Opencomplai

Legal

Data Processing Agreement

Last updated September 22, 2026

This Data Processing Agreement (“DPA”) applies when CheckRef Ltd provides the hosted Opencomplai service at app.opencomplai.com to a business customer, on a free or paid plan. It forms part of the agreement under which the customer uses the hosted service: our Terms and, for a paid plan, its order form or other agreement. It sets out how we process personal data on the customer's behalf.

This DPA does not cover the open-source Opencomplai software. When you run pip install opencomplai and use the CLI on its own, without pushing results to the hosted service, CheckRef does not receive or process any of your data. Artifacts the CLI pushes to the hosted service are covered by this DPA.

1. Definitions

In this DPA:

  • “Agreement” means our Terms together with, for a paid plan, the order form or other written agreement between CheckRef and the Customer for the Service.
  • “CheckRef”, “we” and “us” mean CheckRef Ltd, a company registered in England and Wales with company number 15416191, whose registered office is at 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ, United Kingdom.
  • “Customer” means the business or organisation that has entered into the Agreement with CheckRef.
  • “Authorised Users” means the individuals the Customer allows to use the Service, such as its employees and contractors.
  • “Customer Personal Data”means personal data that CheckRef processes on the Customer's behalf in providing the Service, as described in Annex 1. It does not include Account Data.
  • “Account Data” has the meaning given in section 2.3.
  • “Data Protection Laws”means all laws relating to data protection and privacy that apply to the processing of Customer Personal Data under the Agreement, including the UK GDPR, the Data Protection Act 2018 and, where it applies, Regulation (EU) 2016/679 (the “EU GDPR”), each as amended or replaced from time to time.
  • “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018.
  • “Service”means the hosted Opencomplai service at app.opencomplai.com and its associated APIs, including the ingestion API that receives evidence artifacts from the Customer's CI pipelines.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by CheckRef or its Sub-processors.
  • “Sub-processor” means a third party engaged by CheckRef that processes Customer Personal Data in providing the Service.
  • “EU SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
  • “Controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings given to them in the Data Protection Laws.

2. Roles of the parties

  1. 2.1
    For Customer Personal Data, the Customer is the controller (or, where it acts for another controller, a processor) and CheckRef is the Customer's processor (or sub-processor).
  2. 2.2
    The Customer is responsible for the lawfulness of the Customer Personal Data that it and its Authorised Users put into the Service, including having a lawful basis for the processing and giving any notices that Data Protection Laws require. The Customer must not use the Service to process special category data or personal data relating to criminal convictions and offences.
  3. 2.3
    CheckRef is an independent controller, not a processor, for the limited personal data it needs to run accounts and the customer relationship (“Account Data”): the sign-in email address, name (if provided), organisation memberships and roles of Authorised Users and records of invitations; the IP addresses and request information CheckRef uses to secure sign-in and the Service; and the details of the Customer's contacts for sales, billing and support correspondence outside the Service. CheckRef processes Account Data as described in its Privacy Policy, and this DPA does not apply to it.

3. Processing on documented instructions

  1. 3.1
    CheckRef will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to other countries, unless UK law, or the law of an EU member state to which CheckRef is subject, requires otherwise. In that case CheckRef will tell the Customer about that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
  2. 3.2
    The Customer's instructions are: the Agreement, including this DPA; the processing that the Customer and its Authorised Users initiate by using the Service, including by sending evidence artifacts to the ingestion API and by configuring and using the dashboard; and any other reasonable written instructions the Customer gives that are consistent with the Agreement. Instructions that would change the scope of the Service or its fees need to be agreed as a change to the Agreement.
  3. 3.3
    CheckRef will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
  4. 3.4
    CheckRef will not sell Customer Personal Data, use it for its own purposes, or use it to train artificial intelligence models.

4. Confidentiality of personnel

  1. 4.1
    CheckRef will ensure that everyone it authorises to process Customer Personal Data is bound by an appropriate duty of confidentiality, whether contractual or statutory.
  2. 4.2
    CheckRef will limit access to Customer Personal Data to personnel who need it to provide, secure or support the Service.

