Parity Backup
Why backupHow it worksCoveragePricingPartnersSign inStart free trial

Data processing agreement

Unreviewed draft · not yet legal advice

This document is a working draft prepared for review. It has not been reviewed by a qualified lawyer and must not be relied on as a published legal document until that review is complete.

Version 0.1, 26 July 2026. This agreement (“DPA”) governs our processing of personal data on your behalf when you use Parity Backup. It forms part of the terms of service between you (“Customer”) and WIKI-TECH LIMITED, company no. 14141095, registered office 21 Curzon Road, Maidstone, Kent ME14 5BB (“Processor”, “we”). It applies from the moment an account is created and needs no separate signature to bind us. If your procurement process requires a countersigned copy, see §13.

1. Definitions

“UK GDPR”, “EU GDPR”, “controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” carry the meanings given in the UK GDPR and the Data Protection Act 2018, and in the EU GDPR where that applies to you. “Customer Personal Data” means personal data contained in the data we back up from your Microsoft 365 tenant, and in the index we build of it.

2. Roles

For Customer Personal Data, the Customer is the controller and we are the processor. Where the Customer is itself a processor acting for its own client, for example a managed service provider running backups for the organisations it supports, we act as sub-processor, the Customer warrants it has authority to appoint us, and every obligation below applies to us on the same terms.

For account, security, billing and enquiry data we are the controller in our own right. That processing is described in the privacy policy and is outside this DPA.

3. Instructions

We process Customer Personal Data only on the Customer’s documented instructions. The instructions are: the terms of service, this DPA, the configuration the Customer sets in the portal (which workloads to protect, on what schedule, with what retention), and the operations the Customer runs (backup, restore, export, deletion). We will tell the Customer if, in our opinion, an instruction infringes data protection law, and may pause the affected processing until it is resolved.

We will not use Customer Personal Data for any purpose of our own. In particular we will not sell it, use it for advertising, or use it to train machine learning models.

4. Confidentiality

Access to Customer Personal Data is limited to personnel who need it to deliver or support the Service. They are bound by contractual confidentiality obligations that survive the end of their engagement. Support access to a customer console is performed through an audited mechanism that requires an access code held by the account owner, and every use is recorded in the audit trail visible to the Customer.

5. Security

We implement and maintain the technical and organisational measures in Annex II, which records the controls in force rather than the ones we intend to add. We may change a measure provided the overall level of security is not reduced, and Annex II is updated when we do.

6. Sub-processors

The Customer gives general authorisation for us to engage the sub-processors listed in Annex III, which is maintained at paritybackup.com/legal/subprocessors. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to the Customer for their performance.

We will give at least 30 days’ notice to the billing contact before a new sub-processor begins processing Customer Personal Data. The Customer may object on reasonable data protection grounds within that period, and if we cannot offer a workable alternative the Customer may terminate the affected part of the Service without penalty, with a refund of fees paid in advance for the period after termination.

7. Storage location and international transfers

Backup content is stored in Finland. A copy of the nightly database backup, which includes the backup index, is held in Germany. Both are in the European Union, and the locations are set out in §5 of the privacy policy.

Where the Customer requires a different storage provider or region, we may agree one in writing, and the order will name the provider and the location. A provider engaged that way is a sub-processor for that Customer’s data only, is subject to §6 in full, and if it holds data outside the UK or EEA the order will record the transfer safeguard relied on. The Customer’s choice of provider does not reduce our obligations under this DPA, but where that provider’s own certifications or measures differ from Annex II, the order will say so rather than leave Annex II implying otherwise.

We are established in the United Kingdom, so operating the Service involves access from the UK to data stored in the EEA. That access relies on the European Commission’s adequacy decision for the United Kingdom, and reciprocally on the UK adequacy regulations for the EEA. Where a sub-processor transfers personal data outside the UK or EEA, that transfer relies on the sub-processor’s own approved safeguards, currently standard contractual clauses in Stripe’s case. If an adequacy decision is withdrawn, we will put appropriate safeguards in place without undue delay.

8. Assisting the Customer

Taking into account the nature of the processing, we will:

  • help the Customer respond to data subject requests. The Customer can search and delete within a snapshot through the portal; where a request cannot be satisfied that way, we will act on the Customer’s written instruction. Deleting data from the source tenant does not reach backward into snapshots already taken, which is the point of a backup and also the thing customers most often expect to happen automatically;
  • provide the information the Customer reasonably needs for a data protection impact assessment or prior consultation with a supervisory authority;
  • assist with the security, breach notification and communication obligations in Articles 32 to 36.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively, and will refer them to the Customer and tell the Customer promptly.

9. Personal data breach

We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information. Where the full picture is not available at once, we will provide it in phases rather than delay the first notice.

10. Deletion and return

The Customer may export its data at any time while the account is active. On termination, the Customer may request return of Customer Personal Data within 30 days, after which we delete it. Deleting an account removes account records, sessions and billing links immediately and deletes stored backup content including prior versions, so that erasure does not leave a recoverable copy.

