Skip to content
worldgovdata

Legal / Data processing addendum

Data processing addendum

The GDPR Article 28 processor agreement, in force automatically for every customer. It opens by telling you the thing most such documents bury: in the ordinary course there is no personal data of yours for us to process, because the API returns country statistics. The rest is here for the cases where that is not true, and for a procurement file that needs it.

Version 2026-07-28Effective 2026-07-28

01

Scope, incorporation and precedence

This data processing addendum (the “Addendum”) forms part of the terms of service between — to be completed — (“we”, “us”) and the customer (“you”), and applies where we process personal data on your behalf in connection with the service.

It takes effect automatically as part of the terms; you do not have to ask for it. Where it conflicts with the terms on the subject of processing personal data, this Addendum prevails. Where it conflicts with the Standard Contractual Clauses referenced in clause 13, the Clauses prevail.

Nothing here changes our role as controller of your account and billing data. That processing is described in the privacy policy and is not covered by this Addendum.

02

Definitions

“Data Protection Law” means Regulation (EU) 2016/679 (the GDPR), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and any other data protection law applicable to the processing.

controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” carry the meanings given in Article 4 GDPR.

Customer Personal Data” means personal data that we process on your behalf under this Addendum, as described in Annex I.

SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018 where UK data is involved.

03

Roles of the parties — read this one

We would rather say that plainly than sell you a processor agreement you do not need. This Addendum exists for the narrower cases where processing on your behalf genuinely does arise, and for the entirely reasonable position that your procurement process needs an Article 28 agreement on file before it can approve a supplier.

Where we are the controller

For your account, authentication, usage and billing records, we determine the purposes and means. We are the controller of that data, not your processor, and the privacy policy is the notice for it. A processor agreement would misdescribe the relationship, so we do not pretend it covers it.

Where we are your processor

You are the controller and we are the processor when:

  • you include personal data about your own people or end users in support correspondence, a bug report or a data-correction request;
  • you submit personal data to the service in a parameter, header or payload that we then store in a log or a usage record; or
  • we agree in writing to process something specific for you that falls outside the ordinary use of the service.

In each case you are responsible for having a lawful basis for giving it to us, and for telling the data subjects. You should not send us personal data you do not need to send.

04

Our instructions, and their limits

We process Customer Personal Data only on your documented instructions, including for international transfers, unless required otherwise by law that applies to us — in which case we tell you first, unless that law forbids it on important grounds of public interest.

Your instructions are: the terms of service, this Addendum, your configuration and use of the service, and anything else you send us in writing that we accept. We will tell you if we consider an instruction infringes Data Protection Law, and we may suspend the affected processing until it is resolved.

We will not sell Customer Personal Data, use it for our own advertising or marketing, use it to train machine-learning models, or combine it with data from other sources to build profiles. Those are not merely absent from our practice — they are outside the instructions this Addendum permits.

05

Confidentiality and personnel

We keep Customer Personal Data confidential and limit access to the people who need it to provide the service, to investigate an incident, or to comply with the law. Everyone with access is bound by an obligation of confidentiality that survives the end of their engagement, and is given the training their role requires.

We do not disclose Customer Personal Data to a public authority unless legally compelled. If we receive such a demand we will, where the law permits, tell you before responding, challenge a demand that appears unlawful or overbroad, and disclose only the minimum required.

06

Security measures

We implement appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, cost, and the risks presented by the processing. The measures in force are set out in Annex II, which is specific rather than decorative.

We may update the measures in Annex II provided the level of protection is not reduced.

07

Subprocessors

You give general written authorisation for us to engage subprocessors. Every current one is named, with its role, location and transfer mechanism, on the subprocessors page, which forms Annex III of this Addendum.

  • We impose data protection obligations on each subprocessor that are no less protective than those in this Addendum, by written contract.
  • We remain fully liable to you for a subprocessor’s performance of its obligations.
  • We give at least 30 days’ notice by email before a new or replacement subprocessor begins processing Customer Personal Data.
  • You may object within that period on reasonable data protection grounds. We will work with you to find a solution; if none is available, either of us may terminate the affected part of the service, and we refund your unused credit balance.
  • Where a subprocessor has to be replaced urgently for security or continuity reasons, we may act first and notify you immediately afterwards with the reason.
08

Assisting with data subject requests

Taking account of the nature of the processing, we assist you with appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests under Chapter III of the GDPR.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively; we will tell them to contact you, and pass the request on promptly unless legally prohibited. Our assistance is free of charge unless a request is unusual in scope, in which case we will agree the cost with you before doing the work.

09

Personal data breach

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Forty-eight hours rather than seventy-two, so that you still have time to meet your own 72-hour deadline to a supervisory authority under Article 33.

