Data processing agreement — consultancy engagements

Version 1.0 · 29 July 2026

This agreement applies where Trauma-Informed Content Consulting processes personal data on a client’s behalf as part of a consultancy engagement. It forms part of the engagement and takes effect when the engagement is agreed.

Clients who need it executed as a countersigned document, or who require their own DPA template to be used instead, should email privacy@traumainformedcontent.com. We’re content to work from your paper where your procurement requires it.

Where this agreement and our terms of service differ on data protection, this agreement wins. Where a signed engagement document sets different data protection terms, that document wins.


1. Parties and roles

Processor: Bankside Communications Limited, company number 14193570, registered office Pearce & Co, Ground Floor, 11 Pierrepont Street, Bath, England, BA1 1LA, trading as Trauma-Informed Content Consulting (“we”, “us”).

Controller: the client named in the engagement (“you”).

You are the controller of personal data contained in material you provide for the engagement. We are your processor in respect of it.

We are a separate, independent controller of the business-relationship data we hold about your staff — names, work contact details, correspondence. That is covered by our privacy policy, not by this agreement.

2. What this covers

Subject matter. Delivering the consultancy services set out in the engagement.

Duration. From the start of the engagement until deletion or return of the material under section 6.

Nature and purpose. Reviewing, analysing, rewriting and advising on content; where the engagement provides for it, conducting or reviewing research; producing deliverables. This may involve AI-assisted analysis under section 4.

Types of personal data. Whatever appears in material you provide. Typically: names, postal and email addresses, telephone numbers, account, case and reference numbers, financial details including balances and arrears, dates and appointment details, correspondence history, case notes, and research participant responses.

Special category data. Our work concerns people in difficulty, so material may contain health data, details of bereavement, disability, or circumstances such as domestic abuse, addiction or financial hardship. Where it does, you must have an Article 9 condition. We will hold it only for as long as the engagement requires.

Categories of data subject. Your customers, claimants, clients, patients, service users, research participants, correspondents and, where relevant, employees.

Redaction. Wherever the work does not depend on identifying details, we will ask you to redact them before sending, and we will remind you if we receive unredacted material we didn’t need. A letter reviews just as well with “[Customer]” and “[Ref]” in place of a name and account number. This is the single most effective control available to either of us and it costs you very little.

3. Our obligations

We will:

a) Process only on your instructions, which are the engagement document, this agreement, and anything you tell us in writing during the work. If we think an instruction breaches UK GDPR, we’ll say so.

b) Keep it confidential, under obligations that survive the engagement.

c) Secure it, with the measures in Annex B, appropriate to the risk under Article 32.

d) Use sub-processors only as set out in section 4.

e) Assist with data subject requests. If a data subject contacts us about your data, we’ll direct them to you and tell you promptly. We’ll help you respond, taking into account the nature of the processing.

f) Assist with Articles 32 to 36 — security assessments, breach notification, DPIAs and prior consultation — taking into account the nature of the processing and the information available to us.

g) Notify breaches without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information available at the time and updates as we learn more. You are responsible for notifying the ICO and data subjects where required.

h) Delete or return all personal data processed on your behalf within 30 days of the engagement ending, per section 6.

i) Demonstrate compliance and allow audits, per section 7.

4. Sub-processors and AI tools

You give general authorisation for the sub-processors in Annex A.

AI-assisted analysis. We use AI tools, including our own Rembrandt Editor, as part of our practice. Where an engagement involves putting your material through an AI tool:

  • We’ll tell you which tool and what it does, before we use it
  • You can decline, and we’ll do the work without it
  • AI-assisted output is always reviewed by a person before it reaches you
  • Content processed through Anthropic’s commercial API is not used to train models
  • Where we use Rembrandt Editor on your material, the full-text retention setting is off unless you ask for it, and stored reviews are deleted at the end of the engagement rather than at their default expiry

We’ll give 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us and we’ll try to resolve it; if we can’t, you may terminate the affected part of the engagement without penalty, with a pro-rata refund of any prepaid fees.

We impose obligations on every sub-processor no less protective than these, and remain liable to you for their performance.

5. International transfers

Client material is held primarily in the United Kingdom and European Union.

Some processors operate in the United States, as listed in Annex A. Those transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful mechanism. We carry out transfer risk assessments and will provide them on request.

Where your procurement requires UK-only processing, tell us before the engagement starts. We can work without US-hosted tools for most engagements, and we’d rather agree that up front than discover it mid-delivery.

6. Retention, deletion and return

We hold client material only for as long as the engagement requires.

