Last updated: 12 August 2026
This Data Processing Agreement (“DPA”) forms part of the the Odyssey Advance Terms of Service between Odyssey Advance® (a trading brand of Odyssey New Media Limited) (“Odyssey Advance”, “we”, “us” or “our”) and the customer using the Odyssey Advance Services (“Customer”, “you” or “your”).
This DPA applies where Odyssey Advance processes Personal Data on behalf of the Customer in connection with the provision of the Odyssey Advance Services.
By using the Services to process Personal Data, the Customer agrees to the terms of this DPA.
For the purposes of this DPA:
Customer acts as the Controller of Customer Personal Data, except where the Customer itself acts as a Processor on behalf of another Controller.
Odyssey Advance, through Odyssey New Media Limited, acts as the Processor of Customer Personal Data where it processes such data on the Customer's documented instructions in connection with providing the Services.
Where the Customer acts as a Processor on behalf of another Controller, Odyssey Advance may act as a Sub-processor.
Each party agrees to comply with the data protection obligations applicable to its respective role.
For the purposes of this DPA:
“Applicable Data Protection Law” means applicable laws relating to privacy and the processing of Personal Data, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and applicable amendments or replacement legislation.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given to them under Applicable Data Protection Law.
“Customer Personal Data” means Personal Data processed by Odyssey Advance on behalf of the Customer through the Services.
“Services” means the Odyssey Advance website, SaaS platform, applications, tools, integrations and related services provided to the Customer.
“Sub-processor” means a third party engaged by Odyssey Advance to process Customer Personal Data on behalf of the Customer in connection with providing the Services.
Odyssey Advance will process Customer Personal Data only to the extent necessary to provide the Services to the Customer and in accordance with the Customer's documented instructions.
Processing will generally continue for the duration of the Customer's use of the Services and for any reasonable period thereafter required to securely delete or return Customer Personal Data, subject to applicable legal requirements.
The subject matter, nature, purpose and categories of processing are described further in Schedule 1 of this DPA.
Odyssey Advance will process Customer Personal Data only on documented instructions from the Customer, including instructions relating to transfers of Personal Data, unless processing is required by applicable law.
The Customer's use and configuration of the Services, including information uploaded, submitted, connected or otherwise processed through Odyssey Advance, constitutes documented instructions for the purposes of this DPA.
Additional instructions may be agreed between the parties in writing.
If Odyssey Advance is required by law to process Customer Personal Data other than in accordance with the Customer's instructions, Odyssey Advance will inform the Customer of that legal requirement before processing unless applicable law prohibits such notification.
If Odyssey Advance reasonably believes that an instruction infringes Applicable Data Protection Law, we may inform the Customer and suspend the relevant processing until the matter has been resolved.
The Customer is responsible for:
The Customer must not instruct Odyssey Advance to process Personal Data in a manner that would violate Applicable Data Protection Law.
Odyssey Advance will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to personnel and authorised parties who reasonably require access for the provision, maintenance, security or support of the Services.
Odyssey Advance will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful:
Security measures will be appropriate to the nature of the processing and the risks presented by the processing.
Measures may include, where appropriate:
Odyssey Advance may update its technical and organisational measures as technologies, threats and industry practices evolve, provided that the overall level of protection is not materially reduced.
Odyssey Advance will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Where reasonably available, the notification will provide information concerning:
Where all relevant information is not immediately available, information may be provided in phases as it becomes available.
Odyssey Advance will take reasonable steps to investigate, contain and mitigate a Personal Data Breach.
Notification of a Personal Data Breach does not constitute an admission of fault or liability by Odyssey Advance.
Taking into account the nature of the processing, Odyssey Advance will provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
These may include requests concerning:
If Odyssey Advance receives a request directly from a Data Subject concerning Customer Personal Data, we will normally direct the Data Subject to the relevant Customer or notify the Customer, unless Applicable Data Protection Law requires us to respond directly.
Taking into account the nature of the processing and information reasonably available to Odyssey Advance, we will provide reasonable assistance to the Customer with its applicable obligations concerning:
The Customer remains responsible for determining whether such measures are required in relation to its own processing activities.
The Customer provides general authorisation for Odyssey Advance to engage Sub-processors where reasonably necessary to provide, maintain, secure or support the Services.
Sub-processors may include providers of:
Odyssey Advance will ensure that Sub-processors processing Customer Personal Data are subject to contractual data protection obligations providing an appropriate level of protection consistent with the requirements applicable to Odyssey Advance under this DPA.
Odyssey Advance remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law.
Where required, Odyssey Advance will make information regarding relevant Sub-processors available to Customers.
Where required by Applicable Data Protection Law, Odyssey Advance will provide reasonable notice of material changes concerning Sub-processors that process Customer Personal Data.
The Customer may raise reasonable data protection objections to a new Sub-processor.
The parties will work in good faith to address legitimate concerns.
Where a reasonable solution cannot be reached, Odyssey Advance may provide the Customer with the option to discontinue the affected functionality or terminate the affected Services in accordance with the applicable Terms and Conditions.
Customer Personal Data may be processed in countries outside the United Kingdom where Odyssey Advance or an authorised Sub-processor operates.
