Data processing addendum
This page sets out the substance of the data processing addendum entered into with each customer. The executable version, including the standard contractual clauses where they apply, is issued alongside the services agreement.
Last updated 1 September 2026
Roles
You are the controller of the personal data you place in the service. Setliva is your processor and processes it only on your documented instructions, of which this addendum and the services agreement are the initial set.
Where your own customer is the controller and you are their processor, we act as sub-processor on the same terms.
We will tell you if, in our opinion, an instruction infringes applicable data protection law. We will not simply carry it out.
Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Setliva receivables and disputes service |
| Duration | The term of the services agreement, plus the deletion period below |
| Nature and purpose | Collection from connected systems, derivation of facts, automated decisioning against customer-configured thresholds, production of notices and representment packets, delivery of communications, and maintenance of an audit trail |
| Types of personal data | Names and contact details; invoice, order and transaction records; payment and settlement history; delivery and carrier records; device, session and IP data; communication records and promises to pay; consent records |
| Categories of data subject | Debtors and their contacts; cardholders; customer personnel who use the service |
| Special category data | None sought or required. Free-text fields may contain whatever a user enters, and customers are instructed to limit them to what the matter requires |
Our obligations
- Process only on your documented instructions, including for transfers.
- Ensure personnel with access are bound by confidentiality and trained appropriately.
- Implement the technical and organisational measures described at /legal/security.
- Engage sub-processors only under the notice and objection process at /legal/sub-processors, and remain liable for them.
- Assist you, taking account of the nature of the processing, in responding to data subject requests. Where we receive a request directly we will forward it to you promptly and not respond ourselves except to say that we have.
- Assist you with impact assessments, prior consultation, and breach notification, and notify you of a personal data breach without undue delay and within 72 hours of becoming aware.
- Delete or return the data at the end of the term as set out below.
- Make available the information needed to demonstrate compliance, and allow for audits as described below.
Automated decision-making
The service reaches recommended actions automatically. Because the effect of those actions can be significant for a data subject, this addendum records specific commitments:
- The logic is rule-based and deterministic; no large language model participates in a decision.
- Every fact a decision rests on is recorded against the source record it was read from, and the decision is reproducible from those inputs.
- You can inspect the reasoning for any case, and can override any decision, with the reason recorded.
- Conditions that should prevent pursuit — open disputes, insolvency, limitation periods, unapplied credits, exhausted contact allowances, unexpired promises to pay — are enforced as hard blocks rather than weighted factors.
You remain responsible for determining whether a given decision produces a legal or similarly significant effect, and for providing human intervention where the law requires it.
International transfers
Where personal data is transferred out of the UK or EEA to a country without an adequacy decision, the transfer is governed by the European Commission’s Standard Contractual Clauses and, for UK data, the ICO International Data Transfer Addendum, each incorporated into the executed addendum.
We will assist with any transfer risk assessment you are required to perform, and will tell you if we become subject to a legal requirement that would prevent us meeting these commitments.
Audit
We will make available the information reasonably necessary to demonstrate compliance with this addendum.
You may audit no more than once in any 12-month period, on 30 days’ notice, during business hours, without disrupting the service, and subject to confidentiality. Where an independent assessment report exists, providing it satisfies this obligation unless you have a specific and documented reason it does not.
An audit following a personal data breach affecting your data is not subject to the frequency limit.
Return and deletion
On termination you may export your data. We will delete it, and instruct sub-processors to delete it, within 90 days of termination, unless we are required by law to retain it.
Audit trail entries are retained as described in the privacy policy. Where personal data must be erased, the personal data in the underlying case is removed and the audit entry is retained in a form recording that a decision occurred without reproducing the personal data behind it. This is necessary for the integrity of the chain and for our own legal obligation to be able to explain decisions.
Obtaining a signed copy
Write to hello@setliva.com and we will issue the executable addendum with the appropriate transfer clauses for your jurisdiction. If you need us to sign your paper instead, send it and we will review it.