Data Processing Agreement
Last updated: May 2026
This Data Processing Agreement is incorporated into the Terms of Service and takes effect when a firm subscribes to Proven Duty. A downloadable PDF version is available upon request.
1. Definitions
- "Controller" means the subscribing IFA firm that determines the purposes and means of processing personal data.
- "Processor" means Proven Duty, which processes personal data on behalf of the Controller.
- "Data Subjects" means the Controller's clients whose personal data is processed.
- "Sub-Processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.
- "UK GDPR" means the retained EU law version of the General Data Protection Regulation as it applies in the UK.
2. Scope and Purpose
This DPA applies to the processing of personal data by Proven Duty in the provision of its compliance analysis service, including:
- Storing and analysing uploaded client documents
- Extracting text for AI compliance assessment
- Generating compliance scores and vulnerability signals
- Producing suitability report drafts and regulatory digests
- Storing audit trails, review history, and service delivery records
- Sending email notifications as configured by the firm
3. Processor Obligations
Proven Duty shall:
- Process personal data only on the Controller's documented instructions, including transfers to third countries, unless required to do so by applicable law.
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and firm-scoped data isolation.
- Not engage a sub-processor without prior specific or general written authorisation. In the case of general written authorisation, the Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
4. Sub-Processors
The Controller authorises the use of the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (eu-west-1) |
| Vercel | Application hosting | UK / EU |
| Google (Gemini API) | AI processing | US / EU |
| Stripe | Payment processing | US / EU |
| Resend | Transactional email | US |
The Controller is informed that Google (Gemini API) and Resend process data in the US. Appropriate safeguards (UK International Data Transfer Agreement or Standard Contractual Clauses) are in place for these transfers.
5. Data Subject Rights
Taking into account the nature of the processing, Proven Duty shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising data subject rights under the UK GDPR.
If Proven Duty receives a request directly from a data subject, it shall promptly notify the Controller without responding to the request itself.
6. Audit Rights
The Controller has the right to audit Proven Duty's compliance with this DPA. In practice, the Controller may satisfy this right by requesting and reviewing Proven Duty's security certifications (e.g., Cyber Essentials), SOC 2 reports (when available), and privacy policy documentation. Proven Duty shall make reasonable efforts to provide evidence of compliance within 30 days of a written request.
7. Data Breach Notification
Proven Duty shall notify the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach. The notification shall include:
- The nature of the breach, including categories and approximate numbers of data subjects and records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
- A contact point where more information can be obtained
8. Data Deletion and Return
Upon termination of the subscription, the Controller may request that Proven Duty:
- Return all personal data to the Controller in a structured, commonly used, machine-readable format (CSV export via the platform); and/or
- Delete all personal data, subject to FCA record-keeping requirements that may require retention for up to 7 years.
9. Contact
For DPA-related enquiries: support@proven-duty.co.uk