SwiftRegistry Data Processing Agreement
Article 28 data-processing terms for Customer Data processed through SwiftRegistry.
| Operator | Red Swift Systems Ltd |
|---|---|
| Company number | 14891467 |
| Registered office | 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom |
| Draft date | 15 August 2026 |
DO NOT EXECUTE YET. This draft contains the Article 28 structure required for a controller-processor or processor-sub-processor relationship, but the current evidence-chain design cannot satisfy a controller's deletion instruction for personal data already written to the immutable chain. That must be remediated or specifically resolved by qualified UK data-protection counsel before this DPA is signed.
This Data Processing Agreement (DPA) forms part of the agreement between the Customer and Red Swift Systems Ltd for use of SwiftRegistry (Agreement). It applies to the extent Red Swift Systems Ltd processes Personal Data on behalf of the Customer.
If the Customer is itself a Processor acting for a third-party Controller, references to the Customer's instructions mean instructions the Customer is authorised to give under its agreement with that Controller.
1. Definitions
Controller, Data Subject, Personal Data, Personal Data Breach, Processor and processing have the meanings given in applicable Data Protection Law. Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 where applicable, and any legislation replacing or amending them.
Customer Personal Data means Personal Data processed by Red Swift Systems Ltd on behalf of the Customer through the Service. Sub-processor means a third party engaged by Red Swift Systems Ltd to process Customer Personal Data on behalf of the Customer.
2. Roles
2.1 Where the Customer determines the purposes and essential means of processing Customer Personal Data, the Customer is the Controller and Red Swift Systems Ltd is the Processor.
2.2 Where the Customer processes Customer Personal Data on behalf of a Client Company or other Controller, the Customer is the Processor and Red Swift Systems Ltd is a Sub-processor.
2.3 Red Swift Systems Ltd acts as an independent Controller for its own account, relationship, security and business-administration data, as described in the SwiftRegistry Privacy Notice. This DPA does not apply to that independent-controller processing.
3. Details of the processing
The subject matter, nature, purpose, duration, categories of Data Subjects and types of Personal Data are set out in Schedule 1.
4. Documented instructions
4.1 Red Swift Systems Ltd will process Customer Personal Data only on the Customer's documented instructions, including instructions contained in the Agreement and the Customer's authorised use of the Service, unless required to do otherwise by UK law.
4.2 If Red Swift Systems Ltd is required by law to process Customer Personal Data outside the Customer's instructions, it will inform the Customer before doing so unless the law prohibits that notice.
4.3 Red Swift Systems Ltd will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Law.
5. Confidentiality
Red Swift Systems Ltd will ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
6. Security
6.1 Red Swift Systems Ltd will implement and maintain appropriate technical and organisational measures proportionate to the risks of the processing, taking account of the state of the art, implementation costs and the nature, scope, context and purposes of processing.
6.2 The current measures are summarised in Schedule 2. Red Swift Systems Ltd may update those measures provided the overall level of protection is not materially reduced.
6.3 The Customer remains responsible for configuring user access appropriately and for the security of its own devices, credentials, exports and local copies.
7. Sub-processors
7.1 The Customer gives general written authorisation for Red Swift Systems Ltd to use the Sub-processors listed in Schedule 3.
7.2 Red Swift Systems Ltd will notify the Customer of an intended new Sub-processor that will materially process Customer Personal Data and will give the Customer a reasonable opportunity to object on data-protection grounds before that Sub-processor begins processing, where practicable.
7.3 Red Swift Systems Ltd will impose data-protection obligations on each Sub-processor that provide an equivalent level of protection for Customer Personal Data as required by Article 28, and remains responsible to the Customer for the performance of those obligations.
8. Data-subject rights
8.1 Taking into account the nature of the processing, Red Swift Systems Ltd will provide reasonable technical and organisational assistance to help the Customer respond to requests by Data Subjects exercising their rights under Data Protection Law.
8.2 If Red Swift Systems Ltd receives a request relating to Customer Personal Data for which it acts only as Processor or Sub-processor, it will not substantively respond except on the Customer's instructions or as required by law, and will direct or forward the request to the Customer where reasonably possible.
8.3 The Customer acknowledges the current technical limitation described in clause 12 concerning erasure of Personal Data already committed to the evidence chain.
9. Assistance with compliance
Taking account of the nature of the processing and information available to it, Red Swift Systems Ltd will reasonably assist the Customer with obligations concerning security of processing, Personal Data Breaches, data-protection impact assessments and prior consultation with the ICO where required.
