Data Processing Agreement

Agreement version: data-processing-agreement-2026-07-21
Effective date: 21 July 2026

Summary

This Data Processing Agreement (DPA) sets out the controller-processor terms required by Article 28 of the UK GDPR between an invited accountancy practice acting as Controller and Ivo Stoykov trading as DutySharp acting as Processor. It applies to the practice-controlled personal data that DutySharp processes on the practice's behalf through the hosted pilot at app.dutysharp.co.uk.

This DPA is published as a versioned document so that it can be incorporated by exact version into the free Pilot Terms and into the separate paid Subscription Terms. The mechanism that records a Controller's acceptance of a specific version is completed separately; this page is the published reference text for each version.

This is a substantive first draft. It is published to make the controller-processor terms clear and versioned. Obtain professional legal review before relying on this text for paid or materially broader processing.

1. Parties and how the Controller is identified

Processor: Ivo Stoykov trading as DutySharp ("DutySharp", "Processor", "we", "us"). Privacy contact: hello@dutysharp.co.uk. Postal address: Ivo Stoykov / DutySharp, Unit 170054, PO Box 7169, Poole, BH15 9EL. ICO registration reference: ZC201109.

Controller: the accountancy practice that receives and accepts a firm-bound pilot invitation ("Controller", "the practice"). The Controller is identified by the firm-bound invitation that DutySharp issues to a specific practice and by the authorised person who acts for that practice. The recording of the Controller's acceptance of a specific version of this DPA is completed through the applicable terms and the hosted pilot application separately from this published text.

Where the practice is a legal person (for example a limited company, LLP, or similar body), the authorised person who accepts terms on the practice's behalf represents that they are authorised to bind that practice. Where the practice is a sole trader or ordinary partnership, the authorised person represents that they are the sole trader or a partner with authority to bind the practice.

This DPA does not cover personal data for which DutySharp is itself a controller. Account administration, authentication, security, service communications, marketing, and any later billing data remain DutySharp-controller matters and are described in the Privacy Notice.

2. Subject matter, duration, nature, and purpose of processing

The subject matter of processing is the practice's use of the hosted pilot to track blocked client work, record missing-item context, prepare draft communications for practitioner review, and exchange files through case-scoped secure upload links.

The nature of processing is the storage, retrieval, presentation, and deletion of practice-controlled company, case, contact, missing-item, draft, and uploaded-file records, together with associated audit and timeline evidence, within the hosted pilot application.

The purpose of processing is to provide the hosted pilot to the Controller for the practitioner workflows described in the Pilot Terms, under the Controller's reasonable instructions within the pilot's documented scope.

The duration of processing is the period during which the Controller has an active hosted pilot account, beginning when the practice first logs in, and ending when the account is closed, the pilot ends, or the Controller requests deletion or return as provided in this DPA, followed by the end-of-service lifecycle described in section 12.

3. Categories of data subjects

The personal data processed on the Controller's behalf relates to the following categories of data subjects:

4. Categories of personal data

The Controller-controlled personal data processed through the hosted pilot typically includes:

The Controller remains responsible for ensuring that any special category data, criminal-offence data, or other data requiring a specific lawful basis under UK GDPR is not entered into the hosted pilot without the Controller's own lawful basis and appropriate safeguards. DutySharp does not invite or expect practitioners to enter special category data into the pilot.

5. Current product boundaries

The hosted pilot processes the data above only within the current product boundaries described here. The following are not part of the hosted pilot:

File uploads are accepted only through case-scoped secure upload links that the practitioner creates from within a blocked case. Files sent outside that flow are not handled by DutySharp. Uploaded files are received, stored, listed, downloaded, and deleted under the practitioner's control.

6. Documented instructions

The Processor shall process the Controller's personal data only on the Controller's documented instructions, as set out in this DPA, the Pilot Terms, the application's documented scope, and any reasonable further instructions given by the Controller through the application or by email to hello@dutysharp.co.uk that are within the pilot's documented scope.

The Processor shall not process the Controller's personal data for any other purpose, including profiling, marketing, training of models on the Controller's data, or sharing with third parties, except where required by UK law. Where a legal obligation requires the Processor to process the Controller's personal data for a purpose other than the Controller's instructions, the Processor shall inform the Controller of that legal requirement before processing, unless the law itself prohibits informing the Controller on important grounds of public interest.

