Legal

Data Processing Agreement

The terms on which REGREP processes personal data on your instructions when you use the platform to prepare, validate and deliver regulatory filings.

Version 1.0 · Effective 22 July 2026

This page is the current text of the agreement. It forms part of our terms of service and applies automatically from the moment you open an account — there is nothing for you to sign for it to take effect.

If your own governance requires a countersigned copy, or the agreement on your own paper, ask us through our contact page.

Section 1Scope and application

This data processing agreement (the “Agreement”) records how REGREP processes personal data on behalf of its customers, as required by Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679) and, where it applies, the United Kingdom General Data Protection Regulation.

It applies whenever you use the platform to convert, validate or generate regulatory filings, and it takes effect on the earlier of your account being created and your subscription starting. It runs for as long as we process customer data on your behalf. Where the terms of service and this Agreement differ on the processing of personal data, this Agreement prevails.

Section 2The parties

The processor under this Agreement is the REGREP company you contract with, determined by where you are established under Section 1 of our terms of service:

Your establishmentProcessorRegistered office
United KingdomREGTIFY (UK) LIMITED (12326692), trading as REGREP17 Sharpley Court, 8a Pocock Street, London SE1 0BJ, United Kingdom
European Union and rest of worldREGTIFY LIMITED (HE355806), trading as REGREPApostolou Andrea 3A, Strovolos, Nicosia 2049, Cyprus
EU office
Bockenheimer Landstraße 17–19
60325 Frankfurt am Main, Germany
Data protection contact
[email protected]
Controller
The customer named on the account or subscription, acting for itself and for any group entity it has authorised to use the platform

Company and imprint details are set out in full on our legal information page.

Section 3Definitions

Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority carry the meanings given to them in the General Data Protection Regulation.

Customer data means the data you upload, connect or otherwise place on the platform so that we can prepare, validate and deliver your regulatory filings, together with the outputs generated from it. Subprocessor means a processor we engage to process customer data on our behalf.

Section 4Roles of the parties

We are not a processor for everything. The role each of us holds depends on the data:

DataOur roleYour role
Customer filing dataRecords inside the filings you prepare, including account holder, seller, counterparty, employee and transaction data Processor Controller
Account, user and billing dataNames, work contact details, access records and invoicing details for your team Controller Controller of the same data in your own capacity
Website, enquiry and marketing dataForm submissions, analytics and consent records Controller Not applicable

This Agreement governs the first row only. Our processing as a controller is described in our privacy policy and GDPR statement.

Section 5Details of the processing

Subject matterProvision of the REGREP platform: conversion, validation and generation of regulatory filings and supporting reports.
DurationThe term of your account or subscription, followed by the deletion periods in section 12.
Nature of the processingReceipt, storage, structural mapping, validation against the applicable regulatory framework, generation and delivery of outputs, and deletion.
PurposeEnabling you to meet your reporting obligations to a supervisor, tax authority or other competent authority.
Types of personal dataIdentification and contact details, tax identification numbers, account and financial data, holdings and transaction data, employment and role data, and any other identifiers contained in the records you submit.
Categories of data subjectsYour account holders and customers, sellers and platform users, counterparties, and your own employees and officers, in each case as identified within reportable records.
Special categoriesNone. Regulatory filings do not require special categories of personal data or criminal-conviction data, and you must not place such data on the platform.

Section 6Processing instructions

We process customer data only on your documented instructions. Your instructions are this Agreement, the terms of service, the configuration you set within the platform, and the operations you choose to run.

We do not use customer data for our own purposes. In particular, we do not sell it, we do not use it for marketing, and we do not use it to develop, train or evaluate any machine-learning model. Aggregated operational metrics that carry no personal data — such as processing volumes and error rates — may be used to run and improve the service.

If we consider that an instruction infringes data protection law, we will tell you and may pause the affected processing until it is resolved. If a law we are subject to requires us to process customer data beyond your instructions, we will inform you before doing so unless that law prohibits it.

Section 7Confidentiality

Access to customer data is granted on a least-privilege basis and only to personnel who need it to deliver or support the service. Every person with access is bound by a duty of confidentiality that continues after their engagement ends, and administrative access is logged.

Section 8Security measures

We implement technical and organisational measures appropriate to the risk, as required by Article 32. The measures in force are summarised here and described more fully on our security page:

MeasureWhat it covers
EncryptionEncryption in transit and at rest across the platform.
Access controlMulti-factor authentication for administrator accounts, least-privilege roles and audit logging of administrative and configuration changes.
Data residencyRegulatory filing data on the platform is held in the European Union.
Network and transportTransport Layer Security 1.2 or higher, a web application firewall, rate limiting and login-attempt protection in front of the origin.
ResilienceAutomated daily backups with an off-site copy, and restores tested every quarter.
SegregationThe staging environment carries no production personal data and has a separate cookie and content-security scope.
Patching and monitoringCritical security patches applied within 48 hours, with malware and file-integrity monitoring and alerting.

We may change these measures as the platform develops, provided the level of protection is not reduced.

