Skip to main content

Legal

Data processing addendum

Last updated: 9 August 2026. This addendum sits with the Terms of use and Privacy notice for the HDR Compass product operated by EWLPS Legal Protocol Systems. This addendum explains our role: independent controller for account and billing data, and not a processor of client case content under the zero-retention model.

1. Roles

For account and billing personal data (organisation name, user name, work email, subscription identifiers), EWLPS Legal Protocol Systems acts as independent controller as described in the Privacy notice — we determine the purposes of providing the SaaS account platform.

For client / matter data (case documents, photos, prompts containing client facts, generated reports), the subscribing firm remains the controller. HDR Compass is designed so that data does not reside on our servers: firm storage (browser File System Access) and firm BYOK AI. We are not a processor of case content under the zero-retention model.

2. What this DPA covers

This document describes how we handle the account platform and the sub-processors we use for it. It is offered so firms can complete supplier due diligence. It is not a substitute for your own DPIA on BYOK AI or local folder processing.

3. Account data we process

  • Organisation and user accounts
  • Subscription / licence status
  • Work email and display name
  • SRA firm number (format-validated, not verified against the SRA register)
  • Legal-acceptance records (versions of Terms, Privacy notice and DPA accepted, and when)
  • Organisation invitations (email address, role, and status of pending invitations)
  • Stripe customer / subscription identifiers

We do not process on our servers:

  • Case documents or file contents
  • AI prompts or completions containing client facts
  • Vetting or case-review report bodies
  • Connected folder inventories beyond the live session

4. Sub-processors (account platform)

  • SupabaseAuthentication and account database hosting. Personal data in profiles/organisations/subscriptions. Region depends on the configured Supabase project (currently UK, London — eu-west-2).
  • StripeSubscription payments and customer billing portal. Name, email, and payment metadata as required to take and manage fees.
  • Firm-chosen AI provider (BYOK)Optional AI drafting / analysis. Prompts and document excerpts are sent from the browser to the firm’s provider under the firm’s API key. HDR Compass is not the controller of that processing relationship.

We will update this page when account-platform sub-processors change in a material way. Firm-chosen AI providers under BYOK are not our sub-processors.

5. Security measures (summary)

  • TLS in transit for the hosted application
  • Access control via authenticated sessions (Supabase Auth)
  • Row Level Security on account tables; service role limited to server billing routes
  • No case-document upload API by design
  • Security headers including Content-Security-Policy

6. Assistance and incidents

For account-data subject requests or suspected personal-data incidents affecting the account platform, contact privacy@ewlps.co.uk (compliance officer: Shaine Stead). We will cooperate reasonably with firms investigating account-platform incidents.

7. Governing law

This addendum is governed by the laws of England and Wales. ICO registration: ZB861396.

Address: 10 Devon Close, Macclesfield, Cheshire SK10 3HB. Not a substitute for negotiated enterprise DPAs where required.