Legal

Data Processing Agreement

Last updated: 30 September 2026

1. Scope

This agreement applies where Prezwell processes personal data on your behalf (for example employee data for payroll). It meets Article 28 of the UK GDPR and forms part of your engagement letter.

2. Our commitments

  • Process personal data only on your documented instructions.
  • Ensure everyone with access is bound by confidentiality.
  • Apply appropriate security: encryption, role-based access and mandatory two-factor authentication.
  • Help you respond to data-subject requests and data-protection impact assessments.
  • Notify you without undue delay, and within 48 hours, of any personal data breach.
  • Delete or return data at the end of the engagement, except where law requires retention.
  • Make available the information needed to demonstrate compliance.

3. Sub-processors

You authorise us to use the following sub-processors, each bound by equivalent terms: cloud hosting providers, specialist accounting platforms (Luca, AccountsPro, AccountsGear, AuditGear, TaxGear), identity-verification providers, email delivery providers and Stripe. We will give notice of material changes so you can object.

4. Transfers

Any transfer outside the UK uses approved safeguards.

5. Retention

AML records: five years after the relationship ends. Accounting, tax and payroll records: at least six years. Backups are rotated and encrypted.

6. Contact

Data protection queries: asim@prezwell.com.