Data Processing Agreement

Version 1.2 Β· Last updated: 29 Jul 2026

Article 28 UK GDPR terms for customers whose use of RedactProof involves us processing personal data on their behalf.

1. Parties and scope

This agreement applies where Popsall Ltd (company no. 16953262, registered in England and Wales, ICO registration ZC164232) processes personal data on behalf of a customer ("you") in connection with RedactProof.

It is incorporated into the RedactProof Terms of Service and applies to you from the moment you accept those Terms. No separate signature is needed. It also applies where an order form between us incorporates it, or where it is signed separately.

It exists because Article 28 UK GDPR requires a written contract between a controller and a processor. The commitments below have been published in our Terms of Service since February 2026; this document restates them in the form Article 28 requires.

On data protection, this agreement prevails over both the Terms of Service and the order form.

If your procurement process needs a countersigned copy, email hello@redactproof.com and we will provide one.

2. What we actually process for you

Read this section before the rest. RedactProof is unusual and the scope is narrow.

Document content is processed in your browser and does not reach us. Detection, redaction and export all run on your device. We do not receive, store or have access to the documents you redact, so for the overwhelming majority of what the product does we are not a processor of your personal data, because there is nothing for us to process.

Three things do reach us and are processed on your behalf:

  • Text extracted from a document, for detection. Only if a user enables the optional Precision detection engine (Pro and Team). Sent to Cloudflare Workers AI for inference, held in volatile memory for the duration of the request. Not written to disk, not retained as document content, never used to train models.
  • Redaction session records. Whenever a redaction session is saved. Coordinates, page index, PII category, exemption codes, confidence and which engine detected it.
  • Team activity records. On a Team plan, where an administrator can view team logs. Which user changed which setting, and when. Held so an administrator can supervise their own organisation.

Session records never contain the detected text. The server accepts only an allowlist of fields, so the words found in your document are stripped before storage rather than merely omitted by the client. A session record can say "a National Insurance number was found at these coordinates on page 4". It cannot say what that number was.

Verification certificates hold cryptographic hashes, not content. A hash of a file cannot be reversed to the file. We are controller of the certificate register rather than your processor, see section 3.

Document usage counting is deliberately blinded. Where a plan counts unique documents, the stored token is a one-way hash of your user ID, the document hash and the billing period. We can count how many distinct documents you processed. We cannot tell which they were.

3. Where we are a controller instead

For your account, billing and support data - name, email address, subscription state, audit events, support correspondence - Popsall Ltd is the controller, not your processor. That processing is governed by our Privacy Policy, not by this agreement.

The same applies to the verification certificate register. A certificate exists so a third party you sent a file to can check it independently, possibly years later. We determine that purpose and we operate the register, so we are its controller. It holds cryptographic hashes, counts of entities redacted, the signature, and the identifier the certificate was issued under. That identifier is a system-generated reference by default, not an email address. A user may choose to show their email instead, and Pro and Team users may choose to show no attribution at all. It holds no document content, and it is kept indefinitely for the reason in section 9.

This matters for who answers what. A subject access request about a RedactProof user account comes to us as controller. A request about the contents of a document you redacted has to go to you, because we do not hold it.

4. Details of processing (Article 28(3))

  • Subject matter. Provision of RedactProof to you under the Terms of Service.
  • Duration. For as long as your subscription is live, plus the retention periods in section 9.
  • Nature and purpose. Automated detection of potentially sensitive information, and recording what was redacted so a redaction can be evidenced.
  • Type of personal data. Any personal data present in text you submit to the optional Precision engine; and the categories of personal data recorded in session metadata.
  • Categories of data subject. Whoever appears in the documents you process. Typically your clients, employees, service users or third parties named in correspondence.

5. Our obligations

We will:

  1. Process personal data only on your documented instructions. Your use of the product, the settings you choose and this agreement are those instructions. If we believe an instruction breaches data protection law we will tell you.
  2. Ensure that anyone authorised to process it is bound by confidentiality.
  3. Keep appropriate technical and organisational measures (section 7).
  4. Not engage a sub-processor except as set out in section 6.
  5. Provide reasonable assistance, taking account of the nature of the processing, in responding to data subject requests. In practice this is short work: we do not hold document content, so most requests concern data we are controller for. Assistance beyond what is reasonable is chargeable at our standard rates, agreed in advance.
  6. Provide reasonable assistance with your obligations under Articles 32 to 36 - security, breach notification and data protection impact assessments - taking account of the information available to us, on the same basis.
  7. Delete or return personal data at the end of the service, as set out in section 9.
  8. Make available the information reasonably needed to demonstrate compliance with Article 28, and allow audits as set out in section 10.

