# **PIIQ - Data Processing Agreement**

**Document Version:** 1.0.0
**Effective Date:** January 5, 2026

## **Nearfield.ai Ltd - Data Processing Agreement**

This Data Processing Agreement ("Agreement") forms part of the Contract for Services ("Principal Agreement") between the Subscriber ("the Data Controller") and:

**Nearfield.ai Ltd**
44 Queens Drive, Stockport, SK4 3JW
(the "Data Processor")

(together as the "Parties")

---

## **RECITALS**

(A) The Subscriber acts as the Data Controller for all Source Data processed through PIIQ.

(B) Nearfield.ai Ltd acts solely as the Data Processor for all Source Data uploaded to the platform.

(C) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

(D) The Parties wish to lay down their rights and obligations.

**IT IS AGREED AS FOLLOWS:**

---

## **1. Definitions and Interpretation**

**1.1** Unless otherwise defined herein, capitalised terms and expressions used in this Agreement shall have the following meaning:

**1.1.1** "Agreement" means this Data Processing Agreement and all Schedules;

**1.1.2** "Subscriber Personal Data" means any Personal Data Processed by the Processor (Nearfield.ai) on behalf of the Subscriber (Data Controller) pursuant to or in connection with the Principal Agreement;

**1.1.3** "Data Protection Laws" means EU Data Protection Laws and, to the extent applicable, the data protection or privacy laws of any other country;

**1.1.4** "EEA" means the European Economic Area;

**1.1.5** "EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR;

**1.1.6** "GDPR" means EU General Data Protection Regulation 2016/679;

**1.1.7** "Data Transfer" means a transfer of Subscriber Personal Data from the Data Controller to the Data Processor, or an onward transfer of Subscriber Personal Data from the Data Processor to a third party;

**1.1.8** "Services" means the PIIQ automated PII detection, identification, and redaction services for DSAR and FOIA compliance that the Company provides through its cloud-based platform.

**1.2** The terms "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

---

## **2. Processing of Subscriber Personal Data**

**2.1** Processor shall:

**2.1.1** comply with all applicable Data Protection Laws in the Processing of Subscriber Personal Data; and

**2.1.2** not Process Subscriber Personal Data other than on the Subscriber's documented instructions.

**2.2** The Subscriber instructs the Processor to process Subscriber's Personal Data.

---

## **3. Processor Personnel**

**3.1** Processor shall:

**3.1.1** take reasonable steps to ensure the reliability of any employee who may have access to the Subscriber Personal Data;

**3.1.2** ensure in each case that access is strictly limited to those individuals who need to know / access the relevant Subscriber Personal Data, as strictly necessary for the purposes of the Principal Agreement;

**3.1.3** comply with Applicable Laws in the context of employee duties to the Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

---

## **4. Security**

**4.1** Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Subscriber Personal Data implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.

**4.2** In assessing the appropriate level of security, the Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.

---

## **5. Subprocessing**

**5.1** The Processor does not currently use any sub-processors for processing Source Data. All processing occurs on Nearfield.ai's own AWS infrastructure within the UK.

**5.1.1 Infrastructure vs Sub-Processors**
Infrastructure providers (AWS, Stripe) provide technical services but do not access, process, or determine the purposes/means of processing Source Data. Therefore, they are not sub-processors under GDPR Article 28(2).

**5.2** If the Processor needs to engage a sub-processor in the future, the Processor shall:
- (a) Provide the Subscriber with 30 days' written notice
- (b) Obtain Subscriber prior written consent
- (c) Ensure the sub-processor is bound by equivalent data protection obligations
- (d) Remain fully liable for the sub-processor's performance

**5.3** Current Infrastructure Providers (not sub-processors as they don't access data):
- Amazon Web Services (AWS) - UK Region (eu-west-2, London)

---

## **6. Data Subject Rights**

**6.1** Taking into account the nature of the Processing, Processor shall, within 5 business days assist the Subscriber by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Subscriber obligations, as reasonably understood by the Processor, to respond to requests to exercise Data Subject rights under the Data Protection Laws. The Processor will assist with access, rectification, erasure, portability. Extensive assistance will be charged at an hourly or daily rate depending on the time required.

**6.1.1 Assistance Scope**
Basic assistance (up to 2 hours per request) is included at no charge. Extensive assistance exceeding 2 hours may be charged at £150/hour or £1,000/day (whichever is lower), subject to prior written agreement.