If the Processor believes that an instruction infringes UK GDPR or other UK data protection law, the Processor shall promptly notify the Controller in writing (by email) without acting on the suspected infringing instruction until the Controller confirms, amends, or withdraws it.

7. Confidentiality

The Processor shall ensure that any person acting under its authority who has access to the Controller's personal data (including the Processor as a sole trader and any future staff, contractor, or agent) processes that data only on the Controller's documented instructions and under a written or otherwise enforceable confidentiality obligation. The Processor currently operates as a sole trader; the obligation applies to the Processor personally and to any future person acting under the Processor's authority.

8. Security measures

The Processor shall implement and maintain the technical and organisational measures described in Schedule 5 (Technical and organisational security measures). Those measures are aligned with the implemented service and are reviewed against the current pilot scope. They are not absolute security guarantees and do not include measures that the current service does not implement.

9. Sub-processor authorisation and equivalent terms

The Controller grants the Processor general written authorisation to engage sub-processors for the hosting, database, object-storage, and supporting infrastructure described in Schedule 4 (Sub-processor status), subject to the conditions in this section. The Processor shall:

The Processor shall not process the Controller's personal data through any sub-processor that does not yet have a written Article 28 contract in place as described above. The current sub-processor status is recorded in Schedule 4. The Processor publishes any material change to that status by updating this DPA's version identifier and effective date.

10. Assistance with data-subject rights

The Processor shall assist the Controller, insofar as possible and by appropriate technical and organisational means, in fulfilling the Controller's obligation to respond to data-subject rights requests relating to the Controller's personal data. The Processor shall forward any data-subject request relating to the Controller's personal data that the Processor receives directly to the Controller without responding to the data subject, except to acknowledge receipt.

11. Assistance with security, breach response, and DPIAs

The Processor shall assist the Controller in ensuring the security of the Controller's personal data, in responding to a personal-data breach affecting the Controller's personal data, and in data-protection impact assessments where required, in each case by appropriate technical and organisational means and to the extent reasonable given the nature of processing and the information available to the Processor.

The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data. The notification shall describe the nature of the breach, the likely consequences, the measures taken or proposed, and the contact for further information. The Processor shall not delay notification in order to investigate fully, and shall provide further information in phases as it becomes available.

12. Deletion or return at end of service

At the Controller's choice, the Processor shall, at the end of the service relating to the Controller's personal data, delete or return all of the Controller's personal data to the Controller, and delete existing copies, unless UK law requires storage of the personal data. This section describes the implemented end-of-service lifecycle. The Processor does not promise instant deletion where the verified behaviour of the deployed providers does not support it.

30-day terminal window: when the Controller's service actually ends, the Processor keeps the Controller's operational data inaccessible for 30 days, tells the Controller's verified contact the exact scheduled deletion date, and sends reminders 14 and 7 days before that date.

Controlled return or earlier deletion: during that window the Controller's verified contact may request a controlled export/return of the firm's data, or earlier deletion. An export request should be made at least seven days before the scheduled deletion date. Where a verified export request is in progress, the scheduled deletion is paused until delivery, and the export is made available through a short-lived, single-use download for seven days. This controlled return path is separate from ordinary product access. Returned data is provided in a structured, commonly used, and machine-readable format; for records that the application cannot export directly, the Processor produces the return from the underlying database in a structured format (for example CSV or JSON) within a reasonable time. The Processor and Controller may agree a reasonable extension where the volume or format of the data requires it.

Operational deletion: after the window ends, or on a verified earlier-deletion request, the Processor deletes the Controller's operational database records and the stored file objects for the Controller's uploads.

Backup and provider copies: once operational deletion completes, any provider-held backup or snapshot copies are put beyond use and are removed through the documented provider retention and expiry cycle rather than instantly. The Processor shall document the deletion in a way the Controller can reasonably verify on request.

Separately justified records: the Processor retains only separately justified billing or tax records and minimum security or audit evidence. These are DutySharp-controller records described in the Privacy Notice, not the Controller's operational data, and they do not include the Controller's client, case, or file content.

