Data processing agreement

These are our standard processor terms for RAMSReady. They apply where you use the service to process personal data for which you are the controller, which is the normal position for an organisation account.

Version 1, 9 October 2026. If your organisation has its own data processing agreement, send it to us and we will review and sign it instead.

1. The parties and their roles

Where you are a sole trader using the service for yourself, you are the data subject rather than a controller, and our privacy notice governs instead.

2. What is processed

3. Our obligations as processor

Under Article 28(3) of the UK GDPR we will:

If we think an instruction from you would breach data protection law, we will tell you rather than simply carry it out.

4. Security measures

We will not materially reduce these measures during the term.

5. Personal data breaches

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data, so that you have time to meet your own 72 hour duty to the ICO. The notification will describe what happened, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we cannot give you everything at once we will give you what we have and follow up.

6. International transfers

Your records are stored in Helsinki, Finland, which is in the European Economic Area and covered by the United Kingdom's adequacy findings, so no additional safeguard is needed for storage. Some of our sub-processors are in the United States. Those transfers rely on the UK Extension to the EU to US Data Privacy Framework, or on the standard contractual clauses in the relevant provider's terms. The current list, with the basis for each, is in our privacy notice.

7. AI processing

The service generates documents by sending the information you enter to the AI providers named in our privacy notice. They are used under paid API terms that do not permit them to train their models on your content. If you would rather your data were not processed this way, the service cannot function, so please do not upload it.

8. Audit, term and signature

You may audit our compliance with these terms once a year on reasonable notice, or more often following a breach, and we will answer a security questionnaire instead where that satisfies you. These terms take effect when you start using the service and end when your account closes and the retention periods in our privacy notice expire.

We are a small company and these are our standard terms rather than a negotiated contract, so they are not solicitor drafted. We would rather sign your own data processing agreement than have you accept wording you are not comfortable with. Email us and we will turn it round quickly. For a countersigned copy of this document on letterhead, ask and we will send one.