Data Processing Agreement


Data Processing Agreement

Last Updated on 25 Jun, 2026

Parties and Execution

Entity details: 
LightWork Holding Ltd
Company number: 15027977
Registered office address: 83 Victoria Street, London, England SW1H 0HW
(referred to as “LightWork” in the Main Agreement and “LightWork” or “Processor” in this DPA).

Entity details: 
The “Customer” as set out in the Main Agreement.
(referred to as “Customer” in the Main Agreement and “Customer” or “Controller” in this DPA).


Variables

Parties’ relationship

Controller to Processor

Parties’ roles

The parties intend that:

  1. the Customer will act as the Controller; and 

  2. LightWork will act as the Processor. 

Contacts

Controller

Processor

As set out in the Main Agreement (via the Order).

As set out in the Notices clause of the Main Agreement.

Main Agreement

The LightWork Terms accepted by the Customer at checkout, which incorporate the Order.

Term

This DPA will commence on the Effective Date as set out in the Main Agreement and will continue for the Term as set out in the Main Agreement.

Breach Notification Period

Without undue delay after becoming aware of a personal data breach.

Sub-processor Notification Period

Not less than 14 days before the new sub-processor is granted access to Personal Data. Such notification shall include the name, location and processing activities of the proposed sub-processor.

Liability Cap

Each party’s aggregate liability under this DPA will not exceed the liability caps as per the Main Agreement.

Governing Law and Jurisdiction

As per the Main Agreement.

Data Protection Laws

All laws, regulations and court orders which apply to the processing of personal data in the United Kingdom (“UK”). This includes the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended from time to time.

Services related to processing

As described in the Main Agreement.

Duration of processing

For the Term of this DPA.

Nature and purpose of processing

Required personal data

The purpose of the Personal Data processing for the identifiable in-scope Personal Data is to enable the Customer’s personnel to access and use the Services and for LightWork to provide the Services. Specifically, to automate tasks and streamline communication between parties involved in lettings, sales and property management workflows. This includes the collection, storage, updating and deletion of such Personal Data.

LightWork may also de-identify and aggregate Personal Data for the purpose of improving the Services, as permitted by the Main Agreement.

Incidental personal data

The Services involve the receipt of unstructured inputs from data subjects via chat, email, WhatsApp, SMS, voice call and other communication channels. As a consequence of providing the Services, LightWork may incidentally receive Personal Data that is not required for, and which LightWork does not seek or solicit in connection with, the provision of the Services ("Incidental Personal Data"). LightWork does not deliberately collect, process or retain Incidental Personal Data and applies the data minimisation measures set out below to limit its retention and use.

Any Incidental Personal Data (as described in the Personal Data section below) is not required by LightWork in order to provide the Services. 

To the extent Incidental Personal Data is processed, the purpose is limited to providing the Services in accordance with the Customer's instructions. LightWork does not process Incidental Personal Data for any independent purpose, other than de-identifying and aggregating data as permitted by the Main Agreement.

The Processor shall implement and maintain technical and organisational measures, proportionate to the nature and volume of processing, to minimise the receipt, retention and use of Incidental Personal Data and to give effect to the data minimisation principle. These measures include: 

  1. role-based access controls limiting personnel access to Personal Data on a need-to-know basis; 

  2. automated deletion of AI prompts and responses in accordance with the Processor's data retention policy; 

  3. configuration of zero-data-retention settings with AI model providers where available; and 

  4. ongoing development of technical capabilities to identify, flag and manage special category data within unstructured inputs. 

The Processor shall review its data minimisation measures at least annually.

The Customer acknowledges that the Services receive unstructured inputs and accordingly the Customer shall:

  1. limit the amount of Incidental Personal Data provided to LightWork; and

  2. ensure that it has an appropriate lawful basis for any Personal Data (including special categories of personal data) that is provided to or processed by LightWork. 