6. Sub-processors

You give general authorisation for the sub-processor below. We will give at least 30 days notice before adding or replacing one, by email to your account address. If you reasonably object on data protection grounds, you may terminate the affected part of the service without penalty for the remainder of the term.

  • Cloudflare, Inc. Application hosting, database, object storage, and AI inference for the optional Precision engine. Global edge network, see section 8.

Stripe (payments), Resend (transactional email) and Google Workspace (business email) process account and billing data for which we are controller, not processor, so they are covered by the Privacy Policy rather than by this agreement.

7. Security

We hold Cyber Essentials certification, whole-organisation scope, certified 23 July 2026 and renewed annually. Measures include encryption in transit and at rest, access control on a least-privilege basis with MFA, and a documented incident response procedure reviewed six-monthly.

The strongest control is architectural rather than procedural: a compromise of our systems exposes no document content, because none is held.

You do not have to take that on trust. Our servers accept only these fields into a redaction record, and discard anything else the browser sends: pageIndex, x, y, width, height, rects, source, piiType, exemptionCodes, confidence, detectionSource, engine.

There is no field for the text that was found, so there is nowhere for it to be stored even in error. That is a filter applied on our side rather than a promise about what the application sends, which is the difference between a control and an intention.

8. International transfers

If a user enables the Precision detection engine, extracted text is processed by Cloudflare Workers AI and inference may occur at any Cloudflare data centre, including outside the UK and EEA. That transfer is from us to Cloudflare, and relies on Cloudflare's data processing terms, which incorporate the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and the EU-US Data Privacy Framework. Both are published, so you can read them without asking us:

There is no restricted transfer between you and us: both parties are in the UK, so no transfer agreement is needed for that leg.

You can prevent this transfer entirely, and show that you have. Precision is opt-in and off by default. A Team administrator can disable it as an organisation-wide policy from the team settings, which forces every member onto on-device detection and prevents any of them opting back in. The block is enforced on our servers when a detection request arrives, not merely hidden in the interface, so it cannot be bypassed by a member, a stale browser session or a modified client.

With that policy set, no extracted text leaves any user's device at any point and there is no international transfer to consider.

Changing that policy is recorded in your team audit log, with who changed it, when, and what it changed from and to. So the control is not only enforceable but evidenced - an administrator can show their own data protection officer the date the policy was set and that it has not moved since.

9. Retention, deletion and return

There is nothing to return. We never receive your documents, so no export at the end of the service is possible or necessary.

On termination we delete account data within 30 days, except:

  • billing records and transaction history, kept up to 7 years for tax and accounting;
  • server logs containing IP addresses or account identifiers, kept up to 90 days for security and abuse detection;
  • records needed for a pending dispute or legal claim, kept until it and any limitation period ends;
  • verification certificate records, kept indefinitely. A certificate exists so that someone you sent a redacted file to can check it later, possibly years later. Deleting the record would break every certificate already in a third party's hands, so these survive account deletion. They contain no document content. The identifier they carry is a system-generated reference by default; a user may choose to show an email address instead, and Pro and Team users may choose to show nothing at all.

10. Audit

We will respond to reasonable written questions about our processing, and provide our Cyber Essentials certificate, security documentation and this agreement's supporting detail on request. Where that is not sufficient for your obligations you may audit no more than once in any 12 months, on 30 days written notice, during business hours, at your cost, subject to confidentiality and without access to other customers' data.

We are a micro-business. Proportionate assurance is available quickly; an on-site audit programme is not something we can absorb repeatedly, which is why the documentation route is offered first.

11. Breach notification

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay, with the information reasonably required for your own regulatory assessment including under the UK GDPR. Our procedure is documented in our incident response playbook, which we will share on request.

12. General

This agreement is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of its courts. Liability under this agreement is subject to the limitations in the Terms of Service. Nothing here limits liability that cannot be limited by law.

Document control

  • Version 1.0, 22 February 2026. Data protection commitments first published, as part of the Terms of Service.
  • Version 1.1, 28 July 2026. Consolidated into a standalone Article 28 agreement.
  • Version 1.2, 29 July 2026. Published here and incorporated into the Terms of Service, so it applies without signature. Breach notification aligned to Article 33(2).