Data Processing Agreement
Agreement version: data-processing-agreement-2026-07-21
Effective date: 21 July 2026
Summary
This Data Processing Agreement (DPA) sets out the controller-processor terms required by Article 28 of the UK GDPR between an invited accountancy practice acting as Controller and Ivo Stoykov trading as DutySharp acting as Processor. It applies to the practice-controlled personal data that DutySharp processes on the practice's behalf through the hosted pilot at app.dutysharp.co.uk.
This DPA is published as a versioned document so that it can be incorporated by exact version into the free Pilot Terms and into the separate paid Subscription Terms. The mechanism that records a Controller's acceptance of a specific version is completed separately; this page is the published reference text for each version.
This is a substantive first draft. It is published to make the controller-processor terms clear and versioned. Obtain professional legal review before relying on this text for paid or materially broader processing.
1. Parties and how the Controller is identified
Processor: Ivo Stoykov trading as DutySharp ("DutySharp", "Processor", "we", "us"). Privacy contact: hello@dutysharp.co.uk. Postal address: Ivo Stoykov / DutySharp, Unit 170054, PO Box 7169, Poole, BH15 9EL. ICO registration reference: ZC201109.
Controller: the accountancy practice that receives and accepts a firm-bound pilot invitation ("Controller", "the practice"). The Controller is identified by the firm-bound invitation that DutySharp issues to a specific practice and by the authorised person who acts for that practice. The recording of the Controller's acceptance of a specific version of this DPA is completed through the applicable terms and the hosted pilot application separately from this published text.
Where the practice is a legal person (for example a limited company, LLP, or similar body), the authorised person who accepts terms on the practice's behalf represents that they are authorised to bind that practice. Where the practice is a sole trader or ordinary partnership, the authorised person represents that they are the sole trader or a partner with authority to bind the practice.
This DPA does not cover personal data for which DutySharp is itself a controller. Account administration, authentication, security, service communications, marketing, and any later billing data remain DutySharp-controller matters and are described in the Privacy Notice.
2. Subject matter, duration, nature, and purpose of processing
The subject matter of processing is the practice's use of the hosted pilot to track blocked client work, record missing-item context, prepare draft communications for practitioner review, and exchange files through case-scoped secure upload links.
The nature of processing is the storage, retrieval, presentation, and deletion of practice-controlled company, case, contact, missing-item, draft, and uploaded-file records, together with associated audit and timeline evidence, within the hosted pilot application.
The purpose of processing is to provide the hosted pilot to the Controller for the practitioner workflows described in the Pilot Terms, under the Controller's reasonable instructions within the pilot's documented scope.
The duration of processing is the period during which the Controller has an active hosted pilot account, beginning when the practice first logs in, and ending when the account is closed, the pilot ends, or the Controller requests deletion or return as provided in this DPA, followed by the end-of-service lifecycle described in section 12.
3. Categories of data subjects
The personal data processed on the Controller's behalf relates to the following categories of data subjects:
- the Controller's clients (natural persons whose company or compliance information is tracked in the hosted pilot);
- client contacts and other contacts recorded by the practitioner against a blocked case or company, including named individuals being chased for missing information;
- individuals who upload files through a case-scoped secure upload link issued by the practitioner, where the practitioner invites a client or third party to upload;
- other natural persons whose personal data the Controller deliberately enters into case notes, contact context, missing-item records, or file metadata.
4. Categories of personal data
The Controller-controlled personal data processed through the hosted pilot typically includes:
- tracked company records, including company name, number, status, and Companies House dates that may identify a Controller client;
- blocked-case records, case labels, case notes, missing-item notes, and case timeline entries that may refer to identifiable individuals;
- client/contact context saved against a case or company, including name, role, email, phone, and free-text contact notes entered by the practitioner;
- generated draft outputs (chase messages, checklists, status summaries) that contain or refer to client-identifiable information;
- case-scoped secure upload requests created by the practitioner, the uploaded files received through those requests, and file metadata (filename, size, checksum, upload/download/delete evidence);
- audit and timeline evidence associated with the above records.
