or an international organisation, unless required to do otherwise by EU or Member State law (or the law of the United Kingdom, where UK GDPR applies) to which BHF is subject. In such a case, BHF will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 Confidentiality (Article 28(3)(b))

BHF will ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. BHF limits access to Customer Personal Data to those of its personnel who need it to perform their duties.

5.3 Security measures (Article 28(3)(c) and Article 32)

BHF will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of natural persons. The measures currently in place are described in Annex 2. BHF may update Annex 2 from time to time provided the overall level of security is not materially reduced.

5.4 Sub-processors (Article 28(2), (3)(d) and (4))

5.4.1 The Customer gives BHF general written authorisation to engage Sub-processors, subject to the conditions in this clause.

5.4.2 The current list of Sub-processors is set out in Annex 3 and is also maintained at bizherofor.com/subprocessors.php.

5.4.3 BHF will give the Customer at least thirty (30) days' prior notice before adding or replacing a Sub-processor. Notice will be given by email to the address the Customer has provided for that purpose, or by an in-Service notification, or by updating the Sub-processor list published at the URL above with a version change.

5.4.4 The Customer may object to a proposed new Sub-processor on reasonable data protection grounds within fourteen (14) days of receiving notice. If the Customer objects and the parties cannot reach a resolution, the Customer may terminate the parts of the Service that require the objected-to Sub-processor, or the Service in full, without penalty, by giving BHF written notice.

5.4.5 Where BHF engages a Sub-processor, BHF will impose on that Sub-processor, by contract, data protection obligations that are equivalent in substance to those imposed on BHF under this DPA. BHF remains fully liable to the Customer for the performance of each Sub-processor's obligations.

5.5 Assistance with data subject rights (Article 28(3)(e))

Taking into account the nature of the processing, BHF will assist the Customer, by appropriate technical and organisational measures and insofar as it is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.

5.6 Assistance with security, breach notification, DPIAs and prior consultation (Article 28(3)(f))

Taking into account the nature of the processing and the information available to BHF, BHF will assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR, including in relation to security of processing, personal data breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.

5.7 Deletion or return at end of contract (Article 28(3)(g))

On termination or expiry of the Service, or at any earlier time on the Customer's written request, BHF will, at the Customer's choice, delete or return all Customer Personal Data to the Customer and delete existing copies. This obligation is subject to:

  • (a) any period during which BHF is required to retain Customer Personal Data by EU, Member State or United Kingdom law; and
  • (b) reasonable technical time needed for deletion from active systems and rolling backups. Backups will be overwritten in the ordinary course, and BHF will not restore any Customer Personal Data from those backups after the deletion date.

BHF will confirm deletion in writing on request.

5.8 Audits and inspections (Article 28(3)(h))

5.8.1 BHF will make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.

5.8.2 BHF will allow for, and contribute to, audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. To keep audits proportionate and to protect the security of BHF's other customers, the parties agree that:

  • (a) the Customer will give BHF at least thirty (30) days' prior written notice of any audit;
  • (b) audits will take place during BHF's normal business hours and be conducted in a manner that does not disrupt BHF's business or compromise the security or confidentiality of any other customer's data;
  • (c) the Customer may not carry out more than one audit in any twelve-month period, save where an audit is required by a Supervisory Authority or follows a Personal Data Breach;
  • (d) the Customer is responsible for the costs of any audit it commissions; and
  • (e) BHF may satisfy this obligation by providing the Customer with independent third-party audit reports (for example, ISO 27001 or SOC 2 reports, where held).

6. Personal Data Breach notification

6.1 BHF will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any case within seventy-two (72) hours of becoming aware.

6.2 The notification will contain, to the extent then known:

  • (a) a description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned;
  • (b) the likely consequences of the breach;
  • (c) the measures taken or proposed to be taken to address the breach; and
  • (d) contact details for BHF's designated point of contact.

6.3 Where BHF cannot provide all of the above information within seventy-two (72) hours, it will provide what is known within that period and provide the remainder in phases as it becomes available.

6.4 Notification of a Personal Data Breach by BHF does not, of itself, constitute an acknowledgement of fault or liability by BHF.

7. International transfers

7.1 BHF processes Customer Personal Data on infrastructure located in the European Union (Amazon Web Services, EU-West-1 region, Ireland), except where the Customer has expressly instructed otherwise or where a Sub-processor listed in Annex 3 processes data outside the EEA.

7.2 Where BHF or any Sub-processor transfers Customer Personal Data outside the European Economic Area or the United Kingdom, BHF will ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including where required the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and the United Kingdom's International Data Transfer Addendum, or such other transfer mechanism as is then recognised by Applicable Data Protection Law.

7.3 The Customer authorises BHF to enter into such transfer mechanisms on the Customer's behalf where necessary to permit the transfer to occur.

8. Controller obligations

8.1 The Customer warrants that:

  • (a) it has established a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for all Processing carried out through the Service;
  • (b) it has provided all notices to, and obtained all consents from, Data Subjects that are required by Applicable Data Protection Law;
  • (c) its instructions to BHF comply with Applicable Data Protection Law; and
  • (d) it will not use the Service to process any category of Personal Data that BHF has excluded in its documentation or Terms of Service.

