Uploaded PDFs (P60, PSS, chargeable-event certificates) are parsed, then permanently deleted from UK-region object storage 24 hours later. An hourly cron enforces the cutoff; nothing carries over between paraplanner sessions.
ParaplanAI · legal · DPA
Data Processing Agreement.
The Article 28 (UK GDPR) contract between your firm (controller) and ParaplanAI (processor). Required if your firm uploads any personal data about end clients — typically anonymised in our calculation and audit flow, but the DPA also covers your client's name (shown on the rendered PDF annex) and any free-text fields that carry further PII.
Pre-launch legal status. This page is a summary, not an executed Article 28 agreement. Do not upload identifiable client data unless your firm has received a separately executed DPA naming the operator and service address.
Headline terms
- Roles. Your firm is the data controller. ParaplanAI is the data processor.
- Purpose limitation. We process client personal data only to provide the calculator + audit-trail service you have subscribed to. No client-data analytics, no AI training, no resale.
- Sub-processors. The current list is in /privacy §4. We notify you 30 days before adding any new sub-processor; you can object.
- Security. AES-256 at rest, TLS 1.3 in flight, RLS on every tenant-scoped table. See /security.
- Retention. Uploaded source PDFs are permanently deleted 24 hours after upload by an hourly automated job. As controller, you set how long finalised calculations are kept (six years by default) and can delete any client, policy or calculation on demand; drafts you never finalise are removed after 90 days. Output PDFs are kept with their calculation. See /data-minimisation.
- International transfers. We do not transfer client personal data outside the UK / EU. Document extraction and PDF rendering are processed in-region; only billing data reaches our international payments processor. See /privacy §2.3 + §5.
- Breach notification. As processor, we notify the affected controller without undue delay and support its Article 33 assessment. For account data where we are controller, we notify the ICO within 72 hours where legally required.
- Sub-processor audit rights. Annual right of access to our latest controls report + sub-processor DPAs.
- Return / deletion on termination. Within 30 days of subscription end, we export your firm's calc audit trail (JSONL) and delete operational data per the retention schedule in /privacy §6.
Retention schedule
The numbers below are the operative retention horizons for personal data your firm passes to ParaplanAI. They are the same numbers documented in /privacy §6 and /data-minimisation — single source of truth across the three pages.
Clients, policies and calculations are yours to delete — one click, whenever you want. You hold your own FCA record; we never force a period on you. Finalised calculations you keep are auto-retained for the window your firm sets (six years by default), then deleted. Drafts you never finalise are removed after 90 days.
The compliance annex you download stays available so it can be re-fetched without re-running the calc. It is kept alongside its calculation under your firm’s retention policy, and goes the moment you delete the record — export it first if you need a copy.
See the data-minimisation page → /data-minimisation.
Execution copy
The execution copy is being held from launch until solicitor review is complete and the operator’s legal name and service address are included. To request the approved version when available, email info@paraplanai.co.uk with your firm name and primary contact. Do not treat this summary as a signed contract or begin uploading identifiable client data in the meantime.
If your firm requires our DPA to be cross-signed onto your standard supplier contract instead, reply to the email above with your template attached and we'll review within 5 business days.
See also
- /privacy → — controller-side personal data, retention, sub-processors
- /data-minimisation → — what we hold, what we don't, and how long for
- /terms → — commercial terms, liability cap, billing
- /security → — controls + breach-notification commitment