Two honest caveats. First, copies persist in our own database backups until those rotate out, which is about a month. Second, where storage immutability is in force on an object, deletion cannot complete before the immutability window lapses; deletion is queued and retried until the storage confirms the object is gone, and we will tell the Customer the window that applies. We do not otherwise retain Customer Personal Data unless law requires it.

11. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28, including this DPA, the current Annex II, the sub-processor list, and responses to a security questionnaire once per year. Where that is not sufficient for the Customer’s regulatory obligations, the Customer or an independent auditor bound by confidentiality may audit us on 30 days’ written notice, no more than once a year unless a supervisory authority or a breach requires otherwise, during business hours, without unreasonable disruption, and at the Customer’s cost. Audits must not require us to disclose another customer’s data.

12. Liability, term and precedence

This DPA takes effect when the account is created and continues while we process Customer Personal Data. Liability under this DPA is subject to the limitations in the terms of service. If this DPA conflicts with the terms of service on the subject of data protection, this DPA prevails. It is governed by the laws of England and Wales.

13. Signature

This DPA is binding without signature. If your procurement requires a countersigned copy, or your own DPA template on your paper, email [email protected] with the legal entity name, registered address and signatory, and we will return an executed copy within five business days.

Processor
WIKI-TECH LIMITED
21 Curzon Road, Maidstone, Kent ME14 5BB
Signature, name, title, date
Customer
Legal entity name
Registered address
Signature, name, title, date

Annex I: description of the processing

Subject matterBackup, restore and export of the Customer’s Microsoft 365 data
DurationFor as long as the account is active, plus the retention and deletion periods in §10
Nature and purposeCopying data from the Customer’s tenant, storing it in deduplicated form, indexing its metadata so items can be found, and writing it back or exporting it on the Customer’s instruction
Categories of data subjectThe Customer’s employees, contractors and any individual who corresponds with them or appears in their files and sites
Types of personal dataWhatever the Customer holds in the covered workloads: email content and attachments, calendar and contact entries, files and documents, list and site content, Teams messages, plus the index (sender, recipients, subject, folder, filename, dates, mailbox identifiers, message authors)
Special category dataNot requested and not required, but the Customer may place it in the covered workloads, in which case it is backed up like anything else

Annex II: technical and organisational measures

In force as at 26 July 2026. Measures that are built but not yet enabled are marked as such rather than listed as protections.

  • Encryption in transit. TLS for all connections: to the Microsoft Graph API, to object storage, to the database, and to the portal.
  • Encryption at rest. Backup content is stored with AES-256 server-side encryption using a key we supply on each request, which the storage provider does not retain, so stored objects cannot be read from the storage alone. The nightly database backup is encrypted before it is copied off-site.
  • Access control. Multi-factor authentication is mandatory on every account type including our administrative console. Passwords are hashed; backup codes are hashed and single-use. Sessions expire and are revoked on suspension.
  • Tenant separation. Every data access is scoped to a single account; snapshots cannot be addressed across accounts. Storage credentials are private to the Service and the bucket has no public access.
  • Least privilege at source. Access to the Customer’s tenant is by application consent the Customer grants and can revoke, and the configuration backup scopes are read-only.
  • Auditability. Security-relevant actions, including support access, restores, exports and administrative changes, are written to an audit trail the Customer can read in the portal.
  • Availability and recovery. The database is dumped nightly, verified as restorable, and copied off-site to a separate provider facility. Operator alerting fires on failed runs, on failed system jobs and on health-check failure.
  • Deletion. Account deletion removes stored objects including prior versions, and queued deletions are retried until storage confirms removal.
  • Facilities. Hosted in Hetzner data centres in Finland and Germany, which the provider certifies to ISO 27001. That is the provider’s certification. WIKI-TECH LIMITED holds Cyber Essentials and does not hold SOC 2 or ISO 27001.
  • Vulnerability management. Dependencies are kept current and the application is patched as part of routine operation. We do not currently commission an annual third-party penetration test.

Annex III: sub-processors

Maintained as a living list at paritybackup.com/legal/subprocessors, currently Hetzner Online GmbH (hosting and storage), Stripe Payments Europe Ltd (payments) and SMTP2GO (transactional email). Microsoft is the Customer’s own platform provider and is not our sub-processor.

Parity Backup

Managed backup for cloud mailboxes, archives, files and sites. Encrypted, deduplicated and stored in the EU.

A product of WIKI-TECH LIMITED, a managed IT provider registered in England and Wales.

Product

  • Why backup
  • How it works
  • Coverage
  • Pricing
  • Free trial

Company

  • Terms of service
  • Privacy policy
  • Data processing agreement
  • Sub-processors
  • [email protected]
  • 020 3822 0899

WIKI-TECH LIMITED · Company no. 14141095 · Registered office: 21 Curzon Road, Maidstone, Kent ME14 5BB

Parity Backup is not affiliated with, endorsed by, or sponsored by Microsoft. Microsoft 365, Exchange Online, OneDrive, SharePoint and Teams are trademarks of the Microsoft group of companies.