P
praeviso
Features Pricing FAQs Knowledge Base Contact
Start Free Trial →
Features Pricing FAQs Knowledge Base Contact Start Free Trial →

Data Processing Agreement

Last updated: 8 July 2026

Contents

    1. Introduction and Parties

    This Data Processing Agreement ("DPA") forms part of the Terms of Service (praeviso.app/terms) between Praeviso Ltd, a company registered in England and Wales with company number 17091118 and registered office at 27 Lysaght Gardens, Newport, NP19 4AT, United Kingdom ("we", "us", "our", "the Processor"), and the customer subscribing to or using the Praeviso project risk management workstation ("the Service") ("you", "your", "the Controller").

    This DPA is incorporated into the Terms of Service by reference and forms part of the agreement between you and us. It applies whenever we process personal data on your behalf in the course of providing the Service.

    For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you are the data controller of the personal data you and your users enter into the Service, and we are the data processor, processing that data on your behalf and on your instructions.

    This DPA does not apply to personal data we process for our own purposes — such as your account, billing, and communication data — for which we act as data controller. That processing is governed by our Privacy Policy (praeviso.app/privacy).

    2. Subject Matter and Duration

    The subject matter of the processing is the personal data contained in the data you and your users enter into the Service ("Your Data"), which we process in order to provide the Service to you.

    The processing lasts for the duration of your subscription (including any free trial), plus the 90-day post-cancellation retention period, until Your Data is deleted or returned in accordance with Section 11.

    3. Nature and Purpose of Processing

    We process Your Data by hosting, storing, displaying, backing up, and otherwise making it available to you and your authorised users through your isolated workstation instance. The sole purpose of the processing is to provide the Service as described in the Terms of Service.

    We do not process Your Data for our own purposes. We do not sell Your Data, share it with advertisers, or use it for profiling or automated decision-making.

    4. Types of Personal Data

    The personal data processed under this DPA may include:

    • Names and email addresses of your users
    • Login credentials, stored as cryptographic hashes (bcrypt) — we never store actual passwords
    • Multi-factor authentication secrets, stored encrypted (AES-256-GCM)
    • Personal data you choose to enter into the risk register and related workstation records — for example, names of risk owners, team members, and stakeholders

    5. Categories of Data Subjects

    The data subjects may include:

    • Your employees and other authorised users of the Service
    • Individuals named or otherwise identified in the project and risk data you enter into the Service

    6. Our Obligations as Processor

    We will:

    • Process Your Data only on your documented instructions. The Terms of Service, this DPA, and your (and your users') use of the Service's features constitute those instructions
    • Ensure that all persons authorised to process Your Data are subject to appropriate obligations of confidentiality
    • Implement and maintain the technical and organisational security measures described in Section 8
    • Assist you as described in Sections 9 and 10
    • Delete or return Your Data as described in Section 11
    • Make available to you the information necessary to demonstrate compliance with this DPA, as described in Section 13
    • Inform you if, in our opinion, an instruction from you infringes the UK GDPR or other applicable data protection law

    7. Sub-processors

    You give us general written authorisation to engage the following sub-processors in the provision of the Service:

    Sub-processor Purpose Location
    Railway Hosting (Admin Platform and marketing site) United States
    Hetzner Hosting (customer workstation instances) and object storage (database archives and backups) Germany
    Stripe Payment processing United States
    Resend Transactional email delivery United States
    Coolify Tenant workstation orchestration (Docker container management) Germany (on Hetzner infrastructure)

    We will notify you of any intended addition or replacement of a sub-processor — by email or by a notice on our website — before the change takes effect, giving you the opportunity to object on reasonable data-protection grounds. If you object and we cannot offer a reasonable alternative, you may cancel your subscription in accordance with the Terms of Service.

    We impose data-protection obligations on each sub-processor that are materially equivalent to those in this DPA, and we remain responsible to you for the performance of each sub-processor's obligations.

    8. Security Measures

    We implement and maintain appropriate technical and organisational measures to protect Your Data, including:

    • Per-tenant database isolation: Each customer organisation has its own separate database. Your Data is never co-mingled with other customers' data
    • Encryption at rest: Customer workstation instances use LUKS full-disk encryption
    • Application-level encryption: Multi-factor authentication secrets and database backups are encrypted using AES-256-GCM
    • Credential protection: Passwords are hashed using bcrypt and are never stored in plain text
    • Encryption in transit: All data is transmitted over TLS
    • Access controls: Role-based access within each organisation; administrative access to our platform is protected by multi-factor authentication
    • Audit logging: System activity is recorded in audit logs
    • Backups: Independent, encrypted backups are maintained to protect against data loss

    9. Assistance with Data Subject Rights

    Taking into account the nature of the processing, we will assist you, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling your obligation to respond to data subjects exercising their rights under UK GDPR — including access, rectification, erasure, restriction of processing, data portability, and objection.

    If a data subject contacts us directly with a request relating to Your Data, we will forward the request to you without undue delay and will not respond to it ourselves except on your instructions or where required by law.

    10. Personal Data Breach Notification

    We will notify you without undue delay after becoming aware of a personal data breach affecting Your Data. Our notification will include, so far as available to us, the information you need to meet your own notification obligations under UK GDPR — including the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.

    We will cooperate with you and take reasonable steps to assist in the investigation, mitigation, and remediation of any such breach.

    11. Deletion and Return of Data

    • You may export Your Data at any time while your subscription is active, and during the 90-day post-cancellation retention period, using the export functionality within the workstation (PDF reports, Excel exports, API access where available)
    • Following cancellation or expiry of your subscription, Your Data — including your isolated customer database — is retained for 90 days and then permanently deleted
    • A minimal financial record (company name, Stripe customer identifier, subscription dates and amounts) is retained for 6 years to meet UK tax and accounting obligations, and is then deleted. We hold this record as data controller; it does not include any of Your Data entered into the workstation

    12. International Transfers

    Customer workstation instances — and therefore Your Data — are hosted in the European Union (Hetzner, Germany), with database archives and backups held on the same EU infrastructure.

    Ancillary processing involves sub-processors based in the United States: Stripe (payment processing), Resend (transactional email delivery), and Railway (hosting of our Admin Platform and marketing site). Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Information Commissioner's Office and/or the UK International Data Transfer Addendum.

    We do not transfer Your Data to any third country without appropriate safeguards.

    13. Audit and Compliance

    On written request, no more than once in any 12-month period and on reasonable notice, we will provide you with the documentation and information reasonably necessary to demonstrate our compliance with this DPA — including descriptions of our security measures and sub-processor arrangements.

    Where that documentation is not sufficient to demonstrate compliance, we will cooperate with audits or inspections conducted by you or your appointed auditor, provided they are carried out in a manner that does not compromise the security of the Service or the confidentiality of other customers' data.

    14. Changes to This DPA

    We may update this DPA from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will notify you at least 30 days before the changes take effect, by email or via a notice on our website.

    15. Governing Law

    This DPA is governed by the laws of England and Wales. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

    16. Contact

    For any questions about this DPA or our data processing practices:

    Email: support@praeviso.app

    Praeviso Ltd
    27 Lysaght Gardens, Newport, NP19 4AT, United Kingdom

    P
    praeviso
    Features Pricing FAQs Knowledge Base Contact Privacy Policy Terms of Service Cookie Policy Acceptable Use Data Processing Agreement
    © 2026 Praeviso. All rights reserved.