5. Security

  1. 5.1
    Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals, CheckRef will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the UK GDPR and, where it applies, the EU GDPR. The measures in place at the date of this DPA are described in Annex 2.
  2. 5.2
    CheckRef may change these measures as technology and risks develop, provided the changes do not reduce the overall level of protection for Customer Personal Data.
  3. 5.3
    The Customer is responsible for the security of its own systems and its use of the Service, including keeping its API keys and signing keys secret, deciding which Authorised Users have access and with which role, and securing the email accounts its Authorised Users sign in with.

6. Sub-processors

  1. 6.1
    The Customer gives CheckRef general authorisation to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Annex 3, and the Customer authorises their use.
  2. 6.2
    CheckRef will give the Customer at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by updating Annex 3 on this page and by emailing the Customer's notice contact under the Agreement or, if there is none, the Authorised Users with the administrator role.
  3. 6.3
    The Customer may object to a new Sub-processor on reasonable grounds relating to data protection by writing to hello@opencomplai.com within the notice period. The parties will then discuss the objection in good faith. If CheckRef cannot reasonably address it, for example by offering an alternative, either party may terminate the affected part of the Service by written notice, and CheckRef will refund any fees the Customer has prepaid for the period after termination.
  4. 6.4
    CheckRef will engage each Sub-processor under a written contract that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent they apply to the service that Sub-processor provides.
  5. 6.5
    CheckRef remains liable to the Customer for each Sub-processor's performance of its data protection obligations as if they were CheckRef's own, subject to section 12.

7. Assistance

  1. 7.1
    Taking into account the nature of the processing, CheckRef will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from individuals exercising their rights under Data Protection Laws. Some Customer Personal Data, such as AI system details, control owners and organisation membership, can be corrected or removed by the Customer's administrators directly in the dashboard. For the rest, including ingested evidence artifacts and support messages, which the Service keeps unchanged as an evidence trail, CheckRef will act on the Customer's written instructions.
  2. 7.2
    If CheckRef receives a request directly from an individual about Customer Personal Data, it will pass the request to the Customer without undue delay and will not respond to it itself, other than to tell the individual to contact the Customer.
  3. 7.3
    Taking into account the nature of the processing and the information available to it, CheckRef will give the Customer reasonable assistance with its obligations under Articles 32 to 36 of the UK GDPR and, where it applies, the EU GDPR: security, Personal Data Breach notifications, data protection impact assessments and prior consultation with supervisory authorities.
  4. 7.4
    Where assistance under this section goes beyond providing information CheckRef already holds or functionality already in the Service, CheckRef may charge its reasonable costs, which it will agree with the Customer in advance.

8. Personal data breaches

  1. 8.1
    CheckRef will notify the Customer of a Personal Data Breach without undue delay and in any event within 48 hours of becoming aware of it.
  2. 8.2
    The notice will describe, as far as the information is available:
    1. the nature of the breach, including, where possible, the categories and approximate number of individuals and personal data records concerned;
    2. the name and contact details of a CheckRef contact who can provide more information;
    3. the likely consequences of the breach; and
    4. the measures CheckRef has taken or proposes to take to address the breach, including to mitigate its possible adverse effects.
    Where not all of this information is available at once, CheckRef will provide it in phases without further undue delay.
  3. 8.3
    CheckRef will send the notice by email to the Customer's notice contact under the Agreement and to the Authorised Users with the administrator role, take reasonable steps to contain and investigate the breach, and keep the Customer informed of material developments.
  4. 8.4
    The Customer, as controller, is responsible for any notification to supervisory authorities or individuals that Data Protection Laws require. CheckRef will not notify third parties of a breach of Customer Personal Data on the Customer's behalf unless the Customer asks it to or the law requires it.
  5. 8.5
    CheckRef's notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.

9. Deletion or return

  1. 9.1
    When the Agreement ends, CheckRef will stop processing Customer Personal Data, except as needed to comply with this section.
  2. 9.2
    Within 30 days after the Agreement ends, CheckRef will delete Customer Personal Data. If the Customer asks in writing before the Agreement ends, CheckRef will first return a copy of the Customer Personal Data to it in a commonly used, machine-readable format such as JSON.
  3. 9.3
    Section 9.2 does not apply to the extent that applicable law requires CheckRef to keep Customer Personal Data. In that case CheckRef will keep it confidential, protect it in accordance with this DPA, and process it only for the purpose the law requires.
  4. 9.4
    Copies in backups and logs kept by CheckRef's Sub-processors are deleted in line with those Sub-processors' standard retention cycles. Until then they remain protected under this DPA and are not otherwise processed.
  5. 9.5
    On request, CheckRef will confirm to the Customer in writing when deletion is complete.