The Controller remains responsible for ensuring that any special category data, criminal-offence data, or other data requiring a specific lawful basis under UK GDPR is not entered into the hosted pilot without the Controller's own lawful basis and appropriate safeguards. DutySharp does not invite or expect practitioners to enter special category data into the pilot.
5. Current product boundaries
The hosted pilot processes the data above only within the current product boundaries described here. The following are not part of the hosted pilot:
- automatic delivery of generated drafts to clients. Drafts are prepared for practitioner review and copy/paste or email-to-self; the practitioner decides whether, when, and how to use any draft;
- optical character recognition (OCR), automated extraction, or automated classification of uploaded files;
- general document management, document version control, or a client portal account system;
- automatic filing, automatic client communication, or autonomous sending of any message.
File uploads are accepted only through case-scoped secure upload links that the practitioner creates from within a blocked case. Files sent outside that flow are not handled by DutySharp. Uploaded files are received, stored, listed, downloaded, and deleted under the practitioner's control.
6. Documented instructions
The Processor shall process the Controller's personal data only on the Controller's documented instructions, as set out in this DPA, the Pilot Terms, the application's documented scope, and any reasonable further instructions given by the Controller through the application or by email to hello@dutysharp.co.uk that are within the pilot's documented scope.
The Processor shall not process the Controller's personal data for any other purpose, including profiling, marketing, training of models on the Controller's data, or sharing with third parties, except where required by UK law. Where a legal obligation requires the Processor to process the Controller's personal data for a purpose other than the Controller's instructions, the Processor shall inform the Controller of that legal requirement before processing, unless the law itself prohibits informing the Controller on important grounds of public interest.
If the Processor believes that an instruction infringes UK GDPR or other UK data protection law, the Processor shall promptly notify the Controller in writing (by email) without acting on the suspected infringing instruction until the Controller confirms, amends, or withdraws it.
7. Confidentiality
The Processor shall ensure that any person acting under its authority who has access to the Controller's personal data (including the Processor as a sole trader and any future staff, contractor, or agent) processes that data only on the Controller's documented instructions and under a written or otherwise enforceable confidentiality obligation. The Processor currently operates as a sole trader; the obligation applies to the Processor personally and to any future person acting under the Processor's authority.
8. Security measures
The Processor shall implement and maintain the technical and organisational measures described in Schedule 5 (Technical and organisational security measures). Those measures are aligned with the implemented service and are reviewed against the current pilot scope. They are not absolute security guarantees and do not include measures that the current service does not implement.
9. Sub-processor authorisation and equivalent terms
The Controller grants the Processor general written authorisation to engage sub-processors for the hosting, database, object-storage, and supporting infrastructure described in Schedule 4 (Sub-processor status), subject to the conditions in this section. The Processor shall:
- carry out sufficient due diligence before engaging a sub-processor;
- enter into a written contract with each sub-processor that imposes the same data-protection obligations as those imposed on the Processor by this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures, before processing the Controller's personal data through that sub-processor;
- remain fully liable to the Controller for the performance of each sub-processor's data-protection obligations;
- inform the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance, giving the Controller the right to object on reasonable data-protection grounds. Objections should be sent to hello@dutysharp.co.uk within that notice period.
The Processor shall not process the Controller's personal data through any sub-processor that does not yet have a written Article 28 contract in place as described above. The current sub-processor status is recorded in Schedule 4. The Processor publishes any material change to that status by updating this DPA's version identifier and effective date.
10. Assistance with data-subject rights
The Processor shall assist the Controller, insofar as possible and by appropriate technical and organisational means, in fulfilling the Controller's obligation to respond to data-subject rights requests relating to the Controller's personal data. The Processor shall forward any data-subject request relating to the Controller's personal data that the Processor receives directly to the Controller without responding to the data subject, except to acknowledge receipt.
11. Assistance with security, breach response, and DPIAs
The Processor shall assist the Controller in ensuring the security of the Controller's personal data, in responding to a personal-data breach affecting the Controller's personal data, and in data-protection impact assessments where required, in each case by appropriate technical and organisational means and to the extent reasonable given the nature of processing and the information available to the Processor.
