Data Processing Agreement (DPA)
Last updated: 18 September 2025
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other agreement (the “Agreement”) between:
- Optax Limited (company no. 13432847) and/or Intrepid Advisors Limited (company no. 12150917), registered in England and Wales with registered office at 170 High Street, Amersham, Buckinghamshire, HP7 0EG (“Processor”, “we”, “us”),
and - The client entity or individual agreeing to the Agreement (“Controller”, “you”).
Together, the “Parties.”
- Subject Matter and Duration
1.1 This DPA applies to the extent we process Personal Data on your behalf in providing the Services under the Agreement.
1.2 The duration of this DPA matches the Agreement term, until deletion or return of data as set out in Section 9.
- Roles of the Parties
2.1 You are the Controller and we are the Processor in relation to any Personal Data processed under the Agreement.
2.2 Each party shall comply with its obligations under applicable data protection laws, including the UK GDPR, EU GDPR (if applicable), and Data Protection Act 2018.
- Processing Instructions
3.1 We shall process Personal Data only on your documented instructions, including those set out in the Agreement and this DPA, except where required by law.
3.2 If we are required by law to process Personal Data, we will notify you unless prohibited from doing so.
- Confidentiality
4.1 We shall ensure our personnel are bound by confidentiality obligations with respect to Personal Data.
- Security
5.1 We shall implement appropriate technical and organisational measures to protect Personal Data, including (without limitation):
- Hosting data in Microsoft Azure with encryption in transit and at rest.
- Role-based access controls and 2FA for administrative access.
- Regular vulnerability scanning and malware protection.
- Audit logging of system access.
- Annual third-party penetration testing.
- Maintenance of ISO 27001 certification.
- Maintenance of SOC 2 Type II certification.
5.2 You are responsible for ensuring the security of your own systems and credentials used to access the Services.
- Subprocessors
6.1 You authorise us to engage subprocessors listed here (“Authorised Subprocessors”).
6.2 We will ensure each subprocessor is bound by data protection obligations not less protective than those set out in this DPA.
6.3 We will notify you of material changes to our subprocessors, giving you an opportunity to object.
- Data Subject Rights
7.1 Taking into account the nature of the processing, we shall assist you, insofar as reasonably possible, to respond to requests from data subjects exercising their rights under applicable data protection law (access, rectification, erasure, restriction, portability, objection).
- International Transfers
8.1 We shall not transfer Personal Data outside the UK or EEA unless:
- The transfer is to a country with an adequacy decision, or
- The recipient has self-certified under the EU-US Data Privacy Framework and/or UK-US Extension, or
- Appropriate safeguards (e.g. Standard Contractual Clauses with UK Addendum) are in place.
- Return and Deletion of Data
9.1 At the end of the Agreement, you will remove your Personal Data or we shall delete your Personal Data in accordance with your instructions, unless retention is required by law.
9.2 Backups will be deleted in the ordinary course of our backup cycle.
- Audit and Compliance
10.1 Upon reasonable request, we will make available information necessary to demonstrate compliance with this DPA.
10.2 Audits may be carried out once per year at your cost, provided they do not unreasonably disrupt our business and with at least 30 days’ notice.
- Liability
11.1 Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
- Governing Law
12.1 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Schedule 1 – Details of Processing
Subject matter: Provision of SaaS services for legal entity structure charting and related modules.
Duration: For the term of the Agreement.
Nature & Purpose of Processing: Hosting, storage, analysis, and management of customer-uploaded data.
Types of Personal Data: May include names, email addresses, organisation details, tax-related identifiers, and other information contained in uploaded documents.
Categories of Data Subjects: Users of the Services, investors, entities, and related persons as determined by the Controller.

