Data processing agreement

This agreement governs the personal data that Independent Check Ltd processes on behalf of an adviser firm using Your Family Financial Hub. It is the contract required by Article 28(3) of the UK GDPR, and it applies from the moment the firm is given access to the product.

The firm is the controller — their clients are their clients, they decide what goes into a hub and why, and they answer to those clients for it. Independent Check Ltd is the processor: we run the software and act on the firm’s instructions. Where this agreement says “we” it means Independent Check Ltd, and “you” means the firm.

1. What we process, and on whose instructions

Article 28(3)(a): we process personal data only on your documented instructions, including where we transfer it outside the United Kingdom, unless we are required to do otherwise by law — in which case we will tell you before processing, unless the law forbids us to.

Your instructions are your use of the product. Creating a household, uploading a document, asking the Companion a question, arranging a meeting: each is an instruction, and the software does that and nothing else with what it is given. We do not read, mine, sell, share or analyse your clients’ information for any purpose of our own, and nothing in a hub is used to train any model.

Annex A sets out the subject matter, the duration, the nature and purpose, the types of personal data and the categories of data subject, as Article 28(3) requires.

2. Confidentiality

Article 28(3)(b): everybody we authorise to process your clients’ data is under a duty of confidence — by contract of employment or engagement where they are our people, and by the terms of the agreements in Annex C where they are a sub-processor.

3. Security

Article 28(3)(c): we take the measures required by Article 32. What those measures actually are is Annex B, written as claims about the software rather than as adjectives, so that you can check them.

4. Sub-processors

Article 28(3)(d) and Article 28(2): you give us general written authorisation to engage the sub-processors listed in Annex C. We will give you at least 30 days’ notice before adding or replacing one, and you may object within that period; if we cannot resolve your objection you may end this agreement and we will return or delete your data under clause 7.

Article 28(4): each sub-processor is bound by written terms imposing the same data protection obligations as this agreement, and we remain fully liable to you for their performance of them.

5. Helping you answer your clients

Article 28(3)(e): we will help you meet requests from your clients to exercise their rights, by appropriate technical and organisational measures and taking account of what we can see.

In practice most of this needs no help from us, which is the design. A household’s whole record can be exported from inside the product — every record, every document, and the machine-readable data behind them — and a household can be deleted from inside the product, which removes every record, every document and the files behind them. Where a request needs something the product does not do, write to us at tom@independentcheck.co.uk and we will do it.

6. Helping you with security, breaches and assessments

Article 28(3)(f): we will help you comply with Articles 32 to 36 — security, breach notification to the ICO and to your clients, data protection impact assessments, and prior consultation — taking account of the nature of the processing and what is available to us.

If there is a personal data breach we will tell you without undue delay after becoming aware of it, with what we know: what happened, which categories and roughly how many people and records are affected, the likely consequences, and what we are doing about it. If we do not have all of it at once we will send what we have and follow up. Reporting to the ICO is yours to do, because you are the controller — our job is to put you in a position to do it inside your 72 hours.

7. Returning and deleting

Article 28(3)(g): when the service ends, we will — at your choice — return your clients’ personal data to you or delete it, and delete the copies we hold, unless we are required by law to keep something.

Tell us which you want within 30 days of the end. If you ask for it back, you get the export the product already produces, one per household. If you ask us to delete, we delete your firm’s database and its documents, and the encrypted backups age out on the schedule in Annex B. Say nothing for 30 days and we delete.

One thing is deliberately not deleted, and you should know about it before you sign. The product keeps an append-only record of what was done in each hub and by whom — an act, a person and a timestamp, carrying no value, no name and no document text. It cannot be edited or deleted, by us or by anybody, because a trail that can be rewritten is not a trail; it is what lets you show what happened to a client’s records, which is a thing a regulated firm is required to be able to do. Deleting a household removes everything those acts were about.

8. Audits and information

Article 28(3)(h): we will give you the information you need to show that we are meeting these obligations, and allow and contribute to audits and inspections by you or an auditor you appoint. Give us reasonable notice; we will not charge you for the first audit in any twelve months.

9. Where the data is, and transfers out of the UK

Your clients’ records are held in Germany, on servers run by Hetzner, and the nightly backups are stored in the European Union by Cloudflare. The United Kingdom has made adequacy regulations for the European Economic Area, so holding them there is not a restricted transfer. Both hold only encrypted files, and neither has a key to them.

Anthropic, who read the documents that are uploaded, process them in the United States. That transfer is made under Anthropic’s own data processing addendum, which incorporates the Standard Contractual Clauses together with the UK International Data Transfer Addendum issued by the ICO.

Brevo, who send the email, hold what they are given in the European Economic Area. The United Kingdom has made adequacy regulations for the EEA, so that is not a restricted transfer and no addendum is required for it.

