Legal
Data Processing Agreement
Last updated · 18 September 2026
Terms · Privacy · DPA · Subprocessors
The short version
This agreement covers the situation where the material you upload contains personal data about other people — your staff, directors, subcontractors, referees, or contracting-authority contacts.
In that situation you are the controller and Mighty Andy is your processor. We act on your instructions, we do not use that personal data for our own purposes, and we are accountable to you for how it is handled.
It sets out what we do about security, who else may process the data, what happens when someone exercises a privacy right, what happens if there is a breach, and what happens to the data at the end.
This is the Data Processing Terms referred to in the Terms of Service and the Privacy Notice. It applies automatically — there is nothing to sign — and it takes effect when you first provide Customer Content containing personal data.
1. Parties and scope
This Data Processing Agreement (the DPA) is entered into between the Customer and:
GUILHEM KUCZYNSKI
Entrepreneur individuel
SIREN: 880 003 629
Registered address: 6 allée des Amandiers, 33140 Villenave-d’Ornon, France
GUILHEM KUCZYNSKI is the structure currently hosting Mighty Andy while its United Kingdom corporate structure is established, and is referred to in this DPA as Mighty Andy.
This DPA forms part of the Terms of Service and applies whenever Mighty Andy processes personal data contained in Customer Content on the Customer’s behalf.
It does not apply to personal data for which Mighty Andy is itself the controller — account details, Customer contacts, purchases, support conversations, security information and Mighty Andy’s own product telemetry. That processing is described in the Privacy Notice.
No signature is required. This DPA takes effect when the Customer first provides Customer Content containing personal data and continues for as long as Mighty Andy processes that data.
2. Roles
The Customer is the controller of personal data contained in Customer Content. The Customer determines why that data is provided and is responsible for having a lawful basis to provide it.
Mighty Andy is the processor of that data and processes it only as described in this DPA.
Where the Customer is itself acting as a processor for another controller, the Customer confirms it has the authority to appoint Mighty Andy as a subprocessor, and references to the Customer in this DPA apply accordingly.
3. Processing instructions
Mighty Andy processes personal data contained in Customer Content:
- to perform Runs and produce diagnostics for the Customer
- to deliver, store and make available the resulting outputs
- to support the Customer and investigate concerns about a Run
- to secure the Service and investigate security incidents
- as otherwise instructed by the Customer in writing
Submitting material for a Run, requesting support, and using the Service in the ordinary way constitute the Customer’s documented instructions.
Mighty Andy does not sell personal data contained in Customer Content, does not use it to build advertising profiles, and does not use it for its own unrelated purposes.
Mighty Andy does not provide Customer Content to third-party general-purpose AI providers for the purpose of training their general-purpose models unless this has been expressly agreed with the Customer. This does not prevent an AI subprocessor from processing Customer Content transiently where that processing is necessary to perform a Run.
Where inference is performed on models operated by Mighty Andy rather than by a third-party provider, no third-party inference provider receives Customer Content for that processing. The obligations in this DPA apply unchanged.
Where Mighty Andy derives generalised knowledge, failure patterns, evaluations or diagnostic heuristics from operating the Service, it does so on a basis that does not identify or reproduce personal data contained in Customer Content.
If Mighty Andy believes an instruction infringes applicable data-protection law, it will inform the Customer and may suspend performance of that instruction until it is resolved.
Where Mighty Andy is required by law to process personal data otherwise than on the Customer’s instructions, it will inform the Customer of that requirement before processing unless the law prohibits it.
4. Confidentiality
Mighty Andy treats personal data contained in Customer Content as confidential.
Access is limited to personnel who need it to provide the Service, support the Customer, investigate a problem, protect the Service or perform legitimate beta evaluation.
Personnel with access are bound by confidentiality obligations that survive the end of their engagement.
During Closed Beta, members of the Mighty Andy team may inspect Customer cases, Run traces and outputs for the purposes described in the Privacy Notice. That inspection is part of providing and improving the Service and remains subject to this DPA.
5. Security
Mighty Andy implements technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing.
