Data Processing Addendum
This Data Processing Addendum ("DPA") applies where Piece of Cake processes personal data on behalf of a business customer — for example, an organization, community, or event host — as part of providing the service. It forms part of our agreement with that customer.
This DPA supplements the agreement between Piece of Cake and its business customers and applies where we process personal data on their behalf. To execute a DPA for your organization, contact hello@itspieceofcake.com. This document is not legal advice.
Last updated: July 28, 2026.
1. Definitions
Terms such as "controller", "processor", "personal data", "processing", "data subject", and "personal data breach" have the meanings given in applicable data-protection law, including the EU/UK General Data Protection Regulation (GDPR). "Customer" means the business customer that agrees to this DPA. "Customer Personal Data" means personal data that we process on the Customer's behalf under the service agreement.
2. Roles of the Parties
For Customer Personal Data — such as the details of a Customer's events and guests — the Customer is the controller and Piece of Cake is the processor. We process Customer Personal Data only on the Customer's documented instructions, including as set out in the service agreement and this DPA.
For a limited set of data we need to run our own business — such as account administration, billing, security, and fraud prevention — Piece of Cake acts as an independent controller, as described in our Privacy Policy.
3. Scope and Instructions
We process Customer Personal Data only to provide, secure, and support the service, and as otherwise instructed by the Customer in writing. We will tell the Customer if, in our opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and access it only as needed to provide the service.
5. Security
We maintain appropriate technical and organizational measures designed to protect Customer Personal Data, including encryption of data in transit, access controls, and monitoring. Our current measures are described in our Privacy Policy and, where offered, our security documentation.
6. Subprocessors
The Customer authorizes us to engage subprocessors to help provide the service. Our current subprocessors are listed at itspieceofcake.com/subprocessors. We remain responsible for our subprocessors' processing of Customer Personal Data and impose data-protection obligations on them that are no less protective than this DPA. We will give the Customer reasonable advance notice of any new subprocessor, and the Customer may object on reasonable data-protection grounds within a reasonable period.
7. AI and Model Training
Where the service uses third-party AI model providers to generate CakeBot's suggestions, those providers act as our subprocessors. We do not permit them to use Customer Personal Data to train their models, and such data is not retained by them beyond what is needed to serve the request. We do not sell Customer Personal Data, and we do not use it to train AI models.
8. International Data Transfers
Where Customer Personal Data is transferred to a country that does not provide an adequate level of protection, we rely on an appropriate transfer mechanism — such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or an equivalent — which are incorporated into this DPA by reference and completed as applicable.
9. Assistance with Data Subject Requests
Taking into account the nature of the processing, we provide reasonable assistance to help the Customer respond to requests from data subjects to exercise their rights (such as access, correction, deletion, objection, and portability) under applicable law.
10. Personal Data Breach
We notify the Customer without undue delay — and, where feasible, within 72 hours — after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to us to help the Customer meet its own notification obligations.
11. Audits
We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, on reasonable prior notice, during business hours, and subject to confidentiality — no more than once per year unless required by a supervisory authority.
12. Return and Deletion
On termination of the service, and at the Customer's choice, we delete or return Customer Personal Data and delete existing copies, unless applicable law requires us to keep it.
13. Liability and Precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the service agreement. If there is a conflict between this DPA and the service agreement on the processing of personal data, this DPA prevails.
14. Contact
To execute this DPA or ask questions, contact LEARNING PATHS TECHNOLOGIES LLP at hello@itspieceofcake.com.
