Data Processing Agreement
The terms on which REGREP processes personal data on your instructions when you use the platform to prepare, validate and deliver regulatory filings.
This page is the current text of the agreement. It forms part of our terms of service and applies automatically from the moment you open an account — there is nothing for you to sign for it to take effect.
If your own governance requires a countersigned copy, or the agreement on your own paper, ask us through our contact page.
Section 1Scope and application
This data processing agreement (the “Agreement”) records how REGREP processes personal data on behalf of its customers, as required by Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679) and, where it applies, the United Kingdom General Data Protection Regulation.
It applies whenever you use the platform to convert, validate or generate regulatory filings, and it takes effect on the earlier of your account being created and your subscription starting. It runs for as long as we process customer data on your behalf. Where the terms of service and this Agreement differ on the processing of personal data, this Agreement prevails.
Section 2The parties
The processor under this Agreement is the REGREP company you contract with, determined by where you are established under Section 1 of our terms of service:
| Your establishment | Processor | Registered office |
|---|---|---|
| United Kingdom | REGTIFY (UK) LIMITED (12326692), trading as REGREP | 17 Sharpley Court, 8a Pocock Street, London SE1 0BJ, United Kingdom |
| European Union and rest of world | REGTIFY LIMITED (HE355806), trading as REGREP | Apostolou Andrea 3A, Strovolos, Nicosia 2049, Cyprus |
- EU office
- Bockenheimer Landstraße 17–19
60325 Frankfurt am Main, Germany - Data protection contact
- [email protected]
- Controller
- The customer named on the account or subscription, acting for itself and for any group entity it has authorised to use the platform
Company and imprint details are set out in full on our legal information page.
Section 3Definitions
Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority carry the meanings given to them in the General Data Protection Regulation.
Customer data means the data you upload, connect or otherwise place on the platform so that we can prepare, validate and deliver your regulatory filings, together with the outputs generated from it. Subprocessor means a processor we engage to process customer data on our behalf.
Section 4Roles of the parties
We are not a processor for everything. The role each of us holds depends on the data:
| Data | Our role | Your role |
|---|---|---|
| Customer filing dataRecords inside the filings you prepare, including account holder, seller, counterparty, employee and transaction data | Processor | Controller |
| Account, user and billing dataNames, work contact details, access records and invoicing details for your team | Controller | Controller of the same data in your own capacity |
| Website, enquiry and marketing dataForm submissions, analytics and consent records | Controller | Not applicable |
This Agreement governs the first row only. Our processing as a controller is described in our privacy policy and GDPR statement.
Section 5Details of the processing
| Subject matter | Provision of the REGREP platform: conversion, validation and generation of regulatory filings and supporting reports. |
|---|---|
| Duration | The term of your account or subscription, followed by the deletion periods in section 12. |
| Nature of the processing | Receipt, storage, structural mapping, validation against the applicable regulatory framework, generation and delivery of outputs, and deletion. |
| Purpose | Enabling you to meet your reporting obligations to a supervisor, tax authority or other competent authority. |
| Types of personal data | Identification and contact details, tax identification numbers, account and financial data, holdings and transaction data, employment and role data, and any other identifiers contained in the records you submit. |
| Categories of data subjects | Your account holders and customers, sellers and platform users, counterparties, and your own employees and officers, in each case as identified within reportable records. |
| Special categories | None. Regulatory filings do not require special categories of personal data or criminal-conviction data, and you must not place such data on the platform. |
Section 6Processing instructions
We process customer data only on your documented instructions. Your instructions are this Agreement, the terms of service, the configuration you set within the platform, and the operations you choose to run.
We do not use customer data for our own purposes. In particular, we do not sell it, we do not use it for marketing, and we do not use it to develop, train or evaluate any machine-learning model. Aggregated operational metrics that carry no personal data — such as processing volumes and error rates — may be used to run and improve the service.
If we consider that an instruction infringes data protection law, we will tell you and may pause the affected processing until it is resolved. If a law we are subject to requires us to process customer data beyond your instructions, we will inform you before doing so unless that law prohibits it.
Section 7Confidentiality
Access to customer data is granted on a least-privilege basis and only to personnel who need it to deliver or support the service. Every person with access is bound by a duty of confidentiality that continues after their engagement ends, and administrative access is logged.
Section 8Security measures
We implement technical and organisational measures appropriate to the risk, as required by Article 32. The measures in force are summarised here and described more fully on our security page:
| Measure | What it covers |
|---|---|
| Encryption | Encryption in transit and at rest across the platform. |
| Access control | Multi-factor authentication for administrator accounts, least-privilege roles and audit logging of administrative and configuration changes. |
| Data residency | Regulatory filing data on the platform is held in the European Union. |
| Network and transport | Transport Layer Security 1.2 or higher, a web application firewall, rate limiting and login-attempt protection in front of the origin. |
| Resilience | Automated daily backups with an off-site copy, and restores tested every quarter. |
| Segregation | The staging environment carries no production personal data and has a separate cookie and content-security scope. |
| Patching and monitoring | Critical security patches applied within 48 hours, with malware and file-integrity monitoring and alerting. |
We may change these measures as the platform develops, provided the level of protection is not reduced.
Section 9Subprocessors
You give us general written authorisation to engage subprocessors. Each is engaged under written terms that impose data protection obligations no less protective than those in this Agreement, and we remain fully liable to you for their performance.
