Data Processing Addendum

Version 1.0 · effective 17 August 2026 · incorporated into the UK Filing Business Terms

This addendum applies where the subscribing business is controller and Dali AI GmbH processes personal data contained in paid-workspace files or mappings on that business's behalf. It does not govern Stripe's