9. Liability

9.1 Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions set out in the Terms of Service.

9.2 Nothing in this DPA excludes or limits either party's liability where such exclusion or limitation is prohibited by Applicable Data Protection Law.

10. Term and termination

10.1 This DPA takes effect on the date the Customer accepts BHF's Terms of Service (or the effective date of this DPA if later) and continues in force for as long as BHF processes Customer Personal Data on the Customer's behalf.

10.2 Clauses 5.7 (deletion or return), 5.8 (audits), 6 (breach notification) and 9 (liability) survive termination.

11. Amendments

11.1 BHF may amend this DPA from time to time to reflect changes in Applicable Data Protection Law, Sub-processor arrangements, or the Service. Amendments will be notified by email or in-Service notification at least thirty (30) days before the effective date, together with a new version number.

11.2 If an amendment materially reduces the protection of Customer Personal Data, the Customer may terminate the Service without penalty by giving written notice before the effective date of the amendment.

12. Governing law and jurisdiction

12.1 This DPA is governed by the laws of Ireland.

12.2 The courts of Ireland have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA.

12.3 Nothing in this clause prevents either party from bringing proceedings before a competent Supervisory Authority.

Annex 1: Description of the processing

Categories of Data Subjects. The following categories of individuals whose Personal Data the Customer processes through the Service, which may include:

  • the Customer's end customers, and the individuals working for those end customers who place orders, receive invoices or otherwise transact with the Customer;
  • the Customer's own staff and contractors who use the Service;
  • the Customer's suppliers, and individuals working for those suppliers;
  • prospective customers of the Customer;
  • recipients of communications sent by the Customer through the Service.

Types of Personal Data. Depending on the Customer's use of the Service, this may include:

  • names, business contact details (email, phone, address), and job titles;
  • order and transaction records, including order references, purchase details, prices and payment status;
  • delivery addresses and delivery instructions;
  • records of communications sent through the Service;
  • login credentials and account activity of the Customer's own users;
  • any additional Personal Data the Customer chooses to enter into free-text fields, upload as attachments, or forward to Service inboxes.

Subject matter of the processing. The provision of the BHF Service to the Customer.

Nature of the processing. Storage, retrieval, display, transmission, transformation, extraction, aggregation, matching, deletion, and other operations necessary to provide the Service.

Purpose of the processing. To enable the Customer to operate its business through the Service, including receiving and processing orders, generating invoices and delivery documentation, sending business communications, managing stock and dispatch, and integrating with the Customer's other business systems.

Duration of the processing. For as long as the Customer maintains an account with BHF, plus any post-termination retention period permitted or required under clause 5.7 or Applicable Data Protection Law.

Annex 2: Technical and organisational measures

The measures BHF currently has in place to secure Customer Personal Data include:

  • hosting on Amazon Web Services in the EU-West-1 (Ireland) region, behind AWS Web Application Firewall and CloudFront;
  • TLS 1.2 or higher for all data in transit;
  • AES-256 encryption at rest for RDS databases and S3 storage;
  • role-based access control with unique user IDs;
  • multi-factor authentication on administrative access;
  • daily database backups with point-in-time recovery;
  • application and access logging via Amazon CloudWatch;
  • regular dependency scanning and patching;
  • sub-processor risk assessed before engagement and reviewed on an ongoing basis;
  • a documented incident response process with the 72-hour customer notification commitment set out in clause 6.

A more detailed statement of measures is available on request to adam@semad.ie.

Annex 3: Sub-processors

The current list of Sub-processors BHF engages to process Customer Personal Data is set out below. The definitive and continuously-maintained list is available at bizherofor.com/subprocessors.php.

Sub-processorService providedLocation of processing
Amazon Web Services EMEA SARLHosting, storage, backup, compute (EC2, RDS, S3), machine learning inference (Amazon Bedrock)European Union (EU-West-1, Ireland)
Twilio SendgridTransactional and marketing email deliveryEuropean Union / United States (with appropriate transfer safeguards)
Mailchimp (Intuit)Marketing email delivery for customers who enable this integrationUnited States (with appropriate transfer safeguards)
Stripe Payments Europe LtdPayment processing for customers who enable this integrationEuropean Union
PayPal (Europe) S.a.r.l. et Cie, S.C.A.Payment processing for customers who enable this integrationEuropean Union
Big Red Cloud LtdAccounting integration for customers who enable this integrationIreland
Xero (UK) LtdAccounting integration for customers who enable this integrationUnited Kingdom
Intuit QuickBooksAccounting integration for customers who enable this integrationUnited States (with appropriate transfer safeguards)
SortMyBooksAccounting integration for customers who enable this integrationIreland
Stock In The ChannelProduct data integration for customers who enable this integrationUnited Kingdom
Microsoft CorporationMail integration (Microsoft 365) for customers who enable this integrationEuropean Union / United States (with appropriate transfer safeguards)
Google Ireland LtdGoogle Business Profile integration for customers who enable this integrationEuropean Union / United States (with appropriate transfer safeguards)

If you have any questions about this Data Processing Agreement, please contact us at adam@semad.ie.

-->