Privacy & Data

Data Processing Agreement

Version 1.0Effective: 22/07/2026
The terms under which FireVault processes personal data on behalf of Customers as a Data Processor under UK GDPR.

1. Purpose and Scope

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions and sets out the terms under which FireVault Ltd ("Processor") processes personal data on behalf of Customers ("Controller") in accordance with UK GDPR and the Data Protection Act 2018.

2. Roles

  • Controller: The Customer determines the purposes and means of processing Compliance Data
  • Processor: FireVault processes Compliance Data on behalf of and on the documented instructions of the Controller

3. Processing Instructions

FireVault will process personal data only on the Controller's documented instructions, including transfers of personal data to a third country, unless required by law. FireVault will inform the Controller if an instruction infringes UK GDPR.

4. Data Subject Rights

FireVault will assist the Controller in responding to data subject rights requests, including:

  • Subject access requests
  • Rectification requests
  • Erasure requests
  • Data portability requests

5. Confidentiality

FireVault personnel authorised to process personal data are bound by confidentiality obligations. Access is limited to personnel who need it to provide the Service.

6. Security Measures

FireVault implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Incident response procedures
  • Staff training on data protection

See our Security Statement for details.

7. Sub-Processors

FireVault uses the following categories of sub-processors:

  • Hosting: cloud infrastructure providers
  • Payment processing: Stripe
  • Email delivery: Resend
  • Analytics: Google Analytics

The Controller grants general authorisation for the use of these sub-processors. FireVault remains liable for the performance of sub-processors. A current list of sub-processors is available on request.

8. Data Breach Notification

FireVault will notify the Controller without undue delay upon becoming aware of a personal data breach. Notification will include:

  • The nature of the breach
  • The likely consequences
  • Measures taken or proposed

9. Data Return and Deletion

Upon termination of the subscription, FireVault will:

  • Make Compliance Data available for export for 30 days
  • Delete all Compliance Data 30 days after account closure
  • Retain audit trail records for a minimum of 6 years as required by law

10. Audit

The Controller has the right to audit FireVault's compliance with this DPA, subject to reasonable notice and confidentiality obligations.

11. Contact

For DPA enquiries, contact info@fire-vault.co.uk.