Data Processing Agreement

How ReguVerity processes personal data on behalf of customers using the platform.

Last Updated: 25 September 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between ReguVerity Ltd ("Processor") and the customer ("Controller") where ReguVerity processes personal data on the customer's behalf.

1. Scope

ReguVerity may process personal data as necessary to provide the services purchased by the customer.

2. Roles

Where the customer determines the purposes and means of processing personal data, the customer acts as Controller and ReguVerity acts as Processor.

Nothing prevents either party from acting as an independent Controller for processing activities for which it independently determines purposes and means.

3. Processing Instructions

ReguVerity will process customer personal data only:

  • On documented customer instructions.
  • As necessary to provide contracted services.
  • Where required by applicable law.

4. Confidentiality

Persons authorised to process customer personal data will be subject to appropriate confidentiality obligations.

5. Security

ReguVerity will maintain appropriate technical and organisational measures designed to protect personal data against:

  • Accidental or unlawful destruction.
  • Loss.
  • Alteration.
  • Unauthorised disclosure.
  • Unauthorised access.

6. Sub-processors

The customer authorises ReguVerity to engage sub-processors where necessary to provide the service, subject to applicable data protection requirements.

ReguVerity will maintain appropriate contractual protections with applicable sub-processors.

A current sub-processor list should be made available to customers.

7. Data Subject Requests

Taking into account the nature of processing, ReguVerity will provide reasonable assistance to customers in responding to applicable data-subject rights requests.

8. Personal Data Breaches

ReguVerity will notify affected customers without undue delay after becoming aware of a qualifying personal data breach affecting personal data processed on their behalf, in accordance with applicable legal and contractual obligations.

9. DPIAs and Regulatory Cooperation

Where reasonably required and taking into account the nature of the processing, ReguVerity will provide reasonable assistance with:

  • Data Protection Impact Assessments.
  • Prior consultations.
  • Regulatory enquiries concerning processing performed by ReguVerity.

10. International Transfers

Where customer personal data is transferred internationally, ReguVerity will implement applicable safeguards required by data protection law.

11. Return and Deletion

Following termination, customer personal data will be returned or deleted in accordance with the agreement, applicable law and legitimate retention requirements.

12. Audit Information

ReguVerity will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to customers, subject to appropriate confidentiality, security and operational safeguards.

13. Processing Details

  • Subject matter: Provision of the ReguVerity platform.
  • Duration: For the duration of the customer's agreement and applicable retention/deletion period.
  • Nature and purpose: Hosting and processing information required to provide compliance, governance, inspection, forms, evidence and related functionality.

Types of data subjects may include:

  • Customer employees
  • Contractors
  • Clients/service users
  • Representatives
  • Suppliers
  • Professional contacts
  • Other individuals whose information customers lawfully process

Categories of personal data may include:

  • Identification information
  • Contact information
  • Employment information
  • Compliance records
  • Training records
  • User activity
  • Customer-uploaded documentation
  • Other information entered by customers

Special-category data may be processed where customers choose to enter such information and have an appropriate lawful basis.