Customer Data Processing Addendum
Last updated July 11, 2026. This addendum forms part of the agreement between a customer and Momentum Support Co-operation LTD (company 17078117) whenever Momentum OS processes personal data on the customer's behalf. It reflects Article 28 of the UK GDPR and should be read with our Privacy Policy at /privacy-policy, Subprocessor Notice at /subprocessors, Security Overview at /security, and GDPR statement at /gdpr.
1. Parties and roles
The customer is the controller and Momentum Support Co-operation LTD is the processor for personal data submitted to Momentum OS as customer service data. Each party remains an independent controller for the personal data it handles for account administration, billing, security, legal compliance, and its own business operations.
The processor is registered in England and Wales under company number 17078117, with its registered office at 5 Brayford Square, London, E1 0SG, United Kingdom. The privacy and data-protection contact is leon@momentumos.co.uk.
2. Processing instructions and purpose
The processor will process customer personal data only on the customer's documented instructions, as set out in the agreement, this addendum, the customer's configured use of the service, and support requests, unless applicable law requires otherwise, in which case the processor will inform the customer unless the law prohibits it.
Processing supports CRM records, HR and payroll workflows, commerce and payments, communications, support, portals, documents, bookings, analytics, automation, AI-assisted features, security, and backup, together with the integrations enabled by the customer. The duration of processing is the subscription term plus the agreed return-or-deletion period.
3. Categories of data subjects and personal data
Data subjects may include the customer's staff and job applicants, prospects, customers, suppliers, portal users, callers, meeting participants, support contacts, and other individuals whose data the customer places in the service.
Personal data may include identity and contact details, CRM activity, employee HR and payroll information, commerce and payment-related data, communications, call recordings and transcripts, uploaded identity documents, support records, documents, booking information, account metadata, and usage events. Special-category and criminal-offence data may be processed only where the customer has established a lawful condition. Customers must not submit data they are not authorised to process.
4. Confidentiality and security measures
The processor will ensure that personnel authorised to process customer personal data are bound by confidentiality obligations and receive access only where needed for their role.
The processor maintains appropriate technical and organisational measures proportionate to risk, including encryption in transit and at rest, role-based access control, tenant isolation, multi-factor authentication support, audit logging, monitoring, backups, and incident handling. These measures are described in the Security Overview at /security. Customers remain responsible for user access, lawful configuration, and connected-service credentials.
5. Subprocessors
The customer gives general written authorisation for the subprocessors listed in the Subprocessor Notice at /subprocessors. The processor imposes data-protection obligations on each subprocessor that are appropriate to its work and remains responsible for its subprocessors' performance of those obligations.
The processor will publish material subprocessor changes through the notice with a reasonable opportunity to object. A customer with a reasonable, documented data-protection objection can contact leon@momentumos.co.uk, and the parties will work in good faith toward a resolution.
6. International transfers
Where the processor or a subprocessor transfers customer personal data outside the UK or EEA, it will rely on a lawful transfer mechanism such as an applicable adequacy decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Addendum to the SCCs, together with any supplementary measures a transfer risk assessment identifies.
The Subprocessor Notice at /subprocessors indicates where providers process data. The customer is responsible for transfers created by its own connected applications and internal processes.
7. Assistance and breach notification
Taking account of the nature of processing and the information available, the processor will provide reasonable assistance with data-subject requests, security, data-protection impact assessments, and prior consultation with regulators where the customer cannot complete the work through available product controls.
The processor will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer service data, and will provide the information reasonably needed for the customer to meet its own notification duties. Breach and security notices should be sent to leon@momentumos.co.uk or reported by phone on +44 1263 808887.
8. Audit rights
The processor will make available to the customer the information reasonably necessary to demonstrate compliance with Article 28 and this addendum, including relevant certifications, summaries, or third-party reports where available.
Any additional audit must be proportionate, requested with reasonable notice, protect the security and confidentiality of other customers, use an agreed independent auditor where appropriate, avoid unreasonable operational disruption, and be conducted no more than once per year unless a regulator or a suspected breach requires otherwise.
9. Return, deletion, and retention
While the service is live, customer service data is retained for the subscription term plus 90 days. Backups are retained for 35 days; security and audit logs for 12 months; billing and tax records for 7 years; and recordings and transcripts for 90 days by default, or a shorter customer-configured period.
On termination or expiry, the processor will, at the customer's choice, delete or return customer personal data, except where law, fraud prevention, dispute preservation, or a documented legal hold requires limited continued retention. Data held in protected backups is removed on the normal backup-expiry cycle.
10. Liability and legal terms
Liability under this addendum follows the limitations in the applicable service agreement or Terms of Service at /terms, to the extent permitted by law.
This addendum is governed by the law governing the applicable agreement, or otherwise by the laws of England and Wales. Formal notices may be sent to leon@momentumos.co.uk; general questions may be sent to info@momentumos.co.uk.