Legal
Data processing addendum
The Art. 28 GDPR terms that apply where we process personal data on your behalf.
Last updated July 25, 2026
1.Parties and roles
This addendum forms part of the contract between you (the controller) and {{legalName}} (the processor).
For assessment answers and account data you are the controller and we act as processor. For our own website analytics, billing records and marketing, we are the controller and the privacy policy applies.
2.Subject matter, duration, nature and purpose
- Subject matter
- Provision of the Ready4KI assessment and reporting service
- Duration
- For the term of the main contract and any agreed retention period
- Nature and purpose
- Collection, storage, structuring and analysis of assessment answers to produce a report
- Categories of data subjects
- Your employees and contractors who use the service or are named in answers
- Categories of personal data
- Name, business contact details, job role, authentication data, usage logs
3.Processing on instructions
We process personal data only on your documented instructions, including regarding transfers to a third country, unless required to do otherwise by law. In that case we inform you before processing, unless the law prohibits it.
The main contract, this addendum and your use of the service constitute your complete instructions.
4.Confidentiality
Personnel authorised to process personal data are bound to confidentiality and trained on their obligations. Access is granted on a need-to-know basis and revoked when it is no longer needed.
5.Security of processing
We implement appropriate technical and organisational measures under Art. 32 GDPR, including:
- Row-level security scoping every record to the owning organisation.
- Server-side entitlement checks before content is rendered, so unpurchased content is never transmitted.
- Encryption in transit, and at rest at the storage layer.
- Least-privilege access, with privileged operations restricted to service credentials that are never exposed to a browser.
- Audit trails for authentication, payment and administrative events.
- Regular restore testing of backups.
6.Sub-processors
You give general authorisation for the sub-processors listed below. We inform you at least {{subprocessorNotice}} before adding or replacing one, and you may object on reasonable data protection grounds.
| Processor | Purpose | Location |
|---|---|---|
Supabase | Database, authentication and file storage |
|
Stripe | Payment processing, tax calculation and invoicing | EU / US (SCCs) |
| Application hosting and content delivery |
|
| Transactional email (confirmations, password resets) |
|
7.Assistance
We assist you, taking into account the nature of processing, in responding to data subject requests, and in meeting your obligations under Art. 32 to 36 GDPR: security, breach notification and data protection impact assessments.
Where a data subject contacts us directly, we refer them to you and inform you promptly.
8.Personal data breach
We notify you without undue delay, and in any event within {{breachNotice}} of becoming aware of a personal data breach, with the information available at that time and further detail as it emerges.
We do not notify a supervisory authority or data subjects on your behalf unless you instruct us to.
9.Return and deletion
On termination, and at your choice, we delete or return all personal data and delete existing copies, unless storage is required by law.
Deleting your account triggers deletion of your organisation's data where you are the last member, subject to statutory retention of invoices.
10.Audits
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits take place during business hours, with reasonable notice, no more than once a year unless there is a specific cause, and subject to confidentiality.
11.International transfers
Where a sub-processor is located outside the EEA, the transfer is covered by Standard Contractual Clauses and, where required, supplementary measures. On request we provide the relevant documentation.
12.Annexes
Annex I, Details of processing: as set out in section 2 above. Annex II, Technical and organisational measures: as set out in section 5 above. Annex III, Sub-processors: as set out in section 6 above.
A countersigned copy of this addendum is available on request for procurement files.
This document is provided by Ready4KI for its own service. It is not legal advice, and it is under review by counsel before launch. Fields shown in braces are pending that review.