10. Personal Data Breaches
10.1 Red Swift Systems Ltd will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
10.2 Where available, the notice will include information reasonably required for the Customer to assess the incident, including the nature of the breach, affected data and Data Subjects, likely consequences and measures taken or proposed.
10.3 Red Swift Systems Ltd will take reasonable steps within its control to contain, investigate and remediate the breach.
11. International transfers
11.1 Red Swift Systems Ltd will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless the transfer is permitted by Data Protection Law.
11.2 The Customer authorises transfers required to use the approved Sub-processors in Schedule 3, subject to appropriate safeguards.
11.3 Clever Cloud SAS is established in France. The United Kingdom treats the EEA as adequate for UK data-transfer purposes, so appointing Clever Cloud in France does not itself require an additional restricted-transfer safeguard. Clever Cloud's data-processing terms are incorporated into its general terms and conditions and rely on the European Commission's standard contractual clauses for controllers and processors adopted by Decision (EU) 2021/915 under Regulation (EU) 2016/679. They do not expressly refer to the UK GDPR. Before live Customer Personal Data is processed, Red Swift Systems Ltd must document that its contractual arrangements with Clever Cloud satisfy the UK GDPR Article 28 processor chain and any UK international-transfer requirements that may arise from downstream processing.
11.4 The application and the PostgreSQL database are deployed in Clever Cloud's London availability zone, which runs on Ionos infrastructure in the United Kingdom. Regional deployment does not by itself preclude access or ancillary processing from outside the United Kingdom, and Clever Cloud's published sub-processor list governs which downstream providers may process data in connection with its service.
12. Return and deletion at the end of processing
12.1 Subject to clause 12.4, at the end of the provision of processing services, Red Swift Systems Ltd will, at the Customer's choice, return Customer Personal Data and delete existing copies, unless applicable UK law requires continued storage.
12.2 Where immediate deletion from backups is not practicable, Red Swift Systems Ltd may place backup copies beyond ordinary use and delete them on the applicable backup lifecycle, provided they remain protected and are not restored except for legitimate disaster recovery.
12.3 The Customer is responsible for exporting and retaining the Client Company's statutory records for as long as the Client Company is legally required to keep them.
BLOCKER TO EXECUTION - clause 12.4: the current application stores member names and addresses inside an append-only evidence chain that rejects deletion and truncation. As built, Red Swift Systems Ltd cannot comply with a controller instruction to delete those Personal Data from the chain. The Service must either be redesigned so the immutable chain does not contain erasable Personal Data (for example, by storing non-identifying commitments while keeping mutable Personal Data outside the chain), or qualified counsel must confirm and document a lawful alternative that satisfies Article 28 and the Customer's instructions. Until then, live shareholder Personal Data should not be committed to the chain.
12.4 This clause is intentionally left as a legal and technical remediation requirement and is not an agreed exception to Article 28(3)(g).
13. Audit and information rights
13.1 Red Swift Systems Ltd will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
13.2 On reasonable notice, and no more than once in a 12-month period unless required by a regulator or a material incident gives reasonable grounds for further review, the Customer may audit compliance itself or through an independent auditor subject to confidentiality and security controls.
13.3 The parties should first use available policies, certifications, supplier reports and written responses where those materials reasonably satisfy the Customer's audit need. On-site or technically intrusive audits may be subject to reasonable cost recovery where permitted by law and agreed in advance.
14. Customer obligations
14.1 The Customer must ensure that it and any relevant Controller have a lawful basis for the processing, provide required privacy information, and issue only lawful instructions.
14.2 The Customer must ensure that the Personal Data supplied is adequate, relevant and limited to what is necessary for the purpose, and must take particular care when transcribing historic registers containing residential or otherwise sensitive address information.
14.3 Where the Customer is a Processor, it warrants that it is authorised by the relevant Controller to appoint Red Swift Systems Ltd as a Sub-processor and to give the instructions contained in the Agreement.
14.4 The Customer must not use the Service to process special-category or criminal-offence data unless the parties expressly agree appropriate safeguards in writing. The current Service is not designed for those categories.
15. Records, notices and regulatory cooperation
Each party will maintain records and information required of it under Data Protection Law and will reasonably cooperate with the ICO or another competent supervisory authority in relation to the processing covered by this DPA.
16. Liability and precedence
16.1 Liability under this DPA is subject to the liability provisions of the main Agreement, except to the extent Data Protection Law requires otherwise.
