SafeLet

Data processing agreement

Last updated 28 August 2026

SafeLet is operated by the account holder named in your contract. Company registration details are not yet published on this deployment. This agreement governs its processing of personal data on behalf of a customer organisation and forms part of our terms of service. It is written to satisfy Article 28 of the UK GDPR. It takes effect when you create an organisation on SafeLet; no signature is required, and a countersigned copy is available on request.

1. Parties and roles

Operator details not configured

Company registration details are not configured on this deployment. Set COMPANY_LEGAL_NAME, COMPANY_NUMBER, COMPANY_REGISTERED_OFFICE, COMPANY_GENERAL_EMAIL and COMPANY_PRIVACY_EMAIL before publishing this page.

“Customer” means the organisation that holds the SafeLet account. “SafeLet” means the operator identified above. “Applicable law” means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.

For personal data about screening subjects the Customer is the controller and SafeLet is the processor. Each party complies with applicable law in its own right. SafeLet is separately a controller for its own account, billing and security data, which is covered by the privacy notice rather than by this agreement.

2. Subject matter and duration

Subject matter: screening names against published sanctions lists, producing certificates and audit records, and re-screening saved subjects when a list is updated. Duration: from creation of the Customer’s organisation until the account is closed and the deletion obligations in section 12 are complete. Individual records are deleted earlier if the Customer’s configured retention period expires first.

3. Nature and purpose of processing

Collection through the Customer’s own input or CSV upload; storage in a managed database; normalisation of names; comparison against the UK Sanctions List, the US OFAC SDN list and the EU consolidated list; scoring of candidate matches; generation of PDF certificates; storage of those certificates; sending of email alerts to the Customer’s users; export of the Customer’s data on request; and deletion at the end of the retention period.

The purpose is to enable the Customer to meet its sanctions obligations and to evidence that it has done so. SafeLet processes the data for no other purpose, does not use it to train models, does not combine it with data from other customers and does not enrich it from third-party sources. SafeLet screens sanctions lists only.

4. Categories of data and data subjects

Data subjects: prospective and current tenants, landlords, guarantors and other parties the Customer chooses to screen; and the Customer’s own staff who use the service.

Categories of personal data: name; date of birth where provided; nationality where provided; role in the tenancy; the Customer’s own reference; screening outcome, score, matched sanctions-list names and the list versions used; review decisions and notes; certificate files; and, for the Customer’s staff, name, email address, role and audit-log activity.

Special category data: not required and not requested. Sanctions designations are published by governments and a match reflects name similarity to a published list, not a criminal conviction. The Customer must not enter special category data or offence data into free-text fields such as a reference or a review note.

5. SafeLet's obligations as processor

SafeLet will: process personal data only on the Customer’s documented instructions, which include the instructions given through the product interface and this agreement; notify the Customer if it believes an instruction infringes applicable law; not transfer data outside the UK except as set out in section 9; assist the Customer with data protection impact assessments and with consultations with the Information Commissioner’s Office, so far as the assistance relates to SafeLet’s processing; and make available the information necessary to demonstrate compliance with Article 28.

6. Customer's obligations as controller

The Customer will: ensure it has a lawful basis for entering each subject’s data and for screening them; provide the information required by Articles 13 and 14 to the people it screens; keep instructions lawful; configure a retention period appropriate to its own obligations; keep its user accounts and access rights current, removing staff who leave; and review every match itself. SafeLet is a screening aid and does not constitute legal advice, and the Customer remains responsible for its decisions, including whether to report a suspected designated person to OFSI.

7. Confidentiality

Access to Customer personal data is limited to SafeLet personnel who need it to provide or support the service. Those personnel are bound by written confidentiality obligations that survive the end of their engagement, receive data protection training appropriate to their role, and have their production access logged and reviewed. SafeLet will not disclose Customer personal data to a third party except as permitted by this agreement or where legally compelled, in which case it will notify the Customer unless prohibited from doing so.

