- Home
- Legal
- DPA
Clear terms for how we process your data.
This DPA sets out how Pace processes personal data on your behalf when you use the Services. Effective date: August 2026.
This document is provided for review and is ready for final legal review before release. It is not legal advice. Questions can be sent to hello@pace.so.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer (the "Controller") and Pace Software, Inc. (the "Processor") governing the processing of personal data in connection with the Services. Capitalized terms have the meanings given in applicable data protection law, including the GDPR and CCPA.
1. Definitions
- Personal data: any information relating to an identified or identifiable natural person processed in the Services.
- Processing: any operation performed on personal data, including collection, storage, use and deletion.
- Applicable law: data protection legislation governing the parties, including the GDPR, the UK GDPR and the CCPA.
2. Roles of the Parties
The Controller determines the purposes and means of processing and remains responsible for ensuring it has lawful bases for the personal data it uploads. The Processor processes personal data only on documented instructions from the Controller and in accordance with this DPA.
3. Details of Processing
The subject matter, nature and purpose of processing are as follows:
- Subject matter: the operation of the profitability platform for agencies.
- Duration:for the term of the Controller's use of the Services, plus a reasonable period for deletion or return as described in Section 11.
- Nature and purpose: hosting and operating the Services, storing client, retainer, time and margin data, providing reporting and alerts, and supporting the Controller.
- Categories of data subjects:the Controller's personnel and any individuals whose information the Controller uploads.
- Categories of personal data: names, work email addresses, roles and any other personal data the Controller chooses to include.
4. Data Subject Rights
The Processor shall assist the Controller, by appropriate technical and organizational measures and to the extent possible, in fulfilling the Controller's obligations to respond to data subject requests. Where the Processor receives a request directly, it shall inform the data subject and the Controller and shall not respond substantively except as required by law.
5. Processor Obligations
The Processor shall:
- Process personal data only on documented instructions, unless required otherwise by law.
- Ensure that persons authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational measures to protect personal data.
- Not sell personal data, and not use it for purposes other than providing the Services.
- Assist the Controller in meeting its obligations regarding security, breach notification and data protection impact assessments.
6. Sub-processors
The Controller grants general authorization for the Processor to engage sub-processors. The Processor shall maintain a list of sub-processors, notify the Controller of any intended changes, and impose data protection obligations on sub-processors that are at least as protective as this DPA. The Controller may object to a new sub-processor on reasonable grounds within a reasonable period of notification.
7. Security
Taking into account the state of the art and the risks involved, the Processor shall implement appropriate technical and organizational measures, including: encryption of personal data in transit (TLS 1.3) and at rest (AES-256); individual authentication and role-based access controls; workspace isolation; and measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems.
8. International Transfers
Where personal data is transferred to a country outside the EEA, the UK or the Controller's jurisdiction, the Processor shall ensure such transfers are made in compliance with applicable law, including through standard contractual clauses or an equivalent recognized mechanism.
9. Audits
Upon the Controller's reasonable request and at reasonable intervals, the Processor shall make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and without compromising the security of other customers.
10. Personal Data Breaches
The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's data, provide reasonable information available to it, and cooperate in the Controller's investigation and remediation. Notification does not constitute an acknowledgement of fault or liability.
11. Deletion and Return
Upon termination of the Services, the Processor shall, at the Controller's choice, delete or return all personal data, unless applicable law requires retention. Deletion shall occur within a reasonable period and in a secure manner.
12. Term
This DPA takes effect upon the Controller's use of the Services and remains in effect until the Services are terminated and all personal data has been deleted or returned in accordance with this DPA.
13. Contact
Questions about this DPA? Contact us at hello@pace.so.