This Data Processing Agreement (the DPA) is made between MDW Consulting Limited trading as WayfinderHQ, a company incorporated in England and Wales with registered number 15902128 whose registered office is at 1501 Norton House, Duke of Wellington Avenue, London, SE18 6PD (WayfinderHQ, we or us), and the firm that subscribes to the WayfinderHQ service (the Firm or you).
This DPA is incorporated into, and forms part of, our Terms and Conditions. It applies automatically from the moment you subscribe to the service or start a free trial. No separate signature is required, and we do not issue a separately executed copy on request as a precondition of it taking effect.
It sets out the terms on which we process personal data on your behalf, and is intended to satisfy Article 28 of the UK GDPR and, where the Protection of Personal Information Act, 2013 (POPIA) applies, sections 19 to 21 and section 72 of that Act.
The Two Roles: Who Is the Controller
There are two distinct sets of personal data involved in the WayfinderHQ service, and the parties have different roles for each. This distinction is important, and it takes precedence over any more general statement about roles elsewhere in our published policies.
- Firm data (we are the processor). For personal data that the Firm and its staff upload into, create in, or generate through the service about the Firm’s own clients, prospects and their representatives, the Firm is the controller (under the UK GDPR) or responsible party (under POPIA), and WayfinderHQ is the processor (under the UK GDPR) or operator (under POPIA). The Firm decides why and how that personal data is processed. We process it only to provide the service, on the Firm’s instructions.
- Account, billing and marketing data (we are the controller). Separately, and in our own right, WayfinderHQ is the controller (or responsible party) for the personal data we hold about the Firm and its staff for our own purposes: account registration and login, subscription and billing records, support correspondence, service notifications, product analytics and marketing. Our processing in that capacity is described in our Privacy Policy, not in this DPA.
- Each party will comply with the data protection laws applicable to it in its respective role. Nothing in this DPA makes either party a joint controller with the other.
Definitions
- In this DPA:
| Term | Meaning |
|---|
| Data Protection Laws | all laws applicable to the processing of personal data under this DPA, including the UK GDPR, the Data Protection Act 2018, and, where applicable, POPIA; |
| UK GDPR | Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018; |
| POPIA | the Protection of Personal Information Act 4 of 2013 (South Africa); |
| Firm Personal Data | the personal data described in the "Details of Processing" table below, which the Firm (as controller or responsible party) makes available to WayfinderHQ for processing through the service; |
| Sub-processor | any third party engaged by WayfinderHQ to process Firm Personal Data on our behalf in connection with the service; |
| Personal Data Breach | a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Firm Personal Data. |
Terms such as “controller”, “processor”, “data subject”, “processing”, “responsible party”, “operator” and “personal information” have the meanings given to them in the applicable Data Protection Laws.
Details of Processing
- As required by Article 28(3) of the UK GDPR, the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are as follows:
| Item | Detail |
|---|
| Subject matter | The provision of the WayfinderHQ client relationship management and client onboarding platform to the Firm. |
| Duration | For the duration of the Firm’s subscription, plus the applicable post-termination grace period set out in the "Deletion and Return of Personal Data" section below. |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, hosting, transmission, display, use, backup, restriction, erasure and destruction of Firm Personal Data, carried out by automated means through the platform. |
| Purpose of the processing | To enable the Firm to capture and manage leads and prospects; to run the onboarding pipeline (registration, questionnaire, pricing, engagement letter, verification, onboarding); to issue and store engagement documentation; to communicate with the Firm’s clients through the client portal, email and SMS; to run identity and AML checks where the Firm chooses to; to sync with the Firm’s accounting system where the Firm connects one; and to provide reporting and support to the Firm. |
| Categories of data subject | The Firm’s staff and other authorised users of the Firm’s account; the Firm’s clients and prospective clients; and, where the Firm’s client is an organisation, that organisation’s directors, officers, beneficial owners and other individual representatives. |
| Types of personal data | Names, job titles and roles; contact details including email addresses, telephone numbers and postal addresses; account credentials and authentication data for the Firm’s users; responses to onboarding questionnaires; business and financial information about the client relevant to scoping the engagement; pricing, quote and engagement letter contents; e-signature records including signatory name, email address, signature and audit trail; messages, notes and activity history recorded against a client or prospect; documents and files uploaded by or on behalf of the Firm or its clients; and, where applicable, accounting data synced from the Firm’s accounting system. |
| Identity and AML verification data (more sensitive) | Where the Firm chooses to run an identity or anti-money-laundering check on a client through our verification provider, the processing additionally covers identity document images and data (such as passport or driving licence), date of birth, address history, biometric facial-likeness data used for liveness and document matching, and the verification result including any politically exposed person, sanctions or adverse media match. This category is more sensitive than the rest, may include special category or biometric data, and carries a higher risk to data subjects. It is processed only where the Firm initiates a check, and only for the purpose of that check and the retention of its result as an audit record. |
- The Firm is responsible for determining that it has a lawful basis for the processing described above, for identifying and satisfying any additional condition required for special category, biometric or criminal-offence data, and for providing any required privacy information to its own clients and staff.
