Data Processing Agreement
Last updated 27 September 2026. This Agreement applies to every client of Fractional Teams and forms part of the terms on which we provide our services. A signed copy is available on request from dpo@fractionalteams.com.
When you engage Fractional Teams, we handle personal data on your behalf: the details of people your outreach campaigns have contacted, public names and comments from your social media channels, and the activity of your own staff in our client portal. UK data protection law requires a written agreement setting out how a service provider handles that data. This is ours. It says what we do with your data, which suppliers we use, where the data goes, how we keep it safe, and what happens when the engagement ends.
Parties
Next Generation ICT Ltd, trading as Fractional Teams, a company registered in England and Wales, of 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom (Fractional Teams, the Processor), and the organisation that has engaged Fractional Teams for the Services (the Client, the Controller), each a Party and together the Parties.
1. Purpose
1.1 Fractional Teams provides the Client with marketing audit, reporting and outreach services as described in the proposal, engagement letter or written correspondence under which the Client engaged Fractional Teams (the Services), including through the client report portal at portal.fractionalteams.com (the Portal).
1.2 In delivering the Services Fractional Teams processes personal data on the Client’s behalf. This Agreement sets out the terms on which it does so, as required by Article 28 of the UK GDPR, and applies to all of the Services.
1.3 If this Agreement conflicts with any other terms agreed between the Parties on a matter of data protection, this Agreement prevails.
2. Definitions
2.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018, and, where it applies to the processing, the EU GDPR, each as amended or replaced.
2.2 Client Personal Data means the personal data described in Annex 1 that Fractional Teams processes on the Client’s behalf.
2.3 Sub-processor means any third party engaged by Fractional Teams to process Client Personal Data.
2.4 Controller, Processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in Data Protection Law.
2.5 Portal Privacy Notice means the privacy notice published at portal.fractionalteams.com/privacy.
3. Roles of the Parties
3.1 For Client Personal Data, the Client is the Controller and Fractional Teams is the Processor.
3.2 Fractional Teams is an independent Controller of the account data of the Client’s users on the Portal (names, work email addresses, login credentials, session and security logs) and of its own business records, as described in the Portal Privacy Notice. This Agreement does not cover that processing.
3.3 The Client confirms that it has a lawful basis for the collection of Client Personal Data, including the data of people its outreach campaigns have contacted, and for its instruction to Fractional Teams to process it.
4. Details of the processing
4.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
5. Fractional Teams’ obligations
Fractional Teams shall:
5.1 process Client Personal Data only on the Client’s documented instructions, including the instructions in this Agreement and any written instructions given in the course of the Services, unless required to do otherwise by law, in which case it will tell the Client before processing unless the law prevents it;
5.2 tell the Client promptly if, in its opinion, an instruction infringes Data Protection Law;
5.3 ensure that every person authorised to process Client Personal Data is bound by a duty of confidentiality;
5.4 implement the technical and organisational measures in Annex 3, and keep them under review so that they remain appropriate to the risk;
5.5 engage Sub-processors only in accordance with clause 7;
5.6 taking into account the nature of the processing, help the Client respond to requests from data subjects exercising their rights, by passing on any such request received directly within five working days and by providing the information the Client reasonably needs;
5.7 help the Client meet its obligations on security, breach notification, data protection impact assessments and prior consultation with the supervisory authority, taking into account the nature of the processing and the information available to Fractional Teams;
5.8 at the Client’s choice, delete or return all Client Personal Data at the end of the Services, and delete existing copies, unless the law requires it to be kept, and confirm in writing when this is done. Deletion from rolling database backups follows the backup retention cycle in Annex 3;
5.9 make available to the Client the information needed to demonstrate compliance with this Agreement, and allow for and contribute to audits, including inspections, conducted by the Client or an auditor it mandates, on reasonable notice and no more than once in any twelve-month period unless a supervisory authority or a personal data breach requires otherwise.
6. Personal data breaches
6.1 Fractional Teams shall notify the Client without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data.
6.2 The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where all of that information is not available at once, Fractional Teams shall provide it in stages without further undue delay.
6.3 Fractional Teams shall not notify data subjects or any supervisory authority of a breach affecting Client Personal Data unless the Client instructs it to, or the law requires it.
7. Sub-processors
7.1 The Client gives Fractional Teams general written authorisation to engage the Sub-processors listed in Annex 2.
7.2 Fractional Teams shall give the Client at least 30 days’ written notice before adding or replacing a Sub-processor, by email to the Client’s nominated contact. Where the change is forced by a Sub-processor’s own change of sub-processor, terms or service on shorter notice, Fractional Teams shall give as much notice as it received and not less than 15 days. The Client may object within that period on reasonable grounds relating to data protection. If the Parties cannot resolve the objection in good faith, the Client may terminate the affected Services on written notice without penalty.
