Parties
This Data Processing Agreement ("Agreement") is entered into between:
Controller: The firm identified in the associated service agreement or onboarding documentation ("Client Firm" or "you").
Processor: Stripy Fish Networks Limited, a company registered in England and Wales, registered address 26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT ("we", "us", or the "Processor"), ICO registration number ZC148489.
1Background and scope
1.1 The Processor provides SYSC 10A compliance assessment, gap analysis, advisory, and compliance documentation services to UK-regulated firms via its Varde product ("Services").
1.2 In providing the Services, the Processor will process certain personal data on behalf of the Controller. This Agreement sets out the terms on which that processing takes place, as required by Article 28 UK GDPR.
1.3 Scope of services covered by this Agreement:
- SYSC 10A call recording compliance assessment (AI-assisted questionnaire and report)
- Gap analysis and compliance advisory services
- Policy documentation services (scoping, drafting, and deployment assistance)
This Agreement does not cover call recording platform services. A separate data processing agreement is required for any service involving the capture, storage, or processing of call recordings.
1.4 The Controller may grant additional individuals — including, without limitation, its own employees, advisers, or a reseller partner's staff — access to the platform as authorised users of the Controller's own organisation. Any such individual acts as the Controller's own authorised representative for the purposes of this Agreement (see clause 3, "Categories of data subjects"); granting that access does not itself create a separate controller or processor relationship between the Processor and that individual or their employer. Where the Controller's organisation is administered by a reseller under a separate reseller agreement between that reseller and the Processor, that agreement governs the reseller's own role — it does not affect this Agreement or the Processor's relationship with the Controller.
1.5 This Agreement does not itself impose a liability cap. The liability cap and exclusions in clause 8 of the commercial Terms and Conditions between the Processor and the Controller apply equally to any claim arising out of or in connection with this Agreement — the two documents are not to be treated as separate baskets for liability purposes.
1.6 Account/login data is separate from the processing covered by this Agreement. A Client Firm user's email address, where it functions as an account or login identifier (registration, authentication, and general account-administration communications), is processed by the Processor as controller in its own right, under the Privacy Notice and clause 1.5 of the Terms and Conditions — not under this Agreement. The "Email address" entry in clause 3 refers only to the email address insofar as it appears within, or is used to deliver, compliance content covered by this Agreement (e.g. as a report recipient, or where captured as part of a data subject's activity within the Services); it does not bring the Processor's own account-administration use of that same address within this Agreement's Article 28 scope. This mirrors the equivalent split in the reseller DPA (clause 1.2A) between account/access data and compliance content.
2Definitions
- "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.
- "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in UK GDPR.
- "Sub-processor" means any third party engaged by the Processor to carry out processing activities on behalf of the Controller under this Agreement.
3Details of processing
| Subject matter | Compliance assessment, advisory, and documentation services for UK-regulated IFA firms |
|---|---|
| Duration | For the term of the service engagement, plus the retention period specified in clause 8 |
| Nature and purpose | Processing personal data to deliver SYSC 10A compliance assessment, gap analysis, advisory recommendations, and policy documentation |
| Type of personal data | Email address (see clause 1.6 for the account/login vs compliance-content split); assessment conversation transcript; compliance report; download history; contact enquiry details; billing details where a paid product is purchased (full name, billing address, phone number, VAT number, transaction and invoice records — collected via Stripe Checkout; full card data never reaches the Processor) |
| Categories of data subjects | Compliance officers and authorised representatives of the Controller |
4Processor obligations
The Processor agrees to:
4.1 Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by UK law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless prohibited from doing so.
4.2 Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate:
- Encryption of personal data at rest (AES-256-GCM)
- Encrypted HTTPS transport for all data in transit
- Access controls limiting data access to authorised personnel only
- Append-only audit logging of all data access events
- File-level permissions (0o600) on all stored personal data
- Systemd process containment limiting filesystem access to defined directories
4.4 Respect the conditions for engaging sub-processors set out in clause 6.
4.5 Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligations to respond to requests for exercising data subjects' rights under UK GDPR. The Processor's administrative tooling provides the following capabilities on request: data export (Article 15 and 20), erasure (Article 17), and rectification (Article 16). Assistance beyond what this tooling provides directly (e.g. bespoke manual work at the Controller's request) may be subject to a reasonable charge, notified to the Controller in advance.