Processing on Documented Instructions
- We will process Firm Personal Data only on the Firm’s documented instructions, including in relation to transfers of Firm Personal Data to a country outside the United Kingdom or to an international organisation, unless we are required to process it by law to which we are subject. Where we are required to process by law, we will inform the Firm of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.
- The Firm’s documented instructions consist of this DPA, the Terms and Conditions, the configuration and settings chosen by the Firm within the service, and the actions the Firm and its users take through the service. Additional instructions outside that scope may be agreed in writing and may be chargeable.
- We will notify the Firm if, in our opinion, an instruction infringes the Data Protection Laws. We are not obliged to carry out an instruction we reasonably believe to be unlawful, and may suspend performance of the relevant instruction pending resolution.
- We will not sell Firm Personal Data, and we will not use it for our own marketing purposes or to train generalised machine-learning models for the benefit of third parties.
Confidentiality of Personnel
- We will ensure that persons authorised to process Firm Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, that access is limited to those who need it to provide or support the service, and that those persons receive appropriate guidance on their data protection obligations.
Security Measures
- Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects, we implement appropriate technical and organisational measures under Article 32 of the UK GDPR. These currently include:
- encryption of data in transit using TLS across the public internet;
- AES-256-GCM encryption at rest for integration credentials and OAuth tokens held for connected third-party systems;
- Postgres row-level security policies that enforce tenant isolation at the database level, so one firm’s records cannot be read or written by another firm’s users;
- role-based access control within the Firm’s account, so the Firm can decide which of its users can see and do what;
- authenticated access to the application, with credentials managed by our authentication provider rather than stored by us in plain form;
- hosting on established infrastructure providers (Supabase for database, authentication and file storage; Vercel for application hosting), which maintain physical and network security controls at the infrastructure layer;
- logging and error monitoring to detect and diagnose faults and suspicious activity;
- backups of the production database, and restricted administrative access to production systems.
- We may update these measures from time to time provided the level of security is not materially reduced. The Firm is responsible for security within its own control, including the strength and confidentiality of its users’ credentials, its choice of who to grant access to, and the prompt removal of access for people who leave.
Sub-processors
- The Firm gives WayfinderHQ general written authorisation to engage Sub-processors for the provision of the service. The current list of Sub-processors, with the purpose of each and the location in which each processes data, is published at https://wayfinderhq.co.uk/subprocessors and forms part of this DPA.
- Where we intend to add a new Sub-processor or replace an existing one, we will give the Firm advance notice by updating that page and, where the change is material, by notifying the Firm’s account contact by email. We will give that notice at least 30 days before the new Sub-processor begins processing Firm Personal Data, except where a shorter period is necessary to maintain the security or continuity of the service, in which case we will give as much notice as is reasonably practicable.
- The Firm may object to a proposed Sub-processor on reasonable data protection grounds by writing to hello@wayfinderhq.co.uk before the change takes effect. We will work with the Firm in good faith to address the objection. If we cannot do so, and the Sub-processor is necessary to provide the service, the Firm may terminate its subscription in respect of the affected part of the service.
