General-Use Data Processing Agreement
Parties to this agreement:
(1) [Customer legal name], a company incorporated in [jurisdiction] with registered address [address] and company number [number] (the "Customer");
and
(2) Little Ears Records Ltd, trading as Scout & Swan, a company incorporated in England and Wales with registered address [address] and company number [number] ("Scout & Swan").
Except where §2A provides otherwise, references in this agreement to the "Controller" are to the Customer, and references to the "Processor" are to Scout & Swan.
Background and Scope
(A) The Controller determines the purposes and means of processing Personal Data in connection with its business activities.
(B) The Processor processes Personal Data on behalf of the Controller in the course of providing the Services (as defined below).
(C) The Controller wishes to engage the Processor to process Personal Data on its behalf, on the terms of this agreement.
(D) This agreement is Scout & Swan's general-use Data Processing Agreement. It applies on identical terms to every non-Enterprise customer, including customers on free, trial and pilot plans, and is not individually negotiated. Where a customer requires bespoke data protection terms, those are agreed separately under an Enterprise agreement.
The parties hereby mutually agree the following:
1. Definitions and Interpretation
"UK GDPR" — Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
"Controller," "processor," "data subject," "personal data," "personal data breach," "supervisory authority," "processing," "appropriate technical and organisational measures" — as defined in the Data Protection Legislation in force at the time.
"Data Protection Legislation" — the Data Protection Act 2018, the UK GDPR, and the Privacy and Electronic Communications Regulations 2003, together with any successor legislation.
"Services" — the Scout & Swan product or products the Customer has subscribed to, as described in the applicable Product Data Processing Policy (see Appendix 1).
"Account Holder" — a person the Customer invites to hold a login to the Services.
"Account Data" — Personal Data relating to an Account Holder, collected by Scout & Swan in order to create, secure and administer a login and the Workspace it belongs to.
"Contributor" — a person whose engineering activity is visible in a repository or tooling account the Customer connects to the Services, and who holds no login to the Services.
"Contributor Data" — Personal Data relating to a Contributor, processed by Scout & Swan solely on the Customer's documented instructions.
"Workspace" — the Customer's tenant within the Services, being the unit at which access, retention and deletion operate.
"Anonymised Data" — data that has been processed such that it no longer identifies, and cannot reasonably be used to re-identify, any individual, including aggregated and obfuscated usage metrics. Anonymised Data falls outside the definition of Personal Data for the purposes of this agreement, and the Processor's use of it (including retention under the Community tier data covenant described in the Product Data Processing Policy) is not restricted by this agreement.
"Sub-processor" — a third party engaged by the Processor to assist in providing the Services, listed in Appendix 2.
1A. Documents Incorporated by Reference
The following published documents form part of this agreement. Scout & Swan maintains them at the locations below and versions each change.
| Document | Covers | Published at |
|---|---|---|
| Master Data and Privacy Statement | How Scout & Swan handles Personal Data across its services | [URL] |
| Product Data Processing Policy | What each product processes, and why | [URL] |
| Data Security and Identity Protection Provisions | Technical and organisational measures | [URL] |
| Processing Details | Categories of data and data subject, purposes, retention, sub-processors | [URL] |
| Privacy Notice | Scout & Swan's own processing as Controller, including Account Data | [URL] |
Where a referenced document changes in a way that materially reduces the protections available under this agreement, Scout & Swan will notify the Customer before the change takes effect.
2. Processing Details
The subject matter, duration, nature and purpose of processing, and the categories of data subject and Personal Data, are as set out in Appendix 1.
2A. Roles of the Parties
2A.1. The Services involve two categories of Personal Data, and the parties hold different roles in respect of each.
2A.2. Contributor Data (Category A). The Customer is the Controller. Scout & Swan is the Processor, and processes Contributor Data only on the Customer's documented instructions, for the purposes set out in Appendix 1. The remainder of this agreement applies to Category A in full.
2A.3. Account Data (Category B). Scout & Swan is the Controller. Account Data is limited to what is necessary to create a login, authenticate the person holding it, secure the session, deliver notifications they have chosen to receive, and maintain an administrative audit record. Scout & Swan's handling of Account Data is described in its published Privacy Notice, and Scout & Swan responds directly to data subject rights requests relating to Account Data.
