Data processing agreement
Plain English draft, September 2026, pending legal review. It forms part of the terms of service. We will sign a copy before you send us anything if you would rather have it on paper.
1. Roles
Your firm is the controller of your clients' personal data. Gatherwell is the processor. We process that data only on your documented instructions, which are the terms of service, this agreement and the actions you take in the product. If we ever think an instruction breaches data protection law we will tell you rather than carry it out quietly.
2. What is processed
| Item | Detail |
|---|---|
| Subject matter | Collecting accounting records and supporting documents from your clients on your behalf |
| Duration | For as long as your account is open, plus the retention period you set, plus a 30-day recovery window |
| Categories of data subject | Your clients and their contacts, and your own staff |
| Categories of personal data | Names, email addresses, mobile numbers, and the contents of documents your clients send: bank statements, invoices, receipts, payslips, tax documents, identification documents where you request them |
| Special category data | Not requested by any template. It can appear incidentally inside a document a client uploads, so it is handled with the same controls as everything else. |
3. Our obligations
- Process only on your instructions, and only for the purpose above.
- Keep the technical and organisational measures set out on the security page, which forms part of this agreement.
- Bind everyone with access to confidentiality, and give access only to those who need it.
- Help you answer a data subject request, a data protection impact assessment or a regulator, within reason and without extra charge for anything proportionate.
- Tell you without undue delay, and within 72 hours of becoming aware, if there is a personal data breach affecting your data, with what we know, what we have done and what we advise.
- Delete or return your data at the end of the agreement, on the schedule in section 6.
- Make available the information you need to demonstrate compliance, and allow an audit on reasonable notice, once a year or after a breach.
4. Sub-processors
You give general authorisation for the sub-processors listed on the security page. We will give 30 days' notice before adding or replacing one. If you reasonably object, tell us within those 30 days and you may terminate without penalty for the remainder of your paid period. Every sub-processor is bound by terms no weaker than these.
5. International transfers
Your clients' data stays in the European Union or the United Kingdom. If a sub-processor ever needs to transfer data outside those, we will rely on an adequacy decision or on standard contractual clauses with a transfer risk assessment, and we will tell you first.
6. Deletion and return
- You can export everything at any time yourself, as JSON plus files in a zip.
- Files are deleted when the retention period you set expires.
- On termination, data is recoverable for 30 days and then permanently deleted. Deletion is recorded in the audit log and a certificate is available on request.
- Backups age out within 35 days. We do not restore a deleted firm from a backup.
7. Liability
Liability under this agreement is subject to the limits in the terms of service, except where data protection law does not permit that.