Last updated: 23 June 2026
Data processing addendum (DPA)
This Data Processing Addendum ("DPA") forms part of, and is governed by, the Master Services Agreement ("MSA") between you ("Controller") and Rated Counsel Limited, trading as regSpace ("regSpace", "Processor") for the provision of the regSpace platform (the "Service"). It is intended to satisfy Article 28 of the UK GDPR and the EU GDPR. Terms not defined here have the meaning given in the UK GDPR and EU GDPR. Where this DPA and the MSA conflict on the processing of personal data, this DPA prevails.
regSpace company details: Rated Counsel Limited, trading as regSpace, company number 11812572, registered office 5 Golden Mede, Waddesdon, England, HP18 0NG. Our ICO registration is in progress and will be published here once issued.
1. Scope and roles
You are the Controller of personal data submitted to, or generated within, the Service. regSpace acts as your Processor for that data. For telemetry, security monitoring, billing, and operation of the Service itself, regSpace acts as an independent Controller on a limited basis, as described in our privacy policy.
2. Nature, purpose, and duration of processing
regSpace processes personal data only to provide the Service: ingesting your policy documents, monitoring primary-source regulators, generating regulatory intelligence outputs (draft regulatory intelligence for your legal review, not legal advice), and supporting review, complaints, and delivery workflows. Processing continues for the term of the MSA and for the post-termination export and deletion window in section 8.
3. Types of personal data and categories of data subject
Account and authentication data relating to your personnel authorised to use the Service; any personal data incidentally contained in submitted policies, registers, or regulator outputs; and contact and submission data of individuals who use a complaints or data-subject-request intake form you publish through the Service. regSpace discourages submission of special-category data and will flag suspected special-category content to you for removal.
4. Controller instructions
regSpace processes personal data only on your documented instructions. Your instructions are set by:
- this DPA and the MSA;
- the configuration choices you make in the portal settings, including data residency, connector configuration, complaints and intake settings, and notification routing;
- the sub-processors you approve under section 7, and your residency and model-key choices (for example, you may bring your own AI provider key so that model inference runs under your own account and data-processing terms; by default regSpace uses its own keys);
- any further written instructions you give, which the parties may agree to handle as a change under the MSA.
regSpace will tell you if, in its opinion, an instruction infringes the UK GDPR, the EU GDPR, or other applicable data protection law, and may suspend the affected processing until the instruction is resolved.
5. Processor obligations
- Process personal data only on your documented instructions.
- Ensure personnel authorised to process personal data are bound by an enforceable duty of confidentiality and access it only on a need-to-know basis.
- Implement and maintain the technical and organisational measures set out in the Annex below and on our security page.
- Engage only approved sub-processors under section 7, on written terms that flow down obligations no less protective than this DPA.
- Assist you, taking into account the nature of the processing and the information available, with your obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments, and prior consultation).
- Assist you in responding to data-subject requests under section 6.
- Notify you of a personal-data breach without undue delay under section 9.
- Make available the information needed to demonstrate compliance, and allow for and contribute to audits under section 7.
6. Assisting with data-subject rights (Art 28(3)(e))
Taking into account the nature of the processing, regSpace will assist you by appropriate technical and organisational measures, so far as possible, to fulfil your obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection).
- Where a data subject contacts regSpace directly about data regSpace processes on your behalf, regSpace will not respond on the substance and will forward the request to you without undue delay, and in any event within five (5) business days of identifying that it relates to you.
- Where you ask regSpace to help locate, export, correct, restrict, or delete a data subject's personal data, regSpace will provide that assistance within ten (10) business days of a complete written request, unless you and regSpace agree a shorter period for an urgent regulatory deadline.
- This assistance is provided at no separate charge, except where a request is manifestly unfounded, excessive, or repetitive, in which case regSpace may agree a reasonable cost with you before proceeding.
7. Sub-processors and audit (Art 28(3)(f))
You authorise regSpace to engage the sub-processors listed on our sub-processor page. regSpace imposes data protection terms on each sub-processor that are no less protective than this DPA, and remains fully liable to you for each sub-processor's performance.
regSpace will give you prior written notice (by email to your administrators and an update to the sub-processor page) at least thirty (30) days before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, the parties will work in good faith to resolve the objection; if it cannot be resolved, you may terminate the affected part of the Service.
