Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Ferrith Ltd, company number 16623234, of 11 Laura Place, Bath, United Kingdom, BA2 4BL ("Ferrith", the processor) and the subscribing organisation (the "Customer", the controller) under the Terms of Service. It applies wherever Ferrith processes personal data on the Customer's behalf in providing the Service, and is written to satisfy Article 28(3) UK GDPR.
1. Definitions and roles
- "Customer Personal Data" means personal data processed by Ferrith on the Customer's behalf: the content of the Customer's Workspace (conversations, documents, agents, workflows, analysis grids and their configuration) and the account data of the Customer's Members processed to run the Workspace (names, email addresses, sign-in and administration records).
- For Customer Personal Data, the Customer is the controller and Ferrith is the processor. Data Ferrith processes for its own purposes, the buyer's billing data, Ferrith's own service records, is described in the Privacy notice, where Ferrith is the controller; it is not governed by this DPA.
- "Data Protection Law" means UK GDPR and the Data Protection Act 2018, as amended.
- Annex I describes the processing; Annex II describes the technical and organisational measures.
2. Instructions — Article 28(3)(a)
- Ferrith processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA, and the Customer's and its Members' use of the Service's controls (what is uploaded, what is asked, what is configured, what is deleted) together constitute those instructions.
- Ferrith does not use Customer Personal Data to train AI models and does not use it for any purpose other than providing the Service. There is no secondary use: no advertising, no profiling, no sale, no sharing beyond the sub-processors in section 6.
- If Ferrith considers an instruction infringes Data Protection Law, it will tell the Customer without undue delay (and may pause the instruction until resolved).
- If law requires Ferrith to process outside the Customer's instructions, Ferrith will inform the Customer before processing unless that law forbids it.
3. Confidentiality — Article 28(3)(b)
Ferrith ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to those who need it to provide and support the Service.
4. Security — Article 28(3)(c)
Ferrith implements and maintains the technical and organisational measures in Annex II, and keeps them under review so they remain appropriate to the risk under Article 32. Ferrith may improve the measures, but not in a way that materially reduces the protection of Customer Personal Data during a subscription.
5. Special category and privileged material
The Customer decides what enters its Workspace, and Ferrith's customers include organisations whose work is sensitive by nature, legal matters (including material subject to legal professional privilege), health information, casework about individuals. The Service applies the Annex II measures to all Customer Personal Data, without needing to be told which content is special; the Customer remains responsible for having a lawful basis (and, where needed, an Article 9 condition) for the personal data it chooses to process.
6. Sub-processors — Article 28(3)(d)
- The Customer gives general written authorisation for the sub-processors Ferrith engages, subject to this section.
- The current list is published at Sub-processors, with a dated change log. At the date of this DPA the sub-processors of Customer Personal Data are Civo (UK cloud infrastructure hosting the Service) and Microsoft (Azure Communication Services — relay of sign-in email to Members: addresses and links, never Workspace content). Stripe processes billing data as described in the Privacy notice; billing data is not Customer Personal Data under this DPA.
- Notice of changes. Ferrith publishes any intended addition or replacement on that page at least 30 days before the new sub-processor processes Customer Personal Data. The page's feed lets the Customer subscribe to changes; the published page and its change log are the agreed notice mechanism.
- Right to object. If the Customer reasonably objects on data-protection grounds within the notice period, the parties will discuss in good faith; if the objection cannot be resolved, the Customer may terminate the affected part of the Service (or, where it cannot be separated, the Agreement) with a proportionate refund of prepaid fees for the terminated part.
- Ferrith imposes on every sub-processor data-protection obligations materially equivalent to this DPA, and remains fully liable to the Customer for its sub-processors' performance.
- For completeness: Ferrith's inference, key management and identity systems are self-hosted on Ferrith's own UK infrastructure, there is no 3rd party AI-model provider, key-management service or identity provider acting as a sub-processor. If the Customer adopts the bring-your-own-key option, the Customer's chosen key vault is the Customer's own supplier, not Ferrith's sub-processor.
7. Assistance with data subjects' rights — Article 28(3)(e)
- The Service itself is the first line of assistance, and its tools operate under the Customer's own control: Workspace admins can permanently erase a Member and their personal data from the Workspace; the Owner can export the Workspace's data in readable form; content can be deleted by those the Customer authorises.
- Taking into account the nature of the processing, Ferrith will assist the Customer with appropriate technical and organisational measures, so far as reasonably possible, in fulfilling the Customer's obligation to respond to data subjects' requests under Articles 12–23. Where a request reaches Ferrith directly, Ferrith will pass it to the Customer without undue delay and will not respond substantively except on the Customer's instruction or where law requires.
8. Assistance with security, breach notification and DPIAs — Article 28(3)(f)
- Ferrith assists the Customer, taking into account the nature of the processing and the information available to Ferrith, with the Customer's obligations under Articles 32–36.
- Personal data breach. Ferrith notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it. Because full facts are rarely available immediately, notification is phased in line with Article 33(4): the first notice states what is known, the nature of the breach, the data and Workspaces concerned so far as known, and the measures taken, and Ferrith supplements it as investigation continues. Notification is made to the Owner and to any breach contact the Customer has registered with support.
- DPIAs. Ferrith will provide reasonable assistance with data protection impact assessments and prior consultation concerning the Service in the first instance through the documentation on this site (the Trust pages, this DPA and its annexes), supplemented on request through support.
