Skip to main content
Liffey
Platform
Architects
Method
Security
Pricing
Insights
Log in Build my brain
Log in Build my brain

Data processing agreement

Last updated 10 August 2026

This is the Article 28 agreement under which Liffey processes personal data on behalf of its customers. It is published in full so that a security or legal review can be completed without requesting it.

It applies automatically to every customer, on every plan. A signed copy, or execution on your own paper, is available on request.

On this page

  1. 1. Parties and scope
  2. 2. Subject matter, duration, nature and purpose
  3. 3. Processing on documented instructions
  4. 4. Confidentiality
  5. 5. Security measures
  6. 6. Sub-processors
  7. 7. AI processing
  8. 8. International transfers
  9. 9. Assistance to the Customer
  10. 10. Return and deletion
  11. 11. Audits and information
  12. 12. Governing law

1. Parties and scope

Liffey is a registered business name of Fractional Edge Limited, registered in Ireland, company number 782670, of 71 Baggot Street, Dublin 2, Ireland ("Liffey", "Processor"). The customer identified in the Order ("Customer", "Controller") is the controller of the personal data processed under this agreement.

This agreement forms part of, and is subject to, the terms and conditions between the parties. Where they conflict on the processing of personal data, this agreement prevails.

It gives effect to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where the Customer is established in the United Kingdom, to the UK GDPR and the Data Protection Act 2018.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the Liffey platform and associated commercial architecture services
DurationThe term of the agreement, plus the return or deletion period in section 10
Nature and purposeHosting, storage, indexing, retrieval, AI-assisted analysis and generation, and presentation of Customer content, on the Customer’s instructions
Categories of data subjectCustomer personnel; the Customer’s own customers, prospects and contacts; other individuals named in Customer content
Types of personal dataBusiness contact details, employment and role information, records of business communications, and any other personal data the Customer chooses to submit
Special categoriesNone. The Customer undertakes not to submit special-category data, national identity numbers, payment card data or health data

3. Processing on documented instructions

Liffey processes personal data only on the Customer’s documented instructions, which comprise this agreement, the terms and conditions, and the Customer’s configuration and use of the platform.

Where Liffey is required by Union or Member State law to process personal data otherwise, it will inform the Customer before processing, unless that law prohibits it on important grounds of public interest.

Liffey will inform the Customer if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality

Liffey ensures that persons authorised to process personal data are bound by an appropriate duty of confidentiality, and that access is limited to those who require it to deliver the service.

5. Security measures

Liffey implements the technical and organisational measures required by Article 32. The current measures are published in full and control by control at liffey.ai/security and at the trust centre. They include, without limitation:

  • Encryption of personal data in transit and at rest
  • Processing at every layer within the European Union
  • Role-based access control, with operator access that is break-glass, time-boxed, reason-stated and self-expiring
  • An append-only audit log recording actor, timestamp and before and after state of every significant action
  • Optional PII redaction at ingestion, available in every workspace, ahead of storage, indexing and AI processing
  • Continuous point-in-time recovery of the database

Liffey may update these measures, provided the level of protection is maintained.

6. Sub-processors

The Customer grants Liffey general written authorisation to engage sub-processors. The current list, with the purpose, processing location and certifications of each, is published at liffey.ai/sub-processors.

Liffey gives the Customer 30 days’ written notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. Where an objection cannot be resolved, the Customer may terminate the affected service on written notice, with a pro-rata refund of prepaid fees.

Liffey imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this agreement, and remains fully liable to the Customer for their performance.

Optional source connectors are engaged only where the Customer chooses to connect them, and only to read the content the Customer authorises.

7. AI processing

AI inference and embedding generation are performed within the European Union by the providers named in the sub-processor list.

Under the enterprise terms Liffey holds with those providers, Customer inputs are excluded from model training, and prompts and responses are processed in memory rather than retained at the AI layer.