Section 9Subprocessors

You give us general written authorisation to engage subprocessors. Each is engaged under written terms that impose data protection obligations no less protective than those in this Agreement, and we remain fully liable to you for their performance.

The subprocessors engaged for the service are:

ProviderPurposeCustomer filing data
Amazon Web ServicesPlatform hosting, compute and storageYes — at rest
CloudflareHosting front end and content deliveryIn transit only
StripePayments and billingNo
Google (Ads, Analytics)Advertising measurement and site analytics (consent-based)No
CookieYesConsent managementNo
MicrosoftTransactional and marketing emailNo

Customer filing data is hosted on Amazon Web Services in European Union regions. Amazon Web Services regions outside the European Union that we operate in are used for services that do not process customer filing data of European Union customers.

We will give you at least 30 days’ notice before adding or replacing a subprocessor that will process customer data. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of your subscription without penalty and receive a refund for the unused period. The current list is maintained and available on request.

Section 10Data subject requests

You remain responsible for responding to data subjects about customer data. Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures, including the search, export and deletion functions available in the platform.

We will not respond to a data subject request about customer data ourselves, other than to confirm that we act as a processor and to direct the individual to you. If such a request reaches us, we will pass it to you without undue delay.

Section 11Assistance and personal data breaches

Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36 — security of processing, breach notification, data protection impact assessments and prior consultation with a supervisory authority.

If we become aware of a personal data breach affecting customer data, we will notify the administrative contact on your account without undue delay and in any event within 48 hours. That notification will describe the nature of the breach, the categories and approximate volumes of data affected, the likely consequences and the measures taken, so far as that information is available to us at the time, and we will update you as our investigation continues. You may report a suspected breach to [email protected] at any time.

Section 12Retention, return and deletion

This is the single retention schedule for the service. Where any other page of this site states a period, this Section governs.

DataLive systemsBackups
Customer data while your subscription is activeRetained so we can provide the service. You can delete it yourself at any time in the platform.Rolling cycle, maximum 35 days
Source files submitted for a runDeleted when the run completesMaximum 35 days
Validation reports, including for test and failed runs30 days from generation, then deleted automaticallyMaximum 35 days
Generated filings and outputsRetained in your account until the post-termination schedule below appliesMaximum 35 days
All customer data after terminationRead-only for 90 days so you can export, then deleted from live systems within a further 30 days — 120 days in totalExpire within 35 days of live deletion; never restored except for disaster recovery
Account and billing recordsRetained for the statutory period, being at least six years from the end of the tax year to which they relateSame period
Web and error logs90 days, with query parameters stripped or hashedNot separately retained

Validation reports can contain record-level data, so they are covered by this Agreement in the same way as any other customer data. Account and billing records are held by us as a controller rather than under this Agreement, and are described in our privacy policy.

We will certify deletion in writing on request.

Section 13Audits and information

We make available the information you need to demonstrate compliance with Article 28: this Agreement, our security documentation, the subprocessor list, retention schedules and completed security questionnaires. For most customers this is enough, and it is the route we ask you to use first.

Where it is not sufficient, you may audit our processing of your customer data once in any twelve-month period, on at least 30 days’ written notice, during business hours, without disrupting the service and subject to confidentiality obligations. A supervisory authority may audit as the law provides. You bear your own costs and our reasonable costs of assisting an audit beyond the documentation route.

Section 14International transfers

Regulatory filing data on the platform is held in the European Union. Where personal data is nonetheless transferred outside the European Economic Area — including to a subprocessor — that transfer relies on an approved mechanism.

The mechanism is an adequacy decision where one is in force for the destination, and otherwise the European Commission’s standard contractual clauses, supplemented by the United Kingdom International Data Transfer Addendum where the transfer is subject to the United Kingdom regime, together with any additional safeguards a transfer risk assessment shows to be necessary. The mechanism applying to a particular provider is available on request.

Section 15Liability, precedence and term

This Agreement is subject to the limitations and exclusions of liability in our terms of service, except where data protection law does not permit them to apply. It remains in force for as long as we process customer data on your behalf; the sections on confidentiality, deletion and liability survive its termination.

This Agreement is governed by the same law as the terms of service, determined by the processor you contract with under Section 2, and the courts of that jurisdiction have jurisdiction. That does not affect the rights of data subjects or the jurisdiction of any supervisory authority. It is published in English, and the English text is the governing version.

Section 16Changes to this agreement

We may update this Agreement to reflect changes to the platform, our subprocessors or the law. Material changes are notified to the administrative contact on your account at least 30 days before they take effect. The version and effective date shown at the start of this page identify the text currently in force; superseded versions are available on request.

Section 17Signed copies and questions

The Agreement applies automatically, so most customers never need a signed copy. If yours does, or if you have a question about how we process your data, email [email protected] or use our contact page. Tell us the account name and the entity that should be named as controller, and we will return a countersigned copy.

REGREP is an independent software provider. Nothing on this page is legal, tax or regulatory advice. Questions about this notice can be sent to [email protected] or via our contact page. See also our legal information, privacy policy, terms of service and GDPR statement.