reginspectBack to RegInspect
Back to Legal Hub

RegInspect · Legal

Data Processing Agreement

Processing terms and schedules for subscribing firms.

Version 2026-09-16 · Updated 2026-09-16

On this page

  1. 1. Parties, scope and precedence
  2. 2. Instructions and confidentiality
  3. 3. Security and assistance
  4. 4. Sub-processors and transfers
  5. 5. Personal data breaches
  6. 6. Return, deletion and lawful retention
  7. 7. Evidence and audits
  8. Schedule 1 — Processing details
  9. Schedule 2 — Security measures

1. Parties, scope and precedence

This DPA forms part of the service agreement between the subscribing firm (Controller) and Drawbridges Business Services Ltd, England and Wales company 15260510 (Processor). The firm and authorised representative are identified in the order or recorded account agreement. An individually signed DPA prevails where it expressly varies these terms.

This DPA governs personal data processed on the Controller’s behalf through RegInspect. It does not apply to information for which the Processor separately acts as controller, as explained in the Privacy Policy. It takes precedence over conflicting service terms on processor obligations. Applicable Data Protection Law means the data-protection law applying to the processing, including UK GDPR and the Data Protection Act 2018, EU GDPR for applicable Malta processing, and applicable Gibraltar data-protection law.

2. Instructions and confidentiality

The Processor will process customer personal data only on documented instructions, including for transfers, unless law requires otherwise. The agreement and authorised use of supported features form the initial instructions. If legally required to process otherwise, the Processor will inform the Controller before processing unless the law prohibits notice.

The Processor will promptly inform the Controller if, in its opinion, an instruction infringes applicable data-protection law. People authorised to process personal data must be subject to confidentiality duties and access limited to their responsibilities.

3. Security and assistance

Taking account of the nature and risks of processing, the Processor will implement appropriate technical and organisational measures, including the measures described in Schedule 2. The parties will cooperate on reasonable information needed to assess those safeguards.

Taking account of the nature of processing and information available, the Processor will assist the Controller with data-subject requests, security, breach assessment, data-protection impact assessments and prior consultation obligations. The Controller remains responsible for decisions and communications required of it by law.

4. Sub-processors and transfers

The Controller gives general written authorisation for service providers engaged to process its information for the agreed service. The public provider list identifies services and purposes; the applicable order and supplier record identify the legal entities and processing arrangements. The Processor will give at least 30 days’ notice of an intended addition or replacement so the Controller can raise a reasoned data-protection objection before the change.

The parties will seek a reasonable alternative if an objection cannot be resolved. No supplier is authorised to use customer data for an incompatible purpose. The Processor will impose equivalent data-protection obligations by written contract and remains responsible to the Controller for its sub-processor’s performance of those obligations.

Restricted transfers require safeguards permitted by the applicable law. Supplier access from another country is assessed as well as storage location. Details of the applicable mechanism and safeguards must be made available on request; this DPA does not itself assert that an unverified supplier arrangement is adequate.

5. Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting its data. Available information will include the nature and likely consequences, affected categories and approximate numbers where known, response measures and a contact point. Information may be supplied in stages as the investigation progresses. The Controller determines its notification obligations; the Processor’s notice obligation is not postponed until a supervisory-authority deadline.

6. Return, deletion and lawful retention

At the end of processing, at the Controller’s choice, the Processor will return or delete customer personal data and delete existing copies unless applicable law requires storage. The parties will arrange a secure export and a documented deletion timetable, taking account of the volume, format, agreed service and legal holds.

Where a legal retention duty prevents deletion, the Processor will identify the duty unless prohibited, restrict the retained data to that purpose and delete it when the duty ends. Backups remain protected and are removed through their controlled expiry cycle; restored data must remain subject to deletion instructions. The Processor will provide reasonable confirmation of completion.

7. Evidence and audits

The Processor will make available information necessary to demonstrate compliance with its processor obligations and allow and contribute to audits, including inspections by the Controller or its mandated auditor. The parties will coordinate reasonable notice, confidentiality and security arrangements without defeating legally required audit rights or urgent investigations.

Schedule 1 — Processing details

Subject matter and duration: hosting and operating the firm’s RegInspect workspace for the service term and the agreed return/deletion period, with any legally required restricted retention.

Nature and purpose: collection, organisation, storage, retrieval, display, analysis, screening requests, authorised disclosure, export and deletion to support client due diligence, risk assessment, compliance workflows, evidence, signatures, communications and user access. Optional AI or identity services process data only when the corresponding function is used or configured.

Data subjects: the firm’s authorised users and staff, clients and prospective or declined clients, directors, partners, trustees, beneficial owners, representatives and other persons recorded for compliance purposes.

Data types: identifiers and contact details, identity documents, ownership and role information, financial and source-of-funds evidence, risk and screening information, compliance communications, documents and audit metadata. Sensitive or criminal-offence-related information may arise in compliance records. The Controller determines the lawful basis and any additional processing conditions.

Controller rights and duties: give lawful documented instructions, provide necessary notices, establish legal bases, keep information accurate, manage user access, specify retention and respond to data subjects. The Controller may exercise the assistance, information, audit and return/deletion rights in this DPA.

Schedule 2 — Security measures

Measures include authenticated access and role controls, tenant-scoped application access, protected transport, cloud storage/database encryption, audit logging, vulnerability management, backup/recovery procedures and incident handling. Privileged access is restricted to authorised personnel.

The security description is a statement of measures to be maintained, not a claim of ISO certification, a completed independent penetration test or guaranteed prevention of every incident. The parties can request relevant operational evidence and agree additional measures appropriate to the processing.

Contact

Drawbridges Business Services Ltd · Company number 15260510
Townshend House, 30 Crown Road, Norwich NR1 3DT, United Kingdom

contact@reginspect.co.uk. For privacy or security matters, include “Privacy” or “Security” in the subject. Do not send sensitive client records in an initial enquiry.

Related legal documents

Terms of ServicePrivacy PolicyCookie PolicyData Protection & Your RightsService Providers & Sub-processorsBilling TermsSecurity PolicyAcceptable Use PolicyRegulatory & AI Disclaimer

Drawbridges Business Services Ltd · Company No. 15260510

contact@reginspect.co.uk