Where the Customer elects to supply its own AI provider, that provider is engaged on the Customer’s instruction, is recorded against the Customer’s workspace, and the Customer is responsible for the terms it holds with that provider.

8. International transfers

All core processing takes place within the European Union: the database, application compute, AI inference, embedding generation and transactional email.

Liffey does not transfer the Customer’s personal data outside the European Economic Area except in two cases. Where the Customer connects an optional source located in a third country, Liffey reads the content the Customer has authorised and stores the derived text within the EU. And where the Customer gives prior documented instruction. In each case a valid Chapter V transfer mechanism applies.

Optional source connectors and their locations are listed at liffey.ai/sub-processors.

9. Assistance to the Customer

Data subject rights. The platform provides self-service means for most requests: content search to locate a data subject’s personal data, document-level and source-level purge for erasure, and export of workspace content. Where a request cannot be satisfied self-service, Liffey provides assistance within 10 business days of a written request. Where a request reaches Liffey directly, it is referred to the Customer.

Personal data breach. Liffey notifies the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer personal data, describing the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Notification is sent to the workspace owners.

Impact assessments. Liffey provides reasonable assistance with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to it.

10. Return and deletion

On termination, the Customer may export its commercial architecture and content through the platform. At the Customer’s written election, Liffey deletes or returns all Customer personal data within 30 days of the end of the agreement, and deletes existing copies, save where Union or Member State law requires storage.

Backups are overwritten on their ordinary cycle, and remain subject to the security measures in section 5 until they are.

11. Audits and information

Liffey makes available the information necessary to demonstrate compliance with Article 28, including its published security documentation and, on request and subject to each provider’s non-disclosure terms, the audit reports and certificates of its sub-processors.

Where those are insufficient, the Customer or an auditor it mandates may conduct an audit, on 30 days’ written notice, no more than once in any twelve-month period, during normal business hours, without disruption to other customers’ environments, and subject to reasonable confidentiality undertakings. Information already available above is used first. A supervisory authority exercising statutory powers is not subject to these limits.

12. Governing law

This agreement is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction, without prejudice to any mandatory right of a data subject or supervisory authority to bring proceedings elsewhere.

To execute a signed copy, or to request one on your own paper, write to privacy@liffey.ai.

Liffey

Commercial intelligence for how your company wins and grows customers.

Platform

  • Overview
  • Watch a live demo
  • Ask anything
  • The memory
  • Patterns and signals
  • The weekly cadence
  • Decision tools
  • In your AI tools
  • Connected to your stack
  • What is a company brain
  • Release log

Company

  • About
  • Architects
  • Method
  • Insights
  • Careers
  • The book
  • Contact

Compare

  • Compare Liffey
  • Build your own brain
  • Company brain platforms
  • Fractional CRO, CCO or CMO
  • ChatGPT, Claude and Copilot

Get started

  • Pricing
  • Find your value leak
  • Build my brain
  • Book a consult
  • FAQ
  • Log in

Trust

  • Security
  • Trust centre
  • Privacy
  • Terms and conditions
  • Data processing agreement
  • Sub-processors
  • Cookie policy
  • Cookie preferences
  • llms.txt
© 2026 Liffey · Registered in Ireland, no. 782670 · 71 Baggot St, Dublin 2, Ireland LinkedIn  ·  Substack

We value your privacy

We use analytics to understand which pages help people, and it stays anonymous until you say otherwise. Nothing is stored on your device without your consent. See our cookie policy.

Your cookie choices

Analytics runs without cookies and without anything that identifies you until you turn it on here. Everything else stays off until you choose it.

Strictly necessaryKeeps you signed in to the product and remembers the choice you make on this panel. These cannot be switched off.
Always on
AnalyticsGoogle Analytics, so we can see which pages are useful. Off means it still counts the page view without cookies and without identifying you. On means it remembers your visit between pages.
MarketingTools that recognise you across visits, so we know whether something we sent you brought you here. These set cookies as soon as they load, so they load only if you turn this on.