Legal
Data Processing Agreement
Version 1.0 · Effective 13 August 2026
This Data Processing Agreement forms part of the agreement between a customer using Parallel North | Planner (the Controller) and 7 Degrees Media Limited trading as Parallel North (the Processor). It applies where Planner processes personal data on the customer’s behalf.
01
Parties and status
The Processor is 7 Degrees Media Limited, company number 17068770, of 2 Police Houses, Station Road, Rossington, Doncaster, England, DN11 0DZ. The customer identified through the Planner account, order or other service agreement is the Controller. Data-protection terms have the meanings given in applicable UK law.
02
Subject matter and duration
The subject matter is the provision, security, support and operation of Parallel North | Planner. Processing begins when the Controller creates or connects an account and continues for the service term, plus the limited deletion and backup periods in the published retention schedule.
03
Nature and purpose
- Authenticate users and administer Planner accounts.
- Read permitted Outlook calendar and mailbox information to display appointments, identify commitments and produce task suggestions.
- Store and organise tasks, clients, projects, deadlines, preferences and delegated work.
- Extract text, actions, responsibilities and deadlines from documents uploaded by authorised users.
- Calculate calendar-aware working plans and send requested operational planning emails.
- Provide security, troubleshooting, backup, recovery and support services.
04
Personal data and data subjects
- Account-holder details, authentication identifiers and working preferences.
- Email sender, recipient, subject, preview or content information available through authorised Microsoft permissions.
- Calendar event titles, times, locations, links and related meeting information.
- Tasks, projects, clients, contacts, deadlines, notes and delegation details.
- Documents, extracted text and information within uploaded files.
- Technical, security and service-operation records.
- Data subjects may include the Controller’s staff, workers, customers, prospects, suppliers, professional contacts and others represented in connected content.
05
Controller instructions and responsibilities
The Processor will process personal data only on the Controller’s documented instructions, including the configuration and use of Planner by authorised users, unless UK law requires otherwise. The Controller is responsible for the lawfulness, accuracy and appropriateness of connected data; required notices and lawful bases; user authority; and avoiding unnecessary or unlawful sensitive data.
06
Confidentiality and personnel
People authorised by the Processor to handle personal data are subject to confidentiality obligations and receive access only where reasonably necessary for operation, security, maintenance or support.
07
Security
- Encryption in transit using HTTPS/TLS.
- Authenticated access and server-side handling of Microsoft credentials and tokens.
- Per-user ownership controls and PostgreSQL row-level security.
- Restricted production network exposure, hardened application containers and security response headers.
- Access controls, password protections, logging, patching and vulnerability management appropriate to the service.
- Backup and recovery controls once enabled under the documented production procedure.
08
Subprocessors
The Controller gives general written authorisation for the subprocessors in the current register. The Processor will impose appropriate obligations on them. Material changes will be published before processing begins where reasonably practicable, allowing a reasonable data-protection objection.
09
International transfers
The Processor will not make a restricted transfer without applicable UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another lawful mechanism. Customer-selected Microsoft tenant locations may affect where Microsoft processes data.
10
Data-subject rights
Taking account of the nature of processing, the Processor will provide reasonable assistance with requests for access, rectification, erasure, restriction, portability and objection. Requests concerning customer-controlled data will be directed to the Controller unless the Processor is instructed or legally required to respond.
11
Incidents and regulatory assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting customer data and provide reasonably available information. It will provide reasonable assistance with security obligations, impact assessments and prior consultation where applicable.
12
Deletion and return
During the service, authorised users may use available export and deletion tools. On termination or documented request, the Processor will delete or return customer data unless law requires retention. Periods and backup expiry are set out in the retention schedule.
13
Information and audit
The Processor will make information reasonably necessary to demonstrate compliance available. No more than once in twelve months, unless required after a material incident or by a regulator, the Controller may request a proportionate audit. Audits must protect other customers and security, use existing independent evidence where sufficient, and take place with reasonable notice. The Controller bears reasonable external costs unless material non-compliance is found.
14
Priority and governing law
This DPA takes priority over conflicting service terms concerning personal-data processing. It is governed by the laws of England and Wales. Enquiries should be sent to support@parallelnorth.co.uk.