Data Processing Agreement
The agreement governing personal data that GovScape (operating entity to be confirmed) processes on your behalf, under Article 28 of the UK GDPR. It applies automatically to every customer, and can be signed as a standalone document where your procurement process requires one.
Last reviewed 9 September 2026
Draft — not yet published
This document is complete except for the facts below, which cannot be determined from the application and must be supplied before it is relied on:
- Registered company name of the operating entity
- Companies House company number
- Registered office address
- ICO registration reference (data protection fee)
- A monitored inbox for privacy and data subject requests
- Supabase project region — where the database, logins and uploaded files actually live
- Sentry data residency — currently the US, with AUD-44 open to move it to the EU
- Confirmation that a UK IDTA or SCC addendum is signed with every processor outside the UK
Filling in lib/legal/entity.ts removes this notice from every legal page.
1How this agreement takes effect
This agreement supplements the terms of service and applies whenever we process personal data on your behalf. You do not have to sign it for it to bind us; it is in force from the moment you begin using the product.
If your procurement process needs a countersigned copy, use the signature block in clause 14 and send it to sales@govscape.app. We will return a countersigned version. If you would rather we signed your own DPA, we will consider it, but this one is the faster route and its annexes are generated from the running system rather than transcribed.
2Definitions and roles
“UK GDPR”, “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” carry the meanings given in the UK GDPR and the Data Protection Act 2018.
You are the controller of the personal data contained in the content you place in GovScape, and of the personal data read from any system you connect. We are the processor of that data.
We are a separate controller in our own right for account administration, billing, security and service improvement, as described in the privacy policy. This agreement does not govern that processing.
3Our obligations
We will:
- process personal data only on your documented instructions — your use of the product, the settings you choose and the connectors you enable constitute those instructions — except where we are required to process by law, in which case we will tell you first unless the law forbids it;
- tell you if, in our opinion, an instruction infringes data protection law;
- ensure everyone authorised to process the data is bound by a duty of confidentiality;
- implement the technical and organisational measures set out in Annex C, and not materially reduce them during the term;
- engage sub-processors only on the terms in clause 5;
- help you respond to data subject requests, as set out in clause 6;
- help you with data protection impact assessments and with prior consultation of a supervisory authority, taking into account what we know about the processing;
- delete or return the data at the end of the agreement, as set out in clause 9;
- make available the information needed to demonstrate compliance with Article 28, and allow audits as set out in clause 10.
4Your obligations
You will:
- ensure you have a lawful basis for the personal data you place in the product, and that any required notice has been given to the people concerned;
- in particular, ensure that people whose personal data appears in uploaded policies and evidence, in files read from a connected system, and in recordings you transcribe, have been informed as the law requires — including that the content will be processed by AI models;
- configure user access appropriately and remove it when someone leaves;
- not place special category data or criminal offence data in the product unless you have told us in advance and we have agreed in writing, since the security measures in Annex C are designed for business governance records.
5Sub-processors
You give general authorisation for us to engage the sub-processors listed in Annex B. We impose data protection obligations on each of them no less protective than those in this agreement, and we remain fully liable to you for their performance.
We will give you at least 30 days’ notice before a new sub-processor begins processing your data, by email to your notified contact. You may object within that period on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the affected part of the service and receive a refund of fees paid for the unused remainder of the term.
Annex B is generated from the application’s source code and verified by an automated check on every build, so a service cannot begin receiving data without appearing in it.
6Data subject requests
Most requests you can satisfy yourself: you can search, correct, export and delete governance records directly in the product.
Where you cannot, contact sales@govscape.app and we will help within a period that lets you meet your own statutory deadline. Two points of honesty about the current state of the product:
- There is no self-service bulk export or account-erasure function yet. Requests of that kind are fulfilled manually by our team.
- Deleting a policy or evidence record removes the underlying file as well as the record. Removal of the file is best-effort: a storage failure at that moment does not block the deletion of the record, and a reconciliation process removes any file left behind. We can confirm in writing that a named file is gone.
- Renewing an evidence item stores the new file alongside the superseded one rather than replacing it, so a document you have replaced is still held until you ask us to remove it.
If a data subject contacts us directly about data we hold as your processor, we will not respond substantively; we will refer them to you and tell you promptly.
7Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — to the extent that information is available, and we will supply the remainder as we establish it rather than delay the first notification until it is complete.
We will not notify a supervisory authority or any data subject on your behalf without your instruction, unless we are separately required to as a controller.
8International transfers
Several of our sub-processors are incorporated outside the United Kingdom, as Annex B shows. Where personal data is transferred outside the UK, we will do so only under a transfer mechanism recognised by UK law: an adequacy regulation, the UK International Data Transfer Agreement, or the EU standard contractual clauses with the UK addendum.
Confirmation of the mechanism in place with each sub-processor is being completed. We state that plainly rather than assert coverage we have not verified, and we will provide the executed documents on request once each is confirmed.
9Deletion and return
On termination, and at your choice, we will delete or return the personal data we process on your behalf. Unless you ask for return within 30 days of termination, we will delete it.
Two exceptions, both stated so they are not discovered later. Audit records are retained as an immutable log for as long as the law and our own record-keeping obligations require, and are removed when the organisation is deleted in full. And backups expire on their own cycle rather than being edited, so data may persist in a backup for a short period after deletion; it remains protected by this agreement until it expires.
10Audit
We will provide, on request, the information reasonably needed to demonstrate compliance with Article 28, including our security documentation and the current sub-processor register.
