Data Processing Agreement
Article 28(3) UK GDPR processor terms between ClientScan Limited and the Controller.
- Reference
- TN-DPA-2026-001
- Version
- 1.1
Parties
ClientScan Limited, trading as TakeNote.ai, a company registered in England and Wales, company number 14828718, registered office 7 Bell Yard, London WC2A 2JR (the "Processor");
and [Insert Client Name], a company registered in England and Wales, company number [ ], registered office [ ], FCA Firm Reference Number [ ] (the "Controller").
Recitals
A. The Controller is an FCA-authorised firm providing financial advisory services and processes personal data in that connection.
B.The Processor provides AI-assisted meeting capture, transcription, summarisation and compliance documentation services (the "Services").
C. In providing the Services the Processor processes personal data on behalf of the Controller.
D.This Agreement is made to satisfy Article 28(3) UK GDPR and supplements the principal service agreement between the Parties (the "Principal Agreement").
1. Definitions
- Applicable Data Protection Law
- The UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any successor or related legislation.
- Client Data
- All personal data processed by the Processor on behalf of the Controller under the Services, including meeting audio, transcripts, summaries, generated documents, client records and associated metadata.
- Data Subject
- An identified or identifiable natural person whose personal data is processed under this Agreement, including the Controller's clients, their dependants, the Controller's personnel and other meeting participants.
- Personal Data Breach
- A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Data.
- Special Category Data
- Personal data within Article 9(1) UK GDPR.
- Sub-processor
- Any third party engaged by the Processor to process Client Data.
Terms not defined here carry the meaning given in the UK GDPR.
2. Roles of the Parties
2.1 In respect of Client Data the Controller is the controller and the Processor is the processor.
2.2 The Processor is an independent controller only in respect of its own account administration, billing and service-security data, which it processes under its own privacy notice.
2.3 Each Party complies with Applicable Data Protection Law in respect of its own activities.
3. Scope and processing instructions
3.1The Processor processes Client Data only on the Controller's documented instructions, as set out in Annex 1, this Agreement and the Principal Agreement.
3.2 The Processor does not process Client Data for any other purpose unless required by law, in which case it informs the Controller before processing unless legally prohibited.
3.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. The Processor may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
3.4The Processor does not use Client Data to train, fine-tune, evaluate or otherwise develop any machine learning or artificial intelligence model, whether its own or a third party's. The Processor contracts with each AI Sub-processor on terms that prohibit such use and require zero retention of Client Data after processing.
4. Special Category Data
4.1 The Parties acknowledge that advisory conversations may disclose Special Category Data, in particular data concerning health relevant to protection, annuity, long-term care or life-expectancy matters, and indicators of vulnerability.
4.2 Such data is not solicited by the Services. It arises incidentally in unstructured speech and cannot be reliably excluded by technical means.
4.3 The Controller is responsible for identifying and documenting its Article 9(2) condition and, where required, its Schedule 1 Data Protection Act 2018 condition, and for maintaining any appropriate policy document required by that Schedule.
4.4 The Processor applies the measures in Annex 2 to all Client Data without distinction as to category.
5. Processor obligations
The Processor shall:
- (a) process Client Data only as set out in clause 3;
- (b) ensure persons authorised to process Client Data are subject to binding confidentiality obligations;
- (c) implement and maintain the measures in Annex 2;
- (d) engage Sub-processors only in accordance with clause 8;
- (e) assist the Controller in responding to Data Subject requests under clause 10;
- (f) assist the Controller in complying with Articles 32 to 36 UK GDPR, including data protection impact assessments and prior consultation;
- (g) notify Personal Data Breaches under clause 11;
- (h) make available information necessary to demonstrate compliance, and submit to audit under clause 13;
- (i) delete or return Client Data under clause 14.
6. Personnel
6.1 The Processor ensures that personnel with access to Client Data are subject to background screening appropriate to the role, where lawful and proportionate.