4.6 Assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to the Processor. As with clause 4.5, assistance beyond routine support may be subject to a reasonable charge, notified to the Controller in advance.
4.7 At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless UK law requires storage of the personal data.
4.8 Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this clause, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes UK GDPR or other applicable UK data protection provisions.
5Controller obligations
The Controller warrants that:
5.1 It has a lawful basis for processing the personal data it provides to the Processor under this Agreement.
5.2 It has notified data subjects as required under Articles 13 and 14 UK GDPR regarding the processing described in this Agreement.
5.3 It will not instruct the Processor to process personal data in a manner that would cause the Processor to breach UK GDPR or any other applicable law.
6Sub-processors
6.1 The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes on reasonable data-protection grounds. If the Controller objects and the parties are unable to resolve the objection, the Controller's remedy is to terminate the Services affected by that sub-processor's engagement.
6.2 Authorised sub-processors at the date of this Agreement:
| Sub-processor | Location | Purpose | Data processed |
|---|---|---|---|
| Anthropic Ireland Limited | Dublin, Ireland (contracting entity); underlying infrastructure extends to the United States — see clause 7 | AI language model inference (Claude API) | Assessment conversation content (see clause 7.2A on anonymisation); retained by Anthropic for up to 30 days for security and operational purposes only; not used for AI model training |
| Fasthosts Internet Limited | United Kingdom | Outbound SMTP relay for invitation and notification emails | Recipient email address; message content (which does not include compliance conversation content) |
| Stripe Payments Europe, Limited | Dublin, Ireland (contracting entity); underlying infrastructure extends to the United States — see clause 7 | Payment processing, billing, and VAT invoicing for paid products | Billing name, email address, billing address, phone number (optional), VAT number (optional), transaction and invoice records. Full card data is held by Stripe alone and never reaches the Processor |
| Amazon Web Services (AWS) | United Kingdom (London, eu-west-2 region) — confirmed live 2026-08-07; see the data-residency checklist in docs/deploy/ |
Server hosting and storage | All personal data listed in clause 3 |
A standalone, more easily bookmarked version of this list is also maintained at /sub-processors — kept in step with the table above, updated whenever it changes.
6.3 Where the Processor engages a sub-processor, it shall impose the same data protection obligations as set out in this Agreement on that sub-processor by way of a contract.
6.4 The Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
6.5 The FCA Register, Companies House, and HMRC VAT Registration Check are queried during registration and profile updates to validate the Controller's firm identity (FCA firm reference number, company number, VAT number). These calls transmit only the firm-level identifier being checked, and the responses received are firm-level information (name, status, registered address) rather than any of the personal data categories listed in clause 3. These services are accordingly not sub-processors under this Agreement. As with the firm-level context sent to Anthropic (clause 7.2A), this may be personal data where the Controller is a sole trader — the Processor's assessment is that this does not change the analysis for a corporate Client Firm, but the Controller should raise this with the Processor if it operates as a sole trader.
7International transfers
7.1 Anthropic Ireland Limited is the contracting entity for the Claude API. Anthropic's infrastructure extends outside the European Economic Area (including to the United States), so this transfer is not covered by UK adequacy alone.
7.2 Anthropic's processing is governed by Anthropic's Data Processing Addendum, incorporated into their Commercial Terms of Service. That instrument incorporates the EU Standard Contractual Clauses (Module Two/Three, governed by the law of the Republic of Ireland) together with the UK International Data Transfer Addendum (Addendum B.1.0, issued by the ICO under s.119A of the Data Protection Act 2018), which extends the SCCs to satisfy the UK's separate transfer regime. The Processor has reviewed and accepts these terms. (Confirmed directly against Anthropic's published DPA — 2026-07-18.)
