Odyssey Advance - Data Processing Agreement (DPA)

Last updated: 12 August 2026

This Data Processing Agreement (“DPA”) forms part of the the Odyssey Advance Terms of Service between Odyssey Advance® (a trading brand of Odyssey New Media Limited) (“Odyssey Advance”, “we”, “us” or “our”) and the customer using the Odyssey Advance Services (“Customer”, “you” or “your”).

This DPA applies where Odyssey Advance processes Personal Data on behalf of the Customer in connection with the provision of the Odyssey Advance Services.

By using the Services to process Personal Data, the Customer agrees to the terms of this DPA.

 

1. Parties and Roles

For the purposes of this DPA:

Customer acts as the Controller of Customer Personal Data, except where the Customer itself acts as a Processor on behalf of another Controller.

Odyssey Advance, through Odyssey New Media Limited, acts as the Processor of Customer Personal Data where it processes such data on the Customer's documented instructions in connection with providing the Services.

Where the Customer acts as a Processor on behalf of another Controller, Odyssey Advance may act as a Sub-processor.

Each party agrees to comply with the data protection obligations applicable to its respective role.

 

2. Definitions

For the purposes of this DPA:

“Applicable Data Protection Law” means applicable laws relating to privacy and the processing of Personal Data, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and applicable amendments or replacement legislation.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given to them under Applicable Data Protection Law.

“Customer Personal Data” means Personal Data processed by Odyssey Advance on behalf of the Customer through the Services.

“Services” means the Odyssey Advance website, SaaS platform, applications, tools, integrations and related services provided to the Customer.

“Sub-processor” means a third party engaged by Odyssey Advance to process Customer Personal Data on behalf of the Customer in connection with providing the Services.

 

3. Scope and Duration of Processing

Odyssey Advance will process Customer Personal Data only to the extent necessary to provide the Services to the Customer and in accordance with the Customer's documented instructions.

Processing will generally continue for the duration of the Customer's use of the Services and for any reasonable period thereafter required to securely delete or return Customer Personal Data, subject to applicable legal requirements.

The subject matter, nature, purpose and categories of processing are described further in Schedule 1 of this DPA.

 

4. Customer Instructions

Odyssey Advance will process Customer Personal Data only on documented instructions from the Customer, including instructions relating to transfers of Personal Data, unless processing is required by applicable law.

The Customer's use and configuration of the Services, including information uploaded, submitted, connected or otherwise processed through Odyssey Advance, constitutes documented instructions for the purposes of this DPA.

Additional instructions may be agreed between the parties in writing.

If Odyssey Advance is required by law to process Customer Personal Data other than in accordance with the Customer's instructions, Odyssey Advance will inform the Customer of that legal requirement before processing unless applicable law prohibits such notification.

If Odyssey Advance reasonably believes that an instruction infringes Applicable Data Protection Law, we may inform the Customer and suspend the relevant processing until the matter has been resolved.

 

5. Customer Responsibilities

The Customer is responsible for:

  • ensuring that Customer Personal Data is collected and processed lawfully;
  • providing appropriate privacy information to Data Subjects;
  • establishing an appropriate lawful basis for the processing;
  • obtaining consent where consent is required;
  • ensuring it has the necessary rights and permissions to provide Personal Data to Odyssey Advance;
  • ensuring its instructions comply with Applicable Data Protection Law;
  • determining whether the Services are appropriate for the types of Personal Data it intends to process; and
  • responding to Data Subjects where the Customer is responsible for doing so as Controller.

The Customer must not instruct Odyssey Advance to process Personal Data in a manner that would violate Applicable Data Protection Law.

 

6. Confidentiality

Odyssey Advance will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Personal Data will be limited to personnel and authorised parties who reasonably require access for the provision, maintenance, security or support of the Services.

 

7. Security of Processing

Odyssey Advance will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure; or
  • access.

Security measures will be appropriate to the nature of the processing and the risks presented by the processing.

Measures may include, where appropriate:

  • access controls;
  • authentication controls;
  • encryption;
  • secure infrastructure;
  • software and application security measures;
  • monitoring and logging;
  • backup and recovery procedures;
  • vulnerability management;
  • confidentiality controls; and
  • procedures for identifying and responding to security incidents.

Odyssey Advance may update its technical and organisational measures as technologies, threats and industry practices evolve, provided that the overall level of protection is not materially reduced.

 

8. Personal Data Breaches

Odyssey Advance will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where reasonably available, the notification will provide information concerning:

  • the nature of the breach;
  • the categories of Personal Data affected;
  • the categories of Data Subjects affected;
  • the likely consequences of the breach; and
  • measures taken or proposed to address and mitigate the breach.

Where all relevant information is not immediately available, information may be provided in phases as it becomes available.

Odyssey Advance will take reasonable steps to investigate, contain and mitigate a Personal Data Breach.

Notification of a Personal Data Breach does not constitute an admission of fault or liability by Odyssey Advance.

 

9. Data Subject Rights

Taking into account the nature of the processing, Odyssey Advance will provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

These may include requests concerning:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection to processing; and
  • rights relating to automated decision-making where applicable.

