Data Processing Agreement
Last updated: 1 June 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Metry Ltd, 5 Beaconsfield St, London N1C 4EW (“Metry”, “Processor”) and the customer that uses the Metry service (“Customer”, “Controller”) (together, the “Parties”). It governs Metry’s processing of personal data on the Customer’s behalf and applies where the EU General Data Protection Regulation (GDPR) and/or the UK GDPR apply.
If there is any conflict between this DPA and the main agreement on the subject of data protection, this DPA prevails.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “sub-processor”, “personal data breach”, and “supervisory authority” have the meanings given in the GDPR. “Data protection law” means the EU GDPR, the UK GDPR, and any applicable implementing or successor legislation.
2. Roles and scope
2.1 For the personal data the Customer collects and manages through the Metry service (“Customer Data”), the Customer is the controller and Metry is the processor.
2.2 Metry processes Customer Data only to provide the service and only on the Customer’s documented instructions, including those in the main agreement, this DPA, and the Customer’s configuration and use of the service. Metry will inform the Customer if, in its opinion, an instruction infringes data protection law.
2.3 The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1.
2.4 The Customer is responsible for the lawfulness of the personal data it provides and the instructions it gives, including having a valid legal basis and, where applicable, the conditions required for any special-category data (Article 9).
2.5 This DPA governs the processing of personal data only. Metry does not warrant the accuracy, completeness, or fitness of any output the Service generates (including AI-generated content and reports), and any results, outcomes, or decisions arising from the Customer’s use of the Service or reliance on its outputs are the Customer’s sole responsibility, as set out in the main agreement.
3. Metry’s obligations
Metry will:
- (a) Instructions — process Customer Data only on the Customer’s documented instructions, including for international transfers, unless required by law (in which case it will inform the Customer, where legally permitted).
- (b) Confidentiality — ensure that persons authorised to process Customer Data are bound by an appropriate duty of confidentiality.
- (c) Security — implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk under Article 32.
- (d) Sub-processors — engage sub-processors only in accordance with Section 4.
- (e) Assistance — taking into account the nature of the processing, assist the Customer by appropriate measures with: responding to data subject requests (Section 5); security, breach notification, and data protection impact assessments; and prior consultation with supervisory authorities (Articles 32–36).
- (f) Breach — notify the Customer of a personal data breach affecting Customer Data without undue delay after becoming aware of it (Section 6).
- (g) Deletion or return — at the end of the provision of the service, delete or return Customer Data as set out in Section 7.
- (h) Demonstrate compliance — make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 8.
4. Sub-processors
4.1 The Customer provides general authorisation for Metry to engage sub-processors to process Customer Data. The sub-processors approved as at the date of this DPA are listed in Annex 3.
4.2 Metry will impose on each sub-processor data protection obligations that are substantially the same as those in this DPA, and remains liable to the Customer for the sub-processor’s performance.
4.3 Metry will give the Customer reasonable prior notice of any intended addition or replacement of a sub-processor. The Customer may object on reasonable data protection grounds within 14 days; the Parties will work in good faith to resolve the objection, and if they cannot, the Customer may terminate the affected part of the service.
5. Data subject requests
Taking into account the nature of the processing, Metry will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. If Metry receives such a request directly relating to Customer Data, it will, where legally permitted, forward it to the Customer and not respond except on the Customer’s instruction.
6. Personal data breaches
Metry will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to it to help the Customer meet its own notification obligations to supervisory authorities and data subjects. Metry will take reasonable steps to mitigate and remediate the breach.
7. Deletion or return of data
On termination or expiry of the service, Metry will, at the Customer’s choice, delete or return Customer Data, and delete existing copies, unless retention is required by law. The Customer may also request deletion of Customer Data during the term as set out in the main agreement and the Privacy Policy. Routine backups are deleted on their ordinary cycle.
8. Audits
Metry will make available the information reasonably necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, no more than once per year (and on a breach), on reasonable prior notice, during business hours, and subject to confidentiality — or, where appropriate, by providing relevant certifications or third-party reports.
9. International transfers
Where Metry transfers Customer Data outside the UK or EEA, it will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement (or Addendum) or the EU Standard Contractual Clauses, together with any additional measures required.
10. Liability and term
10.1 This DPA takes effect on the date the main agreement begins and continues for as long as Metry processes Customer Data.
10.2 Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement.
Annex 1 — Details of the processing
- Subject matter: provision of the Metry platform for monitoring and reporting on portfolios, programmes, and impact.
- Duration: the term of the main agreement, plus any period until deletion or return of Customer Data.
- Nature and purpose: hosting, storage, organisation, and processing of personal data the Customer collects through the service, including AI-assisted extraction of information from documents and drafting of report narratives, solely to provide the service.
- Types of personal data: names, email addresses, organisation and role, and contact details of the Customer’s users and invited submitters; and any personal data contained in the content, metrics, narratives, documents, or beneficiary records the Customer or its submitters enter into the service.
- Categories of data subjects: the Customer’s personnel and users; the Customer’s portfolio company, grantee, or site representatives who submit data (e.g. founders, grantees, site leads); and any individuals referenced in submitted content, including, where the Customer chooses to provide it, beneficiaries of the Customer’s programmes.
- Special-category data: not required by the service. If the Customer chooses to submit special-category data (e.g. within beneficiary records), it is responsible for ensuring a valid Article 9 condition and should minimise such data.
Annex 2 — Technical and organisational security measures
- Encryption of personal data in transit (TLS) and at rest.
- Access control on a least-privilege basis, with authentication for all accounts.
- Logical isolation of each customer’s data from other customers’ data (tenant isolation).
- Public submission links resolve only through controlled server-side checks; the underlying data store is not exposed to anonymous access.
- Use of vetted sub-processors only, each bound by written contract (Annex 3).
- Logging and monitoring of access to the production environment.
- Secure, reputable hosting infrastructure.
- Procedures to detect, report, and respond to personal data breaches.
- Deletion or anonymisation of personal data when no longer required.
(These measures are reviewed and may be updated to maintain an appropriate level of security; any change will not materially reduce protection.)
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Base44 | Application platform, hosting, and data storage | Global |
| GoDaddy | Domain and email services | Global |
A current list of sub-processors is available from hello@metry.ltd on request.
Execution
By clicking to accept — at sign-up, or on entering into the main agreement for the Metry service — the Customer agrees to this DPA on behalf of its organisation. Metry records the acceptance electronically (the accepting user’s name, account email, the DPA version, and the date and time), which together constitute the Customer’s electronic signature. A countersigned copy is available on request to hello@metry.ltd.