7.2A Before conversation content reaches Anthropic, named-individual fields (compliance officer / approver names) are substituted with role descriptors for Layer 3 policy generation; the Layer 1 assessment and Layer 2 gap analysis question sets are designed not to collect named-individual data at all. Firm-level data (legal name, FCA FRN, registered address) is preserved and sent, as this is not personal data under UK GDPR Article 4(1) for a corporate Client Firm — though it may be personal data where the Client Firm is a sole trader, and free-text answers could incidentally include a name the schema doesn't request. This does not remove Anthropic's status as a sub-processor of personal data for this Agreement, but is relevant context for the transfer risk assessment.
7.3 Stripe Payments Europe, Limited is the contracting entity for payment processing. Its infrastructure extends outside the European Economic Area (including to the United States), so this transfer is not covered by UK adequacy alone. Stripe's processing is governed by its Data Processing Addendum, incorporated into its commercial terms of service, which — like Anthropic's — incorporates the EU Standard Contractual Clauses (Module Two/Three) together with the UK International Data Transfer Addendum (Addendum B.1.0). The Processor has reviewed and accepts these terms.
7.4 The Processor's hosting infrastructure (clause 6.2) is located within the United Kingdom. Hosting and storage of personal data under this Agreement does not itself involve any international transfer.
7.5 No other international transfers of personal data are made under this Agreement.
7.6 The Data (Use and Access) Act 2025 reformed the UK GDPR Chapter V transfer framework with effect from 5 February 2026: Article 44 ("general principle for transfers") was omitted, and the governing standard for appropriate-safeguards transfers is now the "data protection test" (Article 46(1A) UK GDPR, inserted by the 2025 Act) rather than the previous adequacy-based framing referred to in clauses 7.1 and 7.3. Section 119A of the Data Protection Act 2018 — the Commissioner's power to issue transfer safeguard documents, including the UK International Data Transfer Addendum referred to in clause 7.2 — remains in force, amended to reference the new test, not repealed. The safeguard mechanisms described in clauses 7.1–7.3 (EU Standard Contractual Clauses plus the UK International Data Transfer Addendum) continue to be available and relied upon under the reformed Article 46; this clause records that the legal test they are assessed against changed on 5 February 2026, without asserting any change to the mechanisms themselves.
8Retention and deletion
8.1 Assessment data (transcript, report, download history) is retained for up to 90 days from the date of completion, plus a further 90-day grace period, after which it is automatically deleted by the Processor's retention management system — unless the Controller's organisation has registered a portal account and is a paying customer, in which case each record is instead retained for up to 6 years from the date of completion, plus a further 364-day grace period. This is a per-record age cap that applies even while the engagement remains active, not extended indefinitely for the duration of the relationship, and is re-evaluated on each scheduled retention run rather than fixed once at the record's creation. This retention determination is made at the level of the Controller's organisation, not any individual user within it. The Processor may retain the Controller's records for longer where the FCA directs it to do so.
8.2 In-progress session data is retained for up to 30 days, after which it is automatically deleted.
8.3 On termination of the service engagement, the Controller may request deletion of all personal data before the retention period expires, subject to any retention obligation imposed on the Controller by law (including the Controller's own retention position under clause 8.1) — the Processor will flag any apparent conflict between the request and clause 8.1 before acting on it, but responsibility for the Controller's own regulatory retention compliance remains with the Controller, not the Processor. Subject to that, the Processor will action such requests within 5 business days and provide written confirmation of deletion.
8.4 The Processor's audit log — a platform-wide security and forensic record — retains event type, timestamp, a hashed token identifier, and, in plaintext, IP address and user agent, for up to 6 years from the date of the event, aligned with the six-year Corporation Tax record-keeping requirement under Schedule 18, paragraph 21 of the Finance Act 1998 (this is the Processor's own company record, not a client obligation). IP address and user agent are personal data. This 6-year ceiling is the Processor's storage-limitation commitment under Article 5(1)(e) UK GDPR; the Processor retains the log for that period under its own legitimate interest in platform security (Article 6(1)(f) UK GDPR). Enforcement of this ceiling is automatic: entries older than 6 years are deleted on a scheduled and startup purge, and the deletion itself is recorded as an audit event.
8.5 Data deleted from the Processor's live systems — whether by an erasure request under clause 4.5, automatic retention expiry under clause 8.1 or 8.2, or a deletion request under clause 8.3 — may persist for up to a further 12 months in encrypted disaster-recovery backup archives, which are rotated and automatically purged on a fixed schedule. During this period the data is encrypted and not accessible in the ordinary course of processing; it would only be accessed in the event of a genuine disaster-recovery restore, in which case any pending deletion obligation is reapplied before the restored system returns to service.
