Legal
Data Processing Agreement
Last updated 2 July 2026
Need a countersigned copy?
This page sets out the standard processing terms that apply whenever NeedsIQ processes client personal data on your behalf. Firms that need a signed and countersigned copy for their compliance file can request one from [email protected] and we will return a countersigned version. These terms apply to your use whether or not a separate copy is signed.
1. Roles
This agreement applies where NeedsIQ processes personal data on behalf of an adviser or firm ("you") as part of the service. For client personal data entered into NeedsIQ, you are the controller and NeedsIQ ("we") is your processor under Article 28 of the UK GDPR. It supplements our Terms of Service and Privacy Policy. Where they conflict on data protection, this agreement prevails.
2. Subject matter, duration, nature and purpose
Subject matter: our processing of client personal data so you can produce fact-finds, draft Demands and Needs letters, draft mortgage suitability reports, and related adviser workflow records.
Duration: for as long as you hold an account, plus the retention period described in the Privacy Policy and clause 9.
Nature and purpose: storing, organising, and processing the data by automated means, including sending it to our AI sub-processor to generate draft text, solely to provide the service and on your instructions. We do not use client data to train shared models and do not process it for our own purposes.
3. Categories of data and data subjects
Data subjects: your clients and, where relevant, their partners and dependants.
Personal data categories: identity and contact details, date of birth, family and dependant details, employment and income, mortgage and financial circumstances, existing cover, objectives, and any notes you enter.
Special category data: health information (for example medical conditions, medications, and smoker status) where you enter it as part of a protection fact-find. You are responsible for having a lawful basis and, for special category data, a valid condition under Article 9 before entering it.
4. Documented instructions
We process client personal data only on your documented instructions, which are: this agreement, the Terms of Service, the in-product actions you take, and any further written instruction you give. We will not process the data for any other purpose. If the law requires us to process it otherwise, we will tell you first unless the law forbids it. If we believe an instruction breaches data protection law, we will tell you.
5. Confidentiality
We ensure that anyone authorised to process client personal data is bound by an appropriate duty of confidentiality and processes it only as needed to deliver and support the service.
6. Security measures
We implement appropriate technical and organisational measures, matching the nature of the data and the risk, including:
- encryption in transit (TLS) and encryption at rest;
- hashed passwords and hashed session and link tokens (raw tokens are never stored);
- server-side authorisation on every request, with client data scoped to the owning adviser and their firm;
- rate limiting and abuse controls on authentication and public endpoints;
- least-privilege production access limited to a small ops team, with audit logging of privileged changes;
- EU hosting, regular encrypted backups, and monitoring and error alerting.
7. Sub-processors
You authorise us to use the sub-processors below to deliver the service. This list is consistent with our Privacy Policy:
- Hetzner Cloud (Finland, EU) for hosting and database.
- Cloudflare for TLS and edge caching.
- Stripe Payments Europe for subscriptions and billing.
- Anthropic for AI generation (request and response not used for training).
- Resend for transactional email.
We impose data protection terms on each sub-processor no less protective than this agreement. We will give you reasonable advance notice before adding or replacing a sub-processor so you can object on reasonable data protection grounds; if we cannot resolve a reasonable objection, you may terminate the affected part of the service.
8. Assisting you
Taking account of the nature of the processing, we will assist you with appropriate measures to help you: respond to data subject requests (access, rectification, erasure, portability, objection); meet your security, breach notification, and data protection impact assessment obligations. We will notify you without undue delay after becoming aware of a personal data breach affecting your client data, with the information you reasonably need to meet your own notification duties.
9. Return or deletion on termination
On termination, and at your choice, we will return or delete the client personal data we process for you, except where we are required to retain it by law or where you have asked us to hold it for the FCA regulatory retention period. Where retained, the data is kept in encrypted storage for that period and then permanently deleted. Backups are cycled out on our normal backup schedule.
10. Audit assistance
We will make available the information reasonably necessary to demonstrate our compliance with Article 28, and will contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and subject to confidentiality. We may satisfy an audit by providing our security documentation and answering reasonable questions.
11. International transfers
Our hosting is in the EU. Where a sub-processor processes data outside the UK or EEA, we ensure an appropriate transfer mechanism (such as the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses) is in place.
12. Contact
Data protection queries and countersignature requests: [email protected].