2A.4. Where a person is both an Account Holder and a Contributor, the two categories remain separate records under separate lawful bases with separate erasure paths. The Customer remains the Controller of that person's Contributor Data irrespective of the status of their login.
2A.5. Nothing in §2A.3 makes Scout & Swan a Controller of Contributor Data, and nothing in §2A.2 makes the Customer a Controller of Account Data.
3. Obligations of the Processor
The Processor agrees to:
3.1. Process Personal Data only on documented instructions from the Controller, which, for the avoidance of doubt, include the standard processing described in the applicable Product Data Processing Policy, agreed by the Controller on subscribing to the Services, unless required to do otherwise by law, in which case the Processor will inform the Controller of that requirement unless prohibited from doing so.
3.2. Provide reasonable assistance to the Controller, having regard to the nature of the processing and the information available to the Processor, in responding to data subject rights requests. The Processor will promptly notify the Controller of any data subject request it receives directly, and will not respond to it except on the Controller's instructions or as required by law.
3.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in the Data Security and Identity Protection Provisions (§1A). These measures apply as published; individual review or approval by the Controller is available only where separately agreed under an Enterprise agreement.
3.4. Take into account the risks of accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data, when assessing the appropriate level of security.
3.5. Remain subject to its own direct responsibilities and liabilities under the Data Protection Legislation. Nothing in this agreement relieves the Processor of these.
3A. The Customer's Warranties in Respect of Contributor Data
3A.1. The Customer warrants that it is the Controller of, or is otherwise lawfully entitled to determine the processing of, all Personal Data present in or derivable from the repositories and tooling accounts it connects to the Services.
3A.2. The Customer warrants that it has a lawful basis under the Data Protection Legislation for disclosing that Personal Data to Scout & Swan and for instructing the processing described in this agreement, and that it has all necessary notices and, where required, consents in place.
3A.3. The Customer is responsible for providing Contributors with any transparency information required by the Data Protection Legislation, and for responding to any request a Contributor makes to exercise their rights. The Processor will provide reasonable assistance under §3.2.
3A.4. The Customer acknowledges that Contributor Data originates from records of work already performed and recorded in the Customer's own systems, and that neither party is able to obtain individual permissions retrospectively in respect of those records. The warranties in §3A.1 and §3A.2 are given on that understanding.
3A.5. The Customer warrants that it will not connect any repository or tooling account containing special category Personal Data as defined in Article 9 of the UK GDPR. The Services are not designed to process it.
3A.6. The Services are not directed at children and are not intended for use by any person under the age of 18. Every Account Holder must be aged 18 or over. Where the Customer becomes aware that a Contributor is under the age of 18, it will notify Scout & Swan so that the processing of that person's Contributor Data can be reviewed. The Customer gives no warranty as to the age of its Contributors.
3A.7. The Customer is responsible for the seats it provisions on connected vendor accounts. Scout & Swan retrieves per-person AI tool usage data only in respect of persons holding a seat on a connected vendor account.
3A.8. The Customer indemnifies Scout & Swan against all claims, losses, fines and reasonable costs arising from a breach of §3A.1, §3A.2, §3A.3 or §3A.5, including any claim by a data subject or regulator that the Customer lacked a lawful basis for the processing it instructed. This indemnity does not extend to §3A.6.
3A.9. Scout & Swan is entitled to rely on the Customer's instructions and warranties, and is not required to verify the Customer's lawful basis.
4. Additional Obligations of the Processor
Taking into account the nature of processing and information available to it, the Processor will provide reasonable assistance to the Controller in:
4.1. Meeting the Controller's obligation to keep Personal Data secure.
4.2. Meeting the Controller's breach notification obligations, including notifying the Controller without undue delay on becoming aware of a Personal Data breach affecting Controller Personal Data. What "without undue delay" means in practice depends on the severity of the breach, assessed by the Processor, consistent with Information Commissioner's Office guidance and the Data Security and Identity Protection Provisions. Notification will describe, so far as then known: the nature of the breach, the categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed.
4.3. Investigating, mitigating, and remediating any such breach.
4.4. Advising data subjects of a breach, where the Controller is required to do so.
4.5. Carrying out data protection impact assessments, and consulting the supervisory authority where such an assessment indicates unmitigated high risk. In each case this is reasonable assistance rather than an unbounded commitment, reflecting the Processor's role and the information reasonably available to it.