Personal Data

Required personal data 

The types of personal data processed are:

Tenants

  • Identity data: first name, last name

  • Contact data: email address, telephone number, residential address

  • Communication data: email, SMS/WhatsApp and call log content

Prospective Tenants

  • Identity data: first name, last name

  • Contact data: email address, telephone number

  • Financial data: details of any adverse credit, combined household income 

  • Employment data: employment status, employment tenure

  • Communication data: email, SMS/WhatsApp and call log content

Prospective Buyers

  • Identity data: first name, last name

  • Contact data: email address, telephone number

  • Financial data: details of financing, mortgage status 

  • Communication data: email, SMS/WhatsApp and call log content

Contractors

  • Identity data: first name, last name, employer

  • Contact data: email address (work), telephone number (personal or work)

  • Job data: specialisation (what type of maintenance they provide, or type of certificate the Contractor services), service area (the geographical area the Contractor provides their services)

  • Communication data: email, SMS/WhatsApp and call log content

Landlords

  • Identity data: first name, last name

  • Contact data: email address (personal or work), telephone number (personal or work)

  • Communication data: email, SMS/WhatsApp and call log content

Customer’s Personnel

  • Identity data: first name, last name, job title/role 

  • Contact data: email address (work), telephone number (work)

  • Communication data: email, SMS/WhatsApp and call log content

Incidental Personal Data

LightWork may incidentally receive Personal Data that is not identified as required Personal Data in the section above, as a consequence of the Services receiving unstructured inputs. This Incidental Personal Data is not required by LightWork to provide the Services and is not deliberately collected or processed. Categories may include:

  1. Any additional Personal Data that may be shared by: 
    a. the Customer’s personnel via the user interface of the Services (specifically as input via the chat functionality); and
    b. data subjects when communicating with the Services via email, WhatsApp, SMS or voice call; and

  2. Any additional Personal Data that may be accessed and processed by LightWork via its access to the Customer’s:
    a. inbound or front-of-house email or messaging inbox (or similar); and
    b. property management system or CRM.

Personal Data processed under this DPA may include special categories of personal data as defined in Article 9 UK GDPR, disclosed incidentally by data subjects through unstructured communications. The Processor shall not actively solicit special category data and shall apply appropriate access controls to any such data identified.

The Customer is responsible for ensuring that it has an appropriate lawful basis under Article 9 UK GDPR for the processing of any special categories of personal data that may be included in Personal Data provided to or shared with LightWork.

Data subjects

The individuals whose Personal Data will be processed are:

  • Tenants

  • Prospective Tenants

  • Prospective Buyers

  • Contractors

  • Landlords 

  • Customer’s personnel

Transfer Mechanism 

Personal Data may be transferred to sub-processors located outside the UK. 

Where such transfers are made to sub-processors in the European Economic Area, they are made in reliance on the adequacy regulations made under section 17A of the Data Protection Act 2018. 

Where such transfers are made to sub-processors located outside the UK and the EEA, the Processor shall ensure that an appropriate transfer mechanism is in place, including the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK Addendum, the UK Extension to the EU-US Data Privacy Framework, or another transfer mechanism recognised as valid under Data Protection Laws. 

The Processor shall notify the Controller in accordance with 3.3 before engaging any sub-processor that would process Personal Data outside the UK.


Annex 1

Security measures. Technical and organisational measures to ensure the security of Personal Data

Security measures found at: www.lightwork.co/legal/security-measures-and-sub-processors


Annex 2

Sub-processors. Current sub-processors 

List of sub-processors found at: www.lightwork.co/legal/security-measures-and-sub-processors

Terms

1.

What is this agreement about?

1.1

Purpose. The parties are entering into this Data Processing Agreement (DPA) for the purpose of processing Personal Data (as defined above).

1.2

Definitions. Under this DPA:
(a) adequate country means a country or territory that is recognised under Data Protection Laws from time to time as providing adequate protection for processing Personal Data; 

(b) Controller, data subject, personal data breach, process/processing, Processor and supervisory authority have the same meanings as in the Data Protection Laws; and

(c) Capitalised terms used but not defined in this DPA have the meaning given to them in the Main Agreement.