The breach procedure: what happens, when, and what the notification contains.
StepWhenWhat
Contain and assessImmediatelyStop the exposure, preserve evidence, establish what data and whose was affected.
Notify you≤ 48 hoursNature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken and proposed, and a contact point. If the full picture is not yet known, we send what we have and follow up in phases rather than waiting.
Supervisory authority≤ 72 hoursWhere we are the controller, we notify the competent authority ourselves within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Where you are the controller, that notification is yours to make and we support it.
Affected individualsWithout undue delayWhere the risk to rights and freedoms is high, and we are the controller, we tell the people affected in plain language.
Post-incidentWithin 30 daysA written account of root cause and the changes made, sent to affected customers.

A notification is not an admission of fault or liability by either of us. Report a suspected breach to us at connect@worldgovdata.com — that route is monitored and is the same one the coordinated disclosure policy on the contact page uses.

10

Impact assessments and prior consultation

We provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36, to the extent they relate to our processing and taking account of the information available to us. Most of what an assessment needs is already on this site: Annex II describes the measures, the subprocessors page describes the chain, and the privacy policy describes retention.

11

Deletion and return

On termination of the service, and at your choice, we delete or return Customer Personal Data and delete existing copies, unless law requires us to keep it. Absent an instruction from you within 30 days of termination, we delete.

  • Self-serve export is available at any time from account settings, in machine-readable JSON — you do not need to ask us or wait for us.
  • Account deletion is self-serve, takes effect immediately, and the record is purged 30 days later.
  • Financial records that tax and accounting law requires us to keep are retained for the statutory period in pseudonymised form, protected and processed only for that purpose. This is the one category deletion cannot clear, and it is a legal obligation rather than a choice.
  • Backups are overwritten on their ordinary rotation. Data in a backup is not restored into production except as part of a disaster recovery, and is deleted again when the cycle completes.
12

Audits and information

We make available all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice, and to keep this workable for both of us:

  • We answer security and privacy questionnaires, and we will hold a call with your security team. This resolves nearly everything and costs nothing.
  • An on-site or remote inspection may be requested once in any twelve-month period, on at least 30 days’ written notice, during business hours, without unreasonably disrupting the service, subject to confidentiality, and at your cost. More frequent audits are permitted where a supervisory authority requires one or following a confirmed breach affecting your data.
  • We will not give access to another customer’s data, to our production credentials, or to anything that would itself create a security risk. Where we cannot show something directly, we will describe it and evidence it another way.
13

International transfers

Customer Personal Data is processed on infrastructure in Germany, inside the European Economic Area. Where a transfer outside the EEA is nevertheless necessary — currently for payment processing and transactional email — it takes place under the SCCs.

  • Module Three (processor to processor) applies between us and a subprocessor outside the EEA.
  • Module Four (processor to controller) applies where you are established outside the EEA and we transfer to you.
  • Where you are the data exporter and we are the importer, the SCCs are incorporated into this Addendum by reference, with the docking clause enabled, the optional clause on local law addressed by the transparency commitment in clause 05, and Annexes I and II below serving as the SCCs’ Annexes I and II. The governing law and forum are as stated in the SCCs, and clause 17 of them applies.
  • For UK transfers the International Data Transfer Addendum applies to the SCCs. For Swiss transfers, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is a competent authority.

Ask us at connect@worldgovdata.com for a copy of the safeguards for any specific transfer.

14

Liability

Each party’s liability under this Addendum is subject to the limitations and exclusions in the terms of service, and claims under this Addendum and under the terms count towards the same single aggregate cap. Nothing here limits a data subject’s rights against either of us under Article 82, or any liability that cannot lawfully be limited.

15

Term, changes and governing law

This Addendum runs for as long as we process Customer Personal Data, and the obligations that by their nature should survive termination do so.

We may update it to reflect a change in law, in a supervisory authority’s guidance, or in how the service works, provided the change does not reduce the protection it gives. A material change is notified to account holders at least 30 days before it takes effect, and the version stamp at the top of this page moves with it.

It is governed by — to be completed —, subject to the SCCs where they specify otherwise and to any mandatory rule of Data Protection Law that says differently.

Annex I

Description of the processing

This annex also serves as Annex I to the SCCs where they are incorporated under clause 13.

A. The parties

Controller / exporter
The customer, as identified by the account. Activities: use of the worldgovdata API and portal.
Processor / importer
— to be completed —, trading as worldgovdata. Activities: provision of the metered data API, the account area and support.
Processor address
— to be completed —
Processor contact
connect@worldgovdata.com

B. Description of the transfer

The processing described for the purposes of Article 28(3) and Annex I(B) of the SCCs.
ItemDetail
Categories of data subjectsYour personnel and contractors who hold or administer an account; and any individual whose personal data you choose to include in support correspondence or submit to the service.
Categories of personal dataContact details (name, email address); authentication data; records of API usage; billing details. Only what you choose to send, plus what the service necessarily generates.
Sensitive dataNone. Special-category data under Article 9 and criminal-offence data under Article 10 must not be submitted to the service, and we apply no additional safeguards for it because it is not expected to be present.
FrequencyContinuous, for the duration of the agreement.
Nature and purposeHosting and storage; provision of the metered API; metering, billing and support; security and abuse prevention. Solely to deliver the service you bought.
DurationFor the term of the agreement plus the retention periods set out in the privacy policy. Financial records are kept for 8 years where tax law requires it.
SubprocessorsAs listed in Annex III, each for the subject matter, nature and duration of the function described there.

