Skip to main content

Data Processing Agreement

Last updated: 15 August 2026

About this Agreement

This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Terms of Service between Threadsovereign Ltd (“Threadsovereign”) and each Customer. It sets out the obligations of both parties in respect of personal data processed by Threadsovereign on behalf of the Customer, in compliance with UK GDPR Article 28 and the Data Protection Act 2018.

By accepting the Terms of Service, the Customer agrees to this DPA. No separate signature is required unless explicitly requested.

1. Introduction

This DPA governs the processing of personal data by Threadsovereign as a data processor acting on behalf of the Customer (data controller) in connection with the provision of the Threadsovereign Platform.

Both parties agree to comply with all applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any successor legislation.

2. Definitions

Terms not defined here have the meanings given in the Terms of Service or UK GDPR:

  • “Controller” — the Customer, who determines the purposes and means of processing
  • “Processor” — Threadsovereign Ltd, who processes personal data on behalf of the Controller
  • “Data Subject” — the individual whose personal data is processed (e.g. project team members, residents, contractors)
  • “Personal Data” — any information relating to an identified or identifiable natural person
  • “Processing” — any operation performed on personal data
  • “Sub-processor” — any third party engaged by Threadsovereign to process personal data
  • “Security Incident” — any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data

3. Roles of the Parties

The parties acknowledge that:

  • The Customer is the Data Controller for personal data relating to the Customer's employees, sub-contractors, residents, clients and any other third parties whose personal data the Customer uploads or generates in the Platform
  • Threadsovereign is the Data Processor for such personal data
  • Threadsovereign is a Data Controller in its own right for personal data processed for its own legitimate business purposes (account management, billing, security) — see the Privacy Policy

4. Scope and Nature of Processing

The following table sets out the details of processing as required by UK GDPR Article 28(3):

ItemDetail
Subject matterProvision of the Threadsovereign Building Safety Compliance Platform
Duration of processingFor the duration of the Terms of Service plus any SI 2024/41 keep window, legal hold, or configured document retention (7–25 years)
Nature and purposeStorage, retrieval, display, export and deletion (where legally permitted) of building safety project data and personnel data, to enable the Customer to manage BSA 2022 compliance obligations
Types of personal dataNames, email addresses, job titles, phone numbers, user activity logs, building addresses, PEEP mobility/health fields, complaint and safety-concern content, and any personal data included by the Customer in uploaded documents or project records
Categories of data subjectsThe Customer's employees and contractors; Residents of buildings managed via the Platform; Clients and their representatives; Other project stakeholders
Special category dataPermitted only as instructed: PEEP mobility/health data (UK GDPR Art.9). Customer must have an Art.6 basis and an Art.9 condition. Optional timestamps: resident_consent_at (Art.9 processing) and fra_share_consent_at (2025 FRA-share). Neither is a save-gate. Counsel must confirm the Art.6/9 pair. Other special category data is not permitted without a written instruction.

5. Threadsovereign's Obligations as Processor

Threadsovereign will:

  • Process personal data only on the documented instructions of the Controller, unless required by law
  • Ensure that all persons authorised to process personal data are bound by appropriate confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 8)
  • Not engage any sub-processor without prior consent (general authorisation as set out in Section 7)
  • Assist the Controller in fulfilling its obligations regarding Data Subject rights requests (see Section 10)
  • Assist the Controller with security, breach notification, DPIAs and prior consultation as required
  • Delete or return personal data at the end of the contract, subject to mandatory retention (see Section 12)
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA
  • Notify the Controller immediately if any instruction would violate applicable data protection law

6. Customer's Obligations as Controller

The Customer is responsible for:

  • Ensuring a lawful basis exists for all personal data uploaded to the Platform
  • Providing appropriate privacy notices to all data subjects whose personal data is entered into the Platform
  • Ensuring that personal data is accurate, adequate and not excessive
  • Ensuring an Article 6 basis and an Article 9 condition exist before recording PEEP health/mobility data, and not uploading other special category data without a written instruction
  • Complying with all applicable data protection law in its capacity as data controller

