Data processing agreement (Version 1)
Last updated: 23 August 2026
Article 28 UK GDPR terms for the personal data Rated Counsel Limited, trading as crmSpace processes on your behalf. You are the controller. We are your processor.
Version 1
These are the Article 28 terms we offer, settled by our counsel and published on 23 August 2026. Using the service accepts the data processing addendum in our terms of service; this longer form is the same bargain with the annexes written out. To have it countersigned for your own records, write to connect@crmspace.ai. The security measures in Annex B describe the product as it stands today.
Tell us what your counsel needs changed: connect@crmspace.ai.
1. Who this is between
This agreement is between the customer, who is the controller, and Rated Counsel Limited, trading as crmSpace, who is the processor. It governs personal data we process on your behalf when you use crmSpace, including the Contracts module. It is written to meet Article 28 of the UK GDPR.
Where you and we have signed a separate order or terms of service, this agreement forms part of them. On data protection matters this agreement takes precedence.
Words defined in the UK GDPR carry those meanings here. Controller, processor, personal data, processing, data subject and personal data breach all mean what that regulation says they mean.
2. What we process, and why
Annex A sets out the subject matter, the duration, the nature and purpose of the processing, the categories of personal data and the categories of data subject. Annex A is part of this agreement.
We process personal data only to provide the service to you, to keep it secure, and to meet our own legal obligations.
3. Our instructions
We process personal data only on your documented instructions. Your instructions are this agreement, your order, and the things your people do in the product. Configuring a retention policy is an instruction. Pressing a button that runs an AI reading is an instruction. Asking us in writing is an instruction.
If the law requires us to process personal data for something other than your instructions, we tell you before we do it, unless that law forbids us from telling you.
If we think an instruction breaks data protection law, we tell you. We may pause that instruction until it is resolved.
An instruction that would move personal data outside the United Kingdom is governed by clause 7, and we will not act on one until the transfer has a basis under that clause.
4. Confidentiality
Everyone we authorise to process your personal data is bound by a duty of confidentiality, by contract or by professional obligation. That duty outlives their work on the service.
We limit access to the people who need it to run the service, and each of them uses a named account.
5. Security
We keep the technical and organisational measures set out in Annex B. Those measures describe the product as it stands, and each of them is published on our security page with the part of the product it rests on.
We may change a measure, and we keep the overall level of protection at least as high as it is on the date of this agreement. Annex B and the security page move together.
We do not hold a SOC 2 report or an ISO 27001 certificate. We say so here for the same reason we say so on the security page: a procurement process should learn it from us, early, rather than at the end of a questionnaire.
6. Sub-processors
You give us general authorisation to appoint the sub-processors listed in Annex C.
Before we add a sub-processor that will handle your personal data, we give workspace administrators at least 30 days' notice by email. If you object on reasonable data protection grounds within that period, we will try to offer a workaround. If we cannot, you may terminate the affected part of the service and we refund any prepaid fees for the period you do not use.
We put obligations on each sub-processor that are at least as protective as the ones in this agreement, and we remain responsible to you for what they do.
7. International transfers
Your records and your documents stay in London. Your records are held in Neon Postgres in AWS eu-west-2, which is London. Uploaded contracts and record attachments are kept in Vercel Blob in London, region lhr1, byte for byte, behind the app's own sign-in. The CRM app, the Contracts app and this website run as Vercel functions in London, region lhr1.
Some sub-processors process outside the United Kingdom. Annex C names the region for each one where we set it, and says that the region follows the sub-processor's own terms where we do not.
Where a transfer leaves the United Kingdom, it relies on adequacy regulations where they apply, and otherwise on the standard contractual clauses with the UK International Data Transfer Addendum. We will give you a copy of the mechanism relied on for any sub-processor you ask about.
8. Helping you meet your own duties
We help you respond to requests from data subjects. The product does most of this itself: subject access export, erasure with suppression so a deleted person does not return on the next import, retention policies, and an Article 30 register you can download. Where the product does not reach, we help you by hand.
We help you with data protection impact assessments and with prior consultation, taking into account what we know about the processing and what you can see for yourself in the product.
If a data subject contacts us directly about your data, we tell them to contact you, and we tell you.
9. Personal data breaches
If we become aware of a personal data breach affecting your personal data, we tell workspace administrators without undue delay and within 72 hours.
We tell you what we know: what happened, which categories and roughly how many records and data subjects are involved, what the likely consequences are, and what we are doing about it. Where we do not have all of it at once, we send what we have and follow up.
10. Return and deletion
You can take your data out at any time while your workspace is live. Records export as CSV. Contracts and their register export as a data room, which is a ZIP of the paper with an index beside it. Nothing is held back to make leaving harder.
