Data Processing Agreement
FileSeal (Sohus Ltd). UK and EU GDPR, Article 28.
This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and Sohus Ltd, trading as FileSeal, company no. 09369062, Flat 6, 365 Camden Road, London, N7 0SH, ICO registration ZC111701 (the "Processor"), for your use of the FileSeal service (the "Service"). It governs the Processor's processing of personal data on your behalf and reflects Article 28 of the UK GDPR and, where the Controller or its data subjects are in the EEA, the EU GDPR (Regulation (EU) 2016/679).
This DPA is incorporated into and forms part of your agreement with FileSeal (our Terms of Service) and applies automatically wherever you use the Service to process personal data of which you are the controller, so no separate signature is required. Where it conflicts with the rest of that agreement on data-protection matters, this DPA prevails.
Need a signed copy?
This DPA is already part of your agreement with FileSeal, so there is nothing separate to sign. If your procurement process requires a counter-signed copy on your own paper, email legal@fileseal.uk and we will return one.
1. Definitions.
"Data Protection Laws" means the UK GDPR and the Data Protection Act 2018 and, where the Controller or its data subjects are in the EEA, the EU GDPR (Regulation (EU) 2016/679). "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "special category data" have the meanings in the Data Protection Laws. "Sub-processor" means any third party engaged by the Processor to process personal data.
2. Roles.
You are the controller and the Processor is the processor of the personal data described in Annex 1. You are responsible for the lawful basis for processing and for the accuracy and lawfulness of the instructions you give. You warrant, on an ongoing basis, that you have a valid lawful basis (and, for special category data, a condition under Article 9) for the processing, that you have authority to give your instructions, that you have given data subjects the information required by Articles 13 to 14, and that your instructions will not cause the Processor to breach the Data Protection Laws.
3. Processing on instructions.
The Processor shall process personal data only on your documented instructions (including this DPA and your use of the Service), unless required by law, in which case it will notify you first unless the law prohibits this. The Processor shall promptly inform you if, in its opinion, an instruction infringes the Data Protection Laws.
4. Confidentiality.
The Processor ensures persons authorised to process the personal data are bound by confidentiality.
5. Security.
The Processor implements appropriate technical and organisational measures under Article 32, as set out in Annex 3.
6. Sub-processors.
You give general authorisation for the Processor to engage the sub-processors listed in Annex 2. The Processor imposes data-protection terms on each sub-processor no less protective than this DPA and remains liable for their performance. The Processor will give you at least 14 days' notice of any intended addition or replacement of a sub-processor and an opportunity to object. If you reasonably object on data-protection grounds and the parties cannot resolve the objection, you may suspend or terminate the affected part of the Service.
7. International transfers.
Personal data submitted through the Service (documents and the details collected via secure links) is stored in the United Kingdom, and all sub-processors process it in the UK or EEA (see Annex 2).
(a) Transfers from the EEA to the UK. Where the Controller or its data subjects are in the EEA, transfer of personal data from the EEA to the United Kingdom relies on the European Commission's adequacy decision for the United Kingdom in force from time to time. If no such adequacy decision is in force, the parties will, without undue delay, put in place the European Commission's Standard Contractual Clauses (controller-to-processor module, Commission Implementing Decision (EU) 2021/914) or another valid Article 46 safeguard.
(b) Onward transfers. For any onward transfer by the Processor to a sub-processor located outside the UK and the EEA, the Processor maintains a valid transfer mechanism for that data: the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs for UK-origin data, and the EU Standard Contractual Clauses for EEA-origin data, as applicable.
8. Data subject rights.
Taking into account the nature of the processing, the Processor assists you by appropriate technical and organisational measures, insofar as possible, to respond to data subject requests.
9. Assistance.
The Processor assists you in ensuring compliance with Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and information available to the Processor. Where assistance under clauses 8 or 9 requires significant resources, the Processor may recover its reasonable costs.
