← Back to home

Data Processing Agreement

Englander Inventory Forecaster · Version 1.0 · 4 August 2026

In plain English

There is nothing here for you to sign. This agreement is already in place — you accepted it when you created your account and agreed to our Terms of Service, which include this document.

It is the formal data protection contract between your business and ours. UK GDPR requires one whenever a company handles personal data on another's behalf, and your accountant, insurer or a larger customer may ask to see it. It lives here permanently so you can read it, save a copy, or send it on whenever you need to.

In practice the Inventory Forecaster handles very little personal data — it deals in products, stock and sales figures, not people. The personal data involved is mainly the names and email addresses of your staff who log in. None of your own customers' details are stored in it.

1. What this agreement covers

This Data Processing Agreement ("DPA") forms part of the Terms of Service for the Englander Inventory Forecaster (the "Service"). It sets out how we handle personal data on your behalf, as required by Article 28 of the UK GDPR.

If anything in this DPA conflicts with the Terms of Service, this DPA wins on data protection matters.

1.1 How this agreement is accepted — no signature needed

This DPA takes effect automatically. Neither of us needs to sign anything. It is accepted when you:

Because this DPA forms part of the Terms of Service (section 16 of those Terms), agreeing to the Terms is agreeing to this document. It is the current version at all times, and the version date at the top tells you when it last changed. We will notify you before any significant change, as set out in section 12.

If your own compliance process specifically requires a countersigned copy on paper, email privacy@englander.ai and we will arrange one — but this is not necessary for the agreement to be binding.

2. Who is responsible for what

2.1 You are the controller; we are the processor

For personal data you put into the Service, or that we collect from your Linnworks account on your instructions, you are the data controller and we are the data processor. You decide what goes in and why; we process it to provide the Service to you.

2.2 Where we are a controller in our own right

For a small set of data we act as controller: your account owner's business contact details, billing and invoicing records, support correspondence, and website analytics. We handle these to run our own business and meet our legal obligations. This is described in our Privacy Policy, not in this DPA.

2.3 Your instructions

We process personal data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, the settings and actions you take within the Service, and any further written instruction you give us. We will tell you if we believe an instruction breaks data protection law.

If we are ever required by law to process your data other than on your instructions, we will tell you first unless the law forbids it.

3. What we will do

We will:

4. What you agree to do

You will:

5. Sub-processors

You give general authorisation for us to use sub-processors. Our current list, what each one does and what it can see, is published at englander.ai/sub-processors and forms part of this DPA.

We will:

If you reasonably object to a new sub-processor within that notice period, we will work with you to find an alternative. If we cannot, you may cancel the affected subscription without penalty and receive a pro-rata refund of prepaid fees.

5.1 No AI or machine learning providers

We do not disclose or transfer your data to any artificial intelligence, large language model or machine learning service, and we do not use your data to train models — our own or anyone else's. The forecasting performed by the Service is conventional statistical analysis carried out within our own database.

Adding any such provider would be the addition of a sub-processor, and would require the 30 days' notice and right to object set out above.

6. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it.

Our notification will describe, as far as we know at the time: what happened, the categories and approximate number of records affected, the likely consequences, what we are doing about it, and a contact point for more information. Where we don't have all the detail immediately, we will provide it in stages as we establish it rather than delay telling you.

We will not make a public statement identifying you as affected without your agreement, unless the law requires it.

7. Helping you with individuals' rights

The Service includes tools that let you access, correct, export and delete records yourself, which will resolve most requests.

If an individual contacts us directly about data we hold for you, we will not respond to the substance ourselves — we will pass the request to you without undue delay, because it is your request to answer as controller.

Where you need help that the Service's own tools can't provide, email privacy@englander.ai and we will assist at no charge for reasonable volumes.

7.1 Exporting your data

You can export your data at any time while your subscription is active, in a common machine-readable format. If you need an export we can't produce through the interface, ask us and we will do it.

7.2 Deleting your data

You can ask us to delete personal data at any time by emailing privacy@englander.ai. We will action it within 30 days and confirm when it is done. See section 9 for what happens automatically when your subscription ends.

8. Audits and information

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, including answering security questionnaires and providing the details of our sub-processors' safeguards.

You may audit our compliance, or appoint an independent auditor to do so, on reasonable written notice (at least 30 days), no more than once in any 12 months unless a breach has occurred or a regulator requires it. Audits must happen during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality. Each side bears its own costs.

Being straight with you

We are a small company and we do not hold ISO 27001, SOC 2 or Cyber Essentials certification. We have not commissioned a third-party penetration test. We would rather tell you that plainly than imply otherwise. Annex 2 describes the security measures we genuinely have in place.

9. Deletion and return when the Service ends

When your subscription ends:

We keep records we are required by law to keep — invoices and payment records — for as long as the law requires (currently 7 years). These contain billing details, not your inventory data.

10. International transfers

Your data is stored in a database hosted in Frankfurt, Germany (EU).

Some of our sub-processors are incorporated in the United States. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with each provider's own safeguards.

11. Liability

The limits and exclusions of liability in the Terms of Service apply to this DPA. Nothing here limits either party's liability to an individual under data protection law, or any liability that cannot lawfully be limited.

12. General

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction. It continues for as long as we process personal data on your behalf. If a provision is found unenforceable, the rest continues to apply.

Annex 1 — Details of the processing

Subject matter Providing the Englander Inventory Forecaster: inventory forecasting, replenishment suggestions and purchase order generation.
Duration For as long as your subscription is active, plus the 30-day deletion period in section 9.
Nature and purpose Collecting your business records from your Linnworks account, storing them, analysing sales patterns, generating reordering suggestions and purchase orders, sending reports and alerts by email, and providing support.
Types of personal data
  • Account users: name, email address, role within the account, sign-in activity.
  • Business contacts: supplier names and contact details, where these identify an individual (for example a sole trader or a named contact at a supplier).
  • Billing: billing contact name and email. Card details are handled by Stripe and never stored by us.

Not included: the Service does not store your own customers' or end-consumers' personal data. It holds product, stock and sales records, not the people who bought things.

Categories of data subject Your staff and other authorised users of your account; individuals who are, or work for, your suppliers.
Special category data None. The Service is not designed for it and it should not be entered.
Automated decision-making None affecting individuals. The Service generates reordering suggestions about products; it makes no automated decisions about people.
Non-personal business data The bulk of what the Service holds is not personal data at all: product catalogue, cost prices, stock levels, roughly two years of sales history, supplier lead times and purchase orders. It is commercially sensitive, and we treat it with the same care.

Annex 2 — Security measures

These are the technical and organisational measures we actually have in place. We have deliberately not listed aspirations.

Keeping customers separate

Access control

Encryption

Resilience and backups

Software and change management

What we do not claim

To summarise

Nothing to sign, nothing to return. This agreement is live between us from the moment you create an account, and this page is always the current version.

Need it for your records? Use the Save or print a copy button at the top of this page. Need a countersigned copy for a compliance process? Email privacy@englander.ai and we will sort it out.