9. Return and deletion — Article 28(3)(g)
- Return. Throughout the subscription the Owner can export the complete Workspace, content and records, in readable form, directly from the product, at no extra charge. The Customer should export before the subscription ends.
- Deletion. When the subscription ends, the Workspace enters a 15-day recovery window (re-subscribing restores it intact). After the window, Ferrith permanently deletes the Workspace: its data is deleted and the Workspace's encryption keys are destroyed, rendering Customer Personal Data irrecoverable everywhere it was stored, backups included. Members' accounts in the sign-in system are deleted with it.
- Ferrith retains after deletion only what Data Protection Law or other law requires it to retain (and its own controller-side records described in the Privacy notice), and confirms deletion in writing on request.
10. Audit and information — Article 28(3)(h)
- Ferrith makes available the information necessary to demonstrate compliance with Article 28: this DPA and its annexes, the Trust pages and Sub-processors list, and on request through support Ferrith's standing evidence pack, including a completed security questionnaire in the Customer's or an industry-standard format.
- Where that information does not reasonably satisfy the Customer's obligations, the Customer (or an independent auditor bound by confidentiality, not a competitor of Ferrith) may audit Ferrith's compliance with this DPA: on at least 30 days' written notice, during business hours, no more than once in any twelve-month period (except following a personal data breach affecting the Customer, or where required by a supervisory authority), at the Customer's cost, and in a manner that does not give access to any other customer's data or disrupt the Service.
- Findings are confidential and used only to verify compliance.
11. International transfers
Customer Personal Data is hosted and processed in the United Kingdom. Workspace content, AI inference, encryption keys and the sign-in system all remain on UK infrastructure operated by Ferrith. The one qualification: sign-in email to Members is relayed by Microsoft Azure Communication Services, which sees addresses and links only. Ferrith will not otherwise transfer Customer Personal Data outside the UK without ensuring a lawful transfer mechanism and updating the published list.
12. Term, liability and precedence
- This DPA applies for as long as Ferrith processes Customer Personal Data, and section 9 survives the end of the Agreement until deletion is complete.
- Liability under this DPA is subject to the limitations in the Terms of Service, save where Data Protection Law does not permit them.
- If this DPA conflicts with any other part of the Agreement regarding the processing of personal data, this DPA prevails.
Annex I — the processing
| Subject matter | Provision of the Ferrith service: a private AI workspace for the Customer's organisation |
| Duration | The subscription term, plus the 15-day recovery window and deletion (section 9) |
| Nature and purpose | Hosting, storage, encryption, retrieval and search, AI inference over Workspace content at Members' instruction, workflow automation, display, export, deletion |
| Categories of data subjects | The Customer's Members (workspace users); individuals whose personal data appears in content the Customer chooses to process |
| Categories of personal data | Members: name, email address, sign-in and administration records. Content: whatever personal data the Customer's documents and conversations contain which, at the Customer's discretion, may include special category data and material subject to legal professional privilege (section 5) |
| Special category data | Processed only as contained in Customer content, at the Customer's discretion, under section 5 |
Annex II — technical and organisational measures
- Encryption at rest, per workspace. Every workspace's content is encrypted at rest (AES-256-GCM) with keys unique to that workspace, held in a key store on Ferrith's UK infrastructure. Destroying a workspace's keys renders its data and every backup of it unreadable, which is how deletion is enforced (section 9).
- Bring your own key (optional). A Customer may hold the workspace's key-encryption key in its own vault. The Customer can then revoke Ferrith's access, after which the workspace's content becomes unreadable to Ferrith within minutes.
- Honest access model. Ferrith operates the Service, and the Service decrypts content at request time to answer Members' requests so Ferrith's protections are engineered controls, not impossibility: operator access to production is restricted to named staff with multi-factor authentication, every use of a workspace's key is logged, and administrative actions are recorded in an audit trail. (With bring-your-own-key, measure 2 adds genuine customer control on top.)
- Encryption in transit. TLS for all traffic between Members and the Service and between the Service's components across networks.
- Isolation between customers. Every workspace's data is segregated by workspace identity at every layer, encrypted under different keys, and every query in the Service is scoped to a single workspace by construction.
- UK-resident processing, self-hosted core. Content, inference, key management and identity run on UK infrastructure Ferrith operates. Prompts and content are never sent to third-party AI providers; the AI models run on Ferrith's own hosted hardware.
- Search-index posture. To make content searchable, the Service stores derived search structures (embedding vectors, and keyed hashes of terms under per-workspace secrets) alongside the encrypted text. These derivations are not readable as text and are keyed or opaque, but they are not themselves encrypted in the way the content is; this is a deliberate, documented design bound by the same isolation and access controls.
- Data minimisation in operations. Service logs and audit records carry metadata only and never message or document content, with the retention windows published in the Privacy notice.
- Personnel and process. Confidentiality obligations for all staff (section 3); least-privilege access; documented breach-response procedure supporting the 48-hour commitment (section 8); backups of the service's stores with restore procedures, subject always to measure 1's guarantee that key destruction survives backups.
- Resilience and testing. Health-monitored infrastructure, tested restore procedures, and security review of changes to the measures above.
Versions
| Version | Effective | Status | What changed |
|---|---|---|---|
| v1.0 | 27 Aug 2026 | Current | Initial version. |