Data processing agreement — Rembrandt Editor

Version 1.0 · 29 July 2026

This agreement applies whenever you use Rembrandt Editor to process content containing personal data for which you are the controller. It takes effect automatically when you accept our terms of service, so there is nothing to sign for Free and Professional. Team customers who need it executed as a countersigned document should email privacy@rembrandteditor.com.

Where this agreement and our terms of service differ on data protection, this agreement wins.


1. Parties and roles

Processor: Bankside Communications Limited, company number 14193570, registered office Pearce & Co, Ground Floor, 11 Pierrepont Street, Bath, England, BA1 1LA, trading as Trauma-Informed Content Consulting (“we”, “us”).

Controller: you, or the organisation on whose behalf you use Rembrandt Editor (“you”).

You are the controller of any personal data contained in the content you submit for review. We are your processor in respect of that data.

We are a separate, independent controller of the data we hold about you as a user of the service — your email address, plan, billing details and usage counters. That is covered by our privacy policy, not by this agreement.

2. What this covers

Subject matter. Providing the Rembrandt Editor content review service.

Duration. From your first use until your account is closed and all stored reviews have been deleted or expired.

Nature and purpose. Transmitting content to an AI provider for analysis; generating and returning a review; where your plan and settings provide for it, storing that review so you can retrieve it and compare later versions against it.

Types of personal data. Whatever appears in the content you choose to submit. Typically this is correspondence and service content, which may contain names, addresses, reference and account numbers, financial details such as balances and arrears, dates, appointment and case details, and — depending on your sector — health information, bereavement details, or details of vulnerability. We do not control what you submit and we do not inspect it. You decide what goes in.

Categories of data subject. Whoever the content concerns. Typically your customers, claimants, clients, patients, service users, employees or correspondents.

Special category data. Rembrandt Editor is designed for content that reaches people in distress, so special category data — particularly health data — may well be present. Where it is, you must have an Article 9 condition for processing it. We recommend redacting or replacing identifying details before submission wherever the review does not depend on them; a review of an arrears letter is no less useful if the name is “[Customer]” and the reference number is “[Ref]”.

3. Our obligations

We will:

a) Process only on your instructions. Your documented instructions are: these terms, this agreement, and the settings you choose in the product — plan, jurisdiction, drafting context, and whether to retain full text. We will not process the personal data in your content for any other purpose. If we believe an instruction breaches UK GDPR, we’ll tell you.

b) Keep it confidential. Anyone we authorise to access the data is bound by confidentiality obligations.

c) Secure it. We implement the measures in Annex B, appropriate to the risk under Article 32.

d) Use sub-processors only as set out in section 4.

e) Help you meet data subject requests. If a data subject contacts us about data we hold as your processor, we’ll direct them to you and tell you promptly. We’ll assist you in responding, taking into account the nature of the processing. In practice you can find and delete any stored review yourself from your review history, so most requests need nothing from us.

f) Help you with Articles 32 to 36. We’ll provide the information you reasonably need for security assessments, breach notification, DPIAs and prior consultation, taking into account the nature of the processing and the information available to us.

g) Tell you about breaches. We’ll notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information available to us at the time and updates as we learn more. You are responsible for notifying the ICO and affected data subjects where required.

h) Delete or return it. On termination we’ll delete all personal data processed on your behalf within 30 days, unless UK or EU law requires us to keep it. Stored reviews also delete automatically at the end of their retention period without you doing anything.

i) Demonstrate compliance and allow audits. We’ll make available the information needed to show we meet these obligations, and allow audits — including inspections — by you or an auditor you mandate. Section 8 sets out how.

4. Sub-processors

You give general authorisation for the sub-processors in Annex A.

If we intend to add or replace one, we’ll give you 30 days’ notice by email to your account address and by updating Annex A. If you reasonably object on data protection grounds within that period, tell us and we’ll try to resolve it. If we can’t, you may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees.

We impose data protection obligations on every sub-processor that are no less protective than those in this agreement, and remain fully liable to you for their performance.

5. International transfers

Personal data in stored reviews is held in the United Kingdom (AWS eu-west-2, London).

Content submitted for review is processed by Anthropic in the United States. Some infrastructure and email processors also operate in the United States, as listed in Annex A.

Transfers outside the UK are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. We carry out transfer risk assessments and will provide them on request.

6. Retention

DataRetention
Free plan reviewsNot stored
Professional stored reviews, including quoted excerpts and, where opted in, full document text90 days from creation, then permanently and automatically deleted
Team stored reviews90 days by default; a different period may be agreed in writing
Uploaded PDFsNot stored
Content held by our AI sub-processorRetained briefly for trust and safety, then deleted, per Anthropic’s commercial terms

You can delete any stored review at any time from your review history. Deletion is immediate and permanent, not a hidden flag.