7.3 Fractional Teams shall impose on each Sub-processor, by written contract, data protection obligations that offer the same level of protection as this Agreement, and remains fully liable to the Client for the Sub-processor’s performance.
7.4 Fractional Teams shall keep Annex 2 current, publish the current version at fractionalteams.com/dpa, and provide it on request.
8. International transfers
8.1 Fractional Teams processes Client Personal Data in the United Kingdom, except where Annex 2 states that a Sub-processor processes data elsewhere.
8.2 Fractional Teams shall not transfer Client Personal Data outside the United Kingdom, or permit a Sub-processor to do so, unless the transfer is covered by adequacy regulations under the Data Protection Act 2018 (including the UK Extension to the EU-US Data Privacy Framework for a certified recipient), or by the ICO’s International Data Transfer Agreement or Addendum, or by another transfer mechanism valid under Data Protection Law, and a transfer risk assessment has been carried out.
8.3 Where the EU GDPR applies to the processing, the same principle applies with the EU adequacy decisions and the EU Standard Contractual Clauses in place of the UK instruments.
9. Client’s obligations
The Client shall:
9.1 comply with Data Protection Law in its own collection and use of Client Personal Data, including providing any privacy information to data subjects and obtaining any consents that are required;
9.2 give Fractional Teams lawful, documented instructions;
9.3 ensure that the users it invites to the Portal keep their credentials secure and use the Portal only for the purposes of the Services;
9.4 nominate a contact for data protection matters, including sub-processor notices under clause 7. Until it does, the Client’s main contact for the Services is the nominated contact.
9.5 Fractional Teams’ contact for data protection matters, including breach notices under clause 6 and data subject requests under clause 5.6, is dpo@fractionalteams.com.
10. Records
10.1 Fractional Teams shall keep the records of processing required by Article 30(2) of the UK GDPR for its processing of Client Personal Data.
11. Term, termination and changes
11.1 This Agreement applies from the date the Client engages Fractional Teams for the Services, or from 27 September 2026 for engagements already under way on that date, and continues for as long as Fractional Teams processes Client Personal Data.
11.2 Clauses 5.8, 5.9, 6 and 12 survive termination.
11.3 Fractional Teams may update this Agreement to reflect changes in the law, in the Services or in its suppliers. It shall give the Client at least 30 days’ notice by email of any change that reduces the Client’s protection, and changes to Annex 2 follow clause 7. The current version is always published at fractionalteams.com/dpa.
12. Liability and governing law
12.1 Each Party’s total liability to the other under or in connection with this Agreement, whether in contract, tort (including negligence) or otherwise, is limited to the fees paid by the Client to Fractional Teams for the Services in the month before the event giving rise to the claim.
12.2 Neither Party is liable to the other for loss of profit, loss of business, or indirect or consequential loss arising under or in connection with this Agreement.
12.3 Nothing in this Agreement limits or excludes either Party’s liability for death or personal injury caused by negligence, for fraud, or for any liability that Data Protection Law does not permit to be limited or excluded.
12.4 This Agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.
Annex 1: Details of the processing
Subject matter. Marketing audit and reporting services covering the Client’s web presence, search and AI-search visibility, social media, paid media and LinkedIn outreach, delivered through monthly reports in the Portal.
Duration. For as long as Fractional Teams provides the Services, plus the deletion period in Annex 3.
Nature and purpose. Collecting performance data about the Client’s marketing channels; storing it; analysing it and preparing written reports and recommendations, including drafts prepared with the help of an AI model; publishing the reports to the Client’s users in the Portal; recording the status of outreach leads as the Client’s users update it; answering questions the Client’s users ask from within a report.
Sources of the data. The Services draw on the following tools. Ahrefs and geogen supply search and AI-search visibility data (domain, keyword, brand mention and citation data) and return no personal data. LinkedIn Marketing Solutions and Reddit Ads supply campaign and spend figures from the Client’s own advertising accounts, which the Client connects through the Portal, and return no personal data. EnquirerAI supplies the outreach figures and lead records from the Client’s own EnquirerAI tenant, to which the Client grants Fractional Teams access; EnquirerAI is the Client’s processor under the Client’s own terms with that provider. Metricool supplies social media analytics for the Client’s brands from an account held by Fractional Teams and is listed as a Sub-processor in Annex 2.
Categories of data subjects.
- People the Client’s LinkedIn outreach campaigns have contacted (prospects and leads).
- Individuals who have interacted publicly with the Client’s social media accounts, to the extent their names and comments appear in social media analytics.
- The Client’s own staff who use the Portal (for the audit trail of lead-status changes and chat transcripts; their account data is covered by the Portal Privacy Notice).
Categories of personal data.
- Outreach leads: name, job title, company, LinkedIn profile URL, campaign, the state of the conversation, and the text of messages exchanged with the Client’s outreach account, capped in length.
