Data Processing Agreement
The terms on which HedgePoint processes personal data on behalf of enterprise customers, in compliance with the UK GDPR and Data Protection Act 2018.
At a glance
A plain-language summary. The full terms below are what legally apply.
- We process personal data only on your documented instructions
- Sub-processors are disclosed, with prior notice of any change
- Breaches are notified to you within 48 hours
- Data is deleted or returned on termination
- International transfers rely on approved safeguards (SCCs / DPF)
Scope & Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between Y-COMMERCIAL TECHNOLOGIES LIMITED t/a HedgePoint ™ (the "Processor") and the customer organisation (the "Controller") for the provision of the HedgePoint platform.
This DPA sets out the terms on which we process personal data on your behalf in compliance with the UK GDPR and the Data Protection Act 2018.
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1)
- Processing: Any operation performed on personal data, including collection, recording, storage, retrieval, and deletion
- Sub-processor: A third party engaged by us to process personal data on your behalf
- Data Subject: The individual whose personal data is being processed
Processor Obligations
- Process personal data only on documented instructions from the Controller
- Ensure personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Controller in responding to data subject rights requests
- Notify the Controller without undue delay upon becoming aware of a personal data breach
- Delete or return all personal data upon termination of the agreement
- Make available all information necessary to demonstrate compliance with GDPR obligations
Security Measures
We implement the following technical and organisational measures:
- AES-256 encryption at rest and TLS 1.3 in transit
- Tenant-level data isolation in our multi-tenant architecture
- Role-based access controls with principle of least privilege
- Comprehensive audit logging of all data access and modifications
- Regular security assessments and penetration testing
- Automated backup with encrypted off-site storage
- Incident response procedures with defined escalation paths
Sub-Processors
We use the following sub-processors. We will notify you before adding or replacing any sub-processor and give you the opportunity to object.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| AWS (Amazon Web Services) | Cloud hosting & storage | EU (Ireland) | EU Data Processing Addendum |
| Postmark | Transactional email | US | EU-US Data Privacy Framework |
| OpenAI | Document parsing AI | US | EU-US Data Privacy Framework, zero-retention API |
| Stripe | Payment processing | US / EU | PCI DSS Level 1, EU entity |
International Transfers
Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms. All sub-processors listed above operate under such safeguards.
Data Breach Notification
In the event of a personal data breach, we will notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach.
Contact
For DPA-related inquiries, contact our Data Protection Officer at info@hedgepoint.app.
Questions about this data processing agreement?
Reach our team at info@hedgepoint.app or write to C/O Smith Butler, Sapper Jordan Rossi Park, Otley Road, Baildon, West Yorkshire BD17 7AX, United Kingdom.
Y-COMMERCIAL TECHNOLOGIES LIMITED t/a HedgePoint ™ · Registered in England & Wales No. 10964842 · Last updated 1 March 2026