Legal

Data Processing Agreement

Last updated: June 2026

1. Scope and parties

This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Data Controller") and RegNexus Limited ("Data Processor"), registered in England and Wales, for the provision of the Lumen by RegNexus platform.

2. Definitions

Terms used in this DPA have the meanings given in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. "Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings defined therein.

3. Processor obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that persons authorised to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Not engage sub-processors without prior written authorisation from the Controller
  • Assist the Controller in responding to data subject requests
  • Delete or return all Personal Data upon termination of the agreement
  • Make available all information necessary to demonstrate compliance

4. Sub-processors

The following sub-processors are currently engaged:

Sub-processorPurposeLocation
Supabase Inc.Database & authenticationEU (eu-west-2)
Vercel Inc.Application hosting & CDNGlobal (edge)
Anthropic PBCAI content generationUnited States
OpenAI Inc.AI content generationUnited States

5. Security measures

The Processor maintains the following technical and organisational measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-Level Security (RLS) for multi-tenant data isolation
  • Hash-chained, immutable audit logs
  • Role-based access controls
  • Regular security assessments and dependency audits
  • Infrastructure hosted on SOC 2 Type II certified providers

6. International data transfers

Where Personal Data is transferred outside the UK/EEA (including to AI sub-processors in the United States), transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards. No personal data is sent to AI models without anonymisation measures.

7. Data breach notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach. The notification shall include the nature of the breach, categories of data affected, likely consequences, and measures taken to mitigate the breach.

8. Data subject rights

The Processor shall assist the Controller in fulfilling data subject rights requests including access, rectification, erasure, restriction, portability, and objection. The Platform provides data export functionality to support these obligations.

9. Audit rights

The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice and confidentiality obligations. The Processor shall provide reasonable assistance and access to relevant information.

10. Term and termination

This DPA remains in effect for the duration of the service agreement. Upon termination, the Processor shall delete or return all Personal Data within 30 days, except where retention is required by law or for regulatory compliance purposes.

11. Contact

For DPA enquiries, contact our Data Protection team at privacy@reg-nexus.com.