Skip to main content

Legal

Data processing addendum

Last updated: 4 September 2026. This addendum sits with the Terms of use and Privacy notice for the HDR Compass product run by Shaine Stead (trading as HDR Compass). This addendum explains our role: independent controller for account and billing data, and not a processor of client case content under the zero-retention model.

1. Roles

For account and billing personal data (organisation name, user name, work email, subscription identifiers), Shaine Stead (trading as HDR Compass) acts as independent controller as described in the Privacy notice: we determine the purposes of providing the SaaS account platform.

For client / matter data (case documents, photos, prompts containing client facts, generated reports), the subscribing firm remains the controller. HDR Compass is designed so that data does not reside on our servers: firm storage (browser File System Access) and firm BYOK AI. We are not a processor of case content under the zero-retention model. HDR Compass is not a party to the firm-provider processing relationship. The firm's AI provider processes case content on the firm's instructions as a processor for the firm, so the firm must hold a data processing agreement with its provider and review international transfer safeguards.

2. What this DPA covers

This document describes how we handle the account platform and the sub-processors we use for it. It is offered so firms can complete supplier due diligence. It is not a substitute for your own DPIA on BYOK AI or local folder processing.

3. Account data we process

  • Organisation and user accounts
  • Subscription / licence status
  • Work email and display name
  • SRA firm number (format-validated, not verified against the SRA register)
  • Legal-acceptance records (versions of Terms, Privacy notice and DPA accepted, and when)
  • Organisation invitations (email address, role, and status of pending invitations)
  • Stripe customer / subscription identifiers

We do not process on our servers:

  • Case documents or file contents
  • AI prompts or completions containing client facts
  • Vetting or case-review report bodies
  • Connected folder inventories beyond the live session

4. Sub-processors (account platform)

  • Supabase: Authentication and account database hosting. Personal data in profiles/organisations/subscriptions. Region depends on the configured Supabase project (currently UK, London: eu-west-2).
  • Stripe: Subscription payments and customer billing portal. Name, email, and payment metadata as required to take and manage fees.

We will update this page when account-platform sub-processors change in a material way. Firm-chosen AI providers under BYOK are not our sub-processors.

5. Security measures (summary)

  • TLS in transit for the hosted application
  • Access control via authenticated sessions (Supabase Auth)
  • Row Level Security on account tables; service role limited to server billing routes
  • No case-document upload API by design
  • Security headers including Content-Security-Policy

6. Assistance and incidents

For account-data subject requests or suspected personal-data incidents affecting the account platform, contact privacy@hdrcompass.co.uk (compliance officer: Shaine Stead). We will cooperate reasonably with firms investigating account-platform incidents.

7. Governing law

This addendum is governed by the laws of England and Wales. ICO registration: ZB861396 (held by Shaine Stead).

Address: 10 Devon Close, Macclesfield, Cheshire SK10 3HB. Not a substitute for negotiated enterprise DPAs where required.