C. Competent supervisory authority

Determined under clause 13 of the SCCs: the authority of the EEA member state in which you, as data exporter, are established; or, where you are not established in the EEA, the authority of the member state in which your Article 27 representative is established; or, failing that, the authority of the member state in which the data subjects whose data is transferred are located. We do not name one here because we do not know where you are.

Annex II

Technical and organisational measures

The measures actually in force, described specifically enough to be checked. Where a measure is absent, this annex says so rather than leaving a gap for you to assume is filled.

Pseudonymisation and minimisation

  • IP addresses are never stored raw. They are stored as HMAC-SHA256 digests computed with a server-side secret held outside the database.
  • Usage records store the route template — for example /v1/data — never the raw request URL or its parameters.
  • Per-request usage events are deleted after 90 days, leaving only an aggregated daily rollup. Login attempts are deleted after 30 days.
  • After account deletion, the financial records the law requires us to keep are retained in pseudonymised form with account identifiers removed.

Encryption

  • All traffic to the site and the API is over HTTPS, with HTTP Strict Transport Security enforced for two years and preload requested.
  • Passwords are hashed with argon2id (time cost 3, memory 64 MiB, parallelism 2) and never logged, returned or included in an error message.
  • Session tokens and API key secrets are stored only as SHA-256 hashes. Neither can be recovered from our database, which is also why a lost key must be replaced rather than retrieved.

Access control and authentication

  • Session cookies are HttpOnly, Secure, SameSite=Lax, path-scoped and carry the __Host- prefix. Sessions expire on a sliding 30-day window with an absolute 90-day cap that is never extended, and are rotated on login and on password change.
  • Every state-changing request is checked for origin and for a double-submitted CSRF token.
  • Repeated failed logins trigger a temporary lockout, per account and per source. API keys are rate-limited per key and per tier.
  • API keys carry scopes, can be given an expiry, and are revocable instantly. A maximum of ten active keys per account limits the blast radius of a leak.
  • Administrative interfaces sit behind a separate host, HTTP authentication, per-IP rate limiting on the challenge, and an optional IP allowlist. Every administrative mutation is written to the audit log.
  • Access to production data is limited to the people who need it to operate the service.

Integrity and accountability

  • The credit ledger is append-only — never updated, never deleted — and every purchase and refund carries a unique idempotency key, so a double-credit is prevented by a database constraint rather than by application logic.
  • Security-relevant actions — logins, key creation and revocation, password changes, email verification, orders, data protection requests, account deletion — are written to an append-only audit log retained for 24 months.
  • Payment webhooks are verified by HMAC over the raw request body using a constant-time comparison, and every event is persisted before it is processed, including ones that fail verification.
  • All database access is parameterised. No credential or internal token is exposed to the browser.

Application and transport hardening

  • A Content Security Policy, plus X-Content-Type-Options: nosniff, X-Frame-Options: DENY, a strict referrer policy, a restrictive permissions policy and cross-origin opener isolation.
  • Request bodies are size-capped; error responses never contain a stack trace or SQL; each request carries an id that appears in the logs so support can correlate an incident without exposing internals.
  • The public API allows cross-origin requests without credentials, which is correct for bearer-token authentication. The account API is not exposed publicly at all.

Availability and resilience

  • Automated database backups, with restoration exercised as part of operations.
  • The application degrades rather than fails: if the account layer is unavailable, the public portal and the free endpoints keep working.
  • A failed request costs zero credits, so an outage cannot consume a customer’s balance.

Governance — including what is missing

  • A written breach procedure, reproduced in clause 09 of this Addendum, with a 48-hour notification commitment to customers.
  • A published coordinated disclosure policy with an undertaking not to pursue good-faith researchers, on the contact page.
  • Subprocessors reviewed against the criteria on the subprocessors page, with an EEA option preferred wherever one exists at comparable quality.
  • Not in place: no ISO 27001 certification, no SOC 2 report, no external penetration test, no formal information security management system, no dedicated security team, and no bug bounty. We would rather you knew that before signing than after an audit request.

Annex III

Authorised subprocessors

The current list, with each provider’s role, processing location and transfer mechanism, is maintained on the subprocessors page and forms part of this Addendum. Keeping it in one place is what stops an annex here and a page there disagreeing about who processes your data.

At the date of this version the authorised subprocessors are: netcup GmbH (hosting, Germany), Cloudflare, Inc. (CDN, DNS and protection), PostHog (cookieless analytics, EU Cloud), Resend (transactional email, United States) and Razorpay Software Private Limited (payment processing, India).

Notice of a change, your right to object, and what happens if we cannot resolve an objection are in clause 07.

For a countersigned counterpart, or to send us your own template, email connect@worldgovdata.com with the legal name and registered address to appear on it.