Data Processing Statement
Effective Date: 17/08/2026 | Version: 1.0 | Next Review: 17/08/2027
Processing terms under the UK GDPR and the Data Protection Act 2018, including the safeguards in Schedule 8 DPA 2018.
1. Roles
For all customer data uploaded to the platform, the supplier is the data controller and PowerView UK Ltd is the data processor. We process that data only on the supplier's documented instructions, which are the instructions given through use of the platform and any written agreement between us.
2. Schedule 8 DPA 2018 safeguards
- Processing is limited to the audit purposes set out in the supplier's instructions.
- A record of processing activities is maintained and available on request.
- Every action is written to an append-only, hash-chained log; entries cannot be altered or erased.
- Personnel with access are bound by confidentiality obligations.
- We assist the controller with data subject requests, DPIAs and breach notifications.
- Personal data breaches are reported to the controller without undue delay and within 72 hours of becoming aware.
- On termination, data is returned or deleted at the controller's choice, subject to the statutory 6-year audit retention.
3. Sub-processors
Complete register, last reviewed 17 August 2026:
- Supabase — Stores compliance data, user accounts, uploaded CSV files and the audit trail. Region: United Kingdom (London, eu-west-2). Safeguard: UK hosting — no international transfer for stored data.
- Resend — Delivers report notifications, deadline alerts and account emails from @powerviewuk.co.uk. Region: European Union (Ireland, eu-west-1). Safeguard: UK GDPR adequacy decision for the EEA; DPA in place.
- Stripe — Subscription checkout, invoicing and payment records. Card data never reaches our systems. Region: European Union / United States. Safeguard: Stripe DPA with UK IDTA and Standard Contractual Clauses.
- Cloudflare — Serves the application and API endpoints; provides the caller IP used for rate limiting. Region: Global edge network, UK/EU points of presence. Safeguard: Cloudflare DPA with UK IDTA and Standard Contractual Clauses.
Controllers are notified of any intended change to this list, with a reasonable opportunity to object. Where processing takes place outside the UK, it is covered by the transfer safeguard stated against that provider.
4. Security measures
- Encryption in transit — TLS 1.2+ on all connections, HSTS enforced.
- Encryption at rest — AES-256 for the database and file storage.
- Tenant isolation — every table carries an organisation identifier and row-level security policies restrict access to the owning organisation.
- Least privilege — role-based access (supplier admin, manager, compliance, viewer); the customer role never sees audit modules.
- Integrity — SHA-256 hash-chained audit log, database triggers blocking updates and deletions, and hash-verified report PDFs.
- Private storage — uploaded files sit in a private bucket, accessible only through short-lived signed URLs.
5. No sale of data
We do not sell, rent or share personal data for marketing purposes, and we do not use supplier customer data to train third-party models. Aggregated, fully anonymised statistics that cannot identify a supplier or an individual may be used to improve detection logic.
6. Contact
Data protection queries and processor agreement requests: privacy@powerviewuk.co.uk.