10. Audits and information

  1. 10.1
    On request, CheckRef will make available to the Customer the information reasonably necessary to demonstrate its compliance with this DPA and with Article 28 of the UK GDPR and, where it applies, the EU GDPR, for example by answering a reasonable security questionnaire and providing relevant documentation.
  2. 10.2
    Where that information is not enough to demonstrate compliance, or a supervisory authority requires it, CheckRef will allow for and contribute to audits, including inspections, by the Customer or an independent auditor it appoints who is bound by confidentiality obligations and is not a competitor of CheckRef, on these conditions:
    1. the Customer gives CheckRef reasonable written notice of at least 30 days;
    2. the audit takes place during normal business hours, is conducted so as to minimise disruption, and does not give access to other customers' data or to CheckRef's confidential information unrelated to Customer Personal Data;
    3. the Customer bears the cost of the audit, including its auditor's fees; and
    4. audits take place no more than once in any 12-month period, unless the audit follows a Personal Data Breach or a supervisory authority requires it.
  3. 10.3
    CheckRef's Sub-processors operate their own infrastructure. For them, the Customer's rights under this section are met by the information and audit reports they make available to CheckRef, which CheckRef will share with the Customer where it is permitted to.
  4. 10.4
    Information the Customer obtains under this section is CheckRef's confidential information, and the Customer may use it only to verify compliance with this DPA and Data Protection Laws.

11. International transfers

  1. 11.1
    CheckRef is established in the United Kingdom. The Service is hosted in the European Union: the application runs in Vercel's Frankfurt (fra1) region, and the database is hosted by Neon in AWS eu-central-1 (Frankfurt, Germany).
  2. 11.2
    Where the Customer is subject to the EU GDPR, transfers of Customer Personal Data to CheckRef in the United Kingdom rely on the European Commission's adequacy decision for the United Kingdom. If that decision stops applying, the parties agree that the EU SCCs (Module Two where the Customer is a controller, and Module Three where it is a processor) will apply to those transfers.
  3. 11.3
    Vercel Inc. and Neon, Inc. are established in the United States. Although Customer Personal Data is hosted in Frankfurt, those providers may access it from outside the UK and the EEA, for example to support and operate their services. For those transfers, CheckRef relies on the EU SCCs and the UK Addendum as incorporated in each provider's data processing agreement with CheckRef. Brevo (Sendinblue SAS) is established in France, in the EEA.
  4. 11.4
    CheckRef will not transfer Customer Personal Data outside the UK and the EEA, or allow a Sub-processor to do so, except in compliance with Data Protection Laws, relying on adequacy decisions or regulations or on appropriate safeguards such as the EU SCCs and the UK Addendum.

12. Liability

  1. 12.1
    Each party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, is subject to the exclusions and limitations of liability in the Agreement.
  2. 12.2
    Nothing in this DPA limits or excludes any liability that cannot be limited or excluded by law.

13. Order of precedence and governing law

  1. 13.1
    This DPA forms part of the Agreement. If there is a conflict in relation to the processing of Customer Personal Data, the following order of precedence applies: (a) the EU SCCs and the UK Addendum, where they apply under section 11; (b) this DPA; (c) the order form or other agreement for the Service; and (d) our Terms.
  2. 13.2
    This DPA, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it, is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where the EU SCCs require otherwise.
  3. 13.3
    CheckRef may update this DPA to reflect changes in Data Protection Laws, the Service or its Sub-processors (for new Sub-processors, section 6 applies). A change that materially reduces the protection of Customer Personal Data will not apply to the Customer during the current term of its Agreement without its written agreement, unless the law requires it. The date at the top of this page shows the latest revision.
  4. 13.4
    If the Customer needs a signed copy of this DPA, it can ask at hello@opencomplai.com.

