Last updated 4 September 2026

Data processing agreement

Between Personal Works Ltd (PERSONAL WORKS LTD, company number 14013912, registered in England and Wales, “we”) and the business customer using underway (“you”). It forms part of our terms and applies whenever we process personal data on your behalf. If you use underway only for yourself, you are the controller of your own recordings and the privacy policy is the document that governs that.

1. Roles

You are the controller of the personal data you and your people put into underway under your account or your Company Record. We are your processor for that data. Each of your members is also a user of underway in their own right, and our privacy policy applies to the account data we hold about them as controller.

2. What we process, and why

Subject matter: video and audio recordings, transcripts, the notes and connected-tool context used to write interview questions, the episodes assembled from them, and the company bible built from what members chose to share. Data subjects: your founders and staff who record, and anyone they mention. Categories: image, voice, name, what they say about their work. Duration: for as long as you use the service and until deleted under section 8. Purpose: transcribing, interviewing, assembling and, on your instruction, publishing episodes, and nothing else.

3. Your instructions

We process your data only on your documented instructions. Those instructions are these terms, the settings you and your members choose in the app (what to record, what to connect, what to publish, what to delete), and any written instruction you send to rich@personalworks.co. If the law requires us to process otherwise we will tell you first unless the law forbids it. If we think an instruction breaks data protection law we will say so.

4. People and confidentiality

Only people who need access to run the service have it, and they are bound by confidentiality. Nobody at underway watches your recordings except to fix a problem you have asked us to fix.

5. Security

Recordings stay on the recording device unless sync is turned on. Synced media is stored in private storage that only the account and our servers can read, never a public bucket. Connection tokens are encrypted at rest. Access to production systems is limited to the people who run them, behind sign-in and keys. Rendering happens on our own workers and the working files are deleted when the job ends. We keep short server logs for security.

6. Sub-processors

You authorise the sub-processors on our subprocessors page, which says what each one does. We will update that page at least 30 days before a new sub-processor handles your data, and announce the change in the app. You may object within those 30 days; if we cannot offer an alternative you may end the service and we will refund any unused period. Each sub-processor is bound by written terms at least as protective as this agreement, and we remain responsible for them.

7. Helping you meet your obligations

If a data subject asks us directly to exercise a right over data you control, we will pass the request to you and help you answer it. We will help with impact assessments and consultations with the ICO where our processing is involved. We will tell you without undue delay, and in any case within 72 hours of becoming aware, of any personal data breach affecting your data, with what we know and what we are doing about it.

8. Deletion and return

Raw footage is downloadable at any time on every plan. Deleting a session deletes it and everything derived from it, everywhere we hold it. When the agreement ends we will delete the personal data we process for you within 30 days of your instruction, unless the law requires us to keep some of it, in which case we will keep only that and process it for nothing else.

9. Audits

On written request, no more than once a year, we will give you the information you reasonably need to show that we meet this agreement, and will allow an audit by you or an auditor you appoint, at your cost, on reasonable notice and during business hours, under confidentiality.

10. International transfers

Some sub-processors are in the United States. Where a transfer from the UK or the EEA takes place we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, as each sub-processor offers them. The privacy policy says which.

11. General

This agreement is governed by the law of England and Wales. If it conflicts with the terms, this agreement wins for the processing it covers. Liability is as set out in the terms. We may update this agreement; if a change matters, we will tell you in the app before it takes effect.

← Back to underway