16.2 If there is a conflict between this DPA and the main Agreement concerning the protection of Customer Personal Data, this DPA prevails. Applicable mandatory transfer clauses prevail over both to the extent of conflict.
17. Term
This DPA begins when Red Swift Systems Ltd first processes Customer Personal Data on the Customer's behalf and continues until that processing ends and all required return, deletion or legally permitted retention obligations have been completed.
18. Governing law
This DPA is governed by the law of England and Wales, subject to the governing-law provisions of any mandatory international transfer mechanism.
Schedule 1 - Details of Processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operating SwiftRegistry to maintain Client Company registers of members and related corporate records. |
| Duration | For the term of the Customer's use of the Service and any limited post-termination period required for return, deletion, legally required retention, backup expiry or dispute preservation. |
| Nature of processing | Collection, receipt, storage, organisation, retrieval, display, access control, correction/rectification, generation of certificates and exports, cryptographic commitment and timestamp anchoring, support and security operations. |
| Purpose | To provide a verifiable system for maintaining a register of members and the related record book on the Customer's documented instructions. |
| Data Subjects | SwiftRegistry users where included in Customer Data; shareholders and former shareholders of Client Companies; joint holders; and individuals whose details appear in related corporate records. |
| Personal Data | Names; corporate names where linked to individuals; joint-holder details; register addresses; membership dates; shareholdings; certificate, allotment, transfer and rectification information; access and role information; and other personal data the Customer elects to include in the statutory record. |
| Special-category data | Not intentionally required or designed for processing. |
Schedule 2 - Current Technical and Organisational Measures
Role-based organisation and Client Company access controls.
Passwords stored as hashes rather than plain text.
Authentication session cookie configured for production with HttpOnly, Secure and SameSite=Lax attributes.
The production service is reached over HTTPS. Encryption at rest for the PostgreSQL add-on remains to be confirmed and is not relied on as a contractual security measure in this draft.
Application and PostgreSQL database deployed in Clever Cloud's London availability zone on Ionos infrastructure in the United Kingdom.
Append-only database controls reject ordinary deletion and truncation of evidence-chain tables, providing tamper-evident history but creating the deletion limitation described in clause 12.
No analytics, tag manager, session-recording or third-party advertising scripts are currently present in the application.
Cryptographic timestamp anchoring transmits a commitment/digest rather than the underlying register record.
Access should be limited to authorised personnel and reviewed when roles change.
Infrastructure backups are used for resilience; product-level disaster-recovery procedures must account for the possibility that restoring a database backup rolls application state back to the backup point.
Schedule 3 - Approved Sub-processors and Other Processing Infrastructure
| Provider | Role | Location / transfer note | Data |
|---|---|---|---|
| Clever Cloud SAS | Application hosting and PostgreSQL infrastructure | Established in France (RCS Nantes B 524 172 699, 4 rue Voltaire, 44000 Nantes). Application and database hosted in the London availability zone, United Kingdom. | Customer Personal Data hosted in the application/database. |
| Ionos (as named in Clever Cloud's published sub-processor list) | Underlying datacentre and network infrastructure for Clever Cloud's London region | United Kingdom (region "London"). | Customer Personal Data within the selected hosting environment. |
Clever Cloud's published sub-processor list, version 1.5 dated 5 November 2025, is incorporated into this Schedule by reference for downstream processing. That list separates data centres, which the customer selects when an application is created, from providers used for Clever Cloud's own business functions. The data centre selected for SwiftRegistry is Ionos in the United Kingdom; no other data centre on the list is engaged. The list also names providers established in the United States, including Twilio for telephone support and Pipedrive for customer-relationship management, which serve Clever Cloud's relationship with its own customers rather than hosting the Service. Clever Cloud's DPA requires at least 30 days' written notice before adding or replacing a sub-processor. Red Swift Systems Ltd must assess any downstream processing that makes Customer Personal Data available outside the United Kingdom or an adequate destination under clause 11.
OpenTimestamps calendar infrastructure receives cryptographic commitments/digests for timestamp anchoring. It does not receive names, addresses, holdings or the underlying register record. Its legal classification for Article 28 purposes should be confirmed as part of final counsel review if the transmitted commitment can be linked to an identifiable individual in context.
Schedule 4 - Execution
| For the Customer | For Red Swift Systems Ltd |
|---|---|
| Name: ______________________________ Title: _______________________________ Signature: ____________________________ Date: _________________________________ | Name: ______________________________ Title: _______________________________ Signature: ____________________________ Date: _________________________________ |