The measures in force are described in Annex B.
Mighty Andy may change those measures as the Service develops, provided the level of protection is not materially reduced.
Mighty Andy does not claim security certifications or assurances it does not hold. Where a Customer requires a particular certification or contractual security commitment, it should raise this before providing material, and Mighty Andy will say clearly what it can and cannot currently support.
6. Subprocessors
The Customer gives general authorisation for Mighty Andy to engage subprocessors to help provide the Service.
The current subprocessors are published and maintained at:
mightyandy.co.uk/legal/subprocessors.html
Mighty Andy maintains that list rather than naming individual providers in this DPA, so that the published position stays accurate as the provider stack changes.
Some entries on that list are a named set of providers performing one function — model inference in particular, which is routed across approved providers and models operated by Mighty Andy. Every provider in such a set is named on the list and bound by this DPA. Moving work between providers already published is an operational decision rather than the engagement of a new subprocessor; adding a provider to a set is a change to the list and is published in advance.
Before a new subprocessor begins processing personal data contained in Customer Content, Mighty Andy will update that list. Customers may subscribe to be notified of changes by writing to [email protected].
A Customer may object to a new subprocessor on reasonable data-protection grounds within 30 days of the list being updated. Mighty Andy will work with the Customer in good faith to address the objection. If it cannot reasonably be resolved, the Customer may stop submitting new Runs and terminate the affected part of the Service, and will be reimbursed for any purchased Runs not delivered.
Mighty Andy imposes data-protection obligations on each subprocessor that are materially equivalent to those in this DPA, and remains responsible to the Customer for a subprocessor’s performance.
7. International transfers
Mighty Andy is currently legally provided from France and serves business Customers primarily established in the United Kingdom.
Some subprocessors may process personal data outside the United Kingdom or the European Economic Area.
Where a transfer requires a safeguard under applicable data-protection law, Mighty Andy will rely on an appropriate mechanism, which may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism.
The subprocessor list records the relevant processing location for each subprocessor.
8. Assistance with data-subject requests
Where an individual exercises a data-protection right in relation to personal data contained in Customer Content, the Customer is responsible for responding as controller.
Mighty Andy will not respond directly to such a request on the Customer’s behalf unless legally required or instructed by the Customer. Where a request reaches Mighty Andy directly, it will pass it to the Customer without undue delay.
Taking into account the nature of the processing, Mighty Andy will provide reasonable assistance to enable the Customer to respond, including by locating, providing, correcting, restricting or deleting relevant material where the Customer cannot readily do so itself.
9. Assistance with assessments
Taking into account the nature of the processing and the information available to it, Mighty Andy will provide reasonable assistance to the Customer with:
- data protection impact assessments
- prior consultation with a supervisory authority
- demonstrating compliance with the security obligations in this DPA
10. Personal data breaches
Mighty Andy will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data contained in that Customer’s Customer Content.
The notification will describe, so far as known at the time:
- the nature of the breach and the categories and approximate volume of data and records affected
- the likely consequences
- the measures taken or proposed to address it and to mitigate its effects
- a contact point for further information
Where the full picture is not available immediately, Mighty Andy will provide information in phases as it is established rather than delaying the initial notification.
Mighty Andy will not notify a supervisory authority or affected individuals on the Customer’s behalf unless instructed to, or legally required to, do so. Notifying the Customer is not an admission of fault.
11. Deletion and return
Retention periods applying during Closed Beta are set out in the Privacy Notice.
The Customer may ask at any time for operational Customer Content to be deleted earlier, by writing to [email protected]. Mighty Andy will normally honour such a request where it can do so without compromising an active service, a security investigation or a legal obligation.
On the Customer’s request, Mighty Andy will return the Customer’s outputs and, where reasonably practicable, the material supplied for a Run, in a commonly used format.
At the end of the relationship, Mighty Andy will delete or anonymise personal data contained in Customer Content within the retention periods described in the Privacy Notice, except where continued retention is required by law.
Where material must be retained for accounting, tax, security, fraud-prevention or legal-claims purposes, it remains subject to this DPA and is not used for any other purpose.
