Skip to main content

GovRedact · Legal

Data Processing Agreement

Last updated 2026-07-02

This Data Processing Agreement (“Agreement”) is made between the local council identified at acceptance (the “Controller”) and Cloudy Group Ltd, trading as CloudyIT, a company registered in England and Wales (company number 04997628) (the “Processor”, “CloudyIT”, “we”), for the GovRedact service. It is accepted electronically by an authorised representative of the Controller before any personal data is uploaded to or processed by GovRedact, and the recorded acceptance (the accepting person, the version of this Agreement, and the date and time) forms part of this Agreement.

Background

The Controller is a data controller of personal data processed in the course of responding to information rights requests and managing its records. CloudyIT provides GovRedact, a software service that assists the Controller to identify and redact personal and exempt information in documents before disclosure, producing auditable disclosure bundles. In providing GovRedact, CloudyIT processes personal data on behalf of, and on the documented instructions of, the Controller. This Agreement sets out the terms on which that processing takes place, as required by Article 28 of the UK GDPR.

1. Definitions and interpretation

In this Agreement: “UK GDPR” means the UK General Data Protection Regulation as defined in the Data Protection Act 2018; “DPA 2018” means the Data Protection Act 2018; “Data Protection Laws” means the UK GDPR, the DPA 2018 and all other applicable laws relating to the processing of personal data; and the terms “controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing” and “special categories of personal data” have the meanings given in the UK GDPR. In the event of any conflict between this Agreement and any other agreement between the Parties in respect of the processing of personal data, this Agreement prevails.

2. Roles and scope of processing

The Parties acknowledge that, for the personal data processed under this Agreement, the Controller is the controller and CloudyIT is the processor. CloudyIT shall process personal data only for the purpose of providing the GovRedact service to the Controller, and only as described in Schedule 1 (Details of Processing). The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Schedule 1.

3. CloudyIT's obligations

CloudyIT shall:

  • process the personal data only on the documented instructions of the Controller (including the instructions inherent in the Controller's use of GovRedact), including with regard to transfers to a third country, unless required to do otherwise by law (in which case CloudyIT shall inform the Controller before processing, unless the law prohibits this);
  • ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • take all measures required by Article 32 of the UK GDPR (security of processing), as further described in Schedule 2 (Security Measures);
  • respect the conditions in clause 4 for engaging a sub-processor;
  • taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as is possible, in fulfilling the Controller's obligation to respond to data subject rights requests, and promptly forward to the Controller any request or complaint CloudyIT receives directly from a data subject relating to the Controller's personal data (without responding to it, unless the Controller instructs otherwise);
  • assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to CloudyIT;
  • at the choice of the Controller, delete or return all the personal data after the end of the provision of services, and delete existing copies unless storage is required by law (see clause 8);
  • make available to the Controller all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits (see clause 9); and
  • immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws.

4. Sub-processors

The Controller grants CloudyIT general written authorisation to engage the sub-processors listed in Schedule 3. CloudyIT shall give the Controller at least 30 days' notice of any intended addition or replacement of a sub-processor (by email to the Controller's administrators and/or by notice within the service), giving the Controller the opportunity to object on reasonable data-protection grounds before the sub-processor begins processing. If the Controller objects and the Parties cannot resolve the objection, the Controller may terminate its use of the affected service. Where CloudyIT engages a sub-processor, it shall do so by way of a written contract imposing data protection obligations equivalent to those in this Agreement, and CloudyIT remains fully liable to the Controller for that sub-processor's performance.

5. International transfers and data location

CloudyIT shall store the Controller's personal data within the United Kingdom, using UK data centre regions (Microsoft Azure UK regions). Processing also takes place in the United Kingdom, save for the AI-assisted redaction step, which is processed by the sub-processor identified in Schedule 3 in the United States. That transfer is made under the UK International Data Transfer Addendum (and, where applicable, the UK Extension to the EU-US Data Privacy Framework), with zero data retention configured so that content submitted to the AI model is not stored or used for model training. CloudyIT shall not transfer personal data outside the UK other than as disclosed in Schedule 3 without the prior documented instruction of the Controller. Any authorised transfer shall be subject to an appropriate transfer mechanism recognised under the Data Protection Laws.

6. Security

CloudyIT shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Schedule 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects. CloudyIT shall ensure that AI-assisted redactions proposed by the service are reviewed and decided upon by the Controller's officers before any disclosure; the service proposes redactions but does not make the final disclosure decision.

7. Personal data breaches

CloudyIT shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data, by email to the Controller's registered administrators and data protection contact. Such notification shall, to the extent possible, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, so as to assist the Controller in meeting its own obligations under Articles 33 and 34 of the UK GDPR. CloudyIT shall document all breaches affecting the Controller's personal data and cooperate with the Controller and the Information Commissioner's Office as reasonably required. Breach questions may be directed to dpo@cloudyit.co.uk.

