Data Processing Agreement

Last updated: July 23, 2026

1. PARTIES AND ROLES

This Data Processing Agreement ("DPA") applies between Recur Ltd ("Processor") and the business client ("Controller") that has engaged Recur to provide any of its services — including lead generation, appointment setting, paid advertising, search engine optimisation, Google Business Profile optimisation, review generation and reputation management — under a signed services agreement (the "Agreement"). In relation to consumer personal data collected through advertising Recur operates on Controller's behalf, Controller is the data controller and Recur is the processor.

Controller accepts and agrees to be bound by this DPA by signing a services agreement with Recur or by using Recur's services, whichever is earlier. Where Controller's signed services agreement incorporates this DPA by reference, that agreement takes precedence in the event of conflict.

2. SCOPE, SUBJECT MATTER AND DURATION

Recur will process personal data only to deliver the services described in the Agreement. Processing continues for the duration of the Agreement plus any statutory retention period. On termination Recur will delete or return personal data as instructed, save where it is required to keep records by law, and save for records evidencing consent to be contacted, opt-out requests, and suppression lists, which Recur retains for as long as necessary to demonstrate compliance with applicable telemarketing and marketing law.

3. CATEGORIES OF DATA AND DATA SUBJECTS

  • Data subjects: homeowners and consumers who respond to Controller's advertising; individuals whose personal data Controller provides to Recur, including Controller's existing and past customers; and Controller's own personnel who use the systems Recur operates.
  • Categories: name, phone number, email, postal town/ZIP, answers to qualification questions, communications with Recur, and campaign interaction data.
  • No special-category data is knowingly collected.

4. PROCESSOR OBLIGATIONS

  • Process personal data only on documented instructions from Controller.
  • Ensure staff and contractors are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (see section 7).
  • Assist Controller with data subject requests, DPIAs and breach notifications.
  • Make available information necessary to demonstrate compliance.
  • Notify Controller without delay if Recur considers that an instruction from Controller infringes applicable data protection law.
  • Allow for and contribute to audits and inspections conducted by Controller or an auditor appointed by Controller, on reasonable prior notice and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach.

5. SUB-PROCESSORS

Controller provides general authorisation for Recur to engage sub-processors, provided Recur imposes equivalent data protection terms on them. The current list of sub-processors is set out in section 14 of our Privacy Policy. Recur will give reasonable notice of new sub-processors and Controller may object on reasonable data protection grounds.

6. INTERNATIONAL TRANSFERS

Where personal data is transferred outside the UK or EEA, Recur relies on UK adequacy regulations, the UK Addendum to the EU Standard Contractual Clauses or the UK Extension to the EU–US Data Privacy Framework, as appropriate.

7. SECURITY MEASURES

Recur maintains encryption in transit and at rest, role-based access control, two-factor authentication for internal systems, reputable third-party hosting, logging and periodic access reviews. Details of security controls are available on request.

8. BREACH NOTIFICATION

Recur will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, and will provide the information Controller needs to comply with its own notification obligations.

9. DATA SUBJECT RIGHTS

Recur will forward any data subject request it receives about Controller's data and will assist Controller in responding, taking into account the nature of the processing.

10. US STATE PRIVACY LAWS

Where Controller is subject to the California Consumer Privacy Act as amended ("CCPA") or a comparable US state privacy law, Recur acts as a "service provider" or "processor" as those terms are defined in the applicable law, and the following applies to personal information Controller discloses to Recur.

Recur shall not sell or share the personal information, as those terms are defined in the CCPA.

Recur shall not retain, use or disclose the personal information for any purpose other than performing the services specified in the Agreement, including retaining, using or disclosing it for a commercial purpose other than those services, or outside the direct business relationship between Recur and Controller, except where permitted by applicable law.

Recur shall not combine the personal information with personal information it receives from or on behalf of any other person, or collects from its own interactions with consumers, except where permitted by applicable law.

Recur certifies that it understands the restrictions in this section and will comply with them.

Recur shall comply with the obligations applicable to it under the CCPA and comparable state laws, and shall provide the same level of privacy protection as those laws require of Controller. Recur shall notify Controller if it determines that it can no longer meet those obligations. Controller may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information.

Controller retains the right to take reasonable and appropriate steps to ensure that Recur uses the personal information in a manner consistent with Controller's obligations under applicable law.

11. RELATED POLICIES

This DPA works alongside our Privacy Policy, Cookie Policy, SMS Terms & Conditions and Terms of Service.

12. CONTACT

Email: contact@recuragency.com
Phone: (213) 814-3755
Post: Recur Ltd, 356 Russell Court, Woburn Place, London, WC1H 0NH