To demonstrate compliance with this DPA, regSpace will:
- provide, on reasonable written request, the information reasonably necessary to show compliance with Article 28;
- allow you, or an independent auditor you mandate who is bound by confidentiality, to inspect the relevant controls no more than once per year, on at least thirty (30) days' notice, during business hours and without unreasonable disruption; and additionally where required following a personal-data breach affecting your data or on the binding instruction of a supervisory authority;
- satisfy an audit request by providing a current third-party assessment or report (for example, a SOC 2 report once available, or regSpace's internal SOC 2 control mapping in the interim) in lieu of an on-site inspection, where that report reasonably addresses the scope of your request.
You bear the cost of an audit you initiate beyond regSpace's standard security pack, unless the audit reveals a material breach of this DPA by regSpace.
8. International transfers
Where a transfer of personal data outside the UK or EEA occurs, the parties rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses for UK transfers, and on the EU Standard Contractual Clauses for EEA transfers, in each case supplemented by the Transfer Impact Assessment that regSpace maintains and will provide on request. The regSpace application and document storage are hosted in Google Cloud europe-west2(London), the database is hosted in AWS eu-west-2(London, managed by Neon, Inc.), and your data is stored there. AI drafting calls are made to the model providers in their own regions, which sit outside that hosting region: Claude through Google Vertex AI in the EU (europe-west1), Gemini on Vertex’s global endpoint, and Anthropic’s direct API for some deployments; each is listed as a sub-processor with its own transfer safeguards. The residency region recorded against your tenant governs the region you are provisioned into as further regions come online.
9. Return or deletion of data (Art 28(3)(g))
On expiry or termination of the MSA, regSpace will, at your written option made within thirty (30) days of termination, return or delete all personal data it processes on your behalf:
- Export: on request, regSpace will make your data available for export in a structured, machine-readable format (CSV or JSON) before deletion.
- Deletion: regSpace will delete the personal data, and instruct sub-processors to delete their copies, within thirty (30) days of the export being completed (or, where no export is requested, within thirty (30) days of termination), and will provide written confirmation of deletion on request.
- Legal-retention minimum: regSpace may retain personal data only to the extent, and for as long as, required by applicable law, in which case it will keep that data isolated, protect it under this DPA's measures, and process it only as required by that law.
10. Personal-data breach notification
regSpace will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations, and will keep you updated as the investigation progresses.
11. Liability
Liability under this DPA is subject to the limitation-of-liability provisions of the MSA.
12. Contact
For DPA-related matters, contact hello@regspace.ai.
Annex - Technical and organisational measures
regSpace maintains the following technical and organisational measures. These reflect the controls in operation today; our security page describes the wider security program, including planned controls clearly labelled as such.
- Tenant isolation: each customer's data is held in its own dedicated Postgres schema, so one customer's queries cannot reach another customer's data.
- Constrained request-path role: the request-handling path runs as a restricted database role that cannot alter schema, truncate tables, or act as a superuser, limiting the blast radius of any application fault.
- Encryption at rest with per-tenant keys: data is encrypted at rest using Google Cloud KMS, with per-tenant customer-managed encryption keys (CMEK) enforced at the storage-bucket level.
- Encryption in transit: TLS is enforced on all hosts.
- Tamper-evident audit trails: material actions are recorded in append-only, hash-chained audit trails (for example, the risk-history record chain), so any later alteration is detectable.
- IP minimisation in complaints intake: a keyed HMAC hash of the submitter's IP address is the only form retained, and it is kept for abuse prevention.
- Authentication and provisioning: single sign-on via SAML and OIDC, and SCIM user provisioning (Okta, Microsoft Entra, Google Workspace, OneLogin, JumpCloud, and a generic connector), so you control access from your own identity provider.
- Access control and confidentiality: least-privilege, role-based access for regSpace staff, who are bound by confidentiality obligations and access customer data only when needed to operate or support the Service.