- Social media: public names and comment text as returned by the social media platforms’ analytics, where present.
- Portal users: name, email address, the record of which user changed a lead status and when, and chat messages sent from a report.
Special category data. None is sought. Message text written by leads may incidentally contain whatever the lead chose to write; Fractional Teams does not analyse it for special category data.
Annex 2: Sub-processors
Fractional Teams processes Client Personal Data in the United Kingdom on its own systems and through the Sub-processors below. Tools that return no Client Personal Data are described in Annex 1 and are not Sub-processors.
Sub-processor | Purpose | Data involved | Location and transfer basis |
|---|---|---|---|
Vultr (The Constant Company, LLC) | Hosting of the Portal server | All Portal data, including Client Personal Data | London, United Kingdom |
Vultr (The Constant Company, LLC) | Encrypted off-site backups of the Portal database | All Portal data, encrypted before upload; Fractional Teams alone holds the key | Amsterdam, Netherlands. The EU is covered by UK adequacy regulations. |
SMTP2GO (Sand Dune Mail Ltd) | Sending of Portal account emails | Names and email addresses of Portal users, report titles | EU data centre in Amsterdam with inbound servers in London and Frankfurt; sending is processed on EU and UK servers only, under SMTP2GO’s Data Processing Agreement. The provider is based in New Zealand, which is covered by UK adequacy regulations. |
Slack (Slack Technologies Limited, part of Salesforce) | The Fractional Teams side of the in-report chat, and internal notifications of lead-status changes | Chat messages, Portal user names, lead names as they appear in status changes | United States. Salesforce, Inc. and Slack Technologies, LLC are certified under the UK Extension to the EU-US Data Privacy Framework. |
Google Workspace (Google Cloud EMEA Limited) | Email correspondence with the Client, and storage of working files for the monthly report cycle in Google Drive | Correspondence; the assembled data files behind each report, which include outreach lead records | Google data centres in the EU and the United States. Google LLC is certified under the UK Extension to the EU-US Data Privacy Framework, and Google’s data processing terms include the ICO International Data Transfer Addendum. |
Anthropic (Anthropic Ireland, Limited) | Drafting of the narrative sections of monthly reports from the data held for the Client | Business performance figures and, for the outreach section, lead names, job titles, companies, LinkedIn profile URLs and message text; retained by Anthropic for 30 days for safety monitoring and not used to train its models | United States. Anthropic’s data processing addendum applies the EU Standard Contractual Clauses with the ICO International Data Transfer Addendum for UK data. |
Metricool Software, S.L. | Social media analytics and scheduling for the Client’s connected brands; source of the social media section of reports | Post data, engagement figures, and public names and comment text returned by the social media platforms | Spain, with all data stored in the EU, which is covered by UK adequacy regulations. |
The Portal’s public pages use Google Analytics 4 and Ahrefs Web Analytics, and the Portal is monitored by Better Stack. None of these receives Client Personal Data: the analytics tools see only pseudonymous visitor data on pages where no client data is shown, and the monitoring service sees only availability signals. They are described in the Portal Privacy Notice.
Annex 3: Technical and organisational measures
Access control. Every Portal user has an individual login with a password stored as a salted hash and compulsory two-factor authentication for administrators. Access to a Client’s data is scoped per user and enforced on every request, on the web interface, the API and the MCP server alike. One client’s data is never visible to another client. Fractional Teams staff access is limited to named administrators.
Encryption. All traffic is encrypted in transit. Two-factor secrets and connected ad-platform credentials are encrypted at rest with separate keys. API keys are stored hashed and shown once. Database backups are encrypted before they leave the server, with the key held only by Fractional Teams.
Isolation of automated processing. Scheduled jobs that collect data and prepare report drafts run in sandboxed processes with read-only access to the system, separate from the web service, and each holds only the credentials it needs. The web service holds no credentials for external data sources or AI models.
AI model use. Report drafts are produced one client at a time; no request to the AI model contains more than one client’s data. Text from third parties (lead messages, social comments) is passed to the model as data, never as instructions, and the model’s output is checked for cross-client references before a draft is saved. Drafts are reviewed by a person before release to the Client.
Monitoring and logging. Server and error logs record IP address, requested path and time, and are kept on a rolling basis, typically under 90 days. Uptime and scheduled jobs are monitored so that failures are detected the same day.
Backups and retention. The database is backed up nightly to an encrypted off-site copy on a rolling cycle. Account data is deleted on request or within 12 months of the engagement ending; reports, lead history and chat transcripts are deleted with the account.
Security review. The service is reviewed for security before each significant change, and the findings and fixes are recorded.
Sub-processor management. Each Sub-processor is engaged under written terms, and the schedule in Annex 2 is maintained and notified to the Client under clause 7.
Questions about this Agreement: dpo@fractionalteams.com.