Cloudflare is a United States company, and the backups it stores in the European Union are covered by its data processing addendum, which incorporates the Standard Contractual Clauses and the UK Addendum. What it holds is already encrypted, with keys it never has.

If a transfer mechanism we rely on is invalidated, we will move to another valid one or stop the transfer.

10. Term, changes and law

This agreement runs for as long as we process personal data for you. We may update it — to add a sub-processor, or because the law changes — and each version is numbered; this is version 3. A change that affects your rights or our obligations is notified to you and needs your acceptance, which is what the button at the top of this page records. Nothing here reduces your rights or ours under the UK GDPR, and where this agreement and that legislation disagree, the legislation wins. It is governed by the law of England and Wales.

Annex A — the processing

Subject matter. Providing Your Family Financial Hub: holding a household’s documents and the records read out of them, and presenting them to the household, their adviser and whoever else the household has given access.

Duration. For as long as the firm uses the product, and then as clause 7 provides.

Nature and purpose. Storage; reading uploaded documents to produce structured records; computing figures from those records; presenting them; and messaging and scheduling between a household and their adviser. The purpose is the firm’s provision of financial advice to their own clients.

Types of personal data. Names, contact details and dates of birth; family relationships; the contents of documents a household uploads — wills, pension and investment statements, policies, valuations, mortgage statements, correspondence — and the records read out of them, which include financial values, account and policy identifiers, property addresses and named beneficiaries, executors and attorneys; questions, answers and messages written by the household or their adviser; and, for people who sign in, an email address, a password hash and, where they have turned it on, an authenticator secret.

Special category data. Not sought and not asked for. A household’s own documents may nonetheless contain it — a health condition in a letter of wishes, a religious trust in a will — because the household chooses what to upload. It is held under the same measures as everything else and is never used to sort, score or select anybody.

Categories of data subject. The firm’s clients; members of their households and families, including children named in wills or as dependants; professionals a household gives access to, such as solicitors and accountants; and the firm’s own staff who use the product.

Annex B — technical and organisational measures

Separation. Every firm has its own database file and its own encryption key. There is no shared table of clients, so a query cannot return another firm’s data by mistake: a request resolves exactly one firm from the signed-in session, and reaching a second one is refused by the software rather than filtered out of a result.

Encryption. Every sensitive value — names, figures, filenames, document contents, the sentences people write — is encrypted with AES-256-GCM before it is written to disk, individually rather than as a whole-disk measure. The key that opens a firm’s data is itself encrypted with a master key held as an environment secret, which is never written to the same disk as the data. Data in transit is protected with TLS.

Access control. Signing in is a password checked against a scrypt hash, with an optional authenticator code. Inside a household, access is granted per person and per category, so a solicitor given sight of the legal papers cannot see what the family owns; the filter is applied when data is read rather than when a screen is drawn. A firm’s staff reach the households of that firm and no other.

Accountability. Every act on a household’s records writes a record naming who did it and when. Those records cannot be edited or deleted — the database itself refuses it, not merely the application.

Resilience. Backups are taken nightly and held off the server. They are copies of the already-encrypted files, so what leaves the building cannot be read without a key that does not leave with it. Thirty nights are kept and older ones are deleted.

Assurance. The rules above are enforced by automated checks that run before any change is released, including checks that a household’s data cannot be reached without the right permission and that nothing sensitive is written unencrypted. Restoring from a backup is tested, not assumed.

Annex C — sub-processors

Four, and no others. Each is engaged under written terms imposing the obligations in this agreement, and we remain liable to you for them.

Anthropic PBC — reading documents. When a document is uploaded, its text is sent to Anthropic so that its contents can be turned into records. This is the one place a client’s papers leave our systems and it is the thing you most need to have told your clients about. Anthropic does not use it to train models. Processed in the United States under their data processing addendum, which incorporates the Standard Contractual Clauses and the UK International Data Transfer Addendum.

Hetzner Online GmbH — running the server. They hold the encrypted files at rest and have no key to them. Germany.

Cloudflare, Inc. — storing the nightly copies described in Annex B, in its R2 storage, restricted to the European Union. They hold encrypted files and have no key to them.

Brevo (Sendinblue SAS) — sending email. They receive an email address and the text of what is sent. What is sent is deliberately thin: a notification email says how many things are waiting and carries a link, and never a household’s name, a figure, a document title or which household it is about. A password reset carries a single-use link and nothing else. Sent one at a time through their transactional interface and never as a marketing campaign, so nothing your clients receive from us is tracked, profiled or added to a mailing list. Held in the European Economic Area, which the United Kingdom has adequacy regulations for. Each person can turn the notification email off for themselves.

This list changes only as clause 4 says: with at least 30 days’ notice, and a new version of this agreement for you to agree. Write to tom@independentcheck.co.uk with any question about it.

Back to the hub