5. Other Obligations (Both Parties)
5.1. Each party will ensure that any person acting under its authority with access to Personal Data does not process it except on the Controller's instructions, unless required by law.
5.2. Both parties will comply with the Data Protection Legislation. This clause is in addition to, and does not replace, either party's obligations under that legislation.
6. Confidentiality
6.1. The Processor will ensure that persons authorised to process Personal Data under this agreement have committed to confidentiality, or are under an appropriate statutory obligation of confidentiality, in respect of that Personal Data.
6.2. The Processor will not disclose Personal Data supplied by the Controller to any third party, or use it other than to provide the Services, except as permitted by this agreement or required by law.
6.3. This obligation continues for as long as the Processor holds or processes the relevant Personal Data. It does not create a separate fixed-term confidentiality obligation once that data has been deleted in accordance with §10.
6.4. Nothing in this clause prevents either party complying with a legal obligation imposed by a regulator or court. Where possible, the parties will discuss the appropriate response to any such request first.
7. Engaging a Sub-processor
7.1. The Processor has the Controller's general written authorisation to engage the Sub-processors listed in Appendix 2, provided that list is kept up to date and the Controller is notified of material changes with an opportunity to object.
7.2. Where the Processor engages a Sub-processor, it will do so under a written agreement imposing data protection obligations equivalent to those in this agreement.
7.3. The Processor remains fully liable to the Controller for a Sub-processor's performance of its obligations, regardless of any failure by that Sub-processor.
7.4. At self-serve tier, the Processor will publish the identity and nature of Sub-processor activity in Appendix 2. It does not provide copies of the underlying Sub-processor agreements. Extended audit and documentation rights are available under a separately negotiated Enterprise agreement.
8. Sub-processor List
The current list of Sub-processors is set out in Appendix 2, published with this agreement and updated from time to time in accordance with §7.
9. Compliance Documentation and Assurance
9.1. The Processor will make available, on reasonable written request, documentation reasonably necessary to demonstrate compliance with this agreement and the Data Protection Legislation, including its current ISO 27001 gap-analysis or certification status and security summary documentation.
9.2. On-site inspection or third-party-mandated audit rights are not included at self-serve tier, reflecting the operational reality of a multi-tenant self-serve product. Where a Controller requires contractual audit or inspection rights, this is available as a negotiated Enterprise-tier term.
10. Term, Termination, and Data on Exit
10.1. This agreement applies for the duration of the Customer's subscription to the Services, including any free, trial or pilot period.
10.2. Either party may terminate on written notice if:
10.2.1. the other party materially breaches this agreement; or
10.2.2. the other party breaches this agreement and fails to remedy it within 30 days of written notice to do so; or
10.2.3. the other party becomes insolvent or enters liquidation.
10.3. Rights and obligations accrued before termination survive it.
10.4. On termination, Personal Data is retained and deleted in accordance with the retention periods published in the Product Data Processing Policy, currently 1 month after contract end as standard and 3 months for annualised data under Enterprise agreements, rather than a separate destruction deadline set by this agreement. Anonymised Data is not affected by this clause (see §1).
11. International Transfers
Where Personal Data is processed outside the United Kingdom, including by Sub-processors, the Processor will apply the transfer mechanism required under the applicable Data Protection Legislation at the time, which the Processor will specify. As at the date of this agreement this is the UK International Data Transfer Agreement, or the UK Addendum to the European Commission Standard Contractual Clauses. The Processor will use reasonable efforts to ensure a level of protection equivalent to UK GDPR standards, to the best of its ability given the jurisdiction and mechanism available. This does not guarantee an identical level of legal protection to UK processing, and the Processor will inform the Controller if it becomes aware of a material change affecting that equivalence.
12. Liability
12.1. Each party's total liability to the other arising out of or in connection with this agreement, whether in contract, tort, or otherwise, is capped at the total fees paid by the Customer to Scout & Swan in the 12 months preceding the event giving rise to the claim.
12.2. Neither party is liable to the other for indirect or consequential loss, including loss of profits, revenue, or anticipated savings, whether or not such loss was foreseeable.
