Data Processing Addendum
Last updated 25 September 2026
In plain English
- Slurry is built for fake data, and our rules ban real personal data in Simulations.
- If personal data gets in anyway, this addendum sets out how we handle it as your processor, as UK GDPR Article 28 requires.
- We only act on your instructions, keep it secure and confidential, use listed sub-processors, help you with rights requests and breaches, and delete it when the contract ends.
- International transfers are covered by the UK IDTA or the EU Standard Contractual Clauses with the UK Addendum.
- This addendum does not give you permission to upload personal data.
1. Parties and scope
1.1 This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between The Next Renaissance Ltd, trading as Slurry, a company registered in England and Wales with company number 10373346, whose registered office is at [registered office address] ("Processor", "we", "us") and the Customer ("Controller", "you"). It applies automatically when you accept the Agreement, with no signature required. A countersigned copy is available on request from privacy@slurry.io.
1.2 This DPA applies to Customer Personal Data, meaning any personal data contained in Customer Content or Generated Data, or otherwise processed by us on your behalf in providing the Service. It does not apply to personal data we process as a controller (such as account, billing, security and abuse monitoring data), which is covered by our Privacy Policy.
1.3 The Service is designed for synthetic data only. The Agreement and the Acceptable Use Policy prohibit you from including real personal data in the Service. Nothing in this DPA permits you to do so, and your compliance with this DPA does not cure a breach of that prohibition. This DPA exists so that any personal data processed despite the prohibition is protected in accordance with Data Protection Law.
1.4 "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable to the processing, the EU GDPR (Regulation (EU) 2016/679) and other data protection laws applicable to either party, each as amended. "Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the UK GDPR.
1.5 If there is a conflict between this DPA and the rest of the Agreement in relation to Customer Personal Data, this DPA prevails. If there is a conflict between this DPA and the Transfer Mechanism in section 10, the Transfer Mechanism prevails.
2. Roles
2.1 You are the controller (or a processor acting for a third-party controller) of Customer Personal Data, and we are your processor (or sub-processor).
2.2 You are responsible for having a lawful basis and giving any required notices for the processing, and for the accuracy and lawfulness of Customer Personal Data and of your instructions.
3. Instructions
3.1 We will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do so by UK law (or, where applicable, EU or Member State law), in which case we will tell you of that legal requirement before processing unless the law prohibits this on important grounds of public interest.
3.2 Your documented instructions are: the Agreement and this DPA; your configuration and use of the Service (including creating, seeding, mutating and exposing Simulations, configuring webhooks and rules, and using the MCP Server); and any further written instructions agreed between the parties.
3.3 We will tell you immediately if, in our opinion, an instruction infringes Data Protection Law. We may suspend the relevant processing until the instruction is confirmed or changed.
3.4 You authorise us to scan, quarantine, redact and delete Customer Personal Data for the purposes of enforcing the Acceptable Use Policy and keeping the Service secure, and agree that this processing is part of your instructions.
4. Confidentiality
We will ensure that all persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide, secure or support the Service.
5. Security
5.1 We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data as required by Article 32 UK GDPR, including those set out in Annex 2.
5.2 We may update our security measures from time to time, provided the overall level of protection is not materially reduced.
5.3 You are responsible for the security measures within your control, including keeping IP allow-lists enabled and appropriate, protecting API keys and MCP credentials, and not disabling security features.
6. Sub-processors
6.1 You give general written authorisation for us to engage sub-processors. Our current sub-processors are listed at https://slurry.io/legal/subprocessors and in Annex 3.
6.2 We will give at least 30 days' notice before engaging a new or replacement sub-processor to process Customer Personal Data, by updating the list and emailing your account owner. You may object on reasonable data protection grounds within that period by emailing privacy@slurry.io. We will work with you in good faith to address the objection. If we cannot, you may terminate the affected Service by written notice and we will refund prepaid fees for the unused period.
6.3 We will impose on each sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. We remain liable to you for the performance of each sub-processor's obligations.
6.4 A model provider that you engage directly using your own API key is not our sub-processor, and data sent to it is sent on your instruction.
7. Assistance with data subject rights
7.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, to fulfil your obligation to respond to requests from data subjects to exercise their rights under Data Protection Law.
7.2 If we receive a request directly from a data subject relating to Customer Personal Data, we will promptly pass it to you (where we can identify you) and will not respond ourselves except to direct the data subject to you or as required by law.
7.3 The Service allows you to view, edit, export and delete Simulation data yourself. Where you need further assistance, we may charge reasonable costs for assistance that goes beyond the functionality of the Service.
8. Personal data breaches, DPIAs and consultation
8.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include, so far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as it becomes available.
8.2 We will take reasonable steps to contain, investigate and remedy the breach, and will cooperate with you in meeting your obligations under Articles 33 and 34 UK GDPR.
8.3 Our notification of a breach is not an admission of fault or liability.
8.4 Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment and prior consultation with a supervisory authority that you are required to carry out in relation to the Service.
9. Deletion or return
9.1 On termination of the Agreement, you may export Customer Content (including any Customer Personal Data) for 30 days as described in the Terms of Service. After that period we will delete Customer Personal Data within a further 30 days, unless UK law requires us to store it. Backups containing it will be overwritten within 35 days after deletion from live systems.
