Data Processing Agreement
How ReguVerity processes personal data on behalf of customers using the platform.
Last Updated: 25 September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between ReguVerity Ltd ("Processor") and the customer ("Controller") where ReguVerity processes personal data on the customer's behalf.
1. Scope
ReguVerity may process personal data as necessary to provide the services purchased by the customer.
2. Roles
Where the customer determines the purposes and means of processing personal data, the customer acts as Controller and ReguVerity acts as Processor.
Nothing prevents either party from acting as an independent Controller for processing activities for which it independently determines purposes and means.
3. Processing Instructions
ReguVerity will process customer personal data only:
- On documented customer instructions.
- As necessary to provide contracted services.
- Where required by applicable law.
4. Confidentiality
Persons authorised to process customer personal data will be subject to appropriate confidentiality obligations.
5. Security
ReguVerity will maintain appropriate technical and organisational measures designed to protect personal data against:
- Accidental or unlawful destruction.
- Loss.
- Alteration.
- Unauthorised disclosure.
- Unauthorised access.
6. Sub-processors
The customer authorises ReguVerity to engage sub-processors where necessary to provide the service, subject to applicable data protection requirements.
ReguVerity will maintain appropriate contractual protections with applicable sub-processors.
A current sub-processor list should be made available to customers.
7. Data Subject Requests
Taking into account the nature of processing, ReguVerity will provide reasonable assistance to customers in responding to applicable data-subject rights requests.
8. Personal Data Breaches
ReguVerity will notify affected customers without undue delay after becoming aware of a qualifying personal data breach affecting personal data processed on their behalf, in accordance with applicable legal and contractual obligations.
9. DPIAs and Regulatory Cooperation
Where reasonably required and taking into account the nature of the processing, ReguVerity will provide reasonable assistance with:
- Data Protection Impact Assessments.
- Prior consultations.
- Regulatory enquiries concerning processing performed by ReguVerity.
10. International Transfers
Where customer personal data is transferred internationally, ReguVerity will implement applicable safeguards required by data protection law.
11. Return and Deletion
Following termination, customer personal data will be returned or deleted in accordance with the agreement, applicable law and legitimate retention requirements.
12. Audit Information
ReguVerity will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to customers, subject to appropriate confidentiality, security and operational safeguards.
13. Processing Details
- Subject matter: Provision of the ReguVerity platform.
- Duration: For the duration of the customer's agreement and applicable retention/deletion period.
- Nature and purpose: Hosting and processing information required to provide compliance, governance, inspection, forms, evidence and related functionality.
Types of data subjects may include:
- Customer employees
- Contractors
- Clients/service users
- Representatives
- Suppliers
- Professional contacts
- Other individuals whose information customers lawfully process
Categories of personal data may include:
- Identification information
- Contact information
- Employment information
- Compliance records
- Training records
- User activity
- Customer-uploaded documentation
- Other information entered by customers
Special-category data may be processed where customers choose to enter such information and have an appropriate lawful basis.
