Data Processing Addendum

Last updated: 30 July 2026

This Data Processing Addendum applies where Big Ears AI processes personal data on behalf of a client as processor, unless a signed agreement says otherwise.

Parties and roles

This Data Processing Addendum ("DPA") forms part of the agreement between the client ("Client") and Samir James Shamsi, trading as Big Ears AI ("Big Ears AI"), for the use of the Big Ears AI platform and related services.

For Client Personal Data, the Client is the controller and Big Ears AI is the processor, unless otherwise stated in the agreement or required by applicable law.

Definitions

"Client Personal Data" means personal data processed by Big Ears AI on behalf of the Client under the agreement.

"Data Protection Laws" means applicable data protection and privacy laws, including the UK GDPR, Data Protection Act 2018, PECR, and any applicable EU GDPR requirements.

"Subprocessor" means a third party engaged by Big Ears AI to process Client Personal Data on behalf of Big Ears AI.

Processing instructions

Big Ears AI will process Client Personal Data only:

  • to provide, secure, support, and improve the Service for the Client;
  • in accordance with the agreement, this DPA, and documented Client instructions;
  • as required by applicable law, unless legally prohibited from notifying the Client.

Big Ears AI will inform the Client if, in Big Ears AI's reasonable opinion, an instruction infringes Data Protection Laws.

Client responsibilities

The Client is responsible for:

  • having a lawful basis for personal data it provides or instructs us to process;
  • ensuring required notices, consents, and permissions are in place;
  • ensuring users have authority to connect mailboxes or upload Client Content;
  • reviewing AI-generated output and outreach before use;
  • complying with direct marketing, anti-spam, confidentiality, and sector-specific rules.

Confidentiality and security

Big Ears AI will ensure that personnel authorised to process Client Personal Data are subject to confidentiality obligations.

Big Ears AI will implement appropriate technical and organisational measures to protect Client Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage.

Measures include encryption in transit, provider-managed encryption at rest, workspace separation, access controls, restricted administrative access, logging and monitoring, backup and recovery processes, vendor review, and incident response procedures.

Subprocessors

The Client gives Big Ears AI general authorisation to use subprocessors to provide the Service. Big Ears AI will maintain a list of subprocessors on its Subprocessors page.

Big Ears AI will provide notice before adding or replacing a material subprocessor for Client Personal Data, unless the change is urgently required for security, continuity, or legal reasons. Notice may be provided by email, in-app notice, or an update to the Subprocessors page. The Client may object on reasonable data protection grounds within 15 days of notice. If the parties cannot resolve the objection in good faith, the Client may stop using the affected feature or terminate the affected order or service to the extent it depends on that subprocessor.

Big Ears AI will impose data protection obligations on subprocessors that provide a level of protection materially equivalent to this DPA. Big Ears AI remains responsible for subprocessors' performance to the extent required by Data Protection Laws.

International transfers

Big Ears AI may transfer Client Personal Data outside the United Kingdom where necessary to provide the Service. Where required, Big Ears AI will use appropriate safeguards such as adequacy decisions, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, standard contractual clauses, or other lawful transfer mechanisms.

Assistance

Taking into account the nature of processing and information available to Big Ears AI, Big Ears AI will provide reasonable assistance to the Client with data subject requests, security obligations, breach assessments and notifications, DPIAs, prior consultations where required, and deletion or return of Client Personal Data.

Personal data breaches

Big Ears AI will notify the Client without undue delay after becoming aware of a personal data breach affecting Client Personal Data. The notification will include available information about the nature of the breach, affected data, likely consequences, measures taken or proposed, and a contact point for follow-up.

Deletion and return

On termination or expiry of the agreement, Big Ears AI will delete or return Client Personal Data according to the agreement, Client instructions, and applicable law.

Unless otherwise agreed, Big Ears AI will delete Client Personal Data from active systems within 90 days after cancellation or pilot end, except where retention is required for legal, regulatory, dispute, security, or compliance purposes. Encrypted backups may take up to 90 days to be fully purged.

Audit and information

Big Ears AI will make available reasonable information necessary to demonstrate compliance with this DPA. Audits must be limited to what is reasonably necessary, avoid disruption to the Service, protect other clients' confidentiality, and be subject to reasonable notice and confidentiality obligations.

Processing details

Subject matter and duration

The subject matter is the provision of the Big Ears AI platform, PR and marketing intelligence, monitoring, contact intelligence, outreach, reporting, AI-assisted drafting, and related support or managed services. The duration is the term of the agreement plus any retention period described in the agreement, Privacy Policy, or Client instructions.

Categories of data subjects

Client users and administrators; people included in Client Content; journalists, creators, influencers, and professional contacts; email senders and recipients in connected mailbox threads; website or platform users where applicable.

Categories of personal data

Names, work email addresses, job titles, organisations, public professional profiles, outreach history, message content and metadata, uploaded documents, client materials, usage and security logs, account identifiers, and any personal data included in Client Content.

Special category data

Special category data is not intentionally collected or required. Client must not upload special category data unless agreed in writing and lawful safeguards are in place.

Contact

Questions about this DPA can be sent to james@bigears.ai.