(d) Personal Data means the personal data described in the Variables and references to personal data in lower case have the meaning given under Data Protection Laws.

Definitions. Under this DPA:
(a) adequate country means a country or territory that is recognised under Data Protection Laws from time to time as providing adequate protection for processing Personal Data; 

(b) Controller, data subject, personal data breach, process/processing, Processor and supervisory authority have the same meanings as in the Data Protection Laws; and

(c) Capitalised terms used but not defined in this DPA have the meaning given to them in the Main Agreement.

(d) Personal Data means the personal data described in the Variables and references to personal data in lower case have the meaning given under Data Protection Laws.

2.

What are each party’s obligations?

2.1

Controller obligations. Controller instructs Processor to process Personal Data in accordance with this DPA, including through any Affiliate to whom the Main Agreement is assigned in accordance with its terms, and is responsible for providing all notices and obtaining all consents, licences and legal bases required to allow Processor to process Personal Data.

2.2

Processor obligations. Processor will:
(a) only process Personal Data in accordance with this DPA and Controller’s instructions (unless legally required to do otherwise);

(b) not sell, retain or use any Personal Data for any purpose other than as permitted by this DPA and the Main Agreement;

(c) inform Controller immediately if (in its opinion) any instructions infringe Data Protection Laws;

(d) use the technical and organisational measures described in Annex 1 when processing Personal Data to ensure a level of security appropriate to the risk involved;

(e) notify Controller of a personal data breach within the Breach Notification Period and provide assistance to Controller as required under Data Protection Laws in responding to it;

(f) ensure that anyone authorised to process Personal Data is committed to enforceable confidentiality obligations and has access limited to the Personal Data necessary for their role;

(g) without undue delay, provide Controller with reasonable assistance with: 

(i) data protection impact assessments;

(ii) responses to data subjects’ requests to exercise their rights under Data Protection Laws; and 

(iii) engagement with supervisory authorities. The Processor shall not make any admission or statement to a supervisory authority regarding the Controller's

processing without the Controller's prior written consent, except where required by law;

(h) if requested, provide Controller with information necessary to demonstrate its compliance with obligations under Data Protection Laws and this DPA;

(i) allow for audits at Controller’s reasonable request, provided that: 

(i) Processor may meet an audit request by providing its current certifications, latest penetration test summary, technical and organisational measures and a

completed security questionnaire, with an on-site audit only where these do not reasonably address the Controller's concerns;

(ii) audits are limited to once a year and during business hours, on not less than 20 Business Days’ notice;

(iii) the Controller may use a qualified third-party auditor, subject to the auditor being bound by confidentiality obligations acceptable to the Processor (not to be

unreasonably withheld); and 

(iv) the Controller shall bear the cost of the audit; 

(j) return Personal Data upon Controller’s written request or delete Personal Data within 45 days following the end of the Term (subject to the data return provisions of

the Main Agreement), unless retention is legally required; and 

(k) not retain Personal Data for longer than is necessary for the purposes of processing, and shall delete or anonymise Personal Data in accordance with its retention

policy, details of which are available to the Controller on request.

Processor obligations. Processor will:
(a) only process Personal Data in accordance with this DPA and Controller’s instructions (unless legally required to do otherwise);

(b) not sell, retain or use any Personal Data for any purpose other than as permitted by this DPA and the Main Agreement;

(c) inform Controller immediately if (in its opinion) any instructions infringe Data Protection Laws;

(d) use the technical and organisational measures described in Annex 1 when processing Personal Data to ensure a level of security appropriate to the risk involved;

(e) notify Controller of a personal data breach within the Breach Notification Period and provide assistance to Controller as required under Data Protection Laws in responding to it;