10. Personal data breach.
The Processor notifies you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your personal data. The notification describes, to the extent available, the nature of the breach (including, where possible, the categories and approximate number of data subjects and records concerned), its likely consequences, and the measures taken or proposed to address it.
11. Deletion and return.
The Service is designed so that personal data submitted by data subjects is deleted automatically after collection or expiry. On termination, or on your request, the Processor, at your choice, deletes or returns all remaining personal data and deletes existing copies unless required by law to retain it.
12. Audits.
The Processor makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate. The Processor may satisfy this obligation by providing relevant security certifications or independent audit or assessment reports it holds from time to time; on-site inspection applies only where those are insufficient to address a specific, reasonable concern, on reasonable notice (no more than once in any 12-month period except following a personal data breach), subject to confidentiality, and at your reasonable cost.
13. Liability.
Each party is liable to the other for loss it causes by breaching this DPA or applicable data protection law. Each party's total aggregate liability arising out of or in connection with this DPA shall not exceed £1,000,000 (one million pounds). Neither party is liable to the other for indirect or consequential loss, or for administrative fines or penalties imposed on that other party by a supervisory authority. Nothing in this DPA or the main agreement limits or excludes either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded by law. This clause governs liability for data-protection matters in place of any conflicting cap in the main agreement, and nothing in it limits a data subject's rights under Article 82 of the UK GDPR or EU GDPR (as applicable).
14. General.
This DPA is governed by the laws of England and Wales, without prejudice to any mandatory rights the Controller has under the Data Protection Laws. In the event of conflict between this DPA and the main agreement on data-protection matters, this DPA prevails.
15. Notices and survival.
Data-protection notices to the Processor (including a personal data breach, a sub-processor objection, or a request for assistance with data subject rights) may be sent to legal@fileseal.uk. Clauses 4 (confidentiality), 11 (deletion and return) and 12 (audits) survive termination of this DPA.
Annex 1: Description of processing
- Subject matter: provision of the FileSeal secure data-collection and document-transfer Service.
- Duration: the term of the main agreement.
- Nature and purpose: secure request, transfer, one-time collection and automatic deletion of documents and information between you and your data subjects.
- Types of personal data: as determined by you, e.g. names, contact details, dates of birth, addresses, identity documents and financial information, uploaded documents, and special category data where you choose to use the Service for it.
- Categories of data subjects: your clients, recipients and other individuals you request data from.
Annex 2: Authorised sub-processors
(Location = where personal data is processed/stored; entity = where the provider is incorporated.)
| Sub-processor | Purpose | Processing location | Provider entity |
|---|---|---|---|
| Vercel | Application hosting / compute | UK (London, lhr1) | US (Vercel Inc.) |
| Neon | Database | UK (London, eu-west-2) | US (Neon Inc.) |
| Vercel Blob | Encrypted file storage | UK (London, lhr1) | US (Vercel Inc.) |
| Resend | Transactional email (notifications/links, not the documents) | EU (Ireland) | US (Resend Inc.) |
| Auth0 (Okta) | Authentication for your account users | UK | US (Okta Inc.) |
| Sentry | Error monitoring (PII scrubbed; no document content) | EU (Germany) | US (Functional Software, Inc.) |
| Stripe | Billing of the Controller (not data-subject documents) | UK / EEA | US (Stripe, Inc.) |
All sub-processors process personal data in the UK or EEA; none process it in the United States. The "Provider entity" column notes US-incorporated providers (relevant to clause 7(b)), but no data is stored or processed outside the UK/EEA.
Annex 3: Technical and organisational measures
- Encryption: AES-GCM-256, applied client-side before transmission; for zero-knowledge links the key never reaches the Processor.
- Data in transit: TLS.
- Data residency: documents and collected data stored in the UK.
- Access control: authenticated, role-based access; least privilege.
- One-time access and automatic deletion: links are single-use; data is deleted after collection or expiry.
- Audit logging: access and collection events are logged.
- Monitoring: error monitoring with personal-data scrubbing.