Data Processing

Data Processing Agreement

How Credbase handles personal data as your processor under UK GDPR. Forms part of the Terms of Service.

Who this is between

This Data Processing Agreement ("DPA") is between you (or the organisation you represent) as the data controller and Aplera Labs Ltd, a company registered in Scotland (company number SC878012), operating Credbase, as the data processor.

This DPA forms part of the Credbase Terms of Service. If there is a conflict between them for personal data we process on your behalf, this DPA wins.

Roles and responsibilities

You are the controller of the personal data contained in the documents, records and messages you (or people you invite) upload to your Credbase workspace. You decide what to collect, why and for how long.

Credbase is your processor for that data. We process it only on your documented instructions, which are, by default, the actions you and your workspace take inside the product and the settings you choose.

For our own account and billing data about you, we act as controller. That processing is covered by our Privacy Policy, not this DPA.

What we process and why

We process customer personal data for the purpose of providing Credbase to you: storing documents, sending secure upload links, generating AI suggestions for your team to approve, keeping the service secure and providing support.

  • Types of data: contact details, business documents and their contents, workspace activity and anything else you or your recipients upload.
  • Categories of data subjects: your team members, your contractors and their staff, your suppliers, your customers and other business contacts you choose to record.
  • Duration: for as long as your workspace exists, plus a short wind-down period after termination for backup and legal reasons (see "Deletion and return").

Our obligations as processor

As your processor, we will:

  • Process customer personal data only on your documented instructions, unless UK or EU law requires otherwise (in which case we will tell you, unless the law prevents us).
  • Ensure people authorised to access the data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (see the Trust Centre for the current controls).
  • Help you respond to data-subject rights requests and, where relevant, data protection impact assessments and consultations with regulators.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations.
  • Make available the information you reasonably need to demonstrate our compliance with Article 28 UK GDPR, and allow for audits as described below.

Subprocessors

You give us general authorisation to use subprocessors to help provide the service, for hosting, database, transactional email, error monitoring, payment processing and AI-assisted document understanding.

A current list is available on request and will be published in the Trust Centre as the product matures. Before we add or replace a subprocessor, we will update that list and give you a reasonable chance to object on legitimate data-protection grounds. If you reasonably object and we can't offer a workable alternative, you may terminate the affected service.

We remain responsible to you for what our subprocessors do with your data and impose data-protection obligations on them that are no less protective than this DPA.

International transfers

Application data and uploaded documents are hosted on managed cloud infrastructure in the UK and EU. Some subprocessors (for example, certain AI providers) may process data outside the UK/EU. Where they do, we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses or an adequacy decision.

Security measures

We maintain the technical and organisational measures described in our Trust Centre, including encryption in transit and at rest, private-by-default workspaces, role-based access, multi-factor authentication for staff, least-privilege production access and logging of privileged actions.

We may update those measures over time to keep pace with the state of the art, provided the overall level of protection is not reduced.

Audit rights

We know audits matter for regulated buyers. To keep costs and disruption reasonable for both sides, we make available on request written information about our security controls, subprocessors and applicable third-party reports.

Where that isn't enough to meet a mandatory audit obligation, we will co-operate in good faith on a scoped audit at your reasonable cost, conducted by you or a qualified independent auditor bound by confidentiality, on reasonable prior written notice, during working hours and without disrupting the service.

Data-subject requests

If a data subject contacts us directly about data we process on your behalf, we will (unless legally prohibited) tell them to contact you and forward the request where practical. We will provide reasonable assistance so you can respond within legal deadlines.

Deletion and return

You can delete documents, records or entire workspaces at any time from within the product. On termination of the service, we will (at your choice) delete or return the customer personal data we hold, subject to legal retention requirements and our standard backup cycle. Backups age out on that cycle, after which residual copies are unrecoverable.

Liability

The liability limits in the Credbase Terms of Service apply to this DPA as well, and apply in aggregate across the Terms and this DPA. Nothing here creates a separate cap.

Changes to this DPA

We may update this DPA from time to time to reflect changes in law, product or subprocessors. If a change is material, we will give you reasonable notice before it takes effect.

Plain English, not legal advice

This page is written to be easy to read. It is a real, binding document, but it is not legal advice for your business. If you need to check it against your own obligations, please speak to your own lawyer.

Need a signed copy on your paper for procurement? Email privacy@credbase.app and we'll sort it.

Credbase is a product of Aplera Labs Ltd, a company registered in Scotland (company number SC878012). Contact: hello@credbase.app.