(f) ensure that anyone authorised to process Personal Data is committed to enforceable confidentiality obligations and has access limited to the Personal Data necessary for their role;

(g) without undue delay, provide Controller with reasonable assistance with: 

(i) data protection impact assessments;

(ii) responses to data subjects’ requests to exercise their rights under Data Protection Laws; and 

(iii) engagement with supervisory authorities. The Processor shall not make any admission or statement to a supervisory authority regarding the Controller's processing without the Controller's prior written consent, except where required by law;

(h) if requested, provide Controller with information necessary to demonstrate its compliance with obligations under Data Protection Laws and this DPA;

(i) allow for audits at Controller’s reasonable request, provided that: 

(i) Processor may meet an audit request by providing its current certifications, latest penetration test summary, technical and organisational measures and a completed security questionnaire, with an on-site audit only where these do not reasonably address the Controller's concerns;

(ii) audits are limited to once a year and during business hours, on not less than 20 Business Days’ notice;

(iii) the Controller may use a qualified third-party auditor, subject to the auditor being bound by confidentiality obligations acceptable to the Processor (not to be unreasonably withheld); and 

(iv) the Controller shall bear the cost of the audit; 

(j) return Personal Data upon Controller’s written request or delete Personal Data within 45 days following the end of the Term (subject to the data return provisions of the Main Agreement), unless retention is legally required; and 

(k) not retain Personal Data for longer than is necessary for the purposes of processing, and shall delete or anonymise Personal Data in accordance with its retention policy, details of which are available to the Controller on request.

2.3

Warranties. The parties warrant that they and any staff and/or subcontractors will comply with their respective obligations under Data Protection Laws for the Term.

3.

Sub-processing

3.1

Use of sub-processors. Controller gives general consent for Processor to engage other processors (referred to in this section as sub-processors) when processing Personal Data. Processor’s existing sub-processors are listed in Annex 2.

3.2

Sub-processor requirements. Processor will: 
(a) require its sub-processors to comply with equivalent terms as Processor’s obligations in this DPA;
(b) ensure appropriate safeguards are in place before internationally transferring Personal Data to its sub-processor;
(c) be liable for any acts, errors or omissions of its sub-processors as if they were a party to this DPA; and
(d) conduct reasonable due diligence on each sub-processor's data protection practices and security measures prior to engagement, maintain records of such due

diligence, and make a summary available to the Controller on reasonable request.

Sub-processor requirements. Processor will: 
(a) require its sub-processors to comply with equivalent terms as Processor’s obligations in this DPA;
(b) ensure appropriate safeguards are in place before internationally transferring Personal Data to its sub-processor;
(c) be liable for any acts, errors or omissions of its sub-processors as if they were a party to this DPA; and
(d) conduct reasonable due diligence on each sub-processor's data protection practices and security measures prior to engagement, maintain records of such due diligence, and make a summary available to the Controller on reasonable request.

3.3

Approvals. Processor may appoint new sub-processors provided that they notify Controller in writing in accordance with the Sub-processor Notification Period.

3.4

Objection to sub-processors.
(a) Controller may reasonably object in writing to any future sub-processor, provided that the objection is based on reasonable grounds relating to the security or privacy of Personal Data which cannot be adequately mitigated by the measures described in 3.2 and Annex 1.
(b) If Controller objects, Processor may propose an alternative sub-processor or additional measures to address the objection, and Controller shall not unreasonably refuse to accept such alternative.
(c) If the parties do not agree on a solution within 30 days of the objection, either party may terminate the Services under the affected Main Agreement that cannot be provided without the objected-to sub-processor on 30 days' written notice.
(d) During any objection period, the Processor shall not grant the proposed sub-processor access to the Controller's Personal Data until the objection is resolved.

3.5

Urgency. In the event that Processor needs to replace a sub-processor urgently due to a security incident or legal requirement, the Sub-processor Notification Period shall not apply, provided that Processor notifies Controller as soon as reasonably practicable.

4.