If Odyssey Advance receives a request directly from a Data Subject concerning Customer Personal Data, we will normally direct the Data Subject to the relevant Customer or notify the Customer, unless Applicable Data Protection Law requires us to respond directly.

 

10. Assistance With Compliance

Taking into account the nature of the processing and information reasonably available to Odyssey Advance, we will provide reasonable assistance to the Customer with its applicable obligations concerning:

  • security of processing;
  • Personal Data Breach notifications;
  • communications with affected Data Subjects;
  • data protection impact assessments; and
  • consultation with supervisory authorities where required.

The Customer remains responsible for determining whether such measures are required in relation to its own processing activities.

 

11. Sub-processors

The Customer provides general authorisation for Odyssey Advance to engage Sub-processors where reasonably necessary to provide, maintain, secure or support the Services.

Sub-processors may include providers of:

  • cloud hosting and infrastructure;
  • data storage;
  • software infrastructure;
  • artificial intelligence technology;
  • analytics;
  • communications;
  • customer support;
  • security;
  • integrations; and
  • other technical services necessary to operate Odyssey Advance.

Odyssey Advance will ensure that Sub-processors processing Customer Personal Data are subject to contractual data protection obligations providing an appropriate level of protection consistent with the requirements applicable to Odyssey Advance under this DPA.

Odyssey Advance remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law.

Where required, Odyssey Advance will make information regarding relevant Sub-processors available to Customers.

 

12. Changes to Sub-processors

Where required by Applicable Data Protection Law, Odyssey Advance will provide reasonable notice of material changes concerning Sub-processors that process Customer Personal Data.

The Customer may raise reasonable data protection objections to a new Sub-processor.

The parties will work in good faith to address legitimate concerns.

Where a reasonable solution cannot be reached, Odyssey Advance may provide the Customer with the option to discontinue the affected functionality or terminate the affected Services in accordance with the applicable Terms and Conditions.

 

13. International Data Transfers

Customer Personal Data may be processed in countries outside the United Kingdom where Odyssey Advance or an authorised Sub-processor operates.

Where a transfer constitutes a restricted transfer under Applicable Data Protection Law, Odyssey Advance will ensure that an appropriate lawful transfer mechanism is used.

This may include:

  • transfer to a country covered by applicable UK adequacy regulations;
  • the UK International Data Transfer Agreement (“IDTA”);
  • the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses;
  • another recognised contractual safeguard; or
  • another lawful transfer mechanism permitted under Applicable Data Protection Law.

Where required, Odyssey Advance will implement appropriate supplementary safeguards relating to such transfers.

 

14. Return and Deletion of Personal Data

Following termination or expiry of the Customer's use of the Services, Odyssey Advance will, at the Customer's choice and where reasonably practicable, delete or return Customer Personal Data and delete remaining copies.

This obligation does not apply where retention is required by applicable law.

Customer Personal Data may remain temporarily within secure backups or disaster-recovery systems until deleted through normal retention cycles, provided that it remains appropriately protected and is not used for other purposes.

Customers are responsible for exporting Customer Personal Data they wish to retain before termination where appropriate export functionality is available.

 

15. Audits and Compliance Information

Odyssey Advance will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations contained in this DPA and Article 28 of the UK GDPR.

Where such information is insufficient, Odyssey Advance will allow for and reasonably contribute to audits or inspections conducted by the Customer or an independent auditor appointed by the Customer, subject to appropriate confidentiality, security and operational requirements.

Where practicable, audits should:

  • be conducted during normal business hours;
  • be subject to reasonable advance notice;
  • avoid unnecessary disruption to Odyssey Advance or other customers;
  • be limited to information and systems relevant to the Customer's Personal Data; and
  • comply with appropriate confidentiality and security requirements.

Where equivalent compliance information, certifications, assessments or audit reports reasonably satisfy the Customer's requirements, these may be provided instead of a separate audit where permitted by Applicable Data Protection Law.

 

16. Records and Regulatory Cooperation

Odyssey Advance will maintain records relating to processing activities where required by Applicable Data Protection Law.

Odyssey Advance will cooperate with the Information Commissioner's Office or another competent supervisory authority where legally required to do so.

 

17. Use of Artificial Intelligence Services

Certain Odyssey Advance features may use artificial intelligence, machine learning or other automated technologies.

Where Customer Personal Data is processed through such functionality, Odyssey Advance will process that information in accordance with this DPA and the Customer's instructions.

Where an external AI technology provider processes Customer Personal Data on behalf of Odyssey Advance, that provider will be treated as a Sub-processor where required by Applicable Data Protection Law.

Customers should not submit special category Personal Data, highly sensitive Personal Data or other information requiring enhanced protection to AI functionality unless the relevant Odyssey Advance feature is specifically designed and authorised for such processing.

 

18. Special Category and Highly Sensitive Personal Data

Unless expressly agreed otherwise, the Services are not intended for the processing of significant volumes of special category Personal Data or information concerning:

  • health;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data used for identification;
  • sex life or sexual orientation; or
  • criminal convictions and offences.