9.2 You may delete Simulations and their data at any time during the term using the Service. Deletion from live systems takes effect immediately; backups expire as set out above.
9.3 We will confirm deletion in writing on request.
10. International transfers
10.1 We may transfer Customer Personal Data outside the United Kingdom (and, where EU GDPR applies, outside the European Economic Area) only where the transfer complies with Data Protection Law.
10.2 Where we or a sub-processor transfer Customer Personal Data to a country that is not covered by UK adequacy regulations, the transfer will be made under one of the following (each a "Transfer Mechanism"): (a) the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018; (b) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (the "UK Addendum"); or (c) certification of the recipient under the UK Extension to the EU-US Data Privacy Framework.
10.3 Where you are established in the EEA and transfer Customer Personal Data to us in the UK, the transfer relies on the European Commission's adequacy decision for the United Kingdom. If that decision ceases to apply, the parties agree that Module 2 (controller to processor) of the EU Standard Contractual Clauses is incorporated into this DPA, with Annex 1 of this DPA completing Annex I, Annex 2 completing Annex II, Annex 3 completing Annex III, Clause 7 (docking) included, Clause 9 option 2 (general authorisation, 30 days' notice) applied, Clause 11 optional language omitted, and Clauses 17 and 18 governed by the law of, and the courts of, Ireland.
10.4 We will carry out and document a transfer risk assessment where required, and make a summary available on request.
11. Audits and information
11.1 We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, including this DPA, our sub-processor list, a summary of our security measures and, where available, relevant certifications or third-party reports.
11.2 If that information is not sufficient to demonstrate compliance, or where required by a supervisory authority, we will allow for and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you (not being our competitor), on the following terms: at least 30 days' written notice; no more than once in any 12-month period (unless following a personal data breach or at the request of a supervisory authority); during business hours; subject to confidentiality; without access to other customers' data; and at your cost, including our reasonable costs of supporting the audit.
12. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitations are not permitted by Data Protection Law. Nothing in this DPA limits either party's liability to data subjects under Data Protection Law. Your indemnity in the Agreement for breach of the prohibition on real personal data applies to any claim, fine or loss arising from Customer Personal Data you included in breach of that prohibition.
13. Term
This DPA lasts for as long as we process Customer Personal Data on your behalf, and ends automatically when that processing ends and deletion under section 9 is complete.
Annex 1 - Details of processing
| Item | Details |
|---|---|
| Subject matter | Provision of the Slurry simulation service under the Agreement |
| Duration | The term of the Agreement plus the deletion period in section 9 |
| Nature and purpose | Hosting, storing, generating, transforming, mutating, serving through API endpoints and webhooks, scanning for abuse, and deleting Customer Content and Generated Data, in order to provide simulated test environments to the Customer |
| Categories of data subjects | None intended. If included in breach of the Acceptable Use Policy: individuals whose data the Customer includes in Customer Content, such as the Customer's own staff, customers or contacts |
| Categories of personal data | None intended. If included in breach of the Acceptable Use Policy: identifiers and contact details, and any other data the Customer includes |
| Special category and criminal offence data | Prohibited. None intended |
| Frequency | Continuous for the duration of the Agreement |
| Retention | As set out in section 9 and the Privacy Policy |
Annex 2 - Technical and organisational measures
- Access control: API keys and IP allow-lists on every Simulation, enabled by default; role-based access in the client area; multi-factor authentication for customer accounts and mandatory for staff and admin access; least-privilege staff access with logging of administrative actions.
- Encryption: TLS 1.2 or higher for all traffic; encryption at rest for databases and backups provided by our hosting provider; API keys and passwords stored as salted hashes; bring-your-own model keys stored with application-level encryption.
- Separation: logical separation of each customer's Simulations and data by tenant identifier and access checks on every request; separate staging and production environments; no production data used in staging.
- Data minimisation: synthetic-only design; automated scanning of Customer Content and Generated Data for personal data, card numbers and credentials, with blocking or redaction; model providers configured not to train on submitted data where available.
- Network protection: web application firewall, rate limiting and DDoS protection at the edge; outbound webhook controls blocking private, internal and metadata address ranges.
- Monitoring and logging: security and audit logs retained for 12 months; alerting on suspicious activity and abuse patterns.
- Resilience: managed database backups with defined retention; documented restore process.
- Secure development: code review, dependency scanning, secrets kept out of source code and held in a secrets store, security testing before release.
- Incident response: documented incident response process with breach notification timelines as in section 8.
- Personnel: confidentiality obligations for all staff and contractors; access removed promptly on leaving.
- Vendor management: data protection terms with each sub-processor and periodic review of their security posture.
Annex 3 - Authorised sub-processors
As listed at https://slurry.io/legal/subprocessors on the date of this DPA: Railway Corporation (hosting), Stripe (payments), Cloudflare, Inc. (DNS, content delivery and security), Resend (transactional email), Anthropic PBC (hosted language model), OpenRouter, Inc. (hosted language model routing).
The Next Renaissance Ltd, trading as Slurry, registered in England and Wales, company no. 10373346. Questions: legal@slurry.io