
Data Processing Agreement
Data Processing Agreement
Last Updated on 25 Jun, 2026
Parties and Execution
Entity details: | Entity details: |
Variables
Parties’ relationship | Controller to Processor | |
Parties’ roles | The parties intend that:
| |
Contacts | Controller | Processor |
As set out in the Main Agreement (via the Order). | As set out in the Notices clause of the Main Agreement. | |
Main Agreement | The LightWork Terms accepted by the Customer at checkout, which incorporate the Order. | |
Term | This DPA will commence on the Effective Date as set out in the Main Agreement and will continue for the Term as set out in the Main Agreement. | |
Breach Notification Period | Without undue delay after becoming aware of a personal data breach. | |
Sub-processor Notification Period | Not less than 14 days before the new sub-processor is granted access to Personal Data. Such notification shall include the name, location and processing activities of the proposed sub-processor. | |
Liability Cap | Each party’s aggregate liability under this DPA will not exceed the liability caps as per the Main Agreement. | |
Governing Law and Jurisdiction | As per the Main Agreement. | |
Data Protection Laws | All laws, regulations and court orders which apply to the processing of personal data in the United Kingdom (“UK”). This includes the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended from time to time. | |
Services related to processing | As described in the Main Agreement. | |
Duration of processing | For the Term of this DPA. | |
Nature and purpose of processing | Required personal data The purpose of the Personal Data processing for the identifiable in-scope Personal Data is to enable the Customer’s personnel to access and use the Services and for LightWork to provide the Services. Specifically, to automate tasks and streamline communication between parties involved in lettings, sales and property management workflows. This includes the collection, storage, updating and deletion of such Personal Data. LightWork may also de-identify and aggregate Personal Data for the purpose of improving the Services, as permitted by the Main Agreement. Incidental personal data The Services involve the receipt of unstructured inputs from data subjects via chat, email, WhatsApp, SMS, voice call and other communication channels. As a consequence of providing the Services, LightWork may incidentally receive Personal Data that is not required for, and which LightWork does not seek or solicit in connection with, the provision of the Services ("Incidental Personal Data"). LightWork does not deliberately collect, process or retain Incidental Personal Data and applies the data minimisation measures set out below to limit its retention and use. Any Incidental Personal Data (as described in the Personal Data section below) is not required by LightWork in order to provide the Services. To the extent Incidental Personal Data is processed, the purpose is limited to providing the Services in accordance with the Customer's instructions. LightWork does not process Incidental Personal Data for any independent purpose, other than de-identifying and aggregating data as permitted by the Main Agreement. The Processor shall implement and maintain technical and organisational measures, proportionate to the nature and volume of processing, to minimise the receipt, retention and use of Incidental Personal Data and to give effect to the data minimisation principle. These measures include:
The Processor shall review its data minimisation measures at least annually. The Customer acknowledges that the Services receive unstructured inputs and accordingly the Customer shall:
| |
Personal Data | Required personal data The types of personal data processed are: Tenants
Prospective Tenants
Prospective Buyers
Contractors
Landlords
Customer’s Personnel
Incidental Personal Data LightWork may incidentally receive Personal Data that is not identified as required Personal Data in the section above, as a consequence of the Services receiving unstructured inputs. This Incidental Personal Data is not required by LightWork to provide the Services and is not deliberately collected or processed. Categories may include:
Personal Data processed under this DPA may include special categories of personal data as defined in Article 9 UK GDPR, disclosed incidentally by data subjects through unstructured communications. The Processor shall not actively solicit special category data and shall apply appropriate access controls to any such data identified. The Customer is responsible for ensuring that it has an appropriate lawful basis under Article 9 UK GDPR for the processing of any special categories of personal data that may be included in Personal Data provided to or shared with LightWork. | |
Data subjects | The individuals whose Personal Data will be processed are:
| |
Transfer Mechanism | Personal Data may be transferred to sub-processors located outside the UK. Where such transfers are made to sub-processors in the European Economic Area, they are made in reliance on the adequacy regulations made under section 17A of the Data Protection Act 2018. Where such transfers are made to sub-processors located outside the UK and the EEA, the Processor shall ensure that an appropriate transfer mechanism is in place, including the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK Addendum, the UK Extension to the EU-US Data Privacy Framework, or another transfer mechanism recognised as valid under Data Protection Laws. The Processor shall notify the Controller in accordance with 3.3 before engaging any sub-processor that would process Personal Data outside the UK. | |
Annex 1
Security measures. Technical and organisational measures to ensure the security of Personal Data | Security measures found at: www.lightwork.co/legal/security-measures-and-sub-processors |
Annex 2
Sub-processors. Current sub-processors | List of sub-processors found at: www.lightwork.co/legal/security-measures-and-sub-processors |
Terms
1.
What is this agreement about?