The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data. The notification shall describe the nature of the breach, the likely consequences, the measures taken or proposed, and the contact for further information. The Processor shall not delay notification in order to investigate fully, and shall provide further information in phases as it becomes available.
12. Deletion or return at end of service
At the Controller's choice, the Processor shall, at the end of the service relating to the Controller's personal data, delete or return all of the Controller's personal data to the Controller, and delete existing copies, unless UK law requires storage of the personal data. This section describes the implemented end-of-service lifecycle. The Processor does not promise instant deletion where the verified behaviour of the deployed providers does not support it.
30-day terminal window: when the Controller's service actually ends, the Processor keeps the Controller's operational data inaccessible for 30 days, tells the Controller's verified contact the exact scheduled deletion date, and sends reminders 14 and 7 days before that date.
Controlled return or earlier deletion: during that window the Controller's verified contact may request a controlled export/return of the firm's data, or earlier deletion. An export request should be made at least seven days before the scheduled deletion date. Where a verified export request is in progress, the scheduled deletion is paused until delivery, and the export is made available through a short-lived, single-use download for seven days. This controlled return path is separate from ordinary product access. Returned data is provided in a structured, commonly used, and machine-readable format; for records that the application cannot export directly, the Processor produces the return from the underlying database in a structured format (for example CSV or JSON) within a reasonable time. The Processor and Controller may agree a reasonable extension where the volume or format of the data requires it.
Operational deletion: after the window ends, or on a verified earlier-deletion request, the Processor deletes the Controller's operational database records and the stored file objects for the Controller's uploads.
Backup and provider copies: once operational deletion completes, any provider-held backup or snapshot copies are put beyond use and are removed through the documented provider retention and expiry cycle rather than instantly. The Processor shall document the deletion in a way the Controller can reasonably verify on request.
Separately justified records: the Processor retains only separately justified billing or tax records and minimum security or audit evidence. These are DutySharp-controller records described in the Privacy Notice, not the Controller's operational data, and they do not include the Controller's client, case, or file content.
Audit evidence and metadata about deleted records (such as file download and delete evidence, and case timeline entries) may be retained after the underlying file bytes or records are deleted only where: (i) the retained evidence does not itself constitute personal data, because it has been anonymised or reduced to non-identifying event metadata; or (ii) UK law requires the Processor to retain that evidence. The Processor shall not rely on a general processor-side retention right to keep the Controller's personal data after the Controller's instruction to delete or return. Where retained audit evidence remains personal data, the Processor treats it as Controller-controlled personal data and deletes or returns it on the Controller's instruction in the same way as the rest of the Controller's personal data.
13. Compliance information
The Processor shall make available to the Controller information reasonably necessary to demonstrate the Processor's compliance with this DPA and Articles 28 and 32 of the UK GDPR. The Processor shall do this through this published DPA, the linked schedules, the Privacy Notice, and reasonable written responses to specific compliance questions sent to hello@dutysharp.co.uk.
14. Proportionate audit and inspection rights
The Controller may, on reasonable notice and during normal business hours, conduct or commission an audit or inspection of the Processor's compliance with this DPA, to the extent the audit is reasonably necessary and proportionate to the pilot's scope and risk. The Controller shall:
- give at least 14 days' notice except in an urgent security matter;
- conduct the audit in a way that minimises disruption to the Processor's operations and other customers;
- ensure that any auditor is suitably qualified, independent, and not a competitor of the Processor;
- rely on existing third-party audit reports and certifications where they reasonably demonstrate the relevant control, before requesting a new on-site audit.
For the current pilot, the Processor's compliance information is supplied through this DPA, the linked schedules, and the Privacy Notice. On-site audit is not expected for unpaid pilot use.
15. Notification if an instruction appears unlawful
The Processor shall promptly inform the Controller in writing (by email) if, in the Processor's opinion, an instruction given by the Controller infringes UK GDPR or other UK data protection law. The Processor may suspend the affected instruction until the Controller confirms, amends, or withdraws it. This obligation does not make the Processor a legal adviser to the Controller and does not require the Processor to monitor the Controller's general compliance with data-protection law.