**6.2** Processor shall:

**6.2.1** promptly notify Subscriber if it receives a request from a Data Subject under any Data Protection Law in respect of Subscriber Personal Data.

---

## **7. Data Breach**

**7.1** Processor shall notify Subscriber within 24 hours upon Processor becoming aware of a Data Breach affecting Subscriber Personal Data, providing Subscriber with sufficient information to allow the Subscriber to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.

**7.2** Processor shall co-operate with the Subscriber and take reasonable commercial steps as directed by Subscriber to assist in the investigation, mitigation and remediation of each such Personal Data Breach.

---

## **8. Data Protection Impact Assessment and Prior Consultation**

PIIQ processing may trigger DPIA requirements, and this is highlighted in the FAQs however Processor will offer DPIA assistance as part of enterprise onboarding and document security measures to support customer DPIAs.

**8.1 Data Protection Contact**
For any data protection queries, please contact:

**Email:** compliance@nearfield.ai

Nearfield.ai will appoint a Data Protection Officer (DPO) if required under UK GDPR Article 37 as processing volumes scale.

---

## **9. Deletion or Return of Source Data**

**9.1 Temporary Data Holding**
The Processor holds Source Data only for the duration necessary to complete processing:
- During active processing: Data held in volatile memory
- Post-processing: Processed output files held for 30 days for Subscriber access
- After 30 days OR upon Subscriber deletion request: All Source Data permanently deleted

**9.2 No Persistent Storage**
The Processor does not maintain long-term storage of Source Data. All data is automatically deleted per the retention schedule.

**9.3 Account Data Retention**
Subscriber account data (names, emails, billing information) is retained for the duration of the subscription and for 7 years thereafter for accounting and legal compliance purposes.

**9.4 Data Return Upon Request**
Upon Subscriber request, the Processor will provide:
- Processed output files in PDF format
- Original Source Data (if still within 30-day retention period)
- Export provided within 10 business days

**9.5 Deletion Certification**
Upon written request, the Processor will provide written confirmation of data deletion within 15 business days of deletion.

---

## **10. Audit Rights**

**10.1** The Processor shall make available to the Subscriber on request all information necessary to demonstrate compliance with this Agreement.

**10.2** The Processor shall allow for and contribute to audits, including inspections, by the Subscriber or an independent auditor mandated by the Subscriber, subject to:
- (a) 30 days' written notice
- (b) Audits conducted during business hours
- (c) Reasonable frequency (not more than once annually unless breach suspected)
- (d) Confidentiality obligations on auditors
- (e) Subscriber bears costs of audit unless material breach is discovered

**10.3 Alternative Compliance Evidence**
In lieu of on-site audits, the Processor may provide:
- Annual security assessment reports
- Third-party certifications (ISO 27001, SOC 2 Type II when available)
- Completed security questionnaires
- Infrastructure security documentation from AWS

**10.4** The Processor is working toward ISO 27001 and Cyber Essentials Plus certification (expected 2026).

---

## **11. Data Transfer**

**11.1** The Processor shall not transfer or permit the transfer of personal data to any country outside the European Union (EU) or the European Economic Area (EEA) without the prior written consent of the Subscriber.

All personal data processing under this Agreement shall take place exclusively within data centers located in the United Kingdom. Accordingly, no international transfers of personal data occur under normal circumstances.

In the event that any transfer of personal data from the EEA or the UK to a third country outside these territories becomes necessary, the Parties shall ensure that such transfer is conducted in compliance with applicable data protection laws, maintaining an adequate level of protection for the personal data.

To this end, unless otherwise agreed in writing, the Parties will rely on appropriate safeguards, including:
- The use of European Commission-approved Standard Contractual Clauses (SCCs) for transfers from the EEA
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers originating from the UK

The Parties shall also monitor developments related to UK-EU data flows, taking into account the UK's recognition of EU adequacy decisions and any regulatory updates that may affect data transfers.

Furthermore, the Parties agree to conduct and document Transfer Impact Assessments (TIAs) for any transfers of personal data to countries outside the UK or EEA, to evaluate and mitigate risks associated with such transfers.

---

## **12. General Terms**

**12.1 Confidentiality**
Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement ("Confidential Information") confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
- (a) disclosure is required by law;
- (b) the relevant information is already in the public domain.