Where a transfer constitutes a restricted transfer under Applicable Data Protection Law, Odyssey Advance will ensure that an appropriate lawful transfer mechanism is used.
This may include:
Where required, Odyssey Advance will implement appropriate supplementary safeguards relating to such transfers.
Following termination or expiry of the Customer's use of the Services, Odyssey Advance will, at the Customer's choice and where reasonably practicable, delete or return Customer Personal Data and delete remaining copies.
This obligation does not apply where retention is required by applicable law.
Customer Personal Data may remain temporarily within secure backups or disaster-recovery systems until deleted through normal retention cycles, provided that it remains appropriately protected and is not used for other purposes.
Customers are responsible for exporting Customer Personal Data they wish to retain before termination where appropriate export functionality is available.
Odyssey Advance will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations contained in this DPA and Article 28 of the UK GDPR.
Where such information is insufficient, Odyssey Advance will allow for and reasonably contribute to audits or inspections conducted by the Customer or an independent auditor appointed by the Customer, subject to appropriate confidentiality, security and operational requirements.
Where practicable, audits should:
Where equivalent compliance information, certifications, assessments or audit reports reasonably satisfy the Customer's requirements, these may be provided instead of a separate audit where permitted by Applicable Data Protection Law.
Odyssey Advance will maintain records relating to processing activities where required by Applicable Data Protection Law.
Odyssey Advance will cooperate with the Information Commissioner's Office or another competent supervisory authority where legally required to do so.
Certain Odyssey Advance features may use artificial intelligence, machine learning or other automated technologies.
Where Customer Personal Data is processed through such functionality, Odyssey Advance will process that information in accordance with this DPA and the Customer's instructions.
Where an external AI technology provider processes Customer Personal Data on behalf of Odyssey Advance, that provider will be treated as a Sub-processor where required by Applicable Data Protection Law.
Customers should not submit special category Personal Data, highly sensitive Personal Data or other information requiring enhanced protection to AI functionality unless the relevant Odyssey Advance feature is specifically designed and authorised for such processing.
Unless expressly agreed otherwise, the Services are not intended for the processing of significant volumes of special category Personal Data or information concerning:
The Customer is responsible for ensuring that it does not use Odyssey Advance to process such information unless it has determined that the processing is lawful and appropriate and the relevant Services are suitable for that processing.
This DPA forms part of and supplements the Odyssey Advance Terms of Service and any other agreement governing the Customer's use of the Services.
If there is a conflict between this DPA and the Terms and Conditions regarding the processing of Customer Personal Data, this DPA will take precedence to the extent of that conflict.
Liability arising under or in connection with this DPA is subject to the exclusions and limitations of liability contained within the Odyssey Advance Terms and Conditions, except where such limitation is prohibited by Applicable Data Protection Law.
Nothing in this DPA limits either party's liability where liability cannot lawfully be excluded or limited.
This DPA is governed by the laws of England and Wales.
Subject to rights or requirements which cannot lawfully be excluded, the courts of England and Wales will have jurisdiction in relation to disputes arising under this DPA.
Odyssey Advance may update this DPA where reasonably necessary to reflect:
Where changes materially affect the processing of Customer Personal Data, Odyssey Advance will take reasonable steps to notify affected Customers where appropriate.
The current version of this DPA will be made available through the Odyssey Advance website.
Odyssey Advance® is a trading brand of Odyssey New Media Limited, a company registered in England and Wales.
Registered Office: Unit 3 Cuckoo Wharf, Lichfield Road, Birmingham, England, B6 7SS
Company Number: 07297050
For questions relating to this DPA or the processing of Customer Personal Data, please contact us through our Contact page.
Processing of Customer Personal Data as necessary to provide the Odyssey Advance digital marketing SaaS platform and associated functionality to the Customer.
For the duration of the Customer's subscription or use of the Services, together with any limited retention period reasonably necessary following termination for deletion, backups, security, legal or compliance purposes.
Processing may include:
The purpose is to provide, maintain, secure, support and improve the functionality requested by the Customer through Odyssey Advance.
Depending upon how the Customer uses the Services, Customer Personal Data may relate to:
Depending upon the Customer's use of the Services, Customer Personal Data may include:
The Services are not generally intended for the processing of special category Personal Data.
Customers should not submit such information unless the relevant functionality is specifically designed and authorised for that purpose and the Customer has established an appropriate lawful basis and applicable safeguards.
Odyssey Advance maintains technical and organisational measures appropriate to the nature and risk of the processing.
These may include, as appropriate:
Controls designed to restrict access to Personal Data to authorised users and personnel.
Technical measures designed to protect information during processing, transmission and storage where appropriate.
Security measures relating to the systems and infrastructure used to provide Odyssey Advance.
Measures designed to identify, prevent and address vulnerabilities affecting the Odyssey Advance platform.
Appropriate backup, recovery and business-continuity measures designed to protect the availability and resilience of the Services.
Procedures for identifying, investigating and responding to suspected security incidents and Personal Data Breaches.
Appropriate confidentiality obligations and access restrictions for personnel authorised to process Personal Data.
Due diligence and contractual safeguards for Sub-processors that process Customer Personal Data on behalf of Odyssey Advance.
These measures may be updated as technology, risks and the Odyssey Advance Services evolve, provided that the overall level of protection is not materially reduced.