8. Return and deletion of data

Ordinary service deletion follows the fixed periods in Schedule 1. On termination, CloudyIT shall delete or return remaining Controller personal data in accordance with those periods, unless retention is required by law. CloudyIT retains only the anonymised case shell and the time-limited audit record required for accountability.

9. Audit and records

CloudyIT shall maintain records of its processing activities carried out on behalf of the Controller and shall make available to the Controller, on reasonable request, the information necessary to demonstrate compliance with this Agreement and Article 28 of the UK GDPR. CloudyIT shall allow for and contribute to audits and inspections by the Controller or its mandated auditor, on reasonable prior notice (not less than 14 days, save where a supervisory authority requires otherwise) and during normal business hours, no more than once in any 12-month period unless a personal data breach has occurred, subject to appropriate confidentiality undertakings and without compromising the security or data of other customers.

10. Term, liability and general

This Agreement takes effect on acceptance by the Controller and continues for as long as CloudyIT processes personal data on behalf of the Controller. Liability under this Agreement is subject to the limitations and exclusions of liability set out in the Terms of Service between the Parties, save that nothing limits either Party's liability where it cannot lawfully be limited. This Agreement is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1 — Details of processing

Subject matterIdentification and redaction of personal and exempt information in the Controller's documents in order to produce disclosure bundles for information rights responses.
DurationFor the term of the Controller's use of GovRedact and until data is deleted under the retention periods below.
Nature and purposeIngestion of documents and mailbox exports; text extraction; AI-assisted identification of personal and exempt data; officer review; generation of redacted bundles; secure disclosure.
Types of personal dataAs contained in the Controller's documents and correspondence — names, contact details, identifiers, financial details, opinions and free-text content, and potentially special category data and data relating to criminal convictions and offences, depending on the nature of the request being answered.
Categories of data subjectsResidents, requesters, complainants, councillors, council staff, and third parties referenced in the Controller's records.
RetentionRaw uploads: 30 days after upload-batch creation. Case content and bundles: 90 days after the first authenticated officer download. Audit and authentication events: seven years. Anonymised case shell retained.

Schedule 2 — Security measures

CloudyIT implements, at a minimum, the following technical and organisational measures (kept current):

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
  • Strict logical separation of each council's data within the multi-tenant platform.
  • Access control: authentication via the council's own Microsoft Entra ID (or verified council email for non-Microsoft councils); role-based access; immediate revocation on suspension.
  • An immutable, tamper-evident audit trail of significant actions.
  • Secrets held in a managed key vault; no credentials in code.
  • Vulnerability management, dependency and container scanning, and security testing before major releases.
  • Time-limited, revocable secure links for disclosure downloads.
  • Human review of AI-proposed redactions before any disclosure (“AI proposes, officers decide”).
  • CloudyIT support access to a council's data is time-bound, reason-required and visible to the council (just-in-time support access).

Schedule 3 — Authorised sub-processors

Sub-processorService providedLocation of processing
Microsoft (Azure)Cloud hosting, storage, database and supporting infrastructure for the platform.United Kingdom (Microsoft Azure UK regions).
AnthropicAI model used to propose redactions of personal and exempt information.Processed in the United States under the UK International Data Transfer Addendum incorporated into Anthropic's commercial terms, with zero data retention: content is not stored by the provider after processing and is not used for model training. Documents are stored and managed in the UK (Azure UK South); the AI redaction step is the only point at which data is processed outside the UK.
Microsoft (Azure Communication Services)Transactional email delivery (sign-in codes, notifications). Processes recipient email addresses and message content, not case documents.United Kingdom / European Economic Area.
StripePayment processing for pay-per-case billing. Processes the council's billing contact details, not case content.United States, under the UK International Data Transfer Addendum / UK Extension to the EU-US Data Privacy Framework (incorporated into Stripe's Data Transfers Addendum).

Note on data location: documents are stored and managed in the UK (Azure UK South). The AI-assisted redaction step is the one point at which data is processed outside the UK — by our AI provider in the US, under the UK International Data Transfer Addendum, with zero data retention. This is lawful and defensible, but it is not ‘UK-only’.

Acceptance

This Agreement is accepted electronically by an authorised representative of the Controller within GovRedact. The platform records the name and role of the accepting individual, their confirmation of authority to bind the Controller, the version of this Agreement accepted, and the date and time of acceptance. That record constitutes the Controller's signature to this Agreement, and the acceptance date is recorded as the Agreement's signature date. Questions about this Agreement may be directed to dpo@cloudyit.co.uk.