6.2 Personnel receive data protection and information security training on appointment and at least annually.
6.3 Access is granted on a least-privilege basis and revoked promptly on change of role or termination.
7. Security
7.1 The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to the state of the art, cost of implementation, and the nature, scope, context and purposes of processing. Those measures are set out in Annex 2.
7.2 The Processor may update the measures in Annex 2 provided the overall level of security is not materially reduced.
7.3Annex 2 states the Processor's current control position accurately, including controls not yet in place. The Controller acknowledges it has had the opportunity to assess those matters.
8. Sub-processors
8.1 The Controller grants general written authorisation for the engagement of the Sub-processors listed in Annex 3.
8.2The Processor gives the Controller at least 30 days' prior written notice of any intended addition or replacement of a Sub-processor.
8.3 The Controller may object on reasonable data protection grounds within that notice period. If the objection cannot be resolved, the Controller may terminate the affected Services without penalty, with a pro-rata refund of prepaid fees.
8.4The Processor imposes on each Sub-processor data protection obligations no less protective than those in this Agreement, and remains fully liable to the Controller for each Sub-processor's performance.
9. International transfers
9.1 The Processor does not transfer Client Data outside the United Kingdom except as recorded in Annex 3.
9.2 Where a transfer occurs, the Processor ensures it is subject to an appropriate Chapter V UK GDPR mechanism — UK adequacy regulations, an International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — supported by a documented Transfer Risk Assessment and any necessary supplementary measures.
9.3 The Processor provides copies of the relevant transfer mechanism and Transfer Risk Assessment to the Controller on request.
10. Data Subject rights
10.1 The Processor promptly notifies the Controller of any request received directly from a Data Subject and does not respond substantively unless instructed.
10.2 The Processor provides functionality enabling the Controller to satisfy requests for access, rectification, erasure and portability, including structured export of client records, meetings, transcripts, summaries, documents, forms, notes, tasks and signature history, and deletion of a client record and associated data by a firm administrator.
10.3 The Parties acknowledge that meeting audio and transcripts are a contemporaneous record. Rectification is effected by annotation rather than alteration of the original, so that the integrity of the regulatory record is preserved. Erasure of the underlying record remains available to the Controller.
11. Personal Data Breach
11.1 The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Client Data.
11.2The notification includes, to the extent available: the nature of the breach and categories and approximate number of Data Subjects and records concerned; the name and contact details of the Processor's data protection contact; likely consequences; and measures taken or proposed, including mitigation.
11.3 Where information is not available at the time of notification, it is provided in phases without further undue delay.
11.4 The Processor does not notify the ICO or any Data Subject in respect of Client Data unless required by law or instructed by the Controller.
11.5 The Processor maintains a documented incident response procedure.
12. Data protection impact assessments
The Processor provides reasonable assistance with the Controller's data protection impact assessments, including its published DPIA summary and reasonable responses to security questionnaires.
13. Audit
13.1The Controller may verify compliance by requesting evidence of compliance; reviewing security documentation provided under non-disclosure agreement; conducting an on-site audit on at least 30 days' notice, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach; or appointing an independent auditor at the Controller's expense, subject to reasonable confidentiality terms.
13.2Audits are conducted during business hours with minimal disruption and must not compromise the confidentiality or security of other customers' data.
14. Deletion and return
14.1 The Processor processes Client Data for the retention period configured by the Controller. The Controller is solely responsible for determining that period having regard to its own regulatory obligations, including SYSC 10A.1.10 and, where relevant, longer periods applicable to pension transfer and defined benefit advice.
14.2On expiry or termination, the Processor deletes or returns Client Data at the Controller's election within 15 days, save to the extent retention is required by law.
14.3 Client Data may persist in encrypted backups for the backup cycle then in effect, after which it is overwritten.
14.4 The Processor certifies deletion in writing on request.
15. Liability
Liability under this Agreement is subject to the limitations and exclusions in the Principal Agreement, save that nothing limits liability which cannot lawfully be limited.
