GROWTHAIQ / SYSTEM ONLINE
by Codaiq LTD
01System02Solutions03Engagements04Insights

GrowthAIQ quick navigation

Search pages and actions

DE/EN
Assess potential ↗

Legal

Data Processing Agreement

Effective: 25 August 2026

Standard DPA under Article 28 GDPR / UK GDPR · incorporated through the proposal or mutual confirmation

1. Parties and subject

The controller is the Customer identified in the proposal. The processor is Codaiq LTD, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. This DPA applies where GrowthAIQ processes personal data on the Customer’s behalf.

2. Duration, nature and purpose

Processing continues for the main contract plus orderly return and deletion periods. Depending on scope, processing may cover hosting, development, maintenance, automation, analysis, CRM and workflow integration, AI-assisted processing, support and client portal access.

3. Data and data subjects

Possible categories include identity, contact, communication, content, contract, billing, usage, device, log, CRM, marketing, support and process data. Data subjects may include employees, customers, prospects, suppliers, partners and users. Special-category data is processed only where expressly agreed and additionally protected.

4. Instructions

The processor acts only on documented Customer instructions, including international transfers, unless legally required otherwise. The main contract, configurations and support instructions constitute documented instructions. If an instruction appears unlawful, we notify the Customer and may pause execution pending clarification.

5. Confidentiality

Authorised personnel are bound by confidentiality and receive only the access necessary for their duties.

6. Technical and organisational measures

  • encrypted transmission and appropriate encryption at rest where available
  • role-based access, tenant separation and least privilege
  • secure authentication and protected administrative access
  • security logging and controlled secret management
  • recovery, change and vulnerability management
  • data minimisation, deletion concepts and controlled test data
  • regular review of safeguards

Measures are adapted to risk, state of the art and project architecture without reducing the agreed protection level.

7. Subprocessors

The Customer generally authorises the services listed under Subprocessors. We provide at least 14 days’ notice of material additions where practical. The Customer may object on substantiated data protection grounds. Subprocessors receive substantially equivalent obligations.

8. Controller assistance

We reasonably assist with data-subject rights, impact assessments, regulatory consultations and security evidence where information is available to us. Additional effort outside scope may be charged unless caused by our breach.

9. Personal data breaches

We inform the Customer without undue delay after becoming aware of a breach affecting processed personal data and provide available information on nature, scope, consequences and remediation. Appropriate containment and investigation begin promptly.

10. Evidence and audits

We provide information necessary to demonstrate compliance. Audits should begin with documents or independent evidence. On-site reviews require reasonable notice, business hours, confidentiality and protection of other customers. The Customer bears cost unless a material breach caused by us is found.

11. International transfers

Transfers outside the EEA or UK use an appropriate mechanism, including adequacy decisions, EU Standard Contractual Clauses with UK Addendum or equivalent safeguards, supported by risk-based supplementary controls.

12. Return and deletion

At service end, personal data is returned or deleted at the Customer’s choice unless legal retention applies. Backups are overwritten through the normal deletion cycle and remain protected and unused for other purposes.

13. Priority and liability

This DPA takes priority for conflicting data protection terms. Otherwise, the main contract’s liability terms apply unless mandatory data protection law provides otherwise.

Schedule: project-specific information

Systems, data fields, deletion periods, recipients, special risks and additional safeguards are documented in the proposal, Statement of Work or a separate schedule.

For binding use, this DPA must be incorporated into the individual contract or confirmed by both parties.

Growth Enterprise System · Europe / Global

Your business.
Ready for the next level.

We connect AI, automation, digital products and organic growth into one system that delivers measurable value for your business.

Assess the complete system ↗
MarketGermany, DACH & internationalDeutsch / English
ScopeStrategy through operationsOne accountable partner
DeliverySenior-ledConsulting, Product, AI & Growth
GovernancePrivacy by DesignGDPR requirements built in

Growth.
Intelligently orchestrated.

The integrated Growth Enterprise package for AI employees, automation, digital experiences, business tools and organic demand.

Projects for ambitious companies
SolutionsAI ImplementationDigital Experience & ToolsOrganic GrowthAutomation & Operations
The SystemComplete systemEngagementsClient OSEnterprise BlueprintUse cases
ResourcesInsightsAI Employee GuideGEO GuideAutomation ROI
CompanyAbout GrowthAIQContactStart a projectLegal notice
Direct contact

Ready for a system that actually performs?

info@growthaiq.com↗+971 58 560 6084↗
Discuss your project ↗
GrowthAIQ by Codaiq LTD · Build once. Compound continuously.
© 2026 Codaiq LTDCompany No. 16537316London · Dubai · Remote
Legal noticePrivacyTermsCookiesDPASubprocessors
↑