Legal

Data Processing Agreement

Shared Wealth Technology, a brand division of Shared Wealth International Ltd

Version 1.0.0 · Effective 3 August 2026

Data Processing Agreement (DPA)

This DPA forms part of the Terms of Service and applies when Shared Wealth International Limited (“Processor”, “we”) processes personal data on behalf of a Customer organisation using SWT Asset Management (“Customer”, “Controller”).

This DPA is intended to meet Article 28 UK GDPR. It does not apply where we act as controller (see the Privacy Notice).

Effective date: 3 August 2026
Version: 1.0.0

1. Subject-matter

ItemDetail
Subject-matterOperation of SWT Asset Management on Customer’s behalf
DurationTerm of Customer’s access plus retention in §9
Nature / purposeHosting and processing Customer-entered business data for asset, capital, CRM, governance, document, and AI-assisted features
Types of dataContact, account, organisational, document, and operational data Customer chooses to store
Data subjectsCustomer staff, portfolio contacts, investors, and other individuals whose data Customer uploads

2. Instructions

We process personal data only on documented Customer instructions (including Platform configuration and uploads), unless required by law.

3. Confidentiality and security

Authorised persons are under confidentiality obligations. Security measures include TLS, encryption at rest for sensitive documents, RBAC, MFA for privileged roles, IDOR controls, CSRF protection, rate limiting, audit logging, and backup procedures.

4. Sub-processors

Customer authorises the sub-processors listed at /subprocessors. We will update that register before adding material new sub-processors; Customer may object on reasonable data-protection grounds.

5. Data subject rights and breach

We will assist Customer with data subject requests and notify Customer without undue delay (and within 48 hours where practicable) after becoming aware of a personal data breach affecting Customer data.

6. International transfers

Transfers outside the UK/EEA use adequacy, UK IDTA, or SCCs with UK Addendum plus appropriate safeguards.

7. Return and deletion

On termination, Customer may export data via available Platform tools. We will delete or anonymise Customer personal data within 90 days after termination or last successful export, except where law requires retention.

8. Audits

We will make available information reasonably necessary to demonstrate Article 28 compliance. Customer may request an audit no more than once per 12 months on 30 days’ notice, or accept a suitable third-party report.

9. Liability and precedence

Liability follows the commercial agreement or, if none, Terms §10. Order of precedence: commercial agreement (commercial matters) → this DPA (data protection) → Terms.

10. Contact

DPO: Cliff Southcombe — privacy@sharedwealth.international

This document is provided for transparency and compliance. It is not legal advice. Final reliance requires counsel sign-off.