Curve — Data Processing Agreement
Last updated: 30 August 2026
This data processing agreement (DPA) applies where Baseline Labs Ltd, trading as Curve and Curve Contracts (Curve), processes personal data on behalf of a client (Client) in performing the Services. It is incorporated into the master engagement letter between Curve and the Client and forms part of the Agreement. Terms defined in the Curve Client Engagement Terms have the same meaning here.
Curve is registered in England and Wales, company number 16968511, registered office 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. Contact for data protection matters: support@curvecontracts.com.
1. Definitions and application
Data Protection Law means the UK GDPR and the Data Protection Act 2018 and, where the Client is established in the European Economic Area or the processing is otherwise within its scope, Regulation (EU) 2016/679 and the national laws implementing it.
Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in Data Protection Law.
Where Regulation (EU) 2016/679 applies to the processing, a reference in this DPA to a provision of the UK GDPR is a reference to the corresponding provision of that Regulation, and this DPA takes effect accordingly. Where both regulations apply, this DPA takes effect under each of them, and the more protective requirement prevails.
Protected Data means personal data contained in Customer Materials, or otherwise provided to or accessed by Curve, that Curve processes on the Client's behalf under the Agreement.
For Protected Data, the Client is the controller and Curve is the processor. Where the Client is itself a processor for a third party, the Client warrants that it has that third party's authority to appoint Curve as a sub-processor on these terms.
This DPA does not apply to personal data that Curve processes as controller in its own right, such as the contact details of the Client's personnel used to administer the relationship, to invoice, and to meet Curve's own legal obligations. Curve's privacy policy governs that processing.
2. Curve's obligations
Curve shall:
a. process Protected Data only on the Client's documented instructions, including on transfers, unless required to do otherwise by law, in which case Curve shall tell the Client before processing unless the law prohibits it. The Agreement, together with the Client's instructions given in the ordinary course of an engagement, are the Client's documented instructions;
b. tell the Client if, in Curve's opinion, an instruction infringes Data Protection Law;
c. ensure that each person authorised to process Protected Data is bound by a duty of confidence;
d. implement and maintain the technical and organisational measures set out in Schedule 2, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing and the risks to data subjects;
e. taking account of the nature of the processing, assist the Client by appropriate technical and organisational measures, so far as reasonably possible, in responding to requests from data subjects exercising their rights;
f. assist the Client in meeting its obligations under Articles 32 to 36 of the UK GDPR and, where Regulation (EU) 2016/679 applies, under Articles 32 to 36 of that Regulation, taking account of the nature of the processing and the information available to Curve;
g. notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Protected Data, and provide the information the Client reasonably needs to meet its own notification obligations;
h. at the Client's choice, delete or return Protected Data at the end of the provision of the Services, and delete existing copies, except to the extent Curve is required to retain them by law, by a professional obligation, or as necessary to bring or defend a legal claim. Protected Data retained on that basis remains subject to this DPA; and
i. make available to the Client the information reasonably necessary to demonstrate compliance with this clause 2, and allow for and contribute to audits under clause 5; and
j. maintain a record of the categories of processing carried out on the Client's behalf, as Article 30(2) of the UK GDPR requires and, where Regulation (EU) 2016/679 applies, as Article 30(2) of that Regulation requires.
3. Sub-processors
The Client gives Curve general authorisation to appoint sub-processors. Curve's sub-processors as at the date of this DPA are listed in Schedule 3.
Curve shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Client for each sub-processor's performance.
Curve shall give the Client at least fourteen (14) days' notice before appointing a new sub-processor or replacing an existing one. The Client may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Client may terminate the affected Engagement Confirmation without penalty, and Curve shall refund any Fees paid in advance for Services not yet performed.
Individual consultants engaged by Curve to perform the Services are sub-processors for the purpose of this clause.
4. International transfers
Curve performs the Services from more than one country, and its consultants and service providers may be located outside the United Kingdom and the European Economic Area. Schedule 3 states the countries concerned.
Curve shall not transfer Protected Data to a country outside the United Kingdom, or outside the European Economic Area where Regulation (EU) 2016/679 applies to the processing, unless a transfer mechanism permitted by Data Protection Law is in place for that transfer and Curve has first carried out a transfer risk assessment.
