| This DPA | forms part of the agreement between the Parties for the Suitxen service |
| Governing law | England & Wales |
| Version | 1.1 — 21 September 2026 |
Parties
- Controller: [Customer firm legal name], of [address] (“Controller”); and
- Processor: Suitxen Ltd, company number 17284189, of 71-75 Shelton Street, Covent Garden, London WC2H 9JQ (“Processor”, “Suitxen”).
1. Definitions and roles
1.1 Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018, each as amended (including by the Data (Use and Access) Act 2025) and together with the Privacy and Electronic Communications Regulations 2003 (“Data Protection Laws”).
1.2 In respect of the personal data processed under the service (Schedule 1), the Controller is the controller and Suitxen is the processor. The Controller is responsible for the lawfulness of the data it provides and the instructions it gives, and warrants that: it has a valid lawful basis under Article 6 (and, for any special-category data it chooses to include, an applicable Article 9 condition) for the processing it instructs; it has given data subjects any transparency information required; and it will input only the personal data necessary for the service, in line with the platform’s pseudonymisation and data-minimisation design.
1.3 To the extent of any conflict between this DPA and the main agreement concerning the processing of personal data, this DPA prevails. This DPA is concluded in electronic form, as permitted by Article 28(9) UK GDPR, either through the Controller’s acceptance of the Terms of Service or, for participants in the Suitxen beta programme, through the beta-gate acceptance sequence under the Beta Programme Agreement (Mutual NDA, then Beta Programme Agreement, then this DPA). During the beta programme, references in this DPA to the “main agreement” are read as references to the Beta Programme Agreement, and clause 3.5 of that Agreement (no special-category data) applies to the processing notwithstanding Schedule 1. Nothing in this DPA excludes or limits any statutory right of a data subject that cannot lawfully be limited by contract.
2. Processing by the Processor
2.1 Suitxen processes the personal data only on the Controller’s documented instructions (including this DPA and the service configuration), unless required to do otherwise by law, in which case it will inform the Controller unless legally prohibited.
2.2 Suitxen will inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.
2.3 The subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects are set out in Schedule 1.
2.4 Suitxen does not use the personal data to train, fine-tune or otherwise improve any AI or machine-learning model, and does not permit any sub-processor to do so: its AI sub-processor is engaged on commercial terms under which submitted content is not used for model training. Client identifying data is pseudonymised before any AI processing. The AI sub-processor’s data-use and retention terms as they apply to Suitxen’s account are recorded in the Sub-processor Register and re-verified at least annually and on any change to those terms.
3. Confidentiality
3.1 Suitxen ensures that persons authorised to process the personal data are bound by confidentiality obligations and are subject to appropriate access controls.
4. Security
4.1 Suitxen implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Schedule 2, in accordance with Article 32.
5. Sub-processors
5.1 The Controller gives general authorisation for Suitxen to engage sub-processors, listed in Schedule 3 / the Sub-processor Register. Suitxen imposes data-protection obligations on each sub-processor equivalent to those in this DPA.
5.2 Suitxen maintains the current list of sub-processors in its Sub-processor Register, published at www.suitxen.co.uk/legal/sub-processors. Before adding or replacing any sub-processor (whether or not the change is material), Suitxen will give the Controller at least 30 days’ notice (by updating that page and by notification within the platform), during which the Controller may object on reasonable data-protection grounds. If the Controller raises a reasonable objection that cannot be resolved, the Controller may terminate the affected part of the service in accordance with the main agreement. Suitxen remains liable for its sub-processors’ performance of their data-protection obligations.
6. Data subject rights
6.1 Taking into account the nature of the processing, Suitxen assists the Controller by appropriate measures, insofar as possible, to respond to requests by data subjects exercising their rights under the UK GDPR.
6.2 If Suitxen receives a request, complaint or other communication directly from a data subject, or from the ICO, relating to the Controller’s personal data, Suitxen will notify the Controller promptly and will not respond to it — beyond acknowledging receipt and directing the sender to the Controller — unless the Controller instructs it to do so or the law requires otherwise.
