Data Processing Agreement
Last updated: August 2026
This Data Processing Agreement is part of our Terms of Service and applies whenever we process personal data on your behalf as part of the Komply service. If this document and the Terms disagree about how we process your data, this document controls; on everything else, including liability, the Terms control.
‘We’, ‘us’ and ‘Komply’ mean Komply, a service operated by Growtal. ‘You’ means the organisation that holds a Komply account. Our registered address and ICO registration number will appear here before launch.
1. Roles
You are the controller of the personal data you and your staff put into Komply — your account details, your venue's assessment answers, and any personal data in the evidence files and training records you upload. We are the processor. We don't decide why that data is processed; you do, and we follow your instructions as set out in this document.
2. What we process
Subject matter:providing the Komply compliance-readiness service — assessing your venue against Martyn's Law, generating action plans and (where your tier requires it) Section 7 statements, and storing your evidence.
Duration: for as long as your account is active, and for the retention periods set out in section 9 (Deletion and return) afterwards.
Nature and purpose: collecting your answers and uploaded files; storing them; using AI models to generate advice and statutory-statement drafts from them; and making the results available to you.
Categories of data subjects: your account holders — owners, admins, and any Designated Senior Individual you name — and, only where you choose to include it, venue staff and contractors named in the evidence and training records you upload.
Categories of personal data: account details (email address, and name where given); organisation and venue contact details; your assessment answers, including any free text you write; the contents of evidence files you upload; training log entries, including staff names, roles and trainers; Designated Senior Individual details; and the names of anyone you record as owning an action.
3. Processing only on your instructions
We process personal data only on your documented instructions — set out in the Terms, this DPA, and your own use of the product's features — including instructions about transferring personal data outside the UK. If we're ever asked to transfer or disclose personal data in a way that goes beyond those instructions, we'll tell you first, unless the law tells us not to. If we ever think an instruction you've given us would break UK data protection law, we'll tell you before carrying it out.
4. Confidentiality
Everyone at Komply who can access personal data is bound by confidentiality — by their employment contract or an equivalent written undertaking — and access is limited to what their role needs.
5. Security
We keep the security measures described in our Privacy Policy, including: mandatory multi-factor authentication on every account; row-level access control at the database, so a query can only ever see data that account is entitled to; evidence files held in an isolated store with signed download links that expire in 15 minutes (60 minutes for compliance reports), never a public URL; encryption in transit and at rest, provided by our hosting and database providers; and automated checks that run on every change we ship, several of them written specifically to stop one organisation's data becoming visible to another.
We do not currently hold a SOC 2 report, ISO 27001 certification, or an independent penetration-test report — we'll tell you if that changes.
6. Sub-processors
We use the sub-processors listed at our sub-processor list, and that list is your general written authorisation for us to use them. We'll add to it only for genuine service needs, and we'll update it at least 30 days before a new sub-processor starts processing your data. If you object to a new sub-processor, your remedy is to terminate your subscription under the Terms — at our size we can't offer a per-customer sub-processor list, so we can't offer a veto either. Where we use a sub-processor to process your data, we require them to protect it to a standard equivalent to this DPA.
7. Helping you meet your own obligations
We give you tools to exercise data subject rights yourself: Account > Export my data returns the operational data we hold about your organisation, including evidence file links — with one exception, set out in section 9: our own record that a deletion took place. Account > Delete my account starts erasure, with a 30-day window to change your mind. You're responsible for responding to your own staff, DSI, or any other data subject who asks you to exercise a right — we're not in a position to know who they are or what they've asked for. Where you need help beyond what those tools do — for example, locating a specific record by hand — we'll assist, and we may charge our reasonable costs for work beyond the self-serve tools.
We'll help you meet your obligations under UK GDPR Articles 32 to 36 — security, breach notification, impact assessments, and prior consultation with the ICO — so far as they relate to the personal data we process for you, using the measures and information already in this document and in reasonable response to specific requests.
8. Breach notification
If we become aware of a personal data breach affecting your data, we'll tell you without undue delay, and give you the information you need to meet your own notification duties to the ICO and to affected individuals.
9. Deletion and return
At the end of your subscription, or at any point before it, you can export everything (Account > Export my data) and delete your account (Account > Delete my account) — that's the choice UK GDPR gives you, and both are available whenever you want them, not only at termination.
Deleting your account disables it immediately. You have 30 days to restore it yourself if you change your mind. After that window, your data is permanently deleted on our next scheduled purge — the purge runs weekly, so this may be a few days after the 30-day mark, not on day 30 exactly.
Two things are kept afterwards, and this is a legal requirement of ours, not a choice: financial records of what you were charged, de-linked from your organisation rather than deleted, to meet our own bookkeeping obligations; and a record that a deletion happened, without the personal data it concerned, kept so we can show a regulator our own process worked.
10. Audits and information
We'll give you the information reasonably necessary to demonstrate our compliance with this DPA — this document, our sub-processor list, and written answers to reasonable questions about how we process your data.
If you need to inspect our processing in person — including because a supervisory authority requires it — you may do so once every 12 months, on at least 30 days' written notice, during business hours, at your own cost, and subject to a confidentiality undertaking protecting our other customers' data and our security posture. We may decline access to anything unrelated to the processing of your data.
11. Your responsibility for what you upload
You're responsible for having a lawful basis to process the personal data you put into Komply — including anyone named in an evidence file or a training log entry — and for giving your own staff and contractors whatever notice UK GDPR requires before their data goes into a system like this one. We never collected that data ourselves; you supplied it, and you're the one who can tell us it shouldn't be there.
12. International transfers
Most of your data — account details, assessment answers, and uploaded evidence — is held and processed in the UK, by Supabase (London) and our rate-limiting store (London). Some sub-processors handle it, or parts of it, elsewhere: Vercel, which hosts the application, processes server-side requests in the United States; Sentry, our error-monitoring provider, processes error diagnostics in the European Union (Germany); our background job queue processes in the European Union. Anthropic, Stripe, Resend and VirusTotal each process the data described for them in our sub-processor listunder their own published data processing terms. Where a sub-processor processes personal data outside the UK, that transfer is made under an appropriate transfer mechanism — such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses — under that sub-processor's own standard contractual terms.
13. Liability
This DPA does not create a separate liability route. Our liability under this DPA is subject to the same cap set out in the Terms — section 5, Limitation of liability — and nothing here increases it.
14. Term and survival
This DPA lasts as long as the Terms do. The sections on confidentiality, deletion and audits survive termination for as long as we hold any of your personal data.
15. Governing law
This DPA is governed by the laws of England and Wales, the same as the Terms.
16. Contact
Data protection enquiries: info@komply.uk