Within 30 days of the engagement ending we will, at your choice:

  • Delete all personal data processed on your behalf, from working files, email and any AI tool used, and confirm deletion in writing; or
  • Return it in a format you specify and then delete our copies

We may retain material for longer only where UK or EU law requires, or where you ask us to in writing — for example to support a follow-on phase. If you ask us to retain it, we’ll agree a period and delete at the end of it.

Deliverables and our own working notes that contain no personal data are not affected and are retained under the engagement’s intellectual property terms.

7. Audit

We’ll respond to reasonable written information requests about our processing within 30 days, and provide our security documentation and transfer risk assessments on request. We’ll complete your standard security questionnaire where you have one.

Where an inspection is genuinely necessary, we’ll cooperate with an audit no more than once in any 12-month period, on 30 days’ notice, during business hours, subject to confidentiality. More frequent audits may take place where a supervisory authority requires it or following a breach affecting your data.

We should be straightforward about scale. This is a single-practitioner practice. We hold no ISO 27001 or SOC 2 certification and will not claim otherwise. What we offer instead is a very short chain of custody: one person, known to you, who can answer any question about where your material is and what has happened to it.

8. Your obligations

You will:

  • Ensure you have a lawful basis for the personal data you give us, and an Article 9 condition where special category data is involved;
  • Redact identifying details the work doesn’t require, before sending;
  • Send material by the secure method agreed at the start of the engagement, not by unencrypted email where it can be avoided;
  • Ensure your privacy notices cover the use of an external content consultancy as a processor;
  • Consider whether a DPIA is required, particularly where content concerns people in vulnerable circumstances;
  • Tell us promptly if instructions change or if a data subject exercises rights over material we hold.

9. Liability

Each party’s liability under this agreement is subject to the limitations in the engagement document, or failing that our terms of service, except where UK GDPR or the Data Protection Act 2018 provides otherwise. Nothing here limits either party’s liability to data subjects or to a supervisory authority.

10. Term and general

This agreement runs for as long as we process personal data on your behalf, and its confidentiality and deletion obligations survive.

It’s governed by the laws of England and Wales, with disputes settled in the courts of England and Wales.

Contact for all matters under this agreement: privacy@traumainformedcontent.com


Annex A — sub-processors

Current as at 29 July 2026. Not every engagement uses every one.

Sub-processorRoleLocationTransfer mechanism
Google Ireland Limited (Google Workspace)Email, calendar, document storage and collaborationEuropean Union and United StatesStandard Contractual Clauses / UK Addendum
Anthropic, PBCAI-assisted analysis, where the engagement provides for itUnited StatesUK Addendum to EU SCCs
Bankside Communications Limited (Rembrandt Editor)Content review tool operated by us; database hosted in LondonUnited Kingdom, with AI processing in the United StatesUK Addendum to EU SCCs for the AI component
Website hostHosting traumainformedcontent.com. Does not process client materialUnited Kingdom / European UnionNot applicable
Accountants and bookkeeping providersInvoicing and financial records. Business contact data only, no client materialUnited KingdomNot applicable

We will name the specific providers behind the generic entries above on request.


Annex B — technical and organisational measures

Access control. Client material is accessible only to Adrie van der Luijt, Director, Bankside Communications Limited. Multi-factor authentication on all business accounts. Devices are encrypted and password-protected, and lock automatically.

Segregation. Client material is held in a folder structure separated by client and engagement, kept apart from general business records, so deletion at the end of an engagement is complete rather than approximate.

Encryption. In transit and at rest across Google Workspace and any hosting used. Secure file transfer for material sent to and from clients, agreed at the start of each engagement.

Data minimisation. We ask for redaction of identifying details the work doesn’t require. We ask for the smallest sample that answers the question, rather than a full corpus. We don’t retain material beyond the engagement without a written request.

AI tool controls. Where AI-assisted analysis is used, it runs through commercial API terms under which content is not used for model training. In Rembrandt Editor, full-text retention is off, and stored reviews of client material are deleted at the end of the engagement rather than left to expire.

Deletion. At the end of an engagement, material is deleted from working storage, email, and any AI tool used, and deletion is confirmed in writing.

Incident response. Breaches affecting client material are notified to the client within 48 hours of becoming aware. Credentials are rotated immediately on any suspicion of exposure.

Organisational. One person has access. That person has four decades of experience in government, regulated-sector and trauma-informed content work, including Universal Credit, Cabinet Office pandemic services and FCA Consumer Duty engagements, and is contractually bound to confidentiality. Any future staff or subcontractor will be bound in writing before receiving access, and clients will be told before a subcontractor touches their material.

Business continuity. Material is held in cloud services with the provider’s own backup and redundancy. We don’t offer a contractual recovery time or recovery point objective, and would rather say so than imply a resilience posture we cannot evidence.