7. Assistance, breach notification & DPIAs
7.1 Suitxen assists the Controller in ensuring compliance with its obligations under Articles 32 to 36 (security, breach notification, data-protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Suitxen.
7.2 Suitxen notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data — giving initial notification in any event within 48 hours of becoming aware, even where the information available is incomplete, and following it with further information in phases as it becomes available — and provides the information the Controller reasonably needs to meet its own notification obligations. As controller, the Controller is responsible for deciding whether to notify the ICO and affected data subjects; the Controller’s own 72-hour period for notifying the ICO runs from the Controller becoming aware of the breach and is separate from Suitxen’s duty to notify the Controller.
8. Return and deletion
8.1 On termination of the service, or on the Controller’s request, Suitxen deletes or returns the personal data (at the Controller’s choice, returned in a structured, commonly used and machine-readable format) and deletes existing copies, unless retention is required by law — in which case the data is retained only for as long as the law requires and remains protected under this DPA. For clarity, the data lifecycle is as follows. Working case data (the fact-find, calculation results, risk profile and worksheets for a case) is deleted automatically seven calendar days after the case is created, whether or not the service has terminated; the Controller should export any worksheets it needs (DOCX / PDF) within that period, and later edits do not extend it. On termination or on request, any remaining personal data processed on the Controller’s behalf (for example case data still within its seven-day cycle, and client personal data contained in support communications) is deleted from production systems within 30 days. Data that Suitxen holds as a controller in its own right — such as the Customer’s business-contact, account-administration, billing and correspondence records — is not governed by this clause and is retained under Suitxen’s Privacy Notice and Data Retention & Deletion Policy. Residual copies may persist in encrypted, access-controlled backups until the rolling backup cycle overwrites them (currently seven days under the hosting plan in use, and in any event no more than a further 30 days); backup data is not restored to live use except where strictly necessary for continuity, and if restored, the deletion is re-applied immediately. Copies of pseudonymised working content held transiently by the AI sub-processor are deleted under that provider’s terms as recorded in the Sub-processor Register. Suitxen will confirm deletion in writing on request.
9. Audit and information
9.1 Suitxen makes available to the Controller the information reasonably necessary to demonstrate compliance with Article 28. Suitxen will respond to audit requests in the first instance by providing its security documentation and any independent certifications it holds from time to time (for example its Information Security & Access Control Policy and its DPIA), which the Controller will accept where these reasonably address its query. An on-site inspection by the Controller, or an auditor it mandates, will be available where that documentation does not reasonably resolve the Controller’s query, where required by a supervisory authority, following a personal data breach, or on a reasonably substantiated suspicion of material non-compliance with this DPA; any such inspection is on reasonable notice (which may be shortened where a supervisory authority requires it, or following a personal data breach) and subject to confidentiality and security. Inspections at the Controller’s own initiative are limited to once in any 12-month period, and the Controller will reimburse Suitxen’s reasonable costs of supporting them; that limit and cost provision do not apply to an inspection required by a supervisory authority, or to an inspection following a personal data breach or a reasonably substantiated suspicion of material non-compliance with this DPA. Nothing in this clause restricts any right a supervisory authority has by law or any right the Controller has under Article 28(3)(h).
9.2 The assistance described in clauses 6, 7 and 9 is provided free of charge to the extent it reflects the platform’s standard capabilities and self-service tools. Where a request is manifestly excessive, or requires work materially beyond those capabilities, Suitxen may charge reasonable costs agreed with the Controller in advance; Suitxen’s compliance with its obligations under Data Protection Laws is never conditional on payment.