When your workspace ends, you have 30 days to export. After that we delete your personal data. Copies inside encrypted backups leave on the backup provider's rolling schedule, which is a further 30 days at most.
Retention and disposal inside a live workspace are yours to set. Retention policies dispose of contracts on the schedule you choose, legal holds keep named paper out of disposal, and what has been disposed of is counted where you can see it.
We keep what the law requires us to keep, such as the invoices we issued to you, for as long as that law requires and no longer.
11. Information and audits
We give you the information you need to show that we meet Article 28. That starts with this agreement, the security page and the sub-processor list, and continues with written answers to your questions.
Once in any 12 month period, and on 30 days' written notice, you may audit our compliance with this agreement, including by inspection. The audit runs first on documents and written answers. Where those leave a question open, it continues as a session with the people who run the service, and as an inspection of the systems and records that hold your data where the question needs one.
You may appoint an independent auditor to carry out the audit on your behalf. We may ask that they are not a competitor of ours and that they sign a confidentiality undertaking, and we will not use either point to prevent an audit going ahead.
Each side pays its own costs. You may audit more often if a supervisory authority requires it, or after a personal data breach affecting your data.
12. AI processing
AI readings run when somebody in your workspace asks for one. They are model calls through the Vercel AI Gateway to the providers named in Annex C. Anthropic models read the paper and write the drafts. Voyage AI produces the clause embeddings that meaning search reads.
We do not use your documents to train models.
What a model provider does with a request once it reaches them is set by that provider's own terms. We name which provider processes what so that you can read those terms yourself, and the current list is Annex C of this agreement.
Every stored reading carries the model that produced it and the version of the prompt that asked, and the tokens the run billed. That record is in your workspace, not only in ours.
13. Liability and duration
This agreement lasts as long as we process personal data for you, plus the deletion window in clause 10.
Liability under this agreement is subject to the limits in the terms of service between us.
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex A. Details of the processing
| Detail | Description |
|---|---|
| Subject matter | Providing the crmSpace CRM and, where you take it, the Contracts module. |
| Duration | The life of your workspace, plus the deletion window in clause 10. |
| Nature of the processing | Storing, organising, retrieving, displaying, exporting, and running AI readings over the records and documents you put in. |
| Purpose | Running your customer relationships and your contracts, on your instructions. |
| Categories of personal data | Business contact details, the content of communications you capture, deal and billing data, the names and details that appear in contracts you upload, and your own workspace members' account data. |
| Categories of data subject | Your contacts, leads, customers, suppliers, counterparties and their signatories, and your own workspace members. |
| Special category data | The service is not designed for special category data. If your documents contain it, it is processed as part of the document, and you remain the controller of that decision. |
| Frequency | Continuous while your workspace is live. |
Annex B. Technical and organisational measures
Each measure below is published on our security page, where it is tied to the part of the product it rests on. Nothing is listed here that is not in the product today, and the security page and this annex are generated from one list so they cannot come apart.
- The CRM app, the Contracts app and this website run as Vercel functions in London, region lhr1.
- Your records are held in Neon Postgres in AWS eu-west-2, which is London.
- Uploaded contracts and record attachments are kept in Vercel Blob in London, region lhr1, byte for byte, behind the app's own sign-in.
- Every request reaches the apps over HTTPS. All three deployments send a Strict-Transport-Security header with a two-year policy that covers subdomains.
- Neon encrypts stored data at rest. That is the database provider's own measure, on their own platform.
- Backups and point-in-time restore are run by Neon, in the same region as the database. The restore window on our plan is six hours.
- Sign-in runs inside the application against your workspace's own database, so no third party holds the accounts.
- Anyone can turn on two-factor sign-in with an authenticator app, and gets backup codes with it.
- Six built-in roles carry named scopes. On Pro and Enterprise, admins compose custom roles from the same grants.
- Every read and every write goes through one authorisation check, scoped to your workspace, before a record is returned or changed.
- Single sign-on through an OIDC identity provider and SCIM 2.0 provisioning are part of the Enterprise plan.
- A contract can be marked confidential or restricted, and then admins, the person who restricted it, and the roles and people named on the policy can open it.
- A stored AI reading is guarded again for each reader: the sources behind it are re-checked against that reader's access before the panel draws, and paper they cannot open is counted rather than shown.
- Every change to a record is appended to an event ledger with the actor, the source and the time, so the workspace can be read as it stood on any past date.
- Every workspace keeps an access log an administrator can read on the settings page. The export downloads the newest 10,000 entries as CSV.
