Data Processing Agreement
Last updated: 2026-08-17 (draft — legal review pending)
1. Read this first
The DPA is a draft. It has not been through legal counsel, and Cyril is not yet a registered legal entity, so there is no company to sign it. We publish it anyway because a draft you can read and hold us to is more useful than a promise that one exists.
If you need an executed DPA before you can use Cyril — and if you are a data controller in the UK or EU, you probably do — contact us and we will tell you honestly where the review has got to.
↓ Download the draft DPA (PDF) — served by the Cyril API, so the link works whether or not you have an account.
2. What a DPA is, and who signs it
When your organisation puts personal data into Cyril, you are the data controller and Cyril is the processor. UK GDPR and EU GDPR Article 28 require that relationship to be governed by a written contract with a specific set of terms in it. The DPA is that contract.
The contracting party will be [Legal entity — to be confirmed]. Until that entity exists, nothing here is executable.
3. What it commits us to
The full text is in the PDF. In summary:
| Section | What it covers |
|---|---|
| 1–2 | Definitions, and the rule that Cyril processes personal data only on your documented instructions |
| 3 | Sub-processors — the canonical list, and 60 days' notice before any always-on provider is added, removed or materially changed, with a right to object |
| 4 | Data subject rights — Cyril assists you in answering access, erasure and portability requests |
| 5 | Breach notification |
| 6 | Deletion and return of data at the end of the agreement |
| 7 | International transfers |
| 8 | Audit rights — documentation on request, and one customer-commissioned audit per year at your expense with 30 days' notice |
| 9–10 | Governing law, and who to contact |
4. What it does not commit us to
Being specific about the gaps matters more than the summary above.
Governing law is unresolved. Section 9 defers to the jurisdiction named in the Terms of Service, and the Terms do not name one yet, because there is no registered entity to anchor it to. That is a real gap, not a drafting convenience.
There is no uptime commitment and no SLA. Section 12 of the Terms of Service says so in terms. Nothing in the DPA creates one.
We hold no certifications. No SOC 2, no ISO 27001, no completed penetration test. Section 8.1 offers documentation "on request" — today that means our written security documentation, not an auditor's report. See the Trust Centre for what does and does not exist.
The 60-day notice is a draft commitment. It is in the document you can download, and it is recorded in our internal vendor policy, so we consider ourselves bound by it. But a draft is a draft.
5. Related documents
- Sub-processors — the canonical Article 28(2) list the DPA's section 3 refers to
- Privacy Policy — how Cyril handles personal data where Cyril is the controller
- Terms of Service — the commercial agreement the DPA sits under
- Trust Centre — security posture, and the current compliance position
6. Contact
Legal enquiries: legal@getcyril.com. Security enquiries: security@getcyril.com. For a custom signed DPA, write to the legal address and say what your review process needs.