12.3. Subject to §12.3.1 and §12.4, this is a single, global cap covering all claims arising out of or in connection with this agreement, with no additional carve-outs for specific claim types, reflecting the low-risk nature of the processing under this agreement.
12.3.1. Nothing in this clause excludes or limits either party's liability for matters that cannot lawfully be excluded or limited under English law, including fraud or death or personal injury caused by negligence. This exists because such exclusions would be void by statute if attempted, not because it has been separately negotiated.
12.4. The cap in §12.1 does not apply to the Customer's indemnity at §3A.8. That indemnity concerns Personal Data the Customer controls and Scout & Swan does not, and losses arising from it are neither foreseeable nor controllable by Scout & Swan.
13. Intellectual Property
13.1. Scout & Swan remains the owner of any materials it provides in delivering the Services, and grants the Customer a limited, non-exclusive right to use them for the agreement's duration.
13.2. The Customer remains the owner of any Personal Data it supplies, and grants Scout & Swan a limited, non-exclusive right to use it only to provide the Services.
14. Entire Agreement
This agreement, together with its Appendices and the documents it references, is the entire agreement between the parties on this subject and supersedes any prior understanding on the same subject. Bespoke variations agreed between the parties must be agreed in writing.
14A. Changes to this Agreement
14A.1. Scout & Swan may update this agreement to reflect changes to the Services, to its Sub-processors, or to applicable law.
14A.2. Where a change materially reduces the protections available to the Customer or to data subjects, Scout & Swan will give at least 30 days' notice before it takes effect, and the Customer may terminate the Services without penalty within that period.
14A.3. Other changes take effect on publication.
15. Severance
If any provision is found invalid or unenforceable, the remainder of this agreement continues in force, and the invalid provision is treated as amended to the minimum extent needed to make it valid, or otherwise disregarded.
16. Governing Law
This agreement is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
17. Acceptance
This agreement is entered into when the Customer accepts the Terms and Conditions of the Services, or creates a Workspace, whichever occurs first. No separate signature is required. The version in force is the version published at the date of acceptance, and Scout & Swan records that version against the Customer's Workspace.
A countersigned copy is available on request for customers whose internal procurement requires one.
Appendix 1: Processing Details
The subject matter, duration, nature and purpose of processing, the categories of data subject, and the categories of Personal Data are set out in the Processing Details document, published at the location given in §1A and incorporated into this agreement by reference. In summary:
- Category A, Contributor Data. Data subjects are Contributors to the Customer's connected repositories and holders of seats on the Customer's connected AI coding tool accounts. Processing is for attribution of AI coding tool usage and cost to the engineering work that produced it, and related product functionality.
- Category B, Account Data. Data subjects are Account Holders. Processing is for account creation, authentication, session security, notification delivery and administrative audit.
- Duration. The term of the Customer's subscription, plus the retention periods published in the Product Data Processing Policy.
Technical and organisational security measures are as described in the Data Security and Identity Protection Provisions, incorporated by reference.
The full classified register underlying the Processing Details document is available for inspection under mutual non-disclosure on request.
Appendix 2: Sub-processors
The Customer authorises Scout & Swan to engage the following Sub-processors in providing the Services.
| Sub-processor | Purpose |
|---|---|
| Amazon Web Services | Compute, database, storage, content delivery, transactional email, message queues, secrets storage, and operational logging |
| Anthropic | AI coding agent vendor. Reconciles the Customer's seats against observed usage by retrieving seat email addresses and per-user usage from the vendor's administrative interface, where the Customer has connected this integration |
| Cursor | AI coding agent vendor. Reconciles the Customer's seats against observed usage by retrieving seat email addresses and per-user usage from the vendor's administrative interface, where the Customer has connected this integration |
| Doppler | Secrets management for Scout & Swan's own operational credentials. Does not process Customer Personal Data in the ordinary course |
| GitHub | Source integration. Reads repository and pull request metadata, including commit author identity, through a read-only application |
| Marketing-site analytics only, for visitors who have consented. Never receives Customer Personal Data or agent usage data | |
| Paddle | Billing, as merchant of record for paid subscriptions |
| AWS Marketplace | Alternative billing channel for AWS Marketplace customers |
Scout & Swan hosts the Services and stores Customer Personal Data in the United Kingdom. Where processing by a Sub-processor takes place outside the United Kingdom, §11 applies.