Skip to content

← Back to Terms

Data Processing Addendum

KinetiRisk — High Peak Pro Ltd. Version: 1.1. Date: 4 June 2026. Last updated: 4 June 2026.

This Data Processing Addendum ("DPA") forms part of and is incorporated into the Terms of Service between High Peak Pro Ltd (trading as KinetiRisk) and the Customer. It governs the processing of personal data by High Peak Pro Ltd on behalf of the Customer in connection with the KinetiRisk Service.

This DPA applies automatically to all Customers whose use of the Service involves the processing of personal data. To request a countersigned copy, contact legal@kinetirisk.com.

Part 1 — Definitions and Interpretation

  • "Applicable Data Protection Law" means UK GDPR (Data Protection Act 2018) for UK-based processing; EU GDPR (Regulation 2016/679) for EU/EEA-based processing; and any successor legislation.
  • "Controller" has the meaning given in Applicable Data Protection Law. The Customer is the Controller of Customer Personal Data.
  • "Customer Personal Data" means any personal data contained within Customer Data that the Customer submits to the Service.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Processor" has the meaning given in Applicable Data Protection Law. High Peak Pro Ltd is the Processor.
  • "Sub-Processor" means any third party appointed by the Processor to process Customer Personal Data on behalf of the Controller.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the ICO under s.119A of the Data Protection Act 2018.

Part 2 — Roles and Scope

2.1 Roles. The Customer is the Controller; High Peak Pro Ltd is the Processor of Customer Personal Data.

2.2 Scope of processing. The subject matter, duration, nature, purpose, types of personal data, and categories of Data Subjects are set out in Schedule A.

2.3 Independence. Nothing in this DPA prevents High Peak Pro Ltd from processing personal data for its own purposes as a Controller (account management, billing, security logging), subject to its Privacy Policy.

Part 3 — Controller Obligations

The Customer represents, warrants, and undertakes that:

  • it has a valid lawful basis for each processing activity described in Schedule A;
  • it has provided all required privacy notices to Data Subjects;
  • it will not instruct the Processor to process Customer Personal Data in a manner that would cause a breach of Applicable Data Protection Law;
  • it will not submit Special Category personal data to the Service.

Part 4 — Processor Obligations

  • 4.1 Processing on instructions only. The Processor shall process Customer Personal Data only on the documented instructions of the Controller.
  • 4.2 Confidentiality. The Processor shall ensure all persons authorised to process Customer Personal Data are subject to a binding duty of confidentiality.
  • 4.3 Security. The Processor shall implement and maintain the technical and organisational measures described in Schedule B.
  • 4.4 Sub-processing. The Processor shall not engage any Sub-Processor other than as set out in Schedule C and in accordance with Part 5.
  • 4.5 Assistance — Data Subject Rights. The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject rights requests.
  • 4.7 Return or deletion. On termination, the Processor shall return or securely delete all Customer Personal Data within 30 days and provide written confirmation.
  • 4.9 Audit rights. The Processor shall permit audits and inspections by the Controller or a mandated third-party auditor, subject to 30 days' prior written notice and no more than one audit per 12-month period.

Part 5 — Sub-Processors

5.1 General authorisation. The Controller provides general written authorisation to engage the Sub-Processors listed in Schedule C.

5.3 Changes to Sub-Processors. The Processor shall notify the Controller by email of any proposed addition or replacement of a Sub-Processor at least 14 days before the change takes effect.

5.4 Objection. The Controller may object to a proposed new Sub-Processor by written notice to legal@kinetirisk.com within 10 days of receiving notice.

Part 6 — International Data Transfers

The Processor shall not transfer Customer Personal Data to a third country except to Sub-Processors listed in Schedule C using the transfer mechanisms specified. Applicable transfer mechanisms include the UK International Data Transfer Addendum (UK Addendum), the UK International Data Transfer Agreement (UK IDTA), and EU Standard Contractual Clauses.

Part 7 — Personal Data Breaches

7.1 Notification. The Processor shall notify the Controller of a confirmed Personal Data Breach within 48 hours of becoming aware of it.

7.2 Content of notification. The notification shall include: a description of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.

Part 8 — Data Protection Impact Assessments

The Processor shall, on written request, provide reasonable assistance in carrying out a Data Protection Impact Assessment (DPIA) as required under Article 35 of GDPR, and in connection with any prior consultation with a Supervisory Authority under Article 36.

Part 9 — Term and Termination

This DPA is effective from the date the Customer first uses the Service involving the processing of personal data, and remains in force for the duration of the Agreement. Obligations relating to return or deletion of Customer Personal Data, confidentiality, and audit rights survive termination for 12 months.

Part 10 — Liability and Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Agreement (§ 4: Limitation of Liability), except to the extent prohibited by Applicable Data Protection Law. Each party shall indemnify the other against fines, penalties, or third-party claims arising from its breach of this DPA.

Part 11 — General Provisions

In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA shall prevail. This DPA is governed by the laws of England and Wales.

Schedule A — Details of Processing

Subject matter: Personal data processed through the KinetiRisk risk management platform.

Nature of processing: Collection, storage, retrieval, use, disclosure, transmission to AI providers for analysis, and deletion of Customer Personal Data.

Purpose: To enable the Customer to use the KinetiRisk Service, including: risk registers, AI-powered risk scoring, reports, escalation notifications, team access management, and audit trails.

Types of personal data: Identity data (name, job title, organisation); Contact data (work email); Account and access data (login credentials, login history, IP address, session tokens); Risk management data (project names, risk titles and descriptions, mitigation actions, owner names); Financial data (subscription status, billing contact — card data processed exclusively by Stripe).

Categories of Data Subjects: Customer employees and team members who are registered users of the Service; individuals named as risk owners or action owners within the Customer's risk data.

Schedule B — Technical and Organisational Security Measures

  • Encryption at rest: AES-256-GCM application-level encryption applied per sensitive field before database persistence; platform-native AES-256 storage encryption provided by Replit EU infrastructure
  • Encryption in transit: TLS 1.3+ for all API and web traffic
  • Access control: Role-based access control (Super Admin, Organisation Admin, Programme Manager, Project Manager, Viewer); principle of minimum necessary access; session-based authentication with secure, short-lived tokens
  • Audit logging: Immutable, timestamped logs of all significant data access, change, and deletion events
  • Infrastructure: Hosted on Replit EU infrastructure (EU data residency); automated daily backups retained for 90 days
  • Incident response: Defined Personal Data Breach notification procedure with 48-hour Controller notification target
  • Security testing: Regular security audits and penetration testing

Schedule C — Authorised Sub-Processors

  • Replit: Cloud infrastructure (EU region) — All Customer Data (encrypted) — UK Addendum / EU SCCs
  • OpenAI (GPT-4): AI risk analysis — Risk title, description, project context — UK Addendum / UK Ext. to EU-US DPF
  • Anthropic (Claude): AI risk analysis (alternative) — Risk title, description, project context — UK Addendum / UK Ext. to EU-US DPF
  • Stripe: Payment processing — Name, email, subscription status — EU subsidiary / adequacy
  • Resend: Transactional email — Email address, risk title, mitigation actions — UK Addendum / EU SCCs
  • Better Auth: Authentication, session management — Email, name, session tokens — UK Addendum / EU SCCs
  • Microsoft Graph API / Google Tasks API: One-way task push — Mitigation action title, due date — SCCs / adequacy
  • Microsoft Teams / Google Chat: Risk escalation notifications — Risk title, score, project name — SCCs / adequacy

Terms of Service · Privacy Policy · Contact Us