7. Sub-processors

The Customer provides general authorisation for Threadsovereign to engage sub-processors, subject to the conditions below. Threadsovereign's current authorised sub-processors are:

Sub-processorLocationPurposeTransfer Safeguard
Supabase Inc.Production and staging United Kingdom / EU (eu-west-2). Former production us-east-1 is parked and not in live use.Postgres, Auth, and some object storageUK adequacy for EU/UK hosting
Vercel Inc.Function region London, United Kingdom (eu-west-2 / lhr1). Vercel’s control plane and global CDN may still process connection metadata outside the UK.Application hosting and serverless functionsUK adequacy for function execution in London; UK–US Data Bridge and/or UK IDTA / SCCs where Vercel or a connected US service still processes data
Vercel Blob (Vercel Inc.)Production Blob store London, United Kingdom (lhr1) — confirmed 2026-08-15 via Vercel Blob store list. Not the same setting as Function Regions; this store happens to match. A separate staging Blob store exists in iad1 and is not used for production files.Uploaded document bytes (golden-thread files)UK adequacy for the London production store. Vercel’s control plane may still process connection metadata outside the UK.
Stripe, Inc.US / EUSubscription billing and invoicesUK–US Data Bridge and/or UK IDTA / SCCs; Stripe DPA
ResendUSTransactional emailUK–US Data Bridge and/or UK IDTA / SCCs
Twilio Inc.USSMS notifications (Professional+ when configured)UK–US Data Bridge and/or UK IDTA / SCCs
Upstash Inc.US / EUAPI rate limitingUK–US Data Bridge and/or UK IDTA / SCCs
Functional Software, Inc. (Sentry)US / EUApplication error monitoring (when DSN configured)UK–US Data Bridge and/or UK IDTA / SCCs
Inngest Inc.USBackground job scheduling (crons, retries)UK–US Data Bridge and/or UK IDTA / SCCs
DocuSign Inc.US / EUHandover / formal sign-off envelopes (when configured)UK–US Data Bridge and/or UK IDTA / SCCs
Google LLC / Microsoft CorporationUS / EUOptional social login and calendar OAuthProvider DPAs; UK–US Data Bridge and/or UK IDTA / SCCs
OpenAI, L.L.C. or Anthropic PBCUSOptional Professional+ AI document extraction (advisory only; FRA scan gated off)UK–US Data Bridge and/or UK IDTA / SCCs; no compliance judgement by the model
Autodesk Inc.USOptional Enterprise CDE import (Revit / AutoCAD / ACC)UK–US Data Bridge and/or UK IDTA / SCCs
PostHog Inc.EU (eu.i.posthog.com by default)Product analytics and optional session replay (consent-gated)UK adequacy for EU hosting when the EU cloud is used

Threadsovereign will provide at least 14 days' prior written notice of any intended change to the list of sub-processors. The Customer may object in writing within 14 days. If the Customer objects and the parties cannot agree, the Customer may terminate the Agreement with 30 days' notice without penalty.

Threadsovereign will ensure all sub-processors are bound by data processing obligations equivalent to those in this DPA before processing commences.

8. Security Measures

Threadsovereign implements the following technical and organisational measures to ensure an appropriate level of security (UK GDPR Article 32):

  • Encryption in transit: TLS 1.2+ for all data in transit
  • Encryption at rest: AES-256 encryption via Supabase/Vercel infrastructure
  • Access controls: Role-based access control (RBAC) with Row Level Security (RLS) at the database level
  • Authentication: Multi-factor authentication available to all users and enforced for platform_admin (AAL2); auth rate limiting (not a published 5-failure / 30-minute lockout)
  • Audit logging: Activity logs of significant actions that application users cannot edit or delete in the product UI (supports SI 2023/907 reg.7(1)(f); not a claim that underlying storage can never be touched for support, legal hold, or security)
  • Data minimisation: Access to personal data is limited to personnel who require it for service delivery
  • Incident response: Documented security incident response procedure
  • Security headers: HTTP security headers (HSTS, CSP, X-Frame-Options) on all responses
  • Vulnerability management: Regular dependency updates and security assessments

