Legal

Data Processing Agreement

How we process personal data on your behalf, as your processor.

Draft pending legal review. This DPA is a working draft and has not yet been reviewed by qualified counsel. For a signed, countersigned DPA, contact dd@sosorry.co.uk.

Last updated: 1 June 2026

This Data Processing Agreement (the “DPA”) forms part of the agreement between you (the “Customer”) and DealBook Ltd, a company registered in England (“DealBook”, “we”, “us”), under which DealBook provides its AI due-diligence service for private funds (the “Service”). It governs the processing of personal data carried out by DealBook on the Customer’s behalf and is designed to satisfy Article 28 of the UK GDPR and the EU GDPR.

1. Definitions

Terms used in this DPA have the meanings given to them in Article 4 of the UK GDPR and the EU GDPR. In particular:

  • Controller— the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor— a natural or legal person which processes personal data on behalf of the controller.
  • Personal data— any information relating to an identified or identifiable natural person (a “data subject”).
  • Processing— any operation performed on personal data, whether or not by automated means, such as collection, storage, use, retrieval, disclosure, or erasure.
  • UK GDPR and EU GDPR— respectively, the retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of England and Wales, and Regulation (EU) 2016/679 as it applies in the EEA; together with the UK Data Protection Act 2018 where applicable.
  • Sub-processor— any processor engaged by DealBook to process personal data on the Customer’s behalf in connection with the Service.

2. Roles of the parties

The Customer is the controller and DealBook is the processorin respect of personal data contained within the documents the Customer uploads to the Service. DealBook processes that personal data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by UK or EU law (in which case DealBook will inform the Customer of that legal requirement before processing, unless the law prohibits it).

Where DealBook determines the purposes and means of processing — for example, in relation to its own account administration, billing, and security logging — DealBook acts as a controller for those activities, which are governed by DealBook’s Privacy Policy rather than this DPA.

3. Subject matter, duration, nature and purpose of processing

  • Subject matter: the personal data contained within the business and financial documents the Customer uploads for due-diligence analysis.
  • Duration:for the term of the Customer’s subscription to the Service, and until the personal data is returned or deleted in accordance with section 10.
  • Nature and purpose: automated and machine-assisted analysis of uploaded documents to extract, structure, verify, and present due-diligence findings, including storage, retrieval, and generation of analysis outputs and reports for the Customer.

4. Categories of personal data and data subjects

The Customer’s uploaded documents are business and financial records that may contain personal data, including:

  • Categories of personal data: names, contact details, and professional and financial information relating to individuals named in fund documentation.
  • Categories of data subjects:the Customer’s personnel, and fund principals, employees, investors, and other individuals named in the documents the Customer chooses to upload.

The Customer is responsible for determining what documents to upload and therefore for the categories of personal data and data subjects involved. The Service is not designed for, and the Customer should not upload, special-category data under Article 9 except where strictly necessary and lawful.

5. Controller instructions

DealBook will process personal data only on the Customer’s documented instructions. The Customer’s acceptance of the Service agreement and this DPA, together with the Customer’s use of the Service’s features, constitute its complete and final instructions. DealBook will inform the Customer if, in its opinion, an instruction infringes the UK GDPR, the EU GDPR, or other applicable data protection law.

6. Processor obligations

  • Confidentiality. DealBook ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality and only access personal data as necessary to perform the Service.
  • Security (Article 32). DealBook implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit and at rest, access controls and least-privilege access, network isolation, logging and monitoring, and measures for resilience and the restoration of availability after an incident.
  • Assistance with data-subject requests. Taking into account the nature of the processing, DealBook assists the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III of the UK/EU GDPR.
  • Assistance with DPIAs and consultation. DealBook assists the Customer in ensuring compliance with its obligations under Articles 32 to 36, including data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to DealBook.
  • Breach notification.DealBook notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and provides the information reasonably available to assist the Customer in meeting its own notification obligations under Articles 33 and 34.

7. Sub-processors

The Customer provides DealBook with general written authorisationto engage the sub-processors listed below. DealBook imposes on each sub-processor data protection obligations equivalent to those set out in this DPA, by way of a contract or other legal act, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

DealBook will give the Customer advance notice of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data protection grounds before that sub-processor begins processing the Customer’s personal data.

Sub-processorPurposeRegion
Amazon Web Services (AWS)LLM inference (Bedrock), email (SES), object storage (S3), compute (Lambda)EU / UK (eu-west-1, eu-west-2)
Google CloudLLM inference (Vertex AI / Gemini)europe-west4 (Netherlands)
SupabasePostgres database, authentication, file storageEU
StripePayment processing (card data is handled by Stripe as an independent controller)EU / global payments network
PostHogProduct analyticsEU cloud
LangfuseLLM observability and tracingEU
InngestBackground job orchestrationEU
VercelApplication hosting and CDNEU edge regions

No foundation-model training on Customer data.The LLM providers DealBook uses for inference — AWS Bedrock and Google Vertex AI — do not, under their enterprise terms, use Customer data submitted through their APIs to train or improve their foundation models.

8. International transfers

All processing of Customer personal data takes place within the United Kingdom and the EEA. DealBook hosts and processes Customer data exclusively in UK and EU regions — AWS (eu-west-1 / eu-west-2), Google Vertex AI (europe-west4), Supabase (EU), and AWS SES (eu-west-1). Because no Customer personal data is transferred to a third country outside the UK or EEA, the standard contractual clauses and other transfer mechanisms for third-country transfers are generally not engaged. Should that position ever change, DealBook will put an appropriate transfer mechanism in place and update this DPA before any such transfer occurs.

9. Audit and information rights

DealBook makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations in Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Where available, DealBook may satisfy audit requests by providing relevant third-party audit reports and certifications. DealBook’s SOC 2 programme is in progress and not yet certified; a report will be made available on request once complete.

10. Return and deletion of data

On termination of the Service, and at the Customer’s choice, DealBook deletes or returns all Customer personal data and deletes existing copies, unless UK or EU law requires storage of the personal data. The Customer may also export or request deletion of personal data during the term in accordance with the Service’s features.

11. Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying Service agreement between the parties. Nothing in this DPA limits liability that cannot be limited under applicable law.

12. Governing law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales, without prejudice to any mandatory data protection rights or remedies available to data subjects or supervisory authorities.

13. Requesting a signed DPA

To request a signed and countersigned copy of this DPA, or to discuss any specific data protection requirements, contact us at dd@sosorry.co.uk.

Need a signed DPA?

We'll get one countersigned for you.

Email us and we'll turn it around quickly.