Version: 1.0
Effective date: 13 August 2026
Last updated: 13 August 2026
1.1 This Data Processing Agreement ("DPA") is entered into between:
1.2 This DPA forms part of, and is incorporated into, BHF's Terms of Service. In the event of any conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.
2.1 In this DPA, the following terms have the following meanings:
3.1 This DPA applies whenever BHF processes Customer Personal Data on the Customer's behalf in connection with the Service.
3.2 The parties acknowledge that, in relation to Customer Personal Data:
3.3 In relation to Personal Data that BHF collects and processes about the Customer itself (for example, the Customer's account holder name, billing details, and login records), BHF acts as Controller. That processing is governed by BHF's Privacy Policy, not this DPA.
3.4 The parties do not intend, by this DPA, to establish any joint controllership relationship under Article 26 GDPR.
4.1 The subject matter, duration, nature and purpose of the processing, the type of Personal Data, and the categories of Data Subjects are set out in Annex 1.
4.2 The Customer's documented instructions to BHF consist of:
4.3 If BHF believes that a Customer instruction infringes Applicable Data Protection Law, BHF will inform the Customer without undue delay and may refuse to carry out the instruction until it is amended or withdrawn.
BHF, as Processor, undertakes the following obligations, which reflect the requirements of Article 28(3) of the EU GDPR and the equivalent provisions of the UK GDPR.
BHF will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of Customer Personal Data to a third country or an international organisation, unless required to do otherwise by EU or Member State law (or the law of the United Kingdom, where UK GDPR applies) to which BHF is subject. In such a case, BHF will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
BHF will ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. BHF limits access to Customer Personal Data to those of its personnel who need it to perform their duties.
BHF will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of natural persons. The measures currently in place are described in Annex 2. BHF may update Annex 2 from time to time provided the overall level of security is not materially reduced.
5.4.1 The Customer gives BHF general written authorisation to engage Sub-processors, subject to the conditions in this clause.
5.4.2 The current list of Sub-processors is set out in Annex 3 and is also maintained at bizherofor.com/subprocessors.php.
5.4.3 BHF will give the Customer at least thirty (30) days' prior notice before adding or replacing a Sub-processor. Notice will be given by email to the address the Customer has provided for that purpose, or by an in-Service notification, or by updating the Sub-processor list published at the URL above with a version change.
5.4.4 The Customer may object to a proposed new Sub-processor on reasonable data protection grounds within fourteen (14) days of receiving notice. If the Customer objects and the parties cannot reach a resolution, the Customer may terminate the parts of the Service that require the objected-to Sub-processor, or the Service in full, without penalty, by giving BHF written notice.
5.4.5 Where BHF engages a Sub-processor, BHF will impose on that Sub-processor, by contract, data protection obligations that are equivalent in substance to those imposed on BHF under this DPA. BHF remains fully liable to the Customer for the performance of each Sub-processor's obligations.
Taking into account the nature of the processing, BHF will assist the Customer, by appropriate technical and organisational measures and insofar as it is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.
Taking into account the nature of the processing and the information available to BHF, BHF will assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR, including in relation to security of processing, personal data breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.
On termination or expiry of the Service, or at any earlier time on the Customer's written request, BHF will, at the Customer's choice, delete or return all Customer Personal Data to the Customer and delete existing copies. This obligation is subject to:
BHF will confirm deletion in writing on request.
5.8.1 BHF will make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.
5.8.2 BHF will allow for, and contribute to, audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. To keep audits proportionate and to protect the security of BHF's other customers, the parties agree that:
6.1 BHF will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any case within seventy-two (72) hours of becoming aware.
6.2 The notification will contain, to the extent then known:
6.3 Where BHF cannot provide all of the above information within seventy-two (72) hours, it will provide what is known within that period and provide the remainder in phases as it becomes available.
6.4 Notification of a Personal Data Breach by BHF does not, of itself, constitute an acknowledgement of fault or liability by BHF.
7.1 BHF processes Customer Personal Data on infrastructure located in the European Union (Amazon Web Services, EU-West-1 region, Ireland), except where the Customer has expressly instructed otherwise or where a Sub-processor listed in Annex 3 processes data outside the EEA.
