Skip to content

Data Processing Agreement

Signable DPA template for RegAlytics customers. Last updated April 2026. This page is the human-readable summary. The full DPA is available as a PDF from your account manager and is incorporated by reference into the MSA.

Request the signable DPA

Preamble

This Data Processing Agreement forms part of the Master Services Agreement between RegAlytics Ltd (the processor) and the customer (the controller). It governs the processing of personal data on behalf of the customer where RegAlytics acts as processor or sub-processor.

Processing activities

RegAlytics processes personal data as necessary to deliver the subscribed services. Categories of data subjects: the customer’s employees, contractors and authorised users. Categories of personal data: name, work email, work phone, role, API usage metadata, and application interaction logs.

Duration: for the term of the subscription, plus a 30-day export window.

Sub-processors

A current list of sub-processors is maintained at /legal/subprocessors. We notify you by email 30 days before any addition or change. Enterprise customers may object in writing; if the objection cannot be resolved, you may terminate the affected service and receive a pro-rated refund.

Security measures

Technical and organisational measures include: SOC 2 Type II certification, ISO 27001 certification, TLS 1.2+ in transit, AES-256 at rest, KMS-managed keys with rotation, least-privilege access controls, full audit logging of operator access, annual penetration testing, and a published incident response process.

A detailed schedule of measures is included in the signed DPA.

International transfers

Where customer data is transferred outside the EU/UK, we rely on the European Commission’s Standard Contractual Clauses (2021 revision) plus the UK International Data Transfer Addendum as applicable. A Transfer Impact Assessment is available on request for customers in regulated sectors.