1.1
Purpose. The parties are entering into this Data Processing Agreement (DPA) for the purpose of processing Personal Data (as defined above).
1.2
2.
What are each party’s obligations?
2.1
Controller obligations. Controller instructs Processor to process Personal Data in accordance with this DPA, including through any Affiliate to whom the Main Agreement is assigned in accordance with its terms, and is responsible for providing all notices and obtaining all consents, licences and legal bases required to allow Processor to process Personal Data.
2.2
2.3
Warranties. The parties warrant that they and any staff and/or subcontractors will comply with their respective obligations under Data Protection Laws for the Term.
3.
Sub-processing
3.1
Use of sub-processors. Controller gives general consent for Processor to engage other processors (referred to in this section as sub-processors) when processing Personal Data. Processor’s existing sub-processors are listed in Annex 2.
3.2
3.3
Approvals. Processor may appoint new sub-processors provided that they notify Controller in writing in accordance with the Sub-processor Notification Period.
3.4
Objection to sub-processors.
(a) Controller may reasonably object in writing to any future sub-processor, provided that the objection is based on reasonable grounds relating to the security or privacy of Personal Data which cannot be adequately mitigated by the measures described in 3.2 and Annex 1.
(b) If Controller objects, Processor may propose an alternative sub-processor or additional measures to address the objection, and Controller shall not unreasonably refuse to accept such alternative.
(c) If the parties do not agree on a solution within 30 days of the objection, either party may terminate the Services under the affected Main Agreement that cannot be provided without the objected-to sub-processor on 30 days' written notice.
(d) During any objection period, the Processor shall not grant the proposed sub-processor access to the Controller's Personal Data until the objection is resolved.
3.5
Urgency. In the event that Processor needs to replace a sub-processor urgently due to a security incident or legal requirement, the Sub-processor Notification Period shall not apply, provided that Processor notifies Controller as soon as reasonably practicable.
4.
International Personal Data transfers
4.1
Instructions. Processor will transfer Personal Data outside the UK, the EEA or an adequate country only on documented instructions from Controller, unless otherwise required by law.
4.2
Transfer mechanism. Where a party is located outside the UK, the EEA or an adequate country and receives Personal Data:
(a) that party will act as the data importer;
(b) the other party is the data exporter; and
(c) the relevant Transfer Mechanism will apply.
4.3
Additional measures. If the Transfer Mechanism is insufficient to safeguard the transferred Personal Data, the data importer will promptly implement supplementary measures to ensure Personal Data is protected to the same standard as required under Data Protection Laws.
4.4
Disclosures. Subject to terms of the relevant Transfer Mechanism, if the data importer receives a request from a public authority to access Personal Data, it will (if legally allowed):
(a) challenge the request and promptly notify the data exporter about it; and
(b) only disclose to the public authority the minimum amount of Personal Data required and keep a record of the disclosure.
5.
Other important information
5.1
Execution and acceptance. This DPA is entered into and executed electronically when the Customer accepts the Main Agreement at checkout (via an Order). The Customer's name, title, company and the date of acceptance are those recorded by LightWork at checkout and form part of this DPA. No manual signature is required.
5.2
Survival. 2.2(e), 2.2(f), 2.2(j), 2.2(k), 4 and 5 shall survive the expiry or termination of this DPA. The Processor's obligations shall continue in respect of any Personal Data retained after termination.
5.3
Order of precedence. In case of a conflict between this DPA and other relevant agreements, they will take priority in this order:
(a) Transfer Mechanism,
(b) DPA,
(c) Main Agreement.
5.4
Notices. Formal notices under this DPA must be in writing and sent to the Contact on the DPA’s front page as may be updated by a party to the other in writing.
5.5
Third parties. Except for Affiliates, no one other than a party to this DPA has the right to enforce any of its terms.
5.6
Entire agreement. This DPA and the Main Agreement supersede all prior discussions and agreements and constitute the entire agreement between the parties with respect to their subject matter and neither party has relied on any statement or representation of any person in entering into this DPA.
5.7
Amendments. LightWork may amend this DPA on not less than 30 days' written notice, provided that, where any amendment would materially reduce the protection of Personal Data or the Customer's rights under this DPA, the Customer may terminate the affected Services before it takes effect. Continued use of the Services after the amendment constitutes acceptance.
5.8
Assignment. Neither party can assign this DPA to anyone else without the other party's consent, provided that assignment of this DPA to an Affiliate or acquirer shall be permitted in accordance with the assignment provisions of the Main Agreement, and any assignment of the Main Agreement shall automatically include assignment of this DPA.
5.9
Waiver. If a party fails to enforce a right under this DPA, that is not a waiver of that right at any time.
5.10
Governing law and jurisdiction. The Governing Law applies to this DPA and all disputes will only be litigated in the courts of the Jurisdiction.