- An Article 30 record of processing activities is built from the workspace and downloads as markdown from the same page.
- Erasing a person tombstones their record, redacts their details from the ledger in place, and suppresses their email so a later import cannot bring them back.
- Retention policies dispose of contracts on a schedule you set, legal holds keep named paper out of it, and what has been disposed of is counted where you can see it.
- Contracts and their register export as a data room, as a streamed ZIP of the paper with the index beside it.
- An audit pack gathers one contract's duties, its evidence files and its register into a single file for whoever is asking.
- Integration credentials your workspace stores, such as a mailbox token or a vendor API key, are sealed with AES-256-GCM before they reach the database.
- Inbound webhooks are signature-verified and fail closed, so an unsigned or replayed request is rejected rather than processed.
- AI readings are produced by model calls addressed to the Vercel AI Gateway, which is where a deployment sends them unless it is configured with a provider key of its own.
- Anthropic models read the paper and write the drafts. Voyage AI's voyage-law-2 turns clauses into the vectors meaning search reads.
- Every reading carries the model that produced it and the version of the prompt that asked, in the same glance as the reading.
- Two readings quote your paper character for character and are refused whole if they cannot: the extraction that builds the register, and the evidence read that weighs a file against a duty.
- Each run records the tokens it billed. Money is worked out from those tokens when a figure is shown, so a price change does not rewrite what a run cost.
- We do not use your documents to train models. That is our own undertaking about what we do with your paper, and it is written into the data processing agreement.
We hold no SOC 2 report and no ISO 27001 certificate. There is none to send.
Annex C. Sub-processors
| Provider | What it does | Where | Transfer basis |
|---|---|---|---|
| Vercel Inc., application hosting | Runs both apps and this website, and the AI Gateway model calls pass through. | Functions in lhr1, London. | No transfer. Processing stays in the United Kingdom. |
| Vercel Inc., Blob document store | Holds uploaded contracts and record attachments, byte for byte, in a private store. | lhr1, London. | No transfer. Processing stays in the United Kingdom. |
| Neon Inc. | The Postgres database that holds every workspace record. | aws-eu-west-2, London. | No transfer. Processing stays in the United Kingdom. |
| Anthropic PBC, reached through the Vercel AI Gateway | The models that read contracts, answer questions and draft. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Voyage AI, reached through the Vercel AI Gateway | Clause embeddings, which is what meaning search reads. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Resend Inc. | Product email, outbound and inbound capture. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Stripe Payments Europe, Ltd. | Subscription billing and payment. | Ireland, with onward processing under Stripe's own terms. | UK adequacy regulations for the EEA. |
| DocuSign, Inc. (only when your workspace connects it) | Electronic signature. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Google LLC (only when your workspace connects it) | Reads and sends mail on a connected Gmail mailbox, and reads calendar events, for the account you connect. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Microsoft Corporation (only when your workspace connects it) | Reads and sends mail on a connected Microsoft 365 mailbox, and reads calendar events, for the account you connect. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Slack Technologies, LLC (only when your workspace connects it) | Posts notifications to the channel your incoming webhook points at. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
| Apollo.io and ZoomInfo (only when your workspace connects it) | Enrichment, on the account and API key your workspace supplies. | Region per the sub-processor's terms. | Adequacy where it applies, otherwise the IDTA with the SCC addendum, under the provider's own data processing terms. |
The recipients below are not processors. A request goes to each of them and none of them holds your personal data as a result, so they are named here for completeness rather than authorised under clause 6. The rows are the same list the security page prints.
| Recipient | What we send | Why it is not a processor |
|---|---|---|
| Companies House | A company name or company number. No customer documents and no personal data. | A public register we look a company up in. They decide what their register holds, not us, so they are a controller of their own data rather than a processor of yours. |
| HMRC and the EU VIES service | A VAT registration number. No customer documents and no personal data. | Public VAT checks. They answer whether a number is valid; they hold nothing of yours as a result. |
| The European Central Bank | Nothing. We fetch their published daily exchange rates. | A one-way download of public reference rates, so no data of yours is involved at all. |
| Whatever your outbound webhooks point at | The signed event payload you subscribed to, to the URL your workspace entered. | You choose the destination, so that recipient is yours rather than one of ours. Zapier, Make, n8n and your own systems all arrive this way. |
Notice of a change to this list goes to workspace administrators by email, at least 30 days before the change. Clause 6 says what happens if you object.
Related
The security page carries the same measures with the part of the product each one rests on. The accuracy page carries what the AI readings scored on a fixed set of contracts whose answers are known, and says so when no run has been published yet.