16. International transfers
The Controller's personal data is processed primarily in the United Kingdom: the application runtime and application logs run in the AWS eu-west-2 (London, UK) region, the PostgreSQL database is in Neon's aws-eu-west-2 (London, UK) region, and uploaded file bytes are stored in Cloudflare R2 under EU jurisdiction. The sub-processor status and processing locations are described in Schedule 4.
Where a sub-processor processes the Controller's personal data outside the United Kingdom, an applicable Article 46 safeguard applies as recorded in Schedule 4: for AWS, the AWS UK GDPR Addendum applies automatically and incorporates the ICO's International Data Transfer Addendum, including UK processor-to-processor clauses for restricted transfers; for Cloudflare and Neon, the providers' incorporated data processing addenda include the EU Standard Contractual Clauses and the UK Addendum.
The Processor does not claim that provider support, corporate access, or sub-processor personnel can never leave a stated region. Where a transfer mechanism or provider contract cannot be verified, the Processor states that fact in Schedule 4 rather than publishing a guessed clause, and the Processor shall not process the Controller's personal data through that sub-processor until the missing safeguard or Article 28 contract is in place.
17. Controller obligations
The Controller warrants that:
- the Controller has a lawful basis under UK GDPR for the processing of personal data that it instructs the Processor to carry out;
- the Controller has provided or will provide the necessary information and notices to its data subjects for the processing carried out through the hosted pilot;
- the Controller will not instruct the Processor to process personal data in a way that infringes UK GDPR or other UK data protection law;
- the Controller is responsible for the accuracy and lawfulness of the personal data it enters into the hosted pilot.
18. Changes to this DPA
When this DPA changes, the Processor will update the version identifier and effective date at the top of the page and publish the new version at https://dutysharp.co.uk/data-processing-agreement. Material changes will be reflected before, or at the same time as, the related change in processing. The version identifier that a Controller has accepted is recorded when this DPA is incorporated by exact version into the applicable terms; that incorporation and acceptance versioning are completed separately from this published text.
19. Professional legal review required
This DPA is a substantive first draft published to make the controller-processor terms clear and versioned. It is not a substitute for professional legal review. Obtain professional legal review before relying on this text, and before any paid or materially broader processing.
Schedule 4 — Sub-processor status
This schedule records the current sub-processor status for the Controller's personal data. Amazon Web Services (AWS), Cloudflare, and Neon are approved sub-processors with present contractual Article 28 terms in place through the Processor's current account agreements. Purelymail, Companies House, and AI providers are listed for transparency but are not sub-processors for the Controller's practice data. Provider, purpose, and processing location are confirmed from official provider documentation and verified deployment records. Where a contractual basis or transfer mechanism cannot be verified, that fact is stated rather than guessed.
Amazon Web Services (AWS)
- Purpose: application runtime and application logging for the hosted pilot. The application runs as an Amazon ECS Express Mode service on AWS Fargate behind an AWS-managed Application Load Balancer; container images are held in Amazon ECR; runtime credentials are held in AWS Secrets Manager and referenced by ARN; application logs are written to Amazon CloudWatch Logs with an explicit 30-day retention. The runtime is ephemeral: the Controller's records persist in the Neon PostgreSQL database and uploaded file bytes in Cloudflare R2 described below, while AWS processes requests in memory and receives redacted, structured log output.
- Processing location: the ECS service, load balancer, ECR images, secrets, and CloudWatch logs are deployed in the AWS
eu-west-2(London, UK) region. The AWS DPA lets the customer select a region and states that AWS will not transfer customer data from the selected region except as necessary to provide the initiated services or to comply with a valid legal requirement. The Processor does not claim that all AWS support, corporate, or sub-processor access is UK-only; for London-region infrastructure, AWS's public sub-processor register identifies Amazon Data Services UK Limited. - Contractual basis: the AWS Service Terms (section 1.14) automatically incorporate the AWS Data Processing Addendum, the Supplementary Addendum, the EU Standard Contractual Clauses, and the AWS UK GDPR Addendum when AWS services process customer data; no separately signed agreement is required for this standard arrangement. The AWS DPA expressly recognises that the AWS customer may itself act as a processor, supporting the Article 28(4) chain in which the practice is controller, DutySharp is the practice's processor, and AWS is a downstream sub-processor acting on instructions that may be based on the Controller's instructions.