7. Your obligations

You will:

  • Ensure you have a lawful basis for processing the personal data you submit, and an Article 9 condition where special category data is involved
  • Ensure your own privacy notices cover the use of an AI content review tool as a processor
  • Not submit personal data you have no lawful basis to process
  • Consider whether identifying details need to be present at all, and redact where they don’t
  • Consider whether a DPIA is required for your use of the service, particularly where content concerns people in vulnerable circumstances
  • Configure the service appropriately, including whether to retain full document text
  • Keep control of who in your organisation holds accounts, and remove access when people leave

8. Audit

We’ll respond to reasonable written information requests about our processing within 30 days, and provide our security documentation and transfer risk assessments on request.

Where an on-site or remote inspection is genuinely necessary, we’ll cooperate with an audit no more than once in any 12-month period, on 30 days’ written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the service. You bear your own costs and reasonable costs we incur.

More frequent audits may take place where a supervisory authority requires it, or following a personal data breach affecting your data.

We should be straightforward about scale: we’re a single-practitioner business, not a platform with an audit team. We hold no ISO 27001 or SOC 2 certification and will not claim otherwise. What we can offer is direct access to the person who built and runs the system.

9. Liability

Each party’s liability under this agreement is subject to the limitations in our terms of service, except where UK GDPR or the Data Protection Act 2018 provides otherwise. Nothing here limits either party’s liability to data subjects or to a supervisory authority.

10. Term and general

This agreement runs for as long as we process personal data on your behalf.

It’s governed by the laws of England and Wales, with disputes settled in the courts of England and Wales.

We may update it to reflect changes in the service, sub-processors or the law, with 30 days’ notice by email to your account address for material changes.

Contact for all matters under this agreement: privacy@rembrandteditor.com


Annex A — sub-processors

Current as at 29 July 2026.

Sub-processorRoleLocation of processingTransfer mechanism
Anthropic, PBCAI model generating the reviewUnited StatesUK Addendum to EU SCCs
Supabase, Inc.Database and authenticationUnited Kingdom (AWS eu-west-2, London)Not applicable
Vercel, Inc.Application hosting and server functionsUnited States, with edge delivery worldwideUK Addendum to EU SCCs
Resend, Inc.Sign-in emailsUnited StatesUK Addendum to EU SCCs
Stripe Payments Europe Ltd / Stripe, Inc.Payments (user billing data only; no review content)Ireland and United StatesStripe’s own transfer mechanisms
Cloudflare, Inc.DNS and denial-of-service protectionUnited States, with global edgeUK Addendum to EU SCCs

Anthropic does not use content submitted through its commercial API to train its models.

Stripe processes only your billing data as controller. It never receives content submitted for review.


Annex B — technical and organisational measures

Access control. Single-use email link authentication; no passwords stored. Row-level security in the database restricts every signed-in user to their own account and their own reviews. Users cannot write directly to the database at all — every write passes through server-side functions that verify the session. Stored reviews can be created only by the server, so a record cannot be forged or altered from a browser. Production access is limited to Adrie van der Luijt, Director of Bankside Communications Limited.

Encryption. TLS on all connections. Encryption at rest provided by the infrastructure platforms. API credentials held only in server-side environment variables, never in the browser bundle.

Data minimisation. Free plan reviews are not stored at all. Full document text is stored only on explicit opt-in, off by default. Uploaded PDFs are never stored. A one-way hash of content supports revision detection without holding the content. The review list view returns counts rather than content.

Retention and deletion. Every stored review carries an expiry timestamp set when it is created. A scheduled job permanently deletes expired reviews daily. Deleting an account cascades to every review belonging to it. Deletion is a hard delete.

Segregation. Each user’s reviews are isolated by row-level security keyed to their authenticated identity. There is no cross-account access path, and no shared or team-wide read access unless a Team agreement provides for it in writing.

Network controls. The API accepts browser requests only from an explicit allow-list of origins. Payment webhooks are cryptographically signature-verified with replay protection before any data is read.

Logging. Server logs record request metadata for security and fault diagnosis, retained 7–30 days by the infrastructure provider. Application logs do not record submitted content.

Vendor management. Sub-processors are selected for their own data protection posture. Data residency is set to the United Kingdom wherever the platform supports it.

Incident response. Breaches are notified to affected controllers within 48 hours of becoming aware. Credentials are rotated immediately on any suspicion of exposure.

Organisational. The business has one person with system access. That person is trained in data protection through four decades of work in government and regulated-sector content, and is contractually bound to confidentiality. Any future staff or contractors will be bound by written confidentiality obligations before receiving access.

Business continuity. The database is backed up by the platform provider under its standard policy. We do not offer a contractual recovery time or recovery point objective, and would rather say so than imply a resilience posture we cannot evidence.