- We will impose on each Sub-processor, by written contract, data protection obligations that are substantially the same as those set out in this DPA, and in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. We remain fully liable to the Firm for the performance of each Sub-processor’s obligations.
Assistance with Data Subject Rights
- Taking into account the nature of the processing, we will assist the Firm by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Firm’s obligation to respond to requests from data subjects exercising their rights (including access, rectification, erasure, restriction, portability and objection). The service provides self-service tools that allow the Firm to search, correct, export and delete records within its own account, and in most cases the Firm can respond to a request directly without our involvement.
- If we receive a request directly from one of the Firm’s data subjects in relation to Firm Personal Data, we will not respond to it substantively ourselves. We will promptly inform the Firm and direct the data subject to the Firm, unless we are legally required to do otherwise.
Personal Data Breaches, DPIAs and Prior Consultation
- We will notify the Firm of a Personal Data Breach affecting Firm Personal Data without undue delay and in any event within 72 hours of becoming aware of it. The notification will describe, so far as we are able at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where we cannot provide all of that information at once, we will provide it in phases without further undue delay.
- We will assist the Firm in meeting the Firm’s own obligations to notify the supervisory authority and, where required, affected data subjects. Reporting a breach to the supervisory authority in respect of Firm Personal Data remains the Firm’s responsibility as controller.
- Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Firm with data protection impact assessments and with any prior consultation with a supervisory authority arising from them.
Deletion and Return of Personal Data
- At the Firm’s choice, we will delete or return Firm Personal Data at the end of the provision of the service. In practice this operates through a grace period following cancellation, during which the Firm may export its data and the account may be reinstated:
- for accounts that have never made a payment, 7 days after cancellation;
- for accounts that have previously paid, 30 days after cancellation.
At the end of the grace period, Firm Personal Data is permanently deleted from the production systems, save for copies we are required to retain by law and copies held on backup or archival media which are overwritten in the ordinary course.
- Statutory record-keeping carve-out. The Firm may be subject to its own record retention duties, for example under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which require anti-money-laundering records to be kept for five years. Deletion under this DPA is not deferred to accommodate those duties. It is the Firm’s responsibility to export and retain any records it is required to keep before the grace period ends. WayfinderHQ does not act as the Firm’s record-keeper and does not retain those records on the Firm’s behalf beyond the grace period.
- The Firm can export its data at any time during the subscription, and during the grace period, using the export tools in the service. If the Firm needs assistance with an export, it should contact hello@wayfinderhq.co.uk before the grace period ends.
Information and Audits
- We will make available to the Firm all information necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Firm or an auditor mandated by the Firm.
- Audits are subject to reasonable conditions: the Firm will give at least 30 days’ written notice (except where an audit follows a Personal Data Breach or is required by a supervisory authority); audits will take place during normal business hours and no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach; the auditor will be bound by confidentiality; and the audit will be conducted so as not to disrupt the service or compromise the confidentiality of other customers’ data. In the first instance we may satisfy an audit request by providing written responses, documentation of our measures, and any third-party certifications or reports available to us from our infrastructure providers.
International Transfers (United Kingdom)
- Firm Personal Data is stored in the United Kingdom on infrastructure operated by Supabase, and the application through which it is processed also runs in the United Kingdom. Some other Sub-processors process Firm Personal Data outside the United Kingdom. Where they do, we will ensure the transfer is made under an appropriate transfer mechanism, being an adequacy decision made by the Secretary of State, the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, together with any supplementary measures required following a transfer risk assessment.
- The Firm authorises those transfers as part of its instructions under this DPA. Details of where each Sub-processor processes data are set out at https://wayfinderhq.co.uk/subprocessors.
South Africa: POPIA Operator Obligations
This section applies in addition to, and not instead of, the sections above where POPIA applies to the processing of personal information under this DPA. In this section the Firm is the responsible party and WayfinderHQ is the operator.