16. Term, order of precedence and governing law
16.1 This Agreement takes effect on the Effective Date and continues while the Processor processes Client Data.
16.2 In the event of conflict, this Agreement prevails over the Principal Agreement in respect of data protection matters. Where a Chapter V transfer mechanism applies, that mechanism prevails over this Agreement to the extent of any conflict.
16.3 This Agreement is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the English courts.
Signed
For and on behalf of each Party:
Processor
- Name
- Title
- Date
- Signature
Controller
- Name
- Title
- Date
- Signature
Annex 1 — Details of processing
- Subject matter
- Provision of AI-assisted meeting capture, transcription, summarisation and compliance documentation.
- Duration
- The term of the Principal Agreement, plus the retention period configured by the Controller.
- Nature
- Collection, recording, storage, transcription, automated text generation, structuring, retrieval, export, erasure.
- Purpose
- Enabling the Controller to meet record-keeping and suitability-documentation obligations under SYSC 10A.1, COBS 9A and the Consumer Duty.
- Data Subjects
- The Controller's clients and prospective clients; dependants and family members discussed in meetings; the Controller's advisers and staff; other meeting participants.
- Categories of personal data
- Identity and contact data; financial data (income, assets, pensions, investments, liabilities, objectives, risk profile, capacity for loss); voice recordings; transcripts and AI-generated summaries and documents; adviser account and authentication data; administrative audit records.
- Special Category Data
- Data concerning health, and vulnerability indicators, arising incidentally in meeting content as described in clause 4.
- Processing operations
- Capture or upload of meeting audio from video conferencing platforms or in person; transcription by automated speech-to-text; speaker identification and labelling; generation of structured summaries including suitability notes, risk profile documentation, capacity-for-loss assessments, vulnerability indicators and action items; secure storage for the Controller-configured retention period; search, retrieval and structured export for authorised users; routing of documents for electronic signature; provision of compliance reporting and dashboards to the Controller's compliance function.
Annex 2 — Technical and organisational measures
- Encryption
- AES-256 at rest; TLS 1.3 in transit. Encryption keys are managed by the Processor's infrastructure providers under their own key management controls.
- Access control
- Role-based access with team-scoped permissions; advisers access their own records while compliance personnel have firm-wide visibility. Microsoft Entra ID single sign-on is available, allowing the Controller to enforce its own MFA and conditional access policy within its tenant.
- Tenant isolation
- Client Data is logically isolated per firm by database row-level security policies scoped to the Controller's company identifier.
- Network
- All network traffic is served over TLS with managed DDoS protection at the edge. Database access is restricted to authenticated application requests.
- Audit logging
- Company and team administration events — including invitations, role and ownership changes, team membership changes and company detail updates — are written to an append-only log recording actor identity, event type, target and timestamp. Database-level triggers prevent modification or deletion, including by administrators and the Processor's own personnel. This log does not currently record client record access, document generation or export events. It does not record IP addresses.
- Resilience
- Automated encrypted backups with point-in-time recovery, giving a one-hour recovery point objective. Backups are encrypted to the same standard as live data.
- Personnel
- DBS checks where lawful and proportionate; binding confidentiality obligations; mandatory annual training; prompt access revocation on departure.
- Vulnerability management
- Automated dependency and vulnerability monitoring with remediation targets of 24 hours (critical), 7 days (high) and 30 days (medium).
- Certifications
- Cyber Essentials certified. ICO registration ZB622400.
Annex 3 — Sub-processors and transfers
See reference document: TakeNote Sub-Processor Register v2.1.
The current list is maintained by the Processor and available on request. Notice of change is given under clause 8.2.
Contact
ClientScan Limited
7 Bell Yard
London WC2A 2JR
United Kingdom
Data protection enquiries: dpo@takenote.ai
Please quote document reference TN-DPA-2026-001. A countersignable copy of this Agreement is available on request.