Where the destination country is not the subject of an adequacy decision, the mechanism is:
a. where only the UK GDPR applies to the processing, the International Data Transfer Agreement issued by the Information Commissioner, or the European Commission's standard contractual clauses together with the Information Commissioner's Addendum to them; and
b. where Regulation (EU) 2016/679 applies to the processing, whether alone or together with the UK GDPR, the European Commission's standard contractual clauses in the module appropriate to the parties' roles, together with the Information Commissioner's Addendum to them where the UK GDPR also applies.
Curve shall apply any supplementary measures the transfer risk assessment identifies as necessary. The United Kingdom is the subject of an adequacy decision of the European Commission adopted on 19 December 2025, and the European Economic Area states are covered by United Kingdom adequacy regulations, so no transfer mechanism is required between the United Kingdom and those states in either direction.
The Client authorises Curve to enter into those instruments with each sub-processor on the Client's behalf, and Curve shall provide a copy on request.
5. Audit
Curve shall, on reasonable written notice and no more than once in any twelve month period unless a personal data breach has occurred or a supervisory authority requires it, allow the Client or an auditor appointed by the Client to inspect Curve's processing of Protected Data. Audits shall take place during business hours, shall not unreasonably disrupt Curve's business, and are subject to confidentiality obligations at least as protective as clause 5 of the Curve Client Engagement Terms. Each party bears its own costs. Curve may satisfy an audit request by providing a written response to the Client's reasonable questions and evidence of the measures in Schedule 2.
6. Liability and general
The limits on liability in clause 9 of the Curve Client Engagement Terms apply to claims under this DPA.
If any provision of this DPA conflicts with the Curve Client Engagement Terms or with the master engagement letter, this DPA prevails in respect of the processing of Protected Data.
Curve may amend this DPA where an amendment is required by a change in Data Protection Law or by a supervisory authority, or to reflect a new transfer mechanism. Curve shall give the Client written notice of any such amendment.
This DPA is governed by the law of England and Wales, and clause 11.2 of the Curve Client Engagement Terms applies to any dispute arising out of it.
Nothing in this DPA limits the Client's own obligations under any data protection or privacy law applicable to it, including the Personal Data Protection Act 2012 of Singapore and the Personal Data (Privacy) Ordinance of Hong Kong.
Schedule 1 — Details of the processing
| Subject matter | Curve's performance of the Services under the Agreement |
| Duration | The term of the Agreement, plus any retention period permitted under clause 2(h) |
| Nature and purpose | Reviewing, drafting, negotiating and advising on contracts and related corporate and commercial documents; corresponding with the Client and, where instructed, with counterparties and their advisers; storing and organising the documents that work produces |
| Types of personal data | Names, job titles, business contact details, signature and signing data, and details of a person's role, shareholding, office or terms of engagement where those appear in the documents the Client provides or the Services produce |
| Categories of data subject | The Client's directors, officers, employees and contractors; the Client's shareholders and investors; the personnel and advisers of counterparties; and any other individual named in the documents concerned |
| Special category data | None. The Client shall not provide special category personal data, or personal data relating to criminal convictions and offences, unless the parties have first agreed additional terms in writing |
Schedule 2 — Technical and organisational measures
Curve maintains at least the following:
a. access to Protected Data limited to the consultants and personnel who need it for the engagement concerned, on a named-account basis;
b. multi-factor authentication on every account used to access Protected Data, and on the underlying identity provider;
c. encryption of Protected Data in transit and at rest, using the encryption provided by Curve's cloud service providers;
d. full-disk encryption and automatic screen locking on every device used to access Protected Data;
e. a password manager for all service credentials, and no sharing of credentials between individuals;
f. storage of Protected Data in Curve's managed cloud services rather than on personal devices or personal accounts, and no use of personal email accounts for engagement material;
g. written confidentiality and data protection obligations in every consultant and subcontractor contract, and removal of access when an engagement or a contract ends;
h. no submission of Protected Data to any artificial intelligence tool that uses submitted content to train models made available to third parties;
i. a documented procedure for identifying, recording and notifying personal data breaches, including the notification in clause 2(g); and
j. review of these measures at least once a year, and after any personal data breach.
Schedule 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Individual legal consultants engaged by Curve | Performance of the Services | United Kingdom, France, Hong Kong |
| Google LLC (Google Workspace) | Email, document storage and collaboration | United States |
| Anthropic PBC (Claude) | Drafting and review assistance, subject to Schedule 2(h) | United States |
| Supabase, Inc. | Engagement records and executed-document storage | United States |
| Vercel, Inc. | Website and engagement-system hosting | United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery of engagement documents | United States |
Curve maintains the current list of sub-processors and provides it on request.