The Customer is responsible for ensuring that it does not use Odyssey Advance to process such information unless it has determined that the processing is lawful and appropriate and the relevant Services are suitable for that processing.

 

19. Relationship With Other Agreements

This DPA forms part of and supplements the Odyssey Advance Terms of Service and any other agreement governing the Customer's use of the Services.

If there is a conflict between this DPA and the Terms and Conditions regarding the processing of Customer Personal Data, this DPA will take precedence to the extent of that conflict.

 

20. Liability

Liability arising under or in connection with this DPA is subject to the exclusions and limitations of liability contained within the Odyssey Advance Terms and Conditions, except where such limitation is prohibited by Applicable Data Protection Law.

Nothing in this DPA limits either party's liability where liability cannot lawfully be excluded or limited.

 

21. Governing Law

This DPA is governed by the laws of England and Wales.

Subject to rights or requirements which cannot lawfully be excluded, the courts of England and Wales will have jurisdiction in relation to disputes arising under this DPA.

 

22. Changes to This DPA

Odyssey Advance may update this DPA where reasonably necessary to reflect:

  • changes to the Services;
  • changes to Sub-processors;
  • changes to Applicable Data Protection Law;
  • changes to regulatory guidance; or
  • changes to our data processing practices.

Where changes materially affect the processing of Customer Personal Data, Odyssey Advance will take reasonable steps to notify affected Customers where appropriate.

The current version of this DPA will be made available through the Odyssey Advance website.

 

23. Contact

Odyssey Advance® is a trading brand of Odyssey New Media Limited, a company registered in England and Wales.

Registered Office: Unit 3 Cuckoo Wharf, Lichfield Road, Birmingham, England, B6 7SS
Company Number: 07297050

For questions relating to this DPA or the processing of Customer Personal Data, please contact us through our Contact page.

 

Schedule 1 - Details of Processing

1. Subject Matter

Processing of Customer Personal Data as necessary to provide the Odyssey Advance digital marketing SaaS platform and associated functionality to the Customer.

2. Duration

For the duration of the Customer's subscription or use of the Services, together with any limited retention period reasonably necessary following termination for deletion, backups, security, legal or compliance purposes.

3. Nature and Purpose of Processing

Processing may include:

  • collection;
  • recording;
  • organisation;
  • storage;
  • retrieval;
  • consultation;
  • analysis;
  • transmission;
  • use;
  • modification;
  • combination;
  • restriction;
  • deletion; and
  • other processing initiated by the Customer through the Services.

The purpose is to provide, maintain, secure, support and improve the functionality requested by the Customer through Odyssey Advance.

4. Categories of Data Subjects

Depending upon how the Customer uses the Services, Customer Personal Data may relate to:

  • the Customer's employees;
  • directors and personnel;
  • contractors;
  • clients and customers;
  • prospective customers and leads;
  • website visitors;
  • marketing contacts;
  • users of digital platforms;
  • individuals contained within connected services; and
  • other individuals whose Personal Data the Customer chooses to process through Odyssey Advance.

5. Types of Personal Data

Depending upon the Customer's use of the Services, Customer Personal Data may include:

  • names;
  • business contact information;
  • email addresses;
  • telephone numbers;
  • company and job information;
  • online identifiers;
  • IP addresses;
  • website and analytics information;
  • marketing and campaign information;
  • communications;
  • account information;
  • customer relationship information;
  • information obtained from connected third-party services; and
  • other Personal Data submitted or made available by the Customer through the Services.

6. Special Category Personal Data

The Services are not generally intended for the processing of special category Personal Data.

Customers should not submit such information unless the relevant functionality is specifically designed and authorised for that purpose and the Customer has established an appropriate lawful basis and applicable safeguards.

 

Schedule 2 - Technical and Organisational Measures

Odyssey Advance maintains technical and organisational measures appropriate to the nature and risk of the processing.

These may include, as appropriate:

Access and Authentication

Controls designed to restrict access to Personal Data to authorised users and personnel.

Data Security

Technical measures designed to protect information during processing, transmission and storage where appropriate.

Infrastructure Security

Security measures relating to the systems and infrastructure used to provide Odyssey Advance.

Application Security

Measures designed to identify, prevent and address vulnerabilities affecting the Odyssey Advance platform.

Availability and Recovery

Appropriate backup, recovery and business-continuity measures designed to protect the availability and resilience of the Services.

Monitoring and Incident Management

Procedures for identifying, investigating and responding to suspected security incidents and Personal Data Breaches.

Personnel

Appropriate confidentiality obligations and access restrictions for personnel authorised to process Personal Data.

Sub-processors

Due diligence and contractual safeguards for Sub-processors that process Customer Personal Data on behalf of Odyssey Advance.

These measures may be updated as technology, risks and the Odyssey Advance Services evolve, provided that the overall level of protection is not materially reduced.

 

Trusted By
Advance beyond your limitations with the all-in-one digital marketing platform.
© 2026 Odyssey Advance®. All Rights Reserved