1. Parties and roles
The customer firm is the controller of personal data relating to its staff seats (names, work email addresses, role assignments) and any other personal data the controller chooses to upload (for example, firm branding that incorporates a person's name). MPS Compare (a trading name of LFM Intelligence Limited) is the processor of that personal data, processing it only on the controller's documented instructions as set out in these terms and in the controller's use of the platform.
The platform is designed not to receive any personal data of the controller's end clients. See clause 4.
2. Subject matter, duration, nature and purpose
- Subject matter: personal data described in clause 3.
- Duration: for as long as the controller maintains an account, plus the audit-trail retention period set out in clause 9.
- Nature: hosting, storage, authentication, audit logging, transactional email, generation of branded PDFs.
- Purpose: delivery of the MPS Compare research and projection service to the controller and its authorised users.
3. Categories of data subjects and personal data
Data subjects: staff seats employed or contracted by the controller and granted access to its firm workspace.
Personal data: work email address, display name (optional), job title (optional), phone number (optional), firm role assignment, authentication metadata (password hash, session timestamps, MFA state, and security events such as sign-ins, failed sign-in attempts and MFA changes, each with timestamp and IP address), and audit-trail records of platform actions taken by the seat (calculation engine version, parameters supplied, output hash).
4. No client personal data
The platform has no field, free-text or otherwise, for the controller to enter the personal data of its end clients. The schema is enforced at the database layer: no column on any table accepts a client-attributable value. The controller agrees not to attempt to encode end-client personal data into platform fields (for example, by placing a client name inside a firm-branding string or watchlist note). Both parties acknowledge that any such attempt is contrary to the design of the service and is not instructed processing under this DPA.
5. Processor obligations
MPS Compare will:
- process personal data only on the controller's documented instructions, including the instructions captured in these terms and in the platform's feature set;
- ensure that personnel authorised to process personal data are under an obligation of confidentiality;
- implement the technical and organisational measures described in clause 7;
- assist the controller in responding to data-subject rights requests (access, rectification, erasure, restriction, portability, objection) insofar as the platform provides such tools;
- assist the controller in meeting its obligations under UK GDPR Articles 32 to 36 (security, breach notification, DPIA) taking into account the nature of the processing and the information available to us;
- notify the controller without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting controller data;
- inform the controller immediately if, in our opinion, an instruction infringes UK GDPR or other UK data-protection law;
- make available the information necessary to demonstrate compliance with these obligations, as described in clause 10;
- on termination of the contract, delete or return personal data as described in clause 9.
6. Sub-processors
The controller authorises MPS Compare to engage the sub-processors listed at /legal/sub-processors. That register is the authoritative list and is kept up to date. We will give the controller at least 30 days' notice (by in-app banner and email to admin seats) of any intended addition or replacement of a sub-processor, during which the controller may object on reasonable data-protection grounds. If we cannot resolve the objection, the controller may terminate the affected service without penalty.
We impose data-protection obligations on each sub-processor that are materially equivalent to those in this DPA, and we remain liable to the controller for sub-processor performance.
7. Security measures
- TLS 1.2+ on every connection.
- Database storage encrypted at rest by the managed provider.
- Object storage (generated PDFs) encrypted at rest.
- Row-Level Security enforced on every multi-tenant table, keyed on firm identifier carried in the user session.
- Append-only audit-trail tables: records can be written and read, never amended or removed, enforced by database-level permissions.
- Snapshot tables (factsheet history) have the same write restrictions: figures cannot be amended in place.
- NIST SP 800-63B-aligned password rules with HaveIBeenPwned screening (enabled before any production user traffic).
- TOTP multi-factor authentication: available to every user, mandatory for staff and firm administrator roles (enrolment required at sign-in and enforced server-side on privileged surfaces).
- Brute-force protection on sign-in: per-IP throttling, a per-account lockout, and a CAPTCHA challenge on the sign-in and password-reset forms.
- Append-only security event log (sign-ins, failed attempts, lockouts, password and MFA changes); firm administrators can review their firm's events in the platform.
- pnpm lockfile committed and deterministic installs; pnpm audit gated in CI; Dependabot enabled.
- No US-region routing for application or data.
8. International transfers
All controller personal data is stored in the United Kingdom (Supabase eu-west-2 / London region). Application compute runs from a CDN edge pinned to Europe. We do not transfer controller personal data outside the UK / EEA.
The AI drafting and insight features send requests to Anthropic's API in the United States. Those requests are designed to carry no personal data (anonymised catalogue data, platform-computed figures, and drafting instructions only; see clause 4 and the acceptable-use restrictions in the terms of service). As a safeguard, Anthropic's data processing addendum incorporates the ICO's International Data Transfer Addendum (version B.1.0) to the EU Standard Contractual Clauses, so any personal data that did reach the API would remain covered by a UK-recognised transfer mechanism.
If we ever need to transfer controller personal data outside the UK / EEA (for example, to introduce a sub-processor with a non-UK / non-EEA location), we will give the notice described in clause 6 and will rely on the UK International Data Transfer Agreement, the ICO's Addendum to the EU Standard Contractual Clauses, or other UK-recognised transfer safeguards, and will adopt a fallback mechanism if a safeguard we rely on is invalidated.
9. Retention, return and deletion
- Active account: personal data retained for as long as the seat is active.
- On account closure: the controller may export staff seat metadata and audit history before closure. Account profile identifiers will be redacted from the user interface after closure.
- Audit trail: retained for a minimum of seven years from the date of each export, in line with the controller's FCA record-keeping obligations (SYSC 9, COBS 9 / 9A). This retention is a documented instruction under this DPA and is excluded from the end-of-services deletion obligation. Audit rows cannot be deleted by the application; removal would require a privileged migration with its own audit footprint.
- Backups: rolling backups are retained for 30 days and then expire on their own schedule.
10. Audit and inspection
The controller may, on reasonable prior notice and no more than once per calendar year (except where a breach has occurred or a regulator requires it), request information necessary to demonstrate compliance with this DPA. We will satisfy such requests by providing our current security documentation and, where available, third-party audit reports (Cyber Essentials Plus, SOC 2, ISO 27001) under non-disclosure terms. An on-site audit will be considered only where a regulator specifically requires it and is at the controller's cost.
11. Changes
We may amend this DPA to reflect changes to the service or to law. Material changes will be communicated with at least 14 days' notice via an in-app banner to admin seats and an email to the firm's billing contact. The version date at the top of this page records the latest effective version.
12. Contact
Data-protection enquiries: privacy@mpscompare.co.uk. Security incidents: security@mpscompare.co.uk.