**12.2 Notices**
All notices and communications given under this Agreement must be in writing and will be delivered personally, sent by post or sent by email to the address or email address set out in the heading of this Agreement at such other address as notified from time to time by the Parties changing address.

---

## **13. Governing Law and Jurisdiction**

**13.1** This Agreement is governed by the laws of England and Wales.

**13.2** Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of England and Wales.

---

# **ANNEX 1: PROCESSING DETAILS**

**Subject Matter:** Processing of personal data within documents for DSAR/FOIA fulfillment

**Duration:** Term of subscription plus 30-day retention period

**Nature of Processing:** Automated identification, analysis, and redaction of PII

**Purpose:** Facilitating Data Controller compliance with DSAR and FOIA obligations

**Types of Personal Data:**
- Names, addresses, contact details
- Identification numbers (NI, passport, driving license)
- Financial information
- Health data (special category)
- Biometric data (special category)
- Criminal records data (special category)
- Any other PII contained in uploaded documents

**Categories of Data Subjects:**
- Employees, contractors, job applicants
- Customers and clients
- Suppliers and business contacts
- Any individuals mentioned in uploaded documents

---

# **ANNEX 2: SECURITY MEASURES**

## **Technical Security Measures**

### **1. Data Encryption**

**In Transit:**
- TLS 1.2 minimum for all data transmission between Subscriber and Service, with TLS 1.3 negotiated by default
- HTTPS enforced for all API endpoints and web interfaces
- Certificate-based authentication for secure communications

**At Rest:**
- All data stored on AWS infrastructure with AES-256 encryption (AWS-managed keys)
- Uploaded files encrypted at rest in AWS S3 (if applicable)
- Database encryption enabled for Subscriber account data

**In Processing:**
- Data processed in isolated AWS Lambda execution environments
- Memory automatically cleared when function execution completes
- No persistent storage of Source Data on processing servers
- Temporary files securely deleted immediately after processing

### **2. Access Controls**

**Infrastructure Access:**
- Zero standing access to production systems
- No SSH or direct server access (serverless architecture)
- API-only access with authentication required
- AWS IAM roles with least-privilege principle
- Multi-factor authentication required for administrative access

**Subscriber Authentication:**
- AWS Cognito for Subscriber identity management
- Multi-factor authentication available
- Password complexity requirements enforced
- Session timeout after 30 minutes of inactivity
- Failed login attempt lockout (5 attempts)

**Role-Based Access Control (RBAC):**
- Subscriber roles: Admin, Standard Subscriber, Read-Only
- Granular permissions per role
- Audit logging of all access and actions

### **3. Network Security**

**Infrastructure:**
- AWS Virtual Private Cloud (VPC) isolation
- AWS WAF (Web Application Firewall) protecting API endpoints
- DDoS protection via AWS Shield
- Rate limiting on API requests
- Geographic restriction: UK-only processing

**Monitoring:**
- Real-time intrusion detection (AWS GuardDuty)
- Automated alerts for suspicious activity
- Continuous vulnerability scanning
- Log aggregation and analysis (AWS CloudWatch)

### **4. Data Lifecycle Management**

**Retention:**
- Source Data: Held only during processing + 30 days post-completion
- Processed Outputs: Available for 30 days, then securely deleted
- Account Data: Retained for subscription term + 7 years (accounting requirements)

**Deletion:**
- Automated deletion workflows
- Secure deletion protocols (volatile memory, file system wiping)
- Deletion verification and audit logging
- User-initiated deletion available anytime

**Backup and Recovery:**
- Automated backups of account data (not Source Data)
- 30-day backup retention for account recovery
- Disaster recovery procedures tested quarterly
- Recovery Time Objective (RTO): 4 hours
- Recovery Point Objective (RPO): 1 hour

### **5. Application Security**

**Secure Development:**
- Regular code reviews and security testing
- Dependency vulnerability scanning
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Penetration testing annually (planned 2026)

**Input Validation:**
- All Subscriber inputs validated and sanitized
- Protection against injection attacks (SQL, command, etc.)
- File upload restrictions (type, size, content validation)
- Output encoding to prevent XSS attacks

### **6. Personnel Security**

**Staff Vetting:**
- Background checks for staff with data access
- Confidentiality agreements for all staff
- Regular security awareness training (quarterly)
- Separation of duties for critical functions

**Access Management:**
- Onboarding/offboarding procedures
- Access reviews quarterly
- Immediate revocation of access upon termination