Deletion extends to subprocessors, which are instructed to delete or anonymise the relevant data on the same basis. Data held in routine backups is deleted or overwritten on the ordinary backup cycle.
12. Audit and compliance information
Mighty Andy will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questions about its processing, security measures and subprocessors.
Where that information is not sufficient, and where applicable data-protection law requires it, the Customer may audit Mighty Andy’s compliance, or appoint an independent auditor to do so. Any such audit:
- requires at least 30 days’ written notice, except where a supervisory authority or a personal data breach requires otherwise
- takes place during normal business hours and without unreasonable disruption to the Service
- is limited to processing relevant to that Customer
- is subject to confidentiality obligations, and must not compromise the confidentiality of other Customers or the security of the Service
- occurs no more than once in any twelve-month period, unless required by a supervisory authority or following a personal data breach
Mighty Andy may charge a reasonable fee for time spent on an audit beyond the provision of the information described above.
13. Liability and precedence
Liability under this DPA is subject to the limitations set out in the Terms of Service, to the extent permitted by applicable law.
For matters concerning the processing of personal data on the Customer’s behalf, this DPA prevails over the Terms of Service and the Privacy Notice to the extent of any inconsistency.
For all other matters, the Terms of Service govern.
Nothing in this DPA excludes or limits liability where doing so would be prohibited by applicable law.
14. Changes
Mighty Andy may update this DPA to reflect changes in the Service, the provider stack, its legal structure or applicable law.
Material changes apply prospectively and will be communicated through the Service, by email, or by another reasonable method.
Mighty Andy will not use an update to this DPA to acquire materially broader rights over personal data supplied under an earlier arrangement.
Annex A · Description of the processing
| Subject matter | Analysis of tender opportunities and related company material to support the Customer’s bid/no-bid decision. |
|---|---|
| Duration | For the term of the Terms of Service, plus the retention periods set out in the Privacy Notice. |
| Nature and purpose | Receipt, storage, extraction, inspection, automated and AI-assisted analysis, generation of diagnostic outputs, delivery of those outputs, support, and security monitoring. |
| Types of personal data | Whatever the Customer chooses to include in Customer Content. Typically names, job titles, professional contact details, employment and qualification information, CV and case-study content, signatures, and references appearing in tender documents, bids, policies, certificates and supporting evidence. |
| Categories of data subject | The Customer’s staff and directors; subcontractors and suppliers; referees and named contacts; contracting-authority personnel; other individuals named in the material supplied. |
| Special category data | Not requested and not required. The Customer should not include special category or criminal-offence data unless it is genuinely necessary for the tender, and remains responsible for the lawful basis and any additional conditions where it does. |
| Frequency | Per Run, as determined by the Customer. |
Annex B · Technical and organisational measures
| Access control | Access to Customer Content is restricted to personnel who need it for the purposes described in clause 4. Administrative access is limited and authenticated. |
|---|---|
| Encryption | Data is transmitted over encrypted connections. Stored Customer Content is held on infrastructure that provides encryption at rest. |
| Segregation | Customer cases are separated so that material from one Customer is not exposed to another. Operational systems are separated where appropriate. |
| Logging and monitoring | Access, Run activity and security events are logged and monitored, and retained as described in the Privacy Notice. |
| Provenance controls | Run records identify which material was inspected and where a conclusion came from, so processing can be reconstructed and audited after the fact. |
| Subprocessor control | Subprocessors are engaged under equivalent data-protection obligations and given only the information reasonably required for their function. |
| Resilience | Customer Content and Run records are held on managed infrastructure with redundancy and backup appropriate to the stage of the Service. |
| Deletion | Retention periods are applied as described in the Privacy Notice, with earlier deletion on request under clause 11. |
| Personnel | Personnel with access are bound by confidentiality obligations surviving the end of their engagement. |
| Incident response | Suspected incidents are investigated on discovery, with Customer notification under clause 10. |
These measures reflect the current stage of the Service. Mighty Andy does not represent that it holds formal security certification.