Data Processing Agreement
Last updated: 06/08/2026 · Koru Solutions, registered in Estonia, company number 17373550
Draft pending legal review — and pending two infrastructure confirmations.
This document has not yet been reviewed by a solicitor. It also currently contains two items marked
[CONFIRM] that must be verified as actually true in production before this is published:
the storage/hosting location for Case Data, and the processing region for AI-assisted analysis.
See the "International transfers" and "Sub-processors" sections below.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms & Conditions between Koru Solutions ("we", "us", the "Processor") and the mediation practice identified on the applicable order or sign-up form ("you", the "Controller"). It applies wherever we process personal data on your behalf as part of the Service, as described in our Privacy Policy. Terms not defined here have the meaning given in the Terms & Conditions.
1. Scope & roles
For the account and case-management data you provide us directly, we act as an independent data controller (see the Privacy Policy). For your Clients' financial disclosure documents and information submitted through the Service, you are the data controller and we are your data processor. This DPA applies to that second category only.
2. Subject matter, duration & nature of processing
| Subject matter | Provision of the resolvio case- and document-management platform to the Controller. |
| Duration | For the term of the Terms & Conditions, plus the 60-day post-termination retention period described there. |
| Nature & purpose | Hosting, storage, AI-assisted analysis, organisation, and presentation of financial disclosure documents and data, so the Controller can conduct mediation case work. |
| Categories of data | Identity and contact details; case and party information; financial disclosure documents (e.g. bank statements, payslips, pension valuations, property valuations); financial figures relating to assets, income, liabilities, and expenses (which may include figures relating to a Client's children, e.g. child-related costs); usage and audit logs. |
| Data subjects | The Controller's Clients and their staff/authorised users; other parties to a mediation (e.g. a Client's former partner) where the Controller adds them to a case. |
3. Processor obligations
We will:
- process personal data only on your documented instructions (including as set out in the Terms & Conditions and this DPA), unless required to do otherwise by law — in which case we'll tell you before processing, unless the law prohibits this;
- ensure our staff who process the data are subject to a duty of confidentiality;
- implement appropriate technical and organisational security measures (see "Security measures" below);
- not engage a new sub-processor without giving you prior notice and the opportunity to object (see "Sub-processors" below);
- assist you in responding to data subject requests and meeting your other obligations under applicable data protection law, as described below;
- notify you without undue delay if we become aware of a personal data breach affecting your data;
- at your election, delete or return all personal data to you at the end of the provision of the Service, subject to the retention period in the Terms & Conditions and any legal retention obligations of our own;
- make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described below.
4. Sub-processors
You authorise us to engage the following sub-processors to help provide the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (Vertex AI) | AI-assisted analysis of uploaded financial documents | [CONFIRM] processing region — see "International transfers" |
| CloudConvert | Converting uploaded documents to PDF for storage and review | EU |
| Stripe | Subscription billing and payment processing | EU/UK & US |
| Amazon Web Services | Application hosting and document storage | [CONFIRM] hosting region — see "International transfers" |
We'll give you at least 30 days' notice before adding or replacing a sub-processor with access to your data (for example, via email or a notice on the Platform). If you reasonably object on data protection grounds within that period, we'll work with you in good faith to address the objection; if we can't resolve it, you may terminate the affected part of the Service without penalty.
5. International transfers
[CONFIRM] This section needs to be finalised against production configuration
before publishing. Our intention is for Case Data to be hosted and processed within the UK
and/or EU. Where a sub-processor transfers personal data outside the UK or EU, we will put in
place an appropriate transfer mechanism before that transfer occurs — such as the UK International
Data Transfer Addendum, EU Standard Contractual Clauses, or an applicable adequacy decision — and
will provide details on request.
6. Security measures
We currently apply the following measures to protect your data. This list will be kept accurate as our infrastructure changes — it should only ever describe what's actually in place, not what's aspirational:
- Encryption in transit (TLS) for all data sent to and from the Service;
- Role-based access control, so access to a case is limited to the staff and Clients assigned to it;
- A full audit trail of uploads, edits, approvals, and shares, including timestamps and the user responsible;
- Authentication and account-level access controls for all users;
[CONFIRM]encryption at rest, and the specific hosting region for stored documents — not yet verified against current production infrastructure at the time of writing.
7. Assisting with data subject rights & DPIAs
Where a data subject makes a request to you concerning their personal data (such as access, correction, or erasure), or where you need to carry out a data protection impact assessment or consult a regulator about the processing under this DPA, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us. We may charge a reasonable fee for assistance that goes materially beyond what the Service already provides you directly (for example, self-service export and deletion tools).
8. Breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting data we process on your behalf, with the information reasonably available to us at the time to help you meet your own notification obligations.
9. Return & deletion of data
This mirrors "Data on termination" in the Terms & Conditions: on termination of the Service, Case Data remains available for export for 60 days, after which it is permanently deleted, except for data we're required to retain for our own legal, accounting, or regulatory obligations.
10. Audit rights
On reasonable written notice, and no more than once per year (except following a personal data breach, or where required by a regulator), we will make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for, and contribute to, an audit — including an inspection — conducted by you or an auditor you mandate, subject to reasonable confidentiality and scheduling conditions.
11. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitation of liability set out in the Terms & Conditions.