Reinza Reminder — Data Processing Agreement (DPA)
Last updated: 12 August 2026
Version: 1.0
Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
- You — the business or other legal entity on whose behalf the account is created (the "Customer"); and
- Reinza Limited, company number 11668166, 128 City Road, London, EC1V 2NX (the "Processor", "we", "us").
It applies whenever we process personal data on your behalf through the Reinza Reminder service (the "Service"), and gives effect to Article 28 of the UK GDPR.
Where terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" are used, they have the meanings given in UK Data Protection Law (the UK GDPR and the Data Protection Act 2018).
1. Roles
1.1 You act as controller or as processor, as applicable to the processing concerned. Where you act as controller of the personal data you enter into or generate in the Service, we act as your processor. Where you act as processor on behalf of another controller, we act as your sub-processor, and references in this DPA to your instructions include the instructions you have received from that controller.
1.2 You confirm that you have a lawful basis for the processing you instruct, that you have provided any required privacy information to data subjects, and that your instructions comply with UK Data Protection Law.
1.3 We act as an independent controller in respect of your own account and billing data; that processing is governed by our Privacy Policy, not by this DPA.
2. Processing details (Article 28(3))
Subject matter: provision of the Reinza Reminder filing deadline reminder service.
Duration: for the term of your subscription, plus the retention period in clause 9.
Nature and purpose: storage, organisation, retrieval, calculation of filing dates, generation of reminders and reports, export, and deletion — all as directed by you through your use of the Service.
Types of personal data: limited, and largely at your discretion. Typically:
- business contact details you choose to record (for example, a client contact name or email address in a free-text note);
- any personal data you enter into free-text fields;
- where you choose to send reminders from your own mailbox, the SMTP credentials for that account.
The Service is designed for data minimisation: it does not require, and we ask you not to enter, National Insurance numbers, Unique Taxpayer References, home addresses, dates of birth, or any special category data (Article 9) or criminal offence data (Article 10). Company information retrieved from Companies House is public register information.
Categories of data subjects: your staff who use the Service; individuals connected with your client companies whose details you choose to record.
3. Our obligations
We will:
3.1 process personal data only on your documented instructions, including with regard to transfers of personal data to a third country or an international organisation, which are given by these Terms, this DPA, and your use of the Service — unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it;
3.2 ensure that anyone authorised to process the data is bound by a duty of confidentiality;
3.3 implement the technical and organisational measures described in Annex A;
3.4 not engage a sub-processor except as set out in clause 5;
3.5 taking into account the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, in responding to requests from data subjects exercising their rights;
3.6 assist you in complying with your obligations under Articles 32–36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to us;
3.7 at your choice, delete or return personal data at the end of the provision of services, as set out in clause 9;
3.8 make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in clause 8.
4. Your obligations
You will: ensure your instructions are lawful; not enter personal data beyond what is necessary for the purpose (see the minimisation note in clause 2); keep your account credentials secure; and manage access within your own organisation.
5. Sub-processors
5.1 You give general authorisation for us to engage sub-processors in respect of the personal data we process on your behalf. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Resend (Plus Five Five, Inc.) | Delivery of reminder and system emails from mail.reinza.com | US, with UK IDTA safeguards |
| Cloudflare, Inc. | Secure traffic delivery and protection | Global network |
| Microsoft | Encrypted off-site backup storage (OneDrive for Business) | United Kingdom |
Stripe Payments Europe, Ltd. processes payment and subscription data relating to your own account. That processing is not carried out on your behalf under this DPA and is described in our Privacy Policy.
5.2 We will give at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, you may terminate your subscription before the change takes effect, and we will refund any fees paid for the period after termination.
5.3 We remain liable to you for the performance of each sub-processor's obligations.
5.4 If you choose to send reminders from your own mailbox, your email provider is not our sub-processor; it acts under your own arrangements with them.
6. Security
We implement the measures set out in Annex A, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals.
7. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide reasonable cooperation to help you meet your own notification obligations.
8. Audit
8.1 On reasonable written request, and no more than once in any 12-month period (unless a personal data breach has occurred, there are reasonable grounds to suspect material non-compliance with this DPA, or a supervisory authority requires it), we will provide information reasonably necessary to demonstrate compliance with this DPA.
8.2 Given the scale of the Service, audits will normally be satisfied by written responses and documentation. Any on-site inspection must be agreed in advance, conducted during business hours, and must not disrupt the Service or compromise the confidentiality of other customers' data. You bear your own costs, and our reasonable costs where an inspection is requested, except that where an inspection identifies a material breach of this DPA by us, we bear our own costs of addressing that breach.
9. Return and deletion
9.1 You may export your data at any time while your account is active.
9.2 Following cancellation, suspension or termination, we retain your data for 30 days, during which you may request an export or reactivate. After that period, we permanently delete it, including from backups within the normal backup rotation cycle (a maximum of a further 90 days).
9.3 We may retain data where required by law, in which case we will continue to protect it under this DPA and process it only for that purpose.
9.4 On written request we will delete data sooner, subject to clause 9.3.
10. International transfers
Personal data is stored in the United Kingdom. Where a sub-processor processes personal data outside the UK, we ensure an appropriate transfer mechanism is in place (an adequacy decision, or the UK International Data Transfer Agreement/Addendum).
11. Liability and general
11.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
11.2 If there is a conflict between this DPA and the Terms of Service in relation to data protection, this DPA prevails.
11.3 This DPA is governed by the laws of England and Wales.
Annex A — Technical and organisational measures
Access control
- Individual account credentials; passwords stored only as bcrypt hashes; no default or shared passwords
- Each customer's data is held in a separate database, isolated from other customers
- Administrative access to the hosting environment is limited to the company director
Transmission and storage
- All traffic encrypted in transit (HTTPS/TLS)
- Hosting infrastructure not directly exposed to the public internet; access mediated by a protected tunnel service
- SMTP credentials you supply are encrypted at rest and used only to send your own reminder emails; the Service never reads your mailbox
Availability and resilience
- Automated daily backups with integrity verification
- Documented restore procedure, periodically tested
- Uninterruptible power supply protecting the hosting equipment
Integrity and accountability
- Append-only audit log of material actions within each customer account
- Application logs retained for diagnosis, subject to the retention periods in the Privacy Policy
Data minimisation by design
- The Service does not request or require National Insurance numbers, Unique Taxpayer References, dates of birth or home addresses
- Company data is drawn from the Companies House public register
- Export and deletion functions provided to support data subject rights
Organisational
- Confidentiality obligations on any person with access
- Changes to the Service tested against an automated test suite before deployment
Reinza Limited
128 City Road, London, EC1V 2NX
Company number 11668166
[email protected]