### **7. Incident Response**

**Procedures:**
- 24/7 monitoring for security incidents
- Defined incident response plan
- Escalation procedures to senior management
- Data breach notification within 24 hours (see Section 7)

**Testing:**
- Incident response drills annually
- Tabletop exercises with key personnel
- Continuous improvement based on lessons learned

### **8. Vendor Management**

**AWS Security:**
- AWS has ISO 27001, SOC 2 Type II, PCI DSS certifications
- AWS DPA in effect
- Regular review of AWS security posture
- AWS security updates applied automatically

### **9. Compliance and Audit**

**Current Status:**
- GDPR and UK GDPR compliant
- Regular compliance assessments
- Internal audits quarterly

**In Progress:**
- ISO 27001 certification (expected Q2 2026)
- Cyber Essentials Plus (expected 2026)
- SOC 2 Type II (expected 2026)

**Documentation:**
- Security policies and procedures maintained
- Change management records
- Audit logs retained for 12 months
- Compliance evidence available upon request

### **10. Business Continuity**

**Availability:**
- Target uptime: 99.5% (excluding planned maintenance)
- Planned maintenance: Notified 7 days in advance
- Redundant infrastructure across multiple availability zones

**Data Recovery:**
- Regular backup testing
- Disaster recovery plan documented and tested
- Alternative processing arrangements identified

---

# **ANNEX 3: INFRASTRUCTURE PROVIDERS**

The Processor uses the following infrastructure providers. These providers do not have access to Source Data content and act as infrastructure providers to Nearfield.ai:

## **1. Amazon Web Services (AWS)**

- **Legal Entity:** Amazon Web Services EMEA SARL
- **Services:** Cloud infrastructure, compute (Lambda), storage
- **Location:** United Kingdom (eu-west-2, London region exclusively)
- **Data Access:** None - infrastructure only, no access to data content
- **Security:** ISO 27001, SOC 2 Type II, AWS DPA in effect

## **2. AWS Cognito**

- **Purpose:** Subscriber authentication and identity management
- **Data Processed:** Subscriber account credentials only (not Source Data)
- **Location:** UK region

## **3. Payment Processor - Stripe**

- **Purpose:** Payment processing
- **Data Processed:** Billing information only (not Source Data)
- **Location:** Stripe, 354 Oyster Point Blvd, South San Francisco, CA 94080

---

## **Change Management**

The Processor will provide 30 days' notice of any material changes to infrastructure providers. Subscriber will be notified via email to registered address. Notification will include: provider name, services provided, location, data access level.

---

## **Electronic Acceptance**

This Agreement (including the Terms & Conditions, Privacy Policy, and this Data Processing Agreement) is executed through electronic acceptance during Subscriber registration as follows:

### **Acceptance Procedure:**

**1. Document Presentation:**
- Subscriber is presented with this Agreement in full during registration
- Subscriber has opportunity to download PDF version for review
- Subscriber cannot proceed with registration without acceptance

**2. Explicit Consent:**
Subscriber must confirm acceptance of:
- Terms & Conditions (Part A)
- Privacy Policy (Part B)
- Data Processing Agreement (Part C)
- Data Controller confirmation
- GDPR compliance acknowledgment
- Special category data lawful basis confirmation

**3. Record Keeping:**
Nearfield.ai records:
- Date and time of acceptance (UTC timestamp)
- IP address from which acceptance occurred
- Version number of Agreement accepted
- Subscriber email address and account identifier
- Electronic signature: Subscriber's typed name

**4. Legal Effect:**
Electronic acceptance constitutes a legally binding agreement under:
- UK Electronic Communications Act 2000
- Electronic Signatures Regulations 2002
- EU Regulation 910/2014 (eIDAS) for EU users

**5. Evidence of Acceptance:**
Subscriber receives confirmation email containing:
- Copy of accepted Agreement (PDF)
- Acceptance timestamp and reference number
- Instructions for accessing Agreement in account dashboard

**6. Changes to Agreement:**
- Material changes: Subscriber must accept updated Agreement (re-acceptance required)
- Minor changes: 30 days' notice provided, continued use constitutes acceptance
- Subscriber can view acceptance history in account dashboard

---

## **Contact Information**

For any inquiries or concerns regarding this Data Processing Agreement, please contact:

**Email:** compliance@nearfield.ai

**Nearfield.ai Ltd**
44 Queens Drive, Stockport, SK4 3JW
