Data Processing Addendum
Last updated: 17 July 2026
1. Scope and incorporation
This Data Processing Addendum (the "DPA") applies when GLORIAPR LTDprocesses personal data on behalf of a B5Tools operator through the API, WordPress plugin, or related Service. It forms part of the Terms of Service. The terms controller, processor, personal data, processing, and personal data breach have the meanings given by applicable UK data protection law.
2. Roles
The operator is the controller for end-user data submitted through its site, application, or integrations. GLORIAPR LTD acts as processor when it processes assessment answers or related request data to provide the Service on that operator's instructions. We remain controller for our own account, billing, security, analytics, legal, and operational records.
3. Processing details
- Subject matter and nature: API scoring, WordPress connection, Connected Site verification, plan and quota checks, result delivery, diagnostics, security, and support.
- Purpose: provide, protect, maintain, and support the Service requested by the operator.
- Duration: the term of the operator's use of the Service, plus the limited retention described in the Privacy Policy or required by law.
- Data subjects: the operator's authorised users and visitors or WordPress users whose data the operator submits to the Service.
- Data categories: operator identity and support data, site and credential metadata, request and usage metadata, assessment answers submitted for scoring, and other personal data the operator lawfully instructs us to process through supported fields.
Metadata-only event endpoints are not intended to receive raw answers, names, email addresses, free-text notes, full trait vectors, special-category data, or other unnecessary personal data.
4. Documented instructions
We process personal data only on documented instructions expressed through the Terms, this DPA, API calls, dashboard settings, plugin settings, and support requests, unless law requires other processing. If law permits, we will notify the operator before processing required by law. We will notify the operator if we believe an instruction infringes applicable data protection law.
5. Confidentiality and security
Personnel authorised to process personal data are subject to confidentiality obligations. We maintain technical and organisational measures appropriate to the nature of the Service, including access controls, HTTPS, one-way API-key hashing, short-lived connection secrets, server-side credential handling, scoped credentials, audit records, and security controls provided by our infrastructure providers.
6. Subprocessors
The operator gives general authorisation for the subprocessors listed on the Subprocessors page. We require subprocessors to protect personal data under terms appropriate to their role. We remain responsible for subprocessor performance to the extent required by applicable law.
We will update the list before a new subprocessor begins relevant processing where practical. An operator may object by emailing us on reasonable data protection grounds. We will work in good faith to address the objection; if no reasonable alternative is available, either party may stop the affected Service.
7. Data-subject requests
Taking account of the nature of processing, we will provide reasonable assistance for requests to access, correct, erase, restrict, port, or object to personal data processed on the operator's behalf. The operator remains responsible for responding to the person and for data held in its own WordPress site, browser storage, email, CRM, or integrations.
8. Personal data breaches
We will notify the operator without undue delay after becoming aware of a personal data breach affecting data processed on the operator's behalf. We will provide available information reasonably needed for the operator's notification and investigation duties and take reasonable steps to contain and remediate the breach.
9. Compliance assistance
Taking account of the information available to us and the nature of processing, we will provide reasonable assistance with security obligations, data protection impact assessments, and regulator consultations that relate to our processing. Additional or unusually burdensome assistance may be subject to a reasonable fee agreed in advance, unless the need arises from our breach of this DPA.
10. Return and deletion
On termination or a valid written request, we will delete or return personal data processed on the operator's behalf where technically feasible, unless law requires retention. This does not cover data controlled by the operator in WordPress or another integration, or B5Tools records retained in our controller capacity for billing, tax, security, fraud prevention, disputes, or legal compliance.
11. Information and audits
We will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant provider or security documentation where available. If that information is insufficient, an operator may request a proportionate audit no more than once in a twelve-month period, subject to reasonable notice, confidentiality, security, and scope requirements. This limit does not apply after a relevant breach or where a regulator requires an audit.
12. International transfers
Where protected data is transferred outside the United Kingdom or European Economic Area, we use an applicable adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer safeguard.
13. Order of precedence and contact
If this DPA conflicts with the Terms on the processing of personal data on the operator's behalf, this DPA controls. Questions or requests under this DPA can be sent to hello@b5tools.ly.