Legal

Data Processing Agreement

How we process personal data on your firm's behalf when you use the Reglo Services, under Article 28 of the UK GDPR.

Last updated: 23 July 2026·UK GDPR / Article 28

This is Reglo's standard Data Processing Agreement (the “DPA”). It applies to customers of the Reglo Services and forms part of the agreement between your organisation and us. If you need a countersigned copy for your records, email privacy@useReglo.com.

1. How this DPA applies

This DPA is entered into between Softwarised Solutions 5000 Ltd (trading as Reglo, company number 15917897) (“Reglo”, “we”, “us”) and the organisation that uses the Reglo Services (the “Customer”, “you”). It forms part of, and is subject to, the agreement under which we provide the Services (the “Agreement”).

It governs our processing of personal data that we process as a processor on your behalf when we provide the Services — for example the personal data of your staff, and any personal data contained in policies, records, or files (including files and matters accessed for reviews). It does not apply to personal data we process as a controller, which is covered by our Privacy Policy.

If there is any conflict between this DPA and the rest of the Agreement in relation to the processing of personal data, this DPA prevails.

2. Definitions

UK GDPR”, “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). “Customer Personal Data” means personal data we process on your behalf under the Agreement. “Sub-processor” means a third party we engage to process Customer Personal Data.

3. Roles and details of processing

You are the controller of Customer Personal Data and we are your processor. You are responsible for the accuracy, quality and lawfulness of Customer Personal Data and for having a lawful basis to provide it to us. The subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subjects are set out in Annex 1.

4. Our obligations

We will:

  • process Customer Personal Data only on your documented instructions (including as set out in the Agreement and your use of the Services), unless required to do otherwise by law — in which case we will inform you first, unless the law prohibits it;
  • ensure that people authorised to process Customer Personal Data are under an appropriate duty of confidentiality;
  • implement appropriate technical and organisational security measures (section 5 and Annex 2);
  • engage sub-processors only in line with section 6, and remain responsible for their performance;
  • assist you as described in section 8, notify you of personal data breaches under section 9, and return or delete Customer Personal Data under section 10;
  • not use AI providers to train their models on Customer Personal Data, and process it only to provide and support the Services.

5. Security measures

We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, the costs of implementation and the risk (UK GDPR Article 32). A summary is set out in Annex 2 and on our security page.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed at usereglo.com/subprocessors (Annex 3). We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable for their performance.

We will give you at least 30 days notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the Services.

7. International transfers

We host Customer Personal Data in the United Kingdom (AWS London, eu-west-2), and our AI inference runs in-region via Amazon Bedrock. Where a sub-processor processes Customer Personal Data outside the UK (see Annex 3), we put in place appropriate safeguards required by Data Protection Law — such as transfers to countries covered by UK adequacy regulations, or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures identified by a transfer risk assessment.

8. Assisting you

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you:

  • respond to requests from data subjects exercising their rights under Data Protection Law (we will also promptly forward any such request we receive directly);
  • meet your obligations on security, breach notification, data protection impact assessments, and prior consultation with the ICO (UK GDPR Articles 32–36).

9. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information you reasonably need to meet your own breach-notification obligations.

10. Return and deletion of data

On termination of the Services, or on your written request, we will delete or return Customer Personal Data and delete existing copies, unless we are required to retain it by law. Files and matters accessed for a review are processed only to provide that review and are not retained beyond that purpose. Routine backups are overwritten on a rolling cycle.

11. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are on reasonable prior notice, no more than once a year (unless required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. Where available, we may satisfy an audit request by providing our then-current security documentation or third-party assessment reports.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

13. Term, governing law and contact

This DPA applies for as long as we process Customer Personal Data under the Agreement. It is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales. Questions about this DPA, or requests for a signed copy, can be sent to privacy@useReglo.com.

Annex 1 — Details of processing

  • Subject matter: provision of the Reglo compliance Services.
  • Duration: the term of the Agreement, plus any period until data is deleted or returned under section 10.
  • Nature and purpose: hosting, monitoring, analysis, policy review, file review, attestation tracking, and evidence management, including AI-assisted processing with human review.
  • Types of personal data: identity and contact details, role and organisation, account and usage data, and any personal data contained in policies, records, attestations, and files or matters you submit or connect for review.
  • Categories of data subjects: your staff and contractors, and individuals referenced in the documents, records or files you process through the Services (which may include your clients).

The Services are not intended for special category or criminal-offence data; please do not submit such data unless we have agreed in writing.

Annex 2 — Technical & organisational measures

  • UK hosting (AWS London, eu-west-2); UK-region AI inference
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access, least-privilege controls, and multi-factor authentication for staff access
  • Network segmentation, secrets management, and audit logging
  • Patching, dependency monitoring, and vulnerability management
  • Documented incident-response, business-continuity, and backup procedures
  • Staff training on data protection and information security

Our current measures are described on our security page.

Annex 3 — Sub-processors

Our current sub-processors, their purpose and location are listed at usereglo.com/subprocessors, which forms part of this DPA. Change-notification and objection rights are described in section 6.

Last updated: 23 July 2026