Data Processing Agreement (DPA)

Last updated: June 2026

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between Creobyte Ltd (trading as ClearFact) and the subscribing adviser firm (“Controller”).

1. Definitions

  • “Controller” means the financial adviser or mortgage broker firm subscribing to ClearFact, who determines the purposes and means of processing Client Personal Data.
  • “Processor” means Creobyte Ltd (trading as ClearFact), company number 17228907, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
  • “Client Personal Data” means any personal data uploaded to the ClearFact platform by the Controller or their clients, including identity documents, financial records, fact-find responses, and correspondence.
  • “UK GDPR” means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.

2. Scope and Purpose

2.1 The Processor shall process Client Personal Data only on the documented instructions of the Controller, for the purpose of providing the ClearFact CRM and client portal service as described in the Terms of Service.

2.2 The categories of data subjects are the Controller’s clients and prospective clients.

2.3 The categories of personal data processed include: full names, contact details, residential addresses, date of birth, identity documents, financial information, employment details, fact-find responses, and electronic signatures.

2.4 The processing shall continue for the duration of the subscription and for 30 days following termination, after which all Client Personal Data shall be permanently deleted.

3. Processor Obligations

The Processor shall:

3.1 Process Client Personal Data only on the Controller’s documented instructions, unless required to do so by UK law, in which case the Processor shall inform the Controller before processing unless prohibited by law.

3.2 Ensure that all personnel authorised to process Client Personal Data are bound by appropriate confidentiality obligations.

3.3 Implement and maintain appropriate technical and organisational security measures in accordance with Article 32 UK GDPR, including as a minimum:

  • AES-256 encryption of all data at rest
  • TLS 1.2+ encryption of all data in transit
  • Role-based access controls
  • Immutable audit trails
  • Regular security assessments

3.4 Not engage any sub-processor without the prior written consent of the Controller. General written consent is given by the Controller’s acceptance of these Terms for the sub-processors listed in Schedule 1. The Processor shall notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.

3.5 Assist the Controller, insofar as possible, in responding to data subject rights requests under UK GDPR (Articles 15–22). The Controller may manage deletion requests directly within the ClearFact portal.

3.6 Assist the Controller in ensuring compliance with obligations under Articles 32–36 UK GDPR (security, breach notification, data protection impact assessments, and prior consultation).

3.7 At the Controller’s choice, delete or return all Client Personal Data at the end of the service relationship, and delete existing copies unless UK law requires storage. Standard account closure results in deletion within 30 days.

3.8 Make available to the Controller all information necessary to demonstrate compliance with this Agreement, and allow for and contribute to audits and inspections. Where the Controller wishes to conduct an audit, it shall provide at least 14 days’ written notice. The Processor may satisfy audit rights through provision of relevant certifications, third-party audit reports, or documented security assessments.

4. Data Breach Notification

4.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data.

4.2 Such notification shall include, to the extent known at the time: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

4.3 The Controller remains responsible for notifying the ICO within 72 hours where required under Article 33 UK GDPR, and for notifying affected data subjects where required under Article 34.

5. International Transfers

5.1 The Processor shall not transfer Client Personal Data outside the United Kingdom without the prior written consent of the Controller.

5.2 All Client Personal Data is stored and processed exclusively on UK-based infrastructure (AWS eu-west-2 London, Vultr London). No international transfers occur in standard processing.

5.3 Where sub-processors operate outside the UK (see Schedule 1), appropriate transfer mechanisms are in place as noted therein.

6. Controller Obligations

The Controller warrants that:

6.1 It has a lawful basis under UK GDPR for processing its clients’ personal data and uploading it to the ClearFact platform.

6.2 It has provided appropriate privacy notices to its clients regarding the use of ClearFact as a data processor.

6.3 It is registered with the ICO as a data controller, or is otherwise lawfully exempt from such registration.

6.4 It will use the platform in compliance with all applicable laws and regulations, including UK GDPR, the Data Protection Act 2018, and FCA requirements.

7. Liability

Each party’s liability under this Agreement is subject to the limitations set out in the Terms of Service. Nothing in this Agreement limits either party’s liability for matters that cannot be excluded by law.

8. Governing Law

This Agreement is governed by the laws of Scotland and subject to the exclusive jurisdiction of the Scottish courts.

Schedule 1 , Authorised Sub-processors

Sub-processor Purpose Location Transfer Mechanism
Amazon Web Services EMEA SARL Document and file storage UK (eu-west-2, London) UK adequacy / AWS DPA
Vultr Holdings LLC Application server hosting UK (London) Vultr DPA
Stripe Payments Europe Ltd Payment processing Ireland (EU) UK adequacy / Stripe DPA
Resend Inc Transactional email delivery EU Standard Contractual Clauses
The SMS Works SMS notifications UK UK-based provider, no transfer

The Processor will maintain this schedule and notify Controllers of any changes with a minimum of 14 days’ notice, providing the right to object.

Schedule 2 , Technical and Organisational Security Measures

The Processor implements the following measures in accordance with Article 32 UK GDPR:

Encryption

  • AES-256 encryption for all data at rest
  • TLS 1.2 minimum for all data in transit
  • Encrypted database backups

Access Controls

  • Role-based access controls (RBAC) within the platform
  • Multi-factor authentication available for all accounts
  • Principle of least privilege for internal system access

Availability and Resilience

  • Automated daily backups with 30-day retention
  • Infrastructure monitoring with automated alerting
  • Incident response procedures documented internally

Testing and Assurance

  • Regular vulnerability assessments
  • Security review on all significant platform changes

Personnel

  • All staff and contractors with data access bound by confidentiality obligations
  • Data protection awareness training for all personnel handling personal data