- Sub-processor changes: AWS publishes its sub-processor register and commits to update it at least 30 days before engaging a new sub-processor. The Processor monitors that register through AWS's update notices and operates its own 14-day advance notice to the Controller under section 9.
- Termination behaviour: under the AWS DPA, customer data is returned or deleted through the applicable service controls up to termination of the AWS agreement and for 90 days afterwards. The Processor's end-of-service deletion under section 12 uses and verifies those service controls, including inspection of resources that AWS reports as retained after a deletion operation.
- Source: AWS Service Terms, https://aws.amazon.com/service-terms/; AWS Data Processing Addendum, https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf; AWS UK GDPR Addendum, https://d1.awsstatic.com/legal/aws-dpa/aws-uk-gdpr-dpa.pdf; AWS sub-processors register, https://aws.amazon.com/compliance/sub-processors/. Deployment, region, logging retention, and canonical-host routing verified through the application repository's AWS synthetic verification, canonical cutover, and production rehearsal records (synthetic data only; no real practice-controlled data was used in those verifications).
Cloudflare
- Purpose: object storage for case-scoped secure uploads (Cloudflare R2, bucket
obliga-app-uploads). Public access is disabled; reads and writes are server-mediated. The public website is also Cloudflare-hosted, but public-site request-access data is DutySharp-controller data covered by the Privacy Notice, not the Controller's practice data. - Processing location: the R2 bucket
obliga-app-uploadsis configured for EU jurisdiction (Standard storage, public access disabled). EU jurisdiction is not UK-only residency. - Contractual basis: the Processor's Cloudflare account is governed by Cloudflare's Self-Serve Subscription Agreement, which states that where Customer Content includes personal data protected by EU and UK Data Protection Laws, "Cloudflare will handle such Personal Data in compliance with Cloudflare's Data Processing Addendum ('Data Processing Addendum'), which is hereby incorporated by reference into this Agreement." The Cloudflare Customer DPA is therefore part of the Processor's current contract with Cloudflare, not a future execution. The DPA incorporates the EU Standard Contractual Clauses and the UK Addendum issued by the ICO for restricted transfers outside the United Kingdom.
- Source: Cloudflare Self-Serve Subscription Agreement, https://www.cloudflare.com/terms/; Cloudflare Customer DPA, https://www.cloudflare.com/cloudflare-customer-dpa/; Cloudflare Sub-Processors list, https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/; bucket jurisdiction recorded in app deployment memory as EU with public access disabled and production use verified.
Neon (a Databricks company)
- Purpose: hosted PostgreSQL database for the hosted pilot application.
- Processing location: the hosted pilot's Neon project reports platform
awsand regionaws-eu-west-2(London, UK), verified through the Neon project metadata. PostgreSQL connections usesslmode=require. - Contractual basis: the Processor's Neon account is governed by the Neon Platform Services Product Specific Schedule, which is subject to the Databricks Master Cloud Services Agreement (MCSA). The MCSA defines the DPA as "the then-current Data Processing Addendum located at databricks.com/legal/dpa" and states that "The terms of the DPA are incorporated by reference and shall apply to the processing of Personal Data as described in the DPA." The Databricks/Neon DPA (including EU SCCs and Article 28 terms) is therefore part of the Processor's current contract with Neon, not a future execution. The Neon Platform Terms apply the DPA's Subprocessor List and Security Addendum to the Neon Platform Services.
- Transfers: the primary database processing is in London, UK, so there is no restricted transfer from a UK Controller to Neon's primary processing. Neon's own sub-processors (AWS, Azure, Grafana, Salesforce) are listed in the public Neon sub-processor page at https://neon.com/subprocessors and are located in the United States; the Databricks DPA imposes equivalent Article 28 obligations on those onward sub-processors.