Audit evidence and metadata about deleted records (such as file download and delete evidence, and case timeline entries) may be retained after the underlying file bytes or records are deleted only where: (i) the retained evidence does not itself constitute personal data, because it has been anonymised or reduced to non-identifying event metadata; or (ii) UK law requires the Processor to retain that evidence. The Processor shall not rely on a general processor-side retention right to keep the Controller's personal data after the Controller's instruction to delete or return. Where retained audit evidence remains personal data, the Processor treats it as Controller-controlled personal data and deletes or returns it on the Controller's instruction in the same way as the rest of the Controller's personal data.

13. Compliance information

The Processor shall make available to the Controller information reasonably necessary to demonstrate the Processor's compliance with this DPA and Articles 28 and 32 of the UK GDPR. The Processor shall do this through this published DPA, the linked schedules, the Privacy Notice, and reasonable written responses to specific compliance questions sent to hello@dutysharp.co.uk.

14. Proportionate audit and inspection rights

The Controller may, on reasonable notice and during normal business hours, conduct or commission an audit or inspection of the Processor's compliance with this DPA, to the extent the audit is reasonably necessary and proportionate to the pilot's scope and risk. The Controller shall:

For the current pilot, the Processor's compliance information is supplied through this DPA, the linked schedules, and the Privacy Notice. On-site audit is not expected for unpaid pilot use.

15. Notification if an instruction appears unlawful

The Processor shall promptly inform the Controller in writing (by email) if, in the Processor's opinion, an instruction given by the Controller infringes UK GDPR or other UK data protection law. The Processor may suspend the affected instruction until the Controller confirms, amends, or withdraws it. This obligation does not make the Processor a legal adviser to the Controller and does not require the Processor to monitor the Controller's general compliance with data-protection law.

16. International transfers

The Controller's personal data is processed primarily in the United Kingdom: the application runtime and application logs run in the AWS eu-west-2 (London, UK) region, the PostgreSQL database is in Neon's aws-eu-west-2 (London, UK) region, and uploaded file bytes are stored in Cloudflare R2 under EU jurisdiction. The sub-processor status and processing locations are described in Schedule 4.

Where a sub-processor processes the Controller's personal data outside the United Kingdom, an applicable Article 46 safeguard applies as recorded in Schedule 4: for AWS, the AWS UK GDPR Addendum applies automatically and incorporates the ICO's International Data Transfer Addendum, including UK processor-to-processor clauses for restricted transfers; for Cloudflare and Neon, the providers' incorporated data processing addenda include the EU Standard Contractual Clauses and the UK Addendum.

The Processor does not claim that provider support, corporate access, or sub-processor personnel can never leave a stated region. Where a transfer mechanism or provider contract cannot be verified, the Processor states that fact in Schedule 4 rather than publishing a guessed clause, and the Processor shall not process the Controller's personal data through that sub-processor until the missing safeguard or Article 28 contract is in place.

17. Controller obligations

The Controller warrants that:

18. Changes to this DPA

When this DPA changes, the Processor will update the version identifier and effective date at the top of the page and publish the new version at https://dutysharp.co.uk/data-processing-agreement. Material changes will be reflected before, or at the same time as, the related change in processing. The version identifier that a Controller has accepted is recorded when this DPA is incorporated by exact version into the applicable terms; that incorporation and acceptance versioning are completed separately from this published text.

19. Professional legal review required

This DPA is a substantive first draft published to make the controller-processor terms clear and versioned. It is not a substitute for professional legal review. Obtain professional legal review before relying on this text, and before any paid or materially broader processing.

Schedule 4 — Sub-processor status

This schedule records the current sub-processor status for the Controller's personal data. Amazon Web Services (AWS), Cloudflare, and Neon are approved sub-processors with present contractual Article 28 terms in place through the Processor's current account agreements. Purelymail, Companies House, and AI providers are listed for transparency but are not sub-processors for the Controller's practice data. Provider, purpose, and processing location are confirmed from official provider documentation and verified deployment records. Where a contractual basis or transfer mechanism cannot be verified, that fact is stated rather than guessed.

Amazon Web Services (AWS)

Cloudflare

Neon (a Databricks company)

Purelymail (Add Rabbit LLC) — controller-side, not a sub-processor

Companies House API — not a sub-processor for practice data

AI/draft providers

Schedule 5 — Technical and organisational security measures

The Processor implements the following technical and organisational measures for the Controller's personal data. These measures are aligned with the implemented service. They are not absolute security guarantees and do not include measures that the current service does not implement.

The following are not currently implemented or claimed and should not be represented to the Controller's clients or data subjects as in place: