Data Processing Agreement
Last updated: 11 June 2026
This Data Processing Agreement (“DPA”) forms part of the Maneuvr Terms of Service (the “Agreement”) between Maneuvr.app (“Maneuvr”, “we”, “us”) and the customer identified in the relevant account or order form (“Customer”). It applies where Maneuvr processes Personal Data on the Customer’s behalf in providing the Service.
1. Definitions
1.1 “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation, each as amended from time to time.
1.2 “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in Data Protection Law.
1.3 “Customer Personal Data” means Personal Data contained within Customer Data (as defined in the Agreement) that Maneuvr processes on the Customer’s behalf.
1.4 “Subprocessor” means any third party engaged by Maneuvr to process Customer Personal Data.
2. Roles and scope
2.1 For Customer Personal Data, the Customer is the controller (or, where the Customer is itself a processor for a third party, Maneuvr is a subprocessor) and Maneuvr is the processor.
2.2 This DPA does not apply to Personal Data for which Maneuvr is the controller (such as account registration, billing and usage data), which is governed by Maneuvr’s Privacy Policy.
2.3 Details of the processing, including subject matter, duration, nature, purpose, categories of data and data subjects, are set out in Annex 1.
3. Customer obligations
3.1 The Customer warrants that it has a lawful basis for the Customer Personal Data it submits to the Service, has provided any required notices to data subjects, and that its processing instructions comply with Data Protection Law.
3.2 The Customer must not submit special category data, criminal offence data, or data relating to children to the Service.
3.3 The Customer is responsible for configuring and using the Service appropriately, including managing user access, roles and permissions within its account.
4. Maneuvr obligations
Maneuvr shall:
4.1 Instructions. Process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by law, in which case Maneuvr will inform the Customer before processing (unless the law prohibits this). Maneuvr will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
4.2 Confidentiality. Ensure that all personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
4.3 Security. Implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Current measures are set out in Annex 2. Maneuvr may update these measures provided the overall level of protection is not reduced.
4.4 Data subject rights. Taking into account the nature of the processing, assist the Customer with appropriate technical and organisational measures to respond to data subject requests under Data Protection Law. If a data subject contacts Maneuvr directly regarding Customer Personal Data, Maneuvr will direct them to the Customer without responding substantively, unless legally required.
4.5 Breach notification. Notify the Customer without undue delay, and in any event within [48/72] hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing sufficient information to enable the Customer to meet its own notification obligations, and cooperating with the Customer’s reasonable remediation efforts.
4.6 Assistance. Provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with the ICO, taking into account the nature of the processing and the information available to Maneuvr.
4.7 Deletion and return. On termination or expiry of the Agreement, at the Customer’s choice, delete or return all Customer Personal Data within [30/60/90] days, and delete existing copies unless retention is required by law. Data in routine backups will be deleted on the normal backup rotation cycle, within [X] days, and remains protected under this DPA until deleted. The Customer may export Customer Data at any time before termination using the Service’s export functionality.
4.8 Records. Maintain records of processing activities carried out on the Customer’s behalf as required by Article 30(2) UK GDPR.
5. Subprocessors
5.1 General authorisation. The Customer authorises Maneuvr to engage the Subprocessors listed in Annex 3.
5.2 Changes. Maneuvr will give the Customer at least [14/30] days’ notice (by email or in-app notification) before adding or replacing a Subprocessor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees.
5.3 Flow-down. Maneuvr will impose data protection obligations on each Subprocessor that are materially equivalent to those in this DPA, and remains liable to the Customer for the performance of its Subprocessors.
6. International transfers
6.1 Maneuvr will not transfer Customer Personal Data outside the UK unless appropriate safeguards are in place under Data Protection Law, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation (including the UK-US Data Bridge where applicable).
6.2 Current transfer locations and mechanisms are identified in Annex 3.
7. Audits
7.1 Maneuvr will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports or certifications where available.
7.2 Where the information in clause 7.1 is insufficient, the Customer may conduct an audit, no more than once per 12-month period (except following a personal data breach or where required by a regulator), on at least 30 days’ written notice, during business hours, without disrupting Maneuvr’s operations, and subject to confidentiality obligations. The Customer bears its own audit costs.
8. Liability and general
8.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law provides otherwise.
8.2 In the event of conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA prevails.
8.3 This DPA is governed by the laws of England and Wales and is subject to the jurisdiction provisions of the Agreement.
8.4 This DPA terminates automatically when Maneuvr ceases to process Customer Personal Data under the Agreement, except for provisions that by their nature survive.
Annex 1 — Details of processing
Subject matter: Provision of the Maneuvr competitor intelligence platform.
Duration: The term of the Agreement, plus the deletion period in clause 4.7.
Nature and purpose: Hosting, storage, organisation, analysis (including AI-assisted analysis), retrieval and display of Customer Data in order to provide competitor intelligence features including signal scoring, gap analysis, battlecards, summaries and conversational querying.
Categories of data subjects: The Customer’s authorised users; individuals incidentally named in Customer Data, such as personnel of tracked companies or the Customer’s own personnel referenced in notes and configurations.
Categories of Personal Data: Names, job titles, business contact details, professional activities and statements, and any other personal data the Customer chooses to include in Customer Data. Special category data, criminal offence data and children’s data are prohibited.
Annex 2 — Technical and organisational measures
- Encryption of data in transit (TLS 1.2+)
- Encryption of data at rest (provided by Supabase infrastructure)
- Password hashing using a memory-hard algorithm (argon2id)
- Role-based access control within the Service (admin, member, viewer)
- Session-based authentication with secure session management
- Least-privilege access for Maneuvr personnel; access to production data restricted and logged
- Logical separation of customer data enforced via Supabase row-level security policies [CONFIRM RLS IS ENABLED ON ALL TABLES]
- Regular backups with defined retention and rotation
- Vulnerability management and timely application of security patches
- Personnel confidentiality obligations
- Incident response process supporting the notification commitment in clause 4.5
Annex 3 — Authorised Subprocessors
| Subprocessor | Service | Location | Transfer mechanism |
|---|---|---|---|
| Google [entity — likely Google Cloud / Google LLC] | AI model processing (Gemini) | United States [or EU/UK endpoint if configured] | [UK-US Data Bridge / IDTA / UK Addendum — confirm] |
| Anthropic [REMOVE THIS ROW IF NO LONGER USED] | AI model processing | United States | [UK-US Data Bridge / IDTA — confirm] |
| Supabase Inc. | Database, authentication, storage and hosting | [PROJECT REGION — select a UK or EU region in Supabase settings] | [Adequacy if UK/EU region; IDTA/UK Addendum if US] |
| [EMAIL PROVIDER] | Transactional email (e.g. password resets) | [LOCATION] | [MECHANISM] |
| Stripe | Payment processing | [LOCATION] | [MECHANISM] |
Current list maintained at [SUBPROCESSORS PAGE URL].