- Section 20 (processing under authority). WayfinderHQ processes personal information only with the knowledge or authorisation of the Firm as responsible party. Persons acting under our authority who have access to personal information will process it only on our instruction, which in turn reflects the Firm’s instructions.
- Section 21(1)(b) (confidentiality). WayfinderHQ treats all personal information that comes to its knowledge as confidential and will not disclose it, unless required by law or in the course of the proper performance of its duties as operator.
- Sections 19 and 21(1)(a) (security safeguards). WayfinderHQ establishes and maintains the security measures referred to in section 19 of POPIA, being appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information, and unlawful access to or processing of personal information. The measures described in the “Security Measures” section above are the measures maintained for this purpose.
- Section 21(2) (security compromise notification). Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, WayfinderHQ will notify the Firm as responsible party immediately, and in any event without delay, so that the Firm can meet its own obligation under section 22 of POPIA to notify the Information Regulator and the affected data subjects. Notification to the Information Regulator and to data subjects remains the responsibility of the Firm.
- WayfinderHQ will provide the Firm with reasonable assistance in responding to requests made under POPIA, including requests for access to, correction of, or deletion of personal information, and in dealing with any enquiry or investigation by the Information Regulator.
South Africa: Section 72 Cross-Border Transfers
- The Firm acknowledges that WayfinderHQ is established in the United Kingdom and that personal information processed through the service, including personal information of South African data subjects, is stored and processed outside the Republic of South Africa by WayfinderHQ and its Sub-processors. That personal information is stored outside the Republic of South Africa on infrastructure operated by Supabase, and is processed outside the Republic of South Africa on infrastructure operated by Supabase and Vercel, and by the other Sub-processors listed in our sub-processor list.
- This DPA is the binding agreement contemplated by section 72(1)(a) of POPIA. By entering into it, WayfinderHQ agrees to be bound, in respect of personal information transferred to it from the Republic of South Africa, to provisions that are substantially similar to the conditions for the lawful processing of personal information set out in Chapter 3 of POPIA, being accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation. Taken together, the obligations in this DPA provide an adequate level of protection for that personal information.
- WayfinderHQ will not transfer personal information received from the Firm to a Sub-processor or other third party in a further country unless that recipient is bound, by written contract, to provisions that uphold principles for the reasonable processing of the information that are substantially similar to the conditions in Chapter 3 of POPIA, including provisions relating to further transfers. This satisfies the requirement in section 72(1)(a) that the agreement include provisions relating to onward transfers.
- Where the Firm relies instead on another ground in section 72(1) (for example the data subject’s consent, or that the transfer is necessary for the performance of a contract with the data subject), it is the Firm’s responsibility as responsible party to establish and document that ground. Nothing in this DPA relieves the Firm of its own obligations under POPIA.
General
- This DPA takes effect when the Firm subscribes to the service or starts a free trial, and continues for as long as we process Firm Personal Data. The obligations relating to confidentiality, security, deletion and international transfers survive termination for as long as we hold any Firm Personal Data.
- Where any term of this DPA conflicts with any other term of the Terms and Conditions in relation to the processing of Firm Personal Data, this DPA prevails. Where any term of this DPA conflicts with a signed Enterprise order form or a separately negotiated data processing agreement between us and the Firm, that signed document prevails.
- We may update this DPA from time to time, for example to reflect changes in law, in our Sub-processors or in our security measures. Where a change materially reduces the Firm’s rights or our obligations, we will give the Firm reasonable advance notice by email to its account contact.
- This DPA is governed by the law of England and Wales and disputes arising under it are subject to the exclusive jurisdiction of the English and Welsh courts. This does not affect any mandatory obligation that applies to either party under POPIA or under any other applicable data protection law.
Contact
- Questions about this DPA, requests for assistance, objections to a Sub-processor and audit requests should be sent to hello@wayfinderhq.co.uk, or by post to MDW Consulting Limited trading as WayfinderHQ, 1501 Norton House, Duke of Wellington Avenue, London, SE18 6PD, United Kingdom.