You may audit us, or appoint an independent auditor who is not a competitor of ours, no more than once in any twelve-month period — and additionally after a personal data breach affecting your data — on 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear the cost unless the audit reveals a material breach of this agreement.
11Artificial intelligence processing
This clause is specific to GovScape and does not appear in a standard DPA. It is here because the AI processing is the part of the service that moves personal data furthest, and a procurement reviewer should not have to infer it from a vendor list.
- Document text you upload, text from files selected for review in a connected system, briefing transcripts, and advisor conversations are transmitted to Anthropic for processing.
- Audio you record for a briefing is transmitted to OpenAI for transcription. We do not retain the audio.
- Content is transmitted as written. It is not redacted or pseudonymised before being sent, so personal data contained in a document is transmitted with it.
- Model output is written into the product as draft content, attributed in the audit log to the model rather than to a person, so that human review is possible and evidenced.
- No decision producing a legal or similarly significant effect on an individual is made by automated means.
- We do not use your content to train models, and we require the same of our AI sub-processors.
12Liability
Each party’s liability under this agreement is subject to the limitations and exclusions in the terms of service. Nothing here limits a data subject’s rights, or either party’s liability to a supervisory authority.
13Precedence, term and law
This agreement lasts as long as we process personal data on your behalf. Where it conflicts with the terms of service on a matter of personal data, this agreement prevails. It is governed by English law, and the courts of England and Wales have exclusive jurisdiction.
14Signature
A countersigned copy is available on request. Complete the block below and send it to sales@govscape.app.
Customer (controller)
- Organisation
- Signed
- Name
- Position
- Date
GovScape (processor)
- Organisation
- GovScape (operating entity to be confirmed)
- Signed
- Name
- Position
- Date
AAnnex A — Particulars of processing
| Subject matter | Provision of the GovScape AI and data governance platform. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in clause 9. |
| Nature and purpose | Hosting, storage, structuring, retrieval and display of governance records; extraction of control information from documents by AI; transcription of recordings; generation of assessments, estimates and reports; transactional email. |
| Types of personal data | Business contact details (name, work email, job title, phone); authentication data; identifiers of people named as accountable for a control, risk, process or AI system; the content of uploaded documents and evidence, which may contain any personal data the customer places there; file names, file paths and file-owner email addresses from a connected environment; audio recordings and their transcripts; audit records identifying who changed what and when. |
| Categories of data subject | The customer’s employees, contractors and officers; people named in the customer’s documents and evidence; participants in recorded briefings; the customer’s own clients where the customer is a consultancy using the product on their behalf. |
| Special category data | Not expected, and not to be submitted without prior written agreement — see clause 4. |
| Frequency | Continuous for the term. |
BAnnex B — Authorised sub-processors
The full register, with the specific data each one receives, is published at /privacy/sub-processors and forms part of this annex. The table below is generated from the same source.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Supabase, Inc. | Application database, user authentication, and file storage. | To be confirmed |
| Vercel Vercel, Inc. | Application hosting, request routing, and scheduled jobs. | London, United Kingdom (region lhr1) |
| Anthropic Anthropic PBC | The AI models behind control extraction, document triage, briefing extraction and the in-product advisor. | To be confirmed |
| OpenAI OpenAI, L.L.C. | Speech-to-text transcription of recorded briefings. | To be confirmed |
| Resend Plus Five Five, Inc. (Resend) | Transactional email. | To be confirmed |
| Sentry Functional Software, Inc. (Sentry) | Error monitoring, performance tracing and session replay. | To be confirmed |
| Upstash Upstash, Inc. | Rate limiting, to stop abuse of public forms and metered endpoints. | To be confirmed |
Systems the customer connects themselves — such as Microsoft 365 — are not sub-processors and remain under the customer’s own agreement with that vendor. They are listed on the register for completeness.
CAnnex C — Technical and organisational measures
Access control
- Each customer’s data is isolated at the database level by row-level security scoped to the organisation, and separately enforced in the application. Neither depends on the other being correct.
- Role-based permissions within an organisation, with privileged actions restricted to administrators.
- Multi-factor authentication available, and enforceable before privileged actions.
- Internal administrative access is limited to named personnel and is logged.
Encryption
- All traffic encrypted in transit over TLS.
- Data encrypted at rest by the database and storage provider.
- OAuth credentials for connected systems are held in a dedicated encrypted secrets store rather than in an application table. A single module in the codebase is permitted to decrypt them, every decryption is written to the audit log with the actor and the reason, and the plaintext is never held beyond the request that needed it.
Integrity of the record
- Every change to a governance record is written to an audit log with the actor, the time and a snapshot of the prior state, in the same database transaction as the change itself — so a change cannot succeed while its audit record fails.
- Audit records cannot be updated or deleted; this is enforced by the database, not by application convention.
- Changes authored by an AI model are recorded as such, distinctly from changes made by a person.
Upload safety
- Uploaded files are validated against their actual file signature rather than the type the browser declares.
- Storage paths are derived on the server from the authenticated organisation, so one customer cannot address another’s files.
- File size and type limits are enforced server-side.
Availability and resilience
- Managed database hosting with provider-managed backups.
- Application code runs in London, United Kingdom (Vercel region lhr1).
- Rate limiting on public and metered endpoints.
- Continuous error monitoring and alerting.
Organisational
- Confidentiality obligations for all personnel with access.
- Access granted on least privilege and removed when a role ends.
- Changes to the application are reviewed and pass an automated test suite, which includes checks that security controls and this sub-processor register remain accurate, before they reach production.