9Security breach notification
9.1 In the event of a personal data breach affecting data processed under this Agreement, the Processor will notify the Controller without undue delay and, where feasible, not later than 48 hours after becoming aware of the breach. This window is deliberately shorter than the Controller's own 72-hour notification deadline to the ICO under Article 33 UK GDPR, so the Controller has runway to investigate and report within its own regulatory clock — it is not intended to be aligned to 72 hours.
9.2 The notification shall include, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.
9.3 The Controller is responsible for notifying the ICO and affected data subjects as required by Articles 33 and 34 UK GDPR.
10Audit rights
10.1 The Controller may request written evidence of compliance with this Agreement no more than once per calendar year without cause. The Processor shall respond within 20 business days.
10.2 The Controller may conduct or commission an on-site audit on reasonable notice (minimum 30 days) and at the Controller's cost, no more than once per calendar year unless a breach has occurred.
11Term and termination
11.1 This Agreement takes effect on the date the associated service engagement commences and remains in force for the duration of that engagement.
11.2 Either party may terminate this Agreement on written notice if the other party commits a material breach of this Agreement and fails to remedy it within 30 days of written notice.
11.3 Obligations under clauses 4, 8, and 9 survive termination of this Agreement.
12Governing law
This Agreement is governed by the laws of England and Wales. Any dispute arising under it shall be subject to the exclusive jurisdiction of the courts of England and Wales.
13Execution
This Agreement is effective when accepted by the Controller as part of the service onboarding process, or by signature of both parties.
13.1 For onboarding via the Processor's self-service platform, acceptance is given by an authorised individual at the Controller's organisation actively ticking a consent checkbox confirming they are authorised to accept this Agreement on the Controller's behalf — presented at self-service registration, or at completion of an administrator- or reseller-initiated account setup, whichever applies. No wet-signature or e-signature document is required. The version of this Agreement in force at that moment, the individual who gave consent, and the date and time of acceptance, are recorded and available to the Controller on request.
13.2 Where the Controller's account was not created via the self-service platform (for example, a bespoke onboarding arrangement executed outside it), this Agreement may instead be executed by signature of both parties on a separately issued signed copy — contact privacy@stripyfish.net to request one.
14Assignment
14.1 The Processor may assign, novate, or transfer its rights and obligations under this Agreement, in whole or in part, including in connection with a sale, merger, reorganisation, or transfer of all or substantially all of its business, provided the assignee agrees to be bound by this Agreement.
14.2 The Controller may not assign or transfer its rights or obligations under this Agreement without the Processor's prior written consent.
15General
15.1 Entire agreement. This Agreement, together with the associated Terms and Conditions and Privacy Notice, constitutes the entire agreement between the parties relating to its subject matter, and supersedes all prior discussions, negotiations, and agreements between them relating to that subject matter. Nothing in this clause excludes liability for fraud or fraudulent misrepresentation.
15.2 Severability. If any provision of this Agreement is found unenforceable or invalid, that provision is limited or eliminated to the minimum extent necessary, and the remaining provisions continue in full force.
15.3 Waiver. No failure or delay by either party in exercising a right under this Agreement operates as a waiver of that right, and no single or partial exercise of a right prevents further exercise of that or any other right.
15.4 Notices. A notice under this Agreement must be given in writing and is validly given if sent to the email address the Controller registered with the Processor, or to legal@stripyfish.net for notices to the Processor (or such other address as either party notifies to the other), and is deemed received 24 hours after sending unless the sender receives a delivery-failure notification.
15.5 Third-party rights. A person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this Agreement.
16Variation
16.1 The Processor may update this Agreement from time to time. It will give at least 30 days' notice of any material change to active Client Firms by email; a change required to reflect a change in applicable data protection law may take effect immediately on notice instead. A change takes effect for the Controller's account from its stated effective date and does not apply retrospectively to processing already carried out under an earlier version. The version of this Agreement in force at any given time is recorded against the Controller's account per clause 13.