This Data Protection & Data Processing Agreement ("DPA") explains how Penned Ltd (company no. 12989856, registered in England & Wales, registered office Polhill Business Centre, London Road, Polhill, Halstead, TN14 7AA; "Penned", "we", "us") processes personal data, and forms part of the agreement between Penned and each business customer ("you", "the Client") who uses our platform and services. It applies from the moment you accept it and for as long as we process personal data on your behalf. Where it conflicts with our general Terms & Conditions on the subject of data protection, this DPA prevails.

It is designed to meet the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law").

1. Roles of the parties

  • Recipient data (the names, addresses and any personalisation fields you provide so we can write and post letters) — you are the controller and Penned is your processor. We process it only on your documented instructions and only to deliver the service.
  • Your account & business-contact data (the details of the people who administer your account) — Penned is an independent controller, and our Privacy Policy governs that processing.

2. Definitions

"personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR. A "sub-processor" is any third party engaged by Penned to process personal data on your behalf.

3. Scope & details of processing

The details required by Article 28(3) are set out in Annex 1 below: the subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject.

4. Your instructions

We will process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law (in which case we will, where lawful, tell you first). Your instructions are: (a) this DPA and our Terms; (b) the configuration and data you submit through the platform; and (c) any further written instructions you give. If we consider an instruction breaches Data Protection Law, we will tell you.

5. Confidentiality

We ensure that everyone authorised to process personal data is bound by a duty of confidentiality and only processes it as needed to perform the service.

6. Security

Taking account of the state of the art, the costs of implementation and the risks to data subjects, we implement appropriate technical and organisational measures to protect personal data, as described in Annex 2. These include encryption in transit, access controls on a least-privilege basis, network and application security, and regular review of our measures.

7. Sub-processors

You give Penned general authorisation to engage sub-processors to help deliver the service. Our current sub-processors are listed in Annex 3. We impose data-protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you reasonable prior notice of any intended addition or replacement of a sub-processor (for example by updating Annex 3 and, on request, notifying your account contact), giving you the opportunity to object on reasonable data-protection grounds.

8. Assisting you with data-subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). If a data subject contacts us directly about your data, we will promptly refer them to you and will not respond without your authorisation, unless legally required.

9. Assisting you with compliance

Taking into account the nature of processing and the information available to us, we will assist you in ensuring compliance with your obligations relating to security of processing (Article 32), personal data breaches (Articles 33–34), data protection impact assessments (Article 35) and prior consultation with the supervisory authority (Article 36).

10. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information you reasonably need to meet your own breach-notification obligations, including the nature of the breach, likely consequences and the measures taken or proposed to address it.

11. International transfers

Some of our sub-processors operate outside the UK. Where personal data is transferred internationally, we rely on an appropriate transfer mechanism under Data Protection Law, such as UK adequacy regulations or the UK International Data Transfer Agreement / the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required.

12. Retention, return & deletion

We process recipient data only for as long as needed to deliver your order and for a short period afterwards for support, reconciliation and legal or accounting requirements, after which it is securely deleted or anonymised. On termination of the service, and on your written request, we will delete or return the recipient data we hold for you and delete existing copies, unless we are required by law to retain it.

13. Audit & information

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits will be on reasonable prior notice, no more than once in any 12-month period (unless required by a supervisory authority or following a breach), during business hours, and subject to confidentiality; we may satisfy audit requests by providing relevant certifications, reports or a completed security questionnaire where these reasonably address your request.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in our Terms & Conditions.

15. Changes

We may update this DPA from time to time — for example to reflect changes to our sub-processors or to the law. Material changes will be notified through the platform or to your account contact, and the revised date will appear at the top of this page.

16. Contact

For any data-protection matter, contact us at [email protected] or 0333 090 9406. You may also complain to the Information Commissioner's Office (ico.org.uk); Penned is registered with the ICO (registration no. ZC202297).


Annex 1 — Details of processing

  • Subject-matter: production and postal delivery of handwritten letters, cards and related items on the Client's behalf.
  • Duration: for the term of the service and the retention period described in section 12.
  • Nature & purpose: collection, storage, rendering (converting the Client's message into a handwriting representation), printing, enveloping, addressing and dispatch via postal carriers.
  • Types of personal data: recipient name; postal address; and any additional personalisation fields or message content the Client chooses to include. Clients should not submit special-category data unless separately agreed in writing.
  • Categories of data subject: the Client's chosen recipients (e.g. the Client's customers, prospects, members or contacts).

Annex 2 — Technical & organisational security measures

  • Encryption of personal data in transit (TLS/HTTPS) and encryption at rest at our infrastructure providers.
  • Role-based, least-privilege access controls and individual authenticated accounts for staff; access to production data limited to those who need it.
  • Authentication and session controls for the platform (including token-based access and password hashing).
  • Network and application security, including reputable cloud infrastructure, firewalling and DDoS/edge protection.
  • Segregation of Clients' data and use of unique identifiers.
  • Logging and monitoring of relevant system activity.
  • Backups and the ability to restore availability of data in a timely manner.
  • Secure deletion of data at the end of its retention period.
  • Staff confidentiality obligations and data-protection awareness.
  • Vendor due diligence and written data-protection terms with sub-processors.

Annex 3 — Sub-processors

We engage the following categories of sub-processor to deliver the service. This list may change under section 7.

  • Cloud hosting & compute — hosting of the platform and APIs.
  • Database — MongoDB (managed database) for storing account, campaign and recipient records.
  • File & object storage — Google Cloud Platform for uploaded files and generated artwork.
  • Handwriting rendering — our handwriting-generation service that converts messages into handwriting output.
  • Transactional email — Twilio SendGrid for service and notification emails.
  • Payments — Stripe for payment processing (Stripe acts as an independent controller for payment data).
  • Security & content delivery — Cloudflare for DNS, edge security and delivery.
  • Print & production partners — trusted production facilities that print and finish items.
  • Postal carriers — national and international postal operators (e.g. Royal Mail, Australia Post) that carry and deliver the finished items.

A current, itemised list of named sub-processors is available on request at [email protected].