Data processing agreement

Draft. This agreement has not been through legal review, and the parts in [square brackets] are not settled yet. It is published so a firm can see exactly what will be offered — do not rely on it as a signed contract.

This agreement covers personal data that [LEGAL ENTITY] (“Colendo”, the processor) handles on behalf of a firm using the service (the controller). It applies from the moment a firm creates an account and forms part of the terms.

1. Who is who

The firm decides what to collect from its clients, from whom, and why. Colendo only stores and moves it on the firm’s instructions. In the regulation’s words, the firm is the controller and Colendo is the processor.

One exception, stated plainly because it cuts the other way: for the firm’s own account — the names and email addresses of its staff, sign-in records, and billing — Colendo is the controller, and the privacy page covers it.

2. What is processed, and for how long

Subject matter: collecting documents and answers from a firm’s clients, chasing for what is missing, and handing the finished set back to the firm.

Data subjects: the firm’s clients, and anyone appearing in documents those clients upload.

Categories of data: names, email addresses, mobile numbers and company names; the documents themselves, which in this profession routinely include bank statements, invoices, receipts and identity documents; the answers clients type; and delivery records of the messages sent to them.

Duration: for as long as the firm has an account, and afterwards as set out in section 8.

3. Only on the firm’s instructions

Colendo processes this data only to provide the service, and only as the firm instructs — through the product itself or in writing. It is never sold, never used to train anything, and never used to market to a firm’s clients.

If the law ever required Colendo to process it otherwise, the firm would be told first, unless telling them is itself prohibited. If an instruction appears to breach data protection law, Colendo will say so rather than carry it out quietly.

4. Confidentiality

Everyone with access is bound to confidentiality, and access is limited to the people who need it to run the service. Colendo’s own staff cannot read a firm’s documents unless that firm grants access, for a stated reason and a limited time; those sessions are read-only, appear in the firm’s own activity log, and can be withdrawn at any moment.

5. Security

The measures in place today, rather than a list of intentions:

  • Each firm’s data is separated in the database itself, not by application code, so a query cannot reach across firms even by mistake.
  • Data is encrypted in transit. At rest it is encrypted by [HOSTING PROVIDER], which holds the database and the documents.
  • Photo metadata — including the location a photo was taken — is stripped twice: in the client’s browser before the file is sent, and again on receipt.
  • Client links are secrets of 256 bits, expire after 90 days, can be protected with a PIN, and are stored only as a scrambled copy, so a link cannot be recovered from a database.
  • Passwords are stored with Argon2id, and sign-ins are rate limited.
  • An append-only activity log records who did what, and cannot be edited or deleted by anyone — including Colendo.

Colendo has not yet been independently penetration tested or certified. That is stated here rather than left to be discovered.

6. Sub-processors

The firm gives general authorisation for the sub-processors listed on the sub-processor page, which names each one, what it does and which country it is in. Each is bound by terms no weaker than these, and Colendo remains responsible for what they do.

Before adding or replacing one, Colendo will give at least 30 days’ notice by email to the firm’s owner. A firm that objects on reasonable data protection grounds may end its subscription before the change takes effect, with a refund of anything paid for time not used.

7. Helping the firm meet its own duties

Requests from data subjects. A firm can export everything held about one client, and erase a client, from within the product — so most access and erasure requests need no help at all. Where help is needed, Colendo will give it, and will pass on any request it receives directly rather than answering on the firm’s behalf.

Breaches. Colendo will tell the firm without undue delay and within 48 hours of becoming aware of a personal data breach affecting their data, with what is known at the time, and will keep them updated. The firm, as controller, decides whether to report it to the ICO.

Assessments. Colendo will provide what a firm reasonably needs for a data protection impact assessment or a prior consultation.

8. Getting it back, and deletion

A firm can export everything at any time, as a ZIP with a readable summary. That does not stop when a subscription lapses or is cancelled: read access and export remain, because losing access to records a firm is obliged to keep would be indefensible.

On written request after the account ends, Colendo will delete the firm’s data within 30 days, backups included as they age out, except where the law requires it to be kept. Nothing is deleted automatically without that request — the professional duty to retain records outlives the subscription.

9. Audit

Colendo will make available whatever is needed to show these obligations are being met, and will allow and contribute to audits by the firm or an auditor it appoints, on reasonable notice and no more than once a year unless a breach or a regulator makes another necessary.

10. Where the data is, and transfers

Documents and client personal data are stored in the UK and EU. Some sub-processors that handle limited data — email delivery, error reporting, billing — operate from outside the UK; each is listed with its country on the sub-processor page, and any transfer relies on the UK’s approved safeguards, which for those outside an adequacy decision means the International Data Transfer Addendum to the standard contractual clauses.

11. Practical matters

This agreement is governed by the law of England and Wales. Notices to Colendo go to [CONTACT EMAIL]; notices to the firm go to its owner’s registered email address.

[LEGAL ENTITY], [REGISTERED ADDRESS], company number [COMPANY NUMBER], ICO registration [ICO NUMBER].

A firm that needs this signed, or needs it on their own paper, should get in touch at [CONTACT EMAIL].