International Personal Data transfers

4.1

Instructions. Processor will transfer Personal Data outside the UK, the EEA or an adequate country only on documented instructions from Controller, unless otherwise required by law.

4.2

Transfer mechanism. Where a party is located outside the UK, the EEA or an adequate country and receives Personal Data: 
(a) that party will act as the data importer;
(b) the other party is the data exporter; and
(c) the relevant Transfer Mechanism will apply.

4.3

Additional measures. If the Transfer Mechanism is insufficient to safeguard the transferred Personal Data, the data importer will promptly implement supplementary measures to ensure Personal Data is protected to the same standard as required under Data Protection Laws.

4.4

Disclosures. Subject to terms of the relevant Transfer Mechanism, if the data importer receives a request from a public authority to access Personal Data, it will (if legally allowed):
(a) challenge the request and promptly notify the data exporter about it; and
(b) only disclose to the public authority the minimum amount of Personal Data required and keep a record of the disclosure.

5.

Other important information

5.1

Execution and acceptance. This DPA is entered into and executed electronically when the Customer accepts the Main Agreement at checkout (via an Order). The Customer's name, title, company and the date of acceptance are those recorded by LightWork at checkout and form part of this DPA. No manual signature is required.

5.2

Survival. 2.2(e), 2.2(f), 2.2(j), 2.2(k), 4 and 5 shall survive the expiry or termination of this DPA. The Processor's obligations shall continue in respect of any Personal Data retained after termination.

5.3

Order of precedence. In case of a conflict between this DPA and other relevant agreements, they will take priority in this order: 
(a) Transfer Mechanism,
(b) DPA,
(c) Main Agreement.

5.4

Notices. Formal notices under this DPA must be in writing and sent to the Contact on the DPA’s front page as may be updated by a party to the other in writing.

5.5

Third parties. Except for Affiliates, no one other than a party to this DPA has the right to enforce any of its terms.

5.6

Entire agreement. This DPA and the Main Agreement supersede all prior discussions and agreements and constitute the entire agreement between the parties with respect to their subject matter and neither party has relied on any statement or representation of any person in entering into this DPA.

5.7

Amendments. LightWork may amend this DPA on not less than 30 days' written notice, provided that, where any amendment would materially reduce the protection of Personal Data or the Customer's rights under this DPA, the Customer may terminate the affected Services before it takes effect. Continued use of the Services after the amendment constitutes acceptance.

5.8

Assignment. Neither party can assign this DPA to anyone else without the other party's consent, provided that assignment of this DPA to an Affiliate or acquirer shall be permitted in accordance with the assignment provisions of the Main Agreement, and any assignment of the Main Agreement shall automatically include assignment of this DPA.

5.9

Waiver. If a party fails to enforce a right under this DPA, that is not a waiver of that right at any time.

5.10

Governing law and jurisdiction. The Governing Law applies to this DPA and all disputes will only be litigated in the courts of the Jurisdiction.

Ready to let Felicity handle the admin?

Book a walk-through to see exactly how Felicity can streamline your property operations

83 Victoria Street, London, SW1H 0HW

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

propertymark industry supplier badge
SOC 2 badge
ISO/IEC 27001 certification badge
LightWork AI Cyber Essentials Plus certification badge

Ready to let Felicity handle the admin?

Book a walk-through to see exactly how Felicity can streamline your property operations

83 Victoria Street, London, SW1H 0HW

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

propertymark industry supplier badge
SOC 2 badge
ISO/IEC 27001 certification badge
LightWork AI Cyber Essentials Plus certification badge

Ready to let Felicity handle the admin?

Book a walk-through to see exactly how Felicity can streamline your property operations

83 Victoria Street, London, SW1H 0HW

© 2026 LightWork Holding Ltd. Company No. 15027977 · VAT: GB488579216

propertymark industry supplier badge
SOC 2 badge
ISO/IEC 27001 certification badge
LightWork AI Cyber Essentials Plus certification badge