- Source: Neon project metadata (verified via the Neon API); Neon Sub-Processors list, https://neon.com/subprocessors; Neon Platform Terms, https://neon.com/platform-terms; Databricks MCSA, https://www.databricks.com/legal/mcsa; Databricks DPA, https://www.databricks.com/legal/dpa.
Purelymail (Add Rabbit LLC) — controller-side, not a sub-processor
- Purpose: outbound email delivery for DutySharp-controlled login codes and service messages. Purelymail processes account/authentication data for which DutySharp is a separate controller. Purelymail does not process the Controller's practice-controlled client, case, or file data.
- Processing location: Purelymail's security documentation confirms that it hosts its servers through Amazon Web Services. Purelymail does not publish a binding processing region.
- Role: listed separately here for transparency. Purelymail is a provider for DutySharp-controller data described in the Privacy Notice, not a sub-processor for the Controller's practice data.
- Source: Purelymail Privacy Policy, https://purelymail.com/privacy; Purelymail Security documentation, https://purelymail.com/docs/security.
Companies House API — not a sub-processor for practice data
- Purpose: source of public company information (name, number, status, accounts and confirmation statement dates) retrieved via the Companies House API for tracked companies.
- Role: Companies House supplies public company data. The Controller's personal data (client/contact context, case notes, missing items, files) is not transferred to Companies House. Companies House is therefore not listed as a sub-processor for the Controller's practice-controlled personal data.
AI/draft providers
- Role: no OpenAI, Ollama, or other AI provider is in the deployed draft-generation path for the hosted pilot. Do not list any AI provider as a sub-processor for the Controller's personal data.
Schedule 5 — Technical and organisational security measures
The Processor implements the following technical and organisational measures for the Controller's personal data. These measures are aligned with the implemented service. They are not absolute security guarantees and do not include measures that the current service does not implement.
- Transport security: TLS for all HTTP and PostgreSQL connections. PostgreSQL connections use
sslmode=require. - Object storage access: the R2 bucket
obliga-app-uploadsis private, with public access disabled. Reads and writes are server-mediated; there is no public storage URL. - Credential storage: runtime credentials are held in AWS Secrets Manager and referenced by ARN, not stored in source code, container images, task definitions, or exported files.
- Firm-scoped access controls: a firm-bound invitation identifies the Controller; firm-user login is email-verified; access to the Controller's practice data is firm-scoped.
- One-time and digested tokens: firm access links and login codes are one-time; only token digests are stored.
- Session security: secure session-cookie configuration.
- Server-side validation and file limits: file uploads are validated server-side with size and type limits.
- Checksum and audit evidence: uploaded files are checksummed; download and delete events are recorded as audit evidence.
- Practitioner-controlled file deletion: file bytes are removed when a practitioner deletes the file from the case workflow.
- Redacted structured logging: structured application logs redact sensitive parameters (verified to hide SQL parameters and error detail), and the application log group has an explicit 30-day retention rather than an indefinite default.
The following are not currently implemented or claimed and should not be represented to the Controller's clients or data subjects as in place:
- universal encryption at rest for the Controller's personal data (the database and object storage rely on provider infrastructure; the Processor does not claim a universal at-rest encryption layer across all stores);
- automated deletion schedules beyond the practitioner-initiated deletion and the end-of-service lifecycle described in this DPA;
- guaranteed availability, service-level objectives, or uptime commitments;
- provider-managed backups or snapshots as a disaster-recovery mechanism;
- multi-factor authentication as a mandatory login control;
- penetration testing or formal incident-response timing commitments;
- information-security certifications (for example ISO 27001, SOC 2) for DutySharp as a sole trader.
Related legal pages
- Hosted Pilot Terms — the free pilot terms; this DPA is designed to be incorporated into them by exact version, with that incorporation completed separately.
- Subscription Terms — version
subscription-terms-2026-07-29; the separate paid First Tier contract, which incorporates this DPA by exact version. These are not the free Pilot Terms. - Privacy Notice — describes the personal data for which DutySharp is a controller, separate from this DPA.