Annex 1: Details of processing

Subject matter
Provision of the Service: a hosted dashboard in which the Customer tracks the compliance status and evidence of its AI systems.
Duration
The term of the Agreement, and afterwards until deletion under section 9.
Nature of processing
Collection (through the dashboard and the ingestion API), signature verification, storage, organisation, structuring, retrieval, consultation, display, reporting, transmission by email for notifications, restriction and erasure.
Purpose
To provide, secure and support the Service for the Customer under the Agreement, and as otherwise instructed by the Customer under section 3.
Data subjects
  • Authorised Users.
  • Individuals named in Customer Personal Data, such as owners of AI systems and controls, reviewers and approvers.
  • Any other individuals whose personal data the Customer chooses to include, for example in free-text fields or support tickets.
Personal data
  • AI system records: system names, owner email addresses, intended purpose, deployment context and notes, as entered by Authorised Users.
  • Control records: control owners (names or email addresses), due dates, who marked a control as satisfied or waived and when, and waiver reasons.
  • Risk classification records: answers to the risk classification questionnaire, the resulting assessment, and the Authorised User who ran it.
  • Evidence artifacts sent from the Customer's CI pipelines: system identifiers, git commit references, policy bundle versions, scan, rule and evaluation results, per-article gap statuses and rationale text, control owners and due dates, SHA-256 hashes of evidence, signing key identifiers and timestamps. The artifact format carries hashes and summary results, not source code or the underlying evidence files, which stay in the Customer's environment. Artifacts contain personal data only where the Customer's configuration puts it there, for example a control owner's name or email address, or personal data in a free-text field or error message.
  • Support tickets raised in the Service: subject, message text and author.
  • Audit log entries recording actions in the Customer's organisation: the type of action, its time and outcome, the identifier of the Authorised User who took it and related details, such as an invited email address.
  • Project and API key records: names, and the Authorised Users who created them.
Special categories
None intended. The Service is not designed to process special category data or personal data relating to criminal convictions and offences, and the Customer must not submit it (section 2.2).
Frequency
Continuous for the term of the Agreement.
Sub-processors
As listed in Annex 3.

Annex 2: Technical and organisational measures

These measures are in place at the date of this DPA. CheckRef does not currently hold third-party security certifications such as SOC 2 or ISO/IEC 27001.

Encryption and hosting

  • All traffic to and from the Service is encrypted in transit with TLS, and HTTP Strict Transport Security (HSTS) is enabled.
  • Data at rest is encrypted by CheckRef's hosting and database providers.
  • The Service is hosted in the European Union, in Frankfurt, Germany (Vercel fra1 region; Neon on AWS eu-central-1).

Access control

  • Sign-in is passwordless, by magic link sent to the user's email address. No passwords are stored.
  • Role-based access (administrator, member and viewer roles) and per-organisation access control are enforced in the application, so an Authorised User can reach only the organisations they belong to, with the permissions of their role.
  • A tenant-scoped audit log records actions in each organisation, such as invitations, membership and role changes, API key changes and control decisions.

Integrity and application security

  • The ingestion API accepts evidence artifacts only when they are authenticated with a valid, unrevoked project API key; any signature an artifact carries is verified on receipt, and one that does not verify is rejected.
  • Public and authentication endpoints are rate limited.
  • Strict security headers are set, including a Content-Security-Policy with per-request nonces and frame-ancestors 'none', which prevents the Service from being framed by other sites.
  • Security vulnerabilities can be reported to security@opencomplai.com.

Organisational measures

  • Confidentiality and need-to-know access for personnel (section 4).
  • Written contracts with Sub-processors (section 6).
  • Personal Data Breach notification within 48 hours (section 8).

Annex 3: Sub-processors

CheckRef uses the following Sub-processors for the Service. Notice of changes is given under section 6.

Sub-processorServiceLocation of processingTransfer mechanism
VercelVercel Inc., United StatesHosting of the web application and APIs, including the ingestion APIFrankfurt, Germany (fra1 region); requests pass through Vercel's global edge networkEU SCCs and UK Addendum, as incorporated in Vercel's data processing agreement
NeonNeon, Inc., United StatesManaged Postgres database that stores Service dataFrankfurt, Germany (AWS eu-central-1)EU SCCs and UK Addendum, as incorporated in Neon's data processing agreement
BrevoSendinblue SAS, FranceTransactional email: sign-in links, invitations, welcome emails and support-ticket notificationsEuropean UnionNot required: established in the EEA, and UK adequacy regulations cover transfers from the UK

Questions?

If you have questions about this DPA or need a signed copy, reach out.

hello@opencomplai.com
Contact