10. International transfers
10.1 Suitxen does not transfer the personal data outside the UK except as necessary to provide the service and with an appropriate transfer basis in place — for personal data hosted by a sub-processor in the EEA, the UK’s adequacy regulations for the EEA; otherwise either the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, as the primary documented basis; where a sub-processor is also certified under the UK Extension to the EU–US Data Privacy Framework (UK–US Data Bridge), that adequacy basis is recorded as an additional basis — together with a transfer risk assessment and supplementary measures, in particular encryption and the pseudonymisation of client data before AI processing. The basis and mechanism applying to each sub-processor are recorded in the Sub-processor Register.
11. Liability, term and law
11.1 To the fullest extent permitted by law, liability between the Parties arising under or in connection with this DPA is subject to the limitations and exclusions in the Terms of Service / Customer Agreement (the “main agreement”), including the single aggregate cap in clause 11 of the Terms. Liability under this DPA counts towards, and does not sit above or in addition to, that cap. During the beta programme, the separate data-protection cap in clause 9.4 of the Beta Programme Agreement applies to liability under this DPA instead. Nothing in this DPA relieves either Party of its own direct statutory responsibilities under Data Protection Laws, limits a data subject’s statutory rights, or limits the powers of the Information Commissioner.
11.2 This DPA takes effect on the start of processing and continues for as long as Suitxen processes the personal data. Obligations that by their nature continue — including confidentiality, security, breach notification, return and deletion, and transfer safeguards — survive termination of the main agreement for as long as Suitxen holds any of the personal data. It is governed by the law of England & Wales, and the Parties submit to the exclusive jurisdiction of its courts.
Schedule 1 — Details of processing
| Subject matter | Provision of the Suitxen financial planning workspace: structured fact-find capture, deterministic financial calculations, risk profiling, and the assembly of draft planning and suitability worksheets for the Controller’s advisers. |
| Duration | For the term of the service agreement; working case data is deleted seven calendar days after the case is created (clause 8.1). |
| Nature & purpose | Capture, storage, deterministic calculation and assembly of draft working documents (worksheets) from pseudonymised case data; AI-assisted drafting, from launch, operates only on pseudonymised working content. All outputs are working drafts that require the Controller’s adviser to review, edit and sign off. |
| Types of personal data | Identity and contact data; financial data (e.g. income, assets, pensions, investments, objectives); and any special-category data (e.g. health) the Controller chooses to include, subject to clause 1.2 — and not permitted during the beta programme (Beta Programme Agreement, clause 3.5). |
| Categories of data subjects | The Controller’s clients and their relevant connected persons. |
Schedule 2 — Security measures
Suitxen applies the measures set out in its Information Security & Access Control Policy, including:
- Encryption in transit and at rest; pseudonymisation of client data before AI processing.
- Role-based, least-privilege access control and MFA; segregation of development from live client data.
- Logging and monitoring (system logs retained 12 months); automatic deletion of working case data seven days after creation; encrypted, access-controlled daily backups held in the same hosting region, retained on a seven-day rolling cycle under the current hosting plan (and in any event overwritten within no more than 30 days), with periodic restoration testing.
- Sub-processor due diligence and equivalent contractual obligations; staff and contractor confidentiality and awareness. A summary of the operating evidence for these measures is available to the Controller on request.
Schedule 3 — Sub-processors
The authorised sub-processors are those listed in Suitxen’s Sub-processor Register (published at www.suitxen.co.uk/legal/sub-processors and provided on request), which forms part of this DPA. Any exceptional engagement of an overseas development contractor as a sub-processor (for authorised production access under the Overseas Development & Data Access Statement) is subject to the clause 5.2 notice-and-objection process before that contractor accesses the Controller’s personal data, and is recorded in the Register.
Execution
This DPA forms part of and is incorporated into the Terms of Service / Customer Agreement. By accepting the Terms of Service — including via the online click-to-accept process at sign-up — or, for beta participants, by accepting this DPA through the beta-gate acceptance sequence, the Controller agrees to and is bound by this DPA, which is valid without any further signature. The signature block below is optional and provided only for Controllers that require a countersigned copy for their records; completing it is not necessary for this DPA to take effect. Electronic and digital signatures are accepted and have the same effect as handwritten signatures.