Data Processing Agreement
Version 1.0, 20 August 2026. The version a firm signs is stored as a hashed PDF and available from its billing page.
Summary of the Data Processing Agreement
The full agreement is Schedule 1 to the Terms of Service and is attested as part of signing them. This page summarises it in plain words; where the two differ, the signed document prevails.
Roles
The firm is the controller of the personal data in client files. ArcGabriel Ltd is the processor. For the firm's own account data, ArcGabriel Ltd is the controller (see the Privacy Policy).
Subject matter and duration
Processing of case documents and the personal data in them for the purpose of compliance review, CRM and client communication, for the duration of the subscription and the 90-day export window after it.
Nature of the data
Identity documents, financial statements, income evidence, addresses, contact details, product details, and for protection files, health information (special category data). Data subjects are the firm's clients, joint applicants and, where documents name them, donors of gifted deposits.
Our obligations (Article 28(3))
Process only on the firm's documented instructions, which the settings in the app and the retention mode you select constitute. Ensure confidentiality of staff. Apply the security measures described on the Security page. Engage sub-processors only from the published list, with 30 days' notice of changes and a right to object. Assist the firm with data subject requests, security and DPIAs. Delete or return data at the end of the service. Make available the information needed to demonstrate compliance and allow audits on reasonable notice.
Sub-processors
- Anthropic: AI model inference over document text and images. EEA and United States under Anthropic's data processing addendum; UK-resident inference on Network tier via AWS Bedrock London.
- Amazon Web Services (Bedrock, London): UK-resident AI inference for Network-tier firms. United Kingdom (eu-west-2).
- Railway: Application hosting and primary database. EEA (Amsterdam).
- Cloudflare R2: Encrypted off-box backups and retained documents. EEA jurisdiction, with UK region under evaluation.
- Microsoft: OneDrive access via Microsoft Graph, delegated per folder. Customer's own Microsoft tenant.
- Stripe: Payments, invoicing, VAT. EEA and United States.
- Resend: Transactional and automation email. EEA and United States.
- Meta (WhatsApp Cloud API) via Twilio: WhatsApp template messages and SMS fallback. EEA and United States.
International transfers
Where a sub-processor is outside the United Kingdom, transfers rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and the sub-processor's own data processing terms.
Breach notification
We notify the firm's primary admin without undue delay and within 48 hours of becoming aware of a personal data breach affecting its data, with what we know at the time and updates as we learn more.
Deletion
Deletion follows the retention mode the firm sets. Soft deletion for seven days, then hard deletion, with the off-box backup expiring on its 35-day cycle. Every deletion is logged, and on request we confirm it in writing.