9. Data Breach Notification

In the event of a Security Incident involving personal data processed under this DPA, Threadsovereign will:

  • Notify the Customer without undue delay and, where feasible, within 48 hours of becoming aware of the incident
  • Provide sufficient information to enable the Customer to meet its own 72-hour ICO notification obligation
  • Include in the notification: the nature of the incident; categories and approximate number of records affected; likely consequences; measures taken or proposed
  • Co-operate with the Customer to investigate and mitigate the incident

Notification should be sent to the Customer's designated contact. Breach notifications from Threadsovereign will be sent from security@threadsovereign.io.

10. Data Subject Rights Requests

Where Threadsovereign receives a request directly from a data subject relating to personal data processed under this DPA, Threadsovereign will:

  • Forward the request to the Customer within 3 business days
  • Not respond to the data subject directly except as instructed by the Customer
  • Assist the Customer by providing technical means to extract, correct, restrict or delete data as instructed

The Customer is responsible for responding to data subject rights requests within the statutory time limit (30 calendar days). Threadsovereign will provide reasonable technical assistance at no additional charge unless the request is disproportionately burdensome.

Note: Records still inside a SI 2024/41 keep window, legal hold, or the Customer's configured retention period cannot be deleted on request. Threadsovereign will provide a written explanation of what cannot be deleted and the legal basis (BSA s.88; SI 2023/907 reg.7; SI 2024/41 Sched.1 — not BSA ss.79–82 as a 15-year clock).

11. International Data Transfers

Transfers of personal data to sub-processors outside the UK are covered by the safeguards detailed in Section 7. Threadsovereign will not transfer personal data to any country or territory outside the UK unless an appropriate transfer safeguard is in place (adequacy decision, UK–US Data Bridge or UK International Data Transfer Agreement/SCCs).

12. Retention and Deletion

On expiry or termination of the Terms of Service, Threadsovereign will (at the Customer's choice):

  • Export all Customer Data in a structured, machine-readable format within 30 days; or
  • Confirm secure deletion of all Customer Data within 90 days of termination

Exception — golden-thread keep windows: Occupied records named in SI 2024/41 Schedule 1 are kept for the windows in that Schedule (typically 7 years; 5 years for BSA s.96 contravention notices). Other golden-thread documents follow the Customer's configured retention (default 7 years, maximum 25). BSA ss.79–82 are the building assessment certificate regime, not a 15-year keep-everything duty. Threadsovereign will keep those records securely and make them accessible to the Customer or a competent authority upon lawful request.

13. Audit Rights

The Customer has the right to audit Threadsovereign's compliance with this DPA. Threadsovereign will:

  • Provide all information reasonably requested to demonstrate compliance
  • Allow audits by the Customer or their appointed auditor, subject to reasonable notice (at least 10 business days), confidentiality obligations, agreement on scope, and reasonable cost-sharing
  • In lieu of a full on-site audit, Threadsovereign may provide written answers, architecture summaries, and (when they exist) a Cyber Essentials certificate ID or an external penetration-test summary. Threadsovereign does not currently hold a SOC 2 report. Cyber Essentials basic has been applied for (2026-08-15). Not certified until an IASME certificate ID exists. We do not claim certification on these pages.

14. Liability

Threadsovereign's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.

Where a data subject brings a claim for compensation and both parties are responsible for the same damage, each party is responsible for the part of the damage it caused. Either party may claim against the other for contribution in proportion to their respective responsibility.

15. Termination

This DPA terminates automatically on expiry or termination of the Terms of Service, subject to Section 12 (retention of mandatory BSA 2022 records) and any provisions that expressly survive termination.

Questions about this DPA

Contact: privacy@threadsovereign.io

Customers requiring a signed DPA for their own records can request a PDF copy with their account details by emailing the above address.