8. Security measures

Taking account of the state of the art and the risks presented, SafeLet implements at least the following: TLS for all data in transit and encryption at rest for the database and file storage; organisation-scoped access control on every query so one customer cannot read another’s data; multi-factor authentication for staff access to production; least-privilege credentials rotated on personnel change; an append-only audit log of checks, reviews, exports and settings changes that application code cannot amend; secure software development practice including code review, dependency scanning and security headers with a per-request content security policy; rate limiting and abuse protection on public endpoints; encrypted backups with tested restores and a 30-day maximum backup age; logging that excludes subject names; and an incident response plan with a named owner and an annual test.

9. Sub-processing and international transfers

The Customer gives general authorisation for SafeLet to engage the sub-processors listed in the annex. SafeLet imposes data protection terms on each sub-processor that are no less protective than this agreement and remains liable to the Customer for their performance.

SafeLet will give at least 30 days’ notice by email to organisation owners before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.

Where personal data is transferred outside the UK, SafeLet relies on the UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. The mechanism applying to each sub-processor is stated in the annex.

10. Data-subject requests and breach notification

Requests. The product lets the Customer read, correct, export and delete subject records itself, which is how most requests are satisfied. If a data subject contacts SafeLet directly, SafeLet will not respond substantively but will forward the request to the Customer without undue delay and will assist the Customer in answering it, including by providing an export in a portable format.

Personal data breach. SafeLet will notify the Customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Customer’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. SafeLet will provide updates as the investigation progresses so that the Customer can meet its own 72-hour notification deadline to the Information Commissioner’s Office. SafeLet does not notify the regulator or data subjects on the Customer’s behalf.

11. Audit and inspection

On request and no more than once a year, or after a breach affecting the Customer, SafeLet will provide its current security documentation, penetration test summary, sub-processor list and answers to a reasonable security questionnaire. Where that is genuinely insufficient to demonstrate compliance, the Customer or an independent auditor bound by confidentiality may audit SafeLet’s processing on 30 days’ notice, during business hours, without access to other customers’ data and without disproportionate disruption. Each party bears its own costs unless the audit reveals material non-compliance, in which case SafeLet bears the reasonable cost of the audit and of remediation.

12. Return and deletion on termination

The Customer may export its organisation’s checks, subjects and certificates at any time while the account is open. On termination the Customer has 30 days to export; after that, SafeLet deletes all Customer personal data from production systems within a further 30 days and confirms deletion in writing on request. Encrypted backups containing the data age out within 30 days of deletion and are not restored except for disaster recovery, in which case the deletion is reapplied. SafeLet retains only what applicable law requires it to keep, such as invoices and accounting records, and keeps it solely for that purpose.

13. Liability, precedence and law

This agreement supplements the terms of service. If there is a conflict about the processing of personal data, this agreement prevails. Liability is subject to the limitations in the terms of service, except that nothing limits liability that cannot be limited by law, including a data subject’s rights under Article 82. This agreement is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.

Annex 1 — Approved sub-processors

This annex matches the sub-processor table in the privacy notice. Both pages are generated from one list, so they cannot fall out of step.

Sub-processorPurposeLocation of processingTransfer mechanism
NeonManaged PostgreSQL database holding subjects, checks and the audit logUnited Kingdom (London)No routine transfer outside the UK; support access under the UK IDTA
NetlifyApplication hosting, edge delivery and certificate file storageUnited Kingdom and European Union edge, United States control planeUK Addendum to the EU standard contractual clauses
ResendTransactional email: sign-in links, monitoring alerts and receiptsEuropean Union and United StatesUK Addendum to the EU standard contractual clauses
Dodo PaymentsMerchant of record for subscriptions and per-check billing: card payments, VAT handling and invoicing. Appears as "Dodo" on your card statement.United Kingdom, European Union, United States and IndiaUK Addendum to the EU standard contractual clauses
SentryError and performance monitoring of the applicationEuropean UnionUK Addendum to the EU standard contractual clauses; personal data scrubbed before send

This document is provided so you can see our processor commitments in full. It describes the contract between us; it is not legal advice about your own obligations, and a solicitor or your professional body should advise you on those.