7.2 Where BHF or any Sub-processor transfers Customer Personal Data outside the European Economic Area or the United Kingdom, BHF will ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including where required the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and the United Kingdom's International Data Transfer Addendum, or such other transfer mechanism as is then recognised by Applicable Data Protection Law.
7.3 The Customer authorises BHF to enter into such transfer mechanisms on the Customer's behalf where necessary to permit the transfer to occur.
8.1 The Customer warrants that:
9.1 Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions set out in the Terms of Service.
9.2 Nothing in this DPA excludes or limits either party's liability where such exclusion or limitation is prohibited by Applicable Data Protection Law.
10.1 This DPA takes effect on the date the Customer accepts BHF's Terms of Service (or the effective date of this DPA if later) and continues in force for as long as BHF processes Customer Personal Data on the Customer's behalf.
10.2 Clauses 5.7 (deletion or return), 5.8 (audits), 6 (breach notification) and 9 (liability) survive termination.
11.1 BHF may amend this DPA from time to time to reflect changes in Applicable Data Protection Law, Sub-processor arrangements, or the Service. Amendments will be notified by email or in-Service notification at least thirty (30) days before the effective date, together with a new version number.
11.2 If an amendment materially reduces the protection of Customer Personal Data, the Customer may terminate the Service without penalty by giving written notice before the effective date of the amendment.
12.1 This DPA is governed by the laws of Ireland.
12.2 The courts of Ireland have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA.
12.3 Nothing in this clause prevents either party from bringing proceedings before a competent Supervisory Authority.
Categories of Data Subjects. The following categories of individuals whose Personal Data the Customer processes through the Service, which may include:
Types of Personal Data. Depending on the Customer's use of the Service, this may include:
Subject matter of the processing. The provision of the BHF Service to the Customer.
Nature of the processing. Storage, retrieval, display, transmission, transformation, extraction, aggregation, matching, deletion, and other operations necessary to provide the Service.
Purpose of the processing. To enable the Customer to operate its business through the Service, including receiving and processing orders, generating invoices and delivery documentation, sending business communications, managing stock and dispatch, and integrating with the Customer's other business systems.
Duration of the processing. For as long as the Customer maintains an account with BHF, plus any post-termination retention period permitted or required under clause 5.7 or Applicable Data Protection Law.
The measures BHF currently has in place to secure Customer Personal Data include:
A more detailed statement of measures is available on request to adam@semad.ie.
The current list of Sub-processors BHF engages to process Customer Personal Data is set out below. The definitive and continuously-maintained list is available at bizherofor.com/subprocessors.php.
| Sub-processor | Service provided | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, backup, compute (EC2, RDS, S3), machine learning inference (Amazon Bedrock) | European Union (EU-West-1, Ireland) |
| Twilio Sendgrid | Transactional and marketing email delivery | European Union / United States (with appropriate transfer safeguards) |
| Mailchimp (Intuit) | Marketing email delivery for customers who enable this integration | United States (with appropriate transfer safeguards) |
| Stripe Payments Europe Ltd | Payment processing for customers who enable this integration | European Union |
| PayPal (Europe) S.a.r.l. et Cie, S.C.A. | Payment processing for customers who enable this integration | European Union |
| Big Red Cloud Ltd | Accounting integration for customers who enable this integration | Ireland |
| Xero (UK) Ltd | Accounting integration for customers who enable this integration | United Kingdom |
| Intuit QuickBooks | Accounting integration for customers who enable this integration | United States (with appropriate transfer safeguards) |
| SortMyBooks | Accounting integration for customers who enable this integration | Ireland |
| Stock In The Channel | Product data integration for customers who enable this integration | United Kingdom |
| Microsoft Corporation | Mail integration (Microsoft 365) for customers who enable this integration | European Union / United States (with appropriate transfer safeguards) |
| Google Ireland Ltd | Google Business Profile integration for customers who enable this integration | European Union / United States (with appropriate transfer safeguards) |
If you have any questions about this Data Processing Agreement, please contact us at adam@semad.ie.