The subprocessors engaged for the service are:
| Provider | Purpose | Customer filing data |
|---|---|---|
| Amazon Web Services | Platform hosting, compute and storage | Yes — at rest |
| Cloudflare | Hosting front end and content delivery | In transit only |
| Stripe | Payments and billing | No |
| Google (Ads, Analytics) | Advertising measurement and site analytics (consent-based) | No |
| CookieYes | Consent management | No |
| Microsoft | Transactional and marketing email | No |
Customer filing data is hosted on Amazon Web Services in European Union regions. Amazon Web Services regions outside the European Union that we operate in are used for services that do not process customer filing data of European Union customers.
We will give you at least 30 days’ notice before adding or replacing a subprocessor that will process customer data. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of your subscription without penalty and receive a refund for the unused period. The current list is maintained and available on request.
Section 10Data subject requests
You remain responsible for responding to data subjects about customer data. Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures, including the search, export and deletion functions available in the platform.
We will not respond to a data subject request about customer data ourselves, other than to confirm that we act as a processor and to direct the individual to you. If such a request reaches us, we will pass it to you without undue delay.
Section 11Assistance and personal data breaches
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36 — security of processing, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
If we become aware of a personal data breach affecting customer data, we will notify the administrative contact on your account without undue delay and in any event within 48 hours. That notification will describe the nature of the breach, the categories and approximate volumes of data affected, the likely consequences and the measures taken, so far as that information is available to us at the time, and we will update you as our investigation continues. You may report a suspected breach to [email protected] at any time.
Section 12Retention, return and deletion
This is the single retention schedule for the service. Where any other page of this site states a period, this Section governs.
| Data | Live systems | Backups |
|---|---|---|
| Customer data while your subscription is active | Retained so we can provide the service. You can delete it yourself at any time in the platform. | Rolling cycle, maximum 35 days |
| Source files submitted for a run | Deleted when the run completes | Maximum 35 days |
| Validation reports, including for test and failed runs | 30 days from generation, then deleted automatically | Maximum 35 days |
| Generated filings and outputs | Retained in your account until the post-termination schedule below applies | Maximum 35 days |
| All customer data after termination | Read-only for 90 days so you can export, then deleted from live systems within a further 30 days — 120 days in total | Expire within 35 days of live deletion; never restored except for disaster recovery |
| Account and billing records | Retained for the statutory period, being at least six years from the end of the tax year to which they relate | Same period |
| Web and error logs | 90 days, with query parameters stripped or hashed | Not separately retained |
Validation reports can contain record-level data, so they are covered by this Agreement in the same way as any other customer data. Account and billing records are held by us as a controller rather than under this Agreement, and are described in our privacy policy.
We will certify deletion in writing on request.
Section 13Audits and information
We make available the information you need to demonstrate compliance with Article 28: this Agreement, our security documentation, the subprocessor list, retention schedules and completed security questionnaires. For most customers this is enough, and it is the route we ask you to use first.
Where it is not sufficient, you may audit our processing of your customer data once in any twelve-month period, on at least 30 days’ written notice, during business hours, without disrupting the service and subject to confidentiality obligations. A supervisory authority may audit as the law provides. You bear your own costs and our reasonable costs of assisting an audit beyond the documentation route.
Section 14International transfers
Regulatory filing data on the platform is held in the European Union. Where personal data is nonetheless transferred outside the European Economic Area — including to a subprocessor — that transfer relies on an approved mechanism.
The mechanism is an adequacy decision where one is in force for the destination, and otherwise the European Commission’s standard contractual clauses, supplemented by the United Kingdom International Data Transfer Addendum where the transfer is subject to the United Kingdom regime, together with any additional safeguards a transfer risk assessment shows to be necessary. The mechanism applying to a particular provider is available on request.
Section 15Liability, precedence and term
This Agreement is subject to the limitations and exclusions of liability in our terms of service, except where data protection law does not permit them to apply. It remains in force for as long as we process customer data on your behalf; the sections on confidentiality, deletion and liability survive its termination.
This Agreement is governed by the same law as the terms of service, determined by the processor you contract with under Section 2, and the courts of that jurisdiction have jurisdiction. That does not affect the rights of data subjects or the jurisdiction of any supervisory authority. It is published in English, and the English text is the governing version.
Section 16Changes to this agreement
We may update this Agreement to reflect changes to the platform, our subprocessors or the law. Material changes are notified to the administrative contact on your account at least 30 days before they take effect. The version and effective date shown at the start of this page identify the text currently in force; superseded versions are available on request.
Section 17Signed copies and questions
The Agreement applies automatically, so most customers never need a signed copy. If yours does, or if you have a question about how we process your data, email [email protected] or use our contact page. Tell us the account name and the entity that should be named as controller, and we will return a countersigned copy.
RelatedDocuments that sit alongside this one
Terms of Service
The terms on which we provide the platform, including subscriptions, credits and cancellation.
Read terms →GDPR Statement
Our GDPR commitments, data-subject rights and how to exercise them.
Read GDPR statement →Security & Data Protection
The controls behind the security measures in section 8, and our assurance status.
Read security →REGREP is an independent software provider. Nothing on this page is legal, tax or regulatory advice. Questions about this notice can be sent to [email protected] or via our contact page. See also our legal information, privacy policy, terms of service and GDPR statement.