RightsHub Data Processing Agreement

Last updated: 6 July 2026 · Version 1.1

This Data Processing Agreement ("DPA") forms part of the RightsHubTerms of Service (the "Agreement") between RightsHub Ltd of Unit A, 82 James Carter Road, Mildenhall, IP28 7DE ("RightsHub", "we", "Processor") and the customer that accepts the Agreement ("Customer", "you", "Controller"). By accepting the Terms of Service at registration, you agree to this DPA on behalf of yourself and the entity you represent. No signature is required for it to take effect.

If you require a counter-signed copy, contact support@rightshub.io.

1. Definitions

Capitalised terms not defined here have the meaning given in the Agreement. The following terms apply:

  1. "Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the Data Protection Act 2018 ("UK GDPR"), and any applicable implementing or successor legislation, as amended from time to time.
  2. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the Data Protection Laws.
  3. "Customer Personal Data" means Personal Data that RightsHub Processes on behalf of the Customer in providing the services.
  4. "Sub-processor" means any third party engaged by RightsHub to Process Customer Personal Data.
  5. "Restricted Transfer" means a transfer of Personal Data to a country outside the UK or EEA not subject to an adequacy decision.
  6. "SCCs" means the standard contractual clauses approved by EU Commission Decision 2021/914; "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.

2. Roles and Scope

  1. For the purposes of the Data Protection Laws, the Customer is the controller and RightsHub is the processor in respect of Customer Personal Data.
  2. RightsHub Processes Customer Personal Data only as a processor on the Customer's behalf. The subject matter, duration, nature, purpose, categories of Data Subjects and types of Personal Data are described in Annex 1, supplemented by the Customer's configuration and use of the services.
  3. The Customer warrants that it has a lawful basis for the Processing and that its instructions comply with Data Protection Laws. The Customer's documented instructions are this DPA, the Agreement, and the Customer's use of the services' features.

3. Processor Obligations

RightsHub shall:

  1. Process Customer Personal Data only on the Customer's documented instructions, including as to Restricted Transfers, unless required otherwise by applicable law (in which case RightsHub will, where legally permitted, inform the Customer before Processing);
  2. inform the Customer if, in its opinion, an instruction infringes Data Protection Laws;
  3. ensure persons authorised to Process the data are bound by appropriate confidentiality obligations;
  4. implement and maintain the technical and organisational measures in Annex 2 in accordance with Article 32 GDPR;
  5. taking into account the nature of Processing, assist the Customer by appropriate measures, insofar as possible, in responding to Data Subject requests under Chapter III GDPR;
  6. assist the Customer in complying with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of Processing and the information available to RightsHub.

4. Sub-processing

  1. The Customer grants RightsHub general authorisation to engage Sub-processors to provide the services. A current list of Sub-processors is available at rightshub.io/subprocessors and the key Sub-processors are listed in Annex 3.
  2. RightsHub will notify the Customer of any intended addition or replacement of a Sub-processor at least 14 days in advance (e.g. by email or via the Sub-processor page's subscription mechanism), giving the Customer the opportunity to object on reasonable data protection grounds. If the Customer objects and the matter cannot be resolved, the Customer may terminate the affected services.
  3. RightsHub imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable for each Sub-processor's performance.

5. International Transfers

  1. RightsHub will not carry out a Restricted Transfer without an appropriate transfer mechanism in place.
  2. Where a Restricted Transfer occurs, the Parties incorporate by reference the EU SCCs (Module Two: Controller-to-Processor) for EEA transfers and the UK Addendum for UK transfers, with RightsHub or its Sub-processor as data importer, completed as set out in Annex 4.

6. Personal Data Breach

  1. RightsHub will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. The notification will include, to the extent available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.

7. Audit and Records

  1. RightsHub will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, which may include third-party certifications or audit reports where available.
  2. RightsHub will allow for and contribute to audits, including inspections, by the Customer or a mandated auditor, no more than once per year (save where required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior notice and subject to confidentiality.

8. Return and Deletion

On termination or expiry of the Agreement, RightsHub will, at the Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless applicable law requires continued storage. RightsHub will confirm deletion in writing on request. Customer Personal Data in routine backups is deleted in line with RightsHub's backup cycle.

9. Liability and Term

  1. Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
  2. This DPA takes effect when the Customer accepts the Agreement and continues for as long as RightsHub Processes Customer Personal Data. In the event of conflict on data protection matters, this DPA prevails over the rest of the Agreement.

10. Changes and Governing Law

  1. RightsHub may update this DPA from time to time; material changes will be notified in advance and the "Last updated" date will change. Continued use of the services after the effective date constitutes acceptance.
  2. This DPA is governed by the laws of England & Wales and subject to the jurisdiction provisions of the Agreement.

Annex 1 — Details of Processing

  • Subject matter: Provision of the RightsHub services under the Agreement.
  • Duration: The term of the Agreement plus any retention period required by law.
  • Nature and purpose: Hosting, storage and processing of rights/licensing data to deliver the RightsHub platform. The platform also displays publicly available social media content (pulled read-only from Meta) and sports fixtures/scores data (from SportsDB); neither feed involves Processing Customer Personal Data. Payment processing is handled by a third-party payment provider on its own infrastructure; RightsHub does not store payment card data. RightsHub also processes uploaded contracts using secure third-party AI models (via API) solely for the purpose of automated rights extraction and parsing. RightsHub explicitly prohibits its AI sub-processors from using Customer Personal Data to train their foundational models.
  • Categories of Data Subjects: The Customer's authorised users and personnel, and the personnel/signatories of the Customer's commercial partners and sponsors whose details are included in uploaded agreements.
  • Categories of Personal Data: Names, email addresses, account credentials, and service usage data of authorised users. Additionally, business contact information, names, job titles, and signatures contained within the contracts and sponsorship agreements uploaded to the platform by the Customer.
  • Special category data: None.

Annex 2 — Technical and Organisational Measures

RightsHub maintains measures appropriate to the risk, including:

  1. encryption of Personal Data in transit (TLS) and at rest;
  2. access controls based on least privilege, with unique credentials and multi-factor authentication for administrative access;
  3. logical separation of customer data and regular backups;
  4. logging and monitoring of access to systems Processing Personal Data;
  5. a documented information security policy and personnel confidentiality and training obligations;
  6. regular testing and review of the effectiveness of these measures; and
  7. a documented incident response and business continuity process.

Annex 3 — Key Sub-processors

Sub-processorPurposeLocation
Vercel Inc.Application hosting and deploymentUSA
SupabaseDatabase hostingEU (Frankfurt / Ireland)
Anthropic PBCAI API for contract parsing and data extractionUSA

The full, current list is maintained at rightshub.io/subprocessors.

Annex 4 — Transfer Mechanism

For Restricted Transfers, the Parties incorporate: (a) the EU SCCs (Module Two: Controller-to-Processor), with the Customer as data exporter and RightsHub as data importer; optional Clause 7 docking clause [included/excluded]; Clause 9 option 2 (general authorisation); Clause 11 optional redress [excluded]; Clause 17 governing law [Member State]; Clause 18 forum [Member State]; and (b) the UK Addendum, completing Tables 1–4 by reference to this DPA and its Annexes. Annexes I, II and III of the SCCs are populated by Annexes 1, 2 and 3 of this DPA respectively.