Legal
Data Processing Agreement
Last updated August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between your firm (“Customer”, the Controller) and Velkron (“Processor”) for use of PromoCheck. It reflects UK GDPR Article 28 and applies whenever Customer submits Personal Data to the Service as part of promotion content or account information. Velkron is not yet incorporated as a limited company (see “Entity status” below); until it is, this DPA is entered into by its sole founder trading as Velkron.
1. Roles
Customer is the Controller of Personal Data within the promotion content and any other material it submits to the Service. Velkron is the Processor, acting only on Customer’s documented instructions as set out in this DPA and the Terms of Service. For account and audit-trail data Velkron collects directly to operate the Service (work email, sign-in records), Velkron acts as an independent Controller, as described in the Privacy & data page.
2. Subject matter, duration and purpose
Subject matter: automated compliance review of financial promotions against FCA rulebooks. Duration: for as long as Customer has an active account, plus the retention period in Section 6. Purpose: to produce a review, a citation-grounded finding, and a sealed audit record for each promotion Customer submits.
3. Categories of data and data subjects
Personal Data processed is whatever Customer includes in submitted promotion text or context — typically none, since financial promotions are marketing copy, but occasionally names, contact details, or testimonials if Customer includes them. Data subjects are Customer’s own staff (as authors/approvers) and, incidentally, anyone named within submitted promotion content.
4. Processor obligations
- Process Personal Data only on Customer’s documented instructions (submitting content to the Service constitutes an instruction to process it for review and audit-trail purposes), unless required otherwise by UK law.
- Ensure anyone processing the data is bound by confidentiality.
- Implement the technical and organisational security measures described on the Security & data page (per-firm isolation, verified sign-in, parameterised SQL, hardened HTTP surface, hash-chained audit trail).
- Not engage a new sub-processor without giving Customer the chance to object; the current sub-processor list is in Section 5.
- Assist Customer, insofar as reasonably possible, with responding to data subject rights requests and with its own GDPR obligations (breach notification, DPIAs) regarding the Service.
- Notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a Personal Data breach affecting Customer’s data.
- At Customer’s choice, delete or return all Personal Data on termination, subject to the retention period in Section 6 where Velkron is independently required to retain records.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates, on reasonable notice.
5. Sub-processors and international transfers
Current sub-processors: Anthropic (language-model provider for standard review; processed in the United States under Anthropic’s API terms, which state that API inputs are not used to train models), Alibaba Cloud DashScope (Qwen) (second, independent language-model provider, engaged only when Customer opts into High-Assurance/two-model consensus review; processed outside the UK/EEA), Vercel (application hosting and, via its Postgres/Neon integration, the audit-trail database), and Resend (transactional email for magic-link sign-in). Where a sub-processor is outside the UK/EEA, transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the sub-processor’s equivalent mechanism. If non-UK/EEA processing by a language-model provider does not meet Customer’s residency requirements, do not enable High-Assurance review; a UK/EU or self-hosted model is available on the Firm plan — contact Velkron before submitting production data.
6. Retention and deletion
Audit records are retained for six years, reflecting the FCA’s financial-promotion record-keeping expectations (COBS 4.11.2R, with COBS 4.11.3G indicating a period of at least six years), then deleted or anonymised. Account data is kept only while the account is active. Customer may request export or deletion of its records at any time, subject to the regulatory retention period above.
7. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.
8. Entity status
As of August 2026, Velkron has not yet completed UK company incorporation. Until it does, PromoCheck is operated by its sole founder trading as Velkron, who is personally the counterparty to this DPA. Velkron will notify Customer and update this page once incorporation completes and a registered company becomes the counterparty of record.
Contact for data-protection matters: contact@velkron.xyz. This DPA is a standard template offered to every pilot and paying customer; it is not yet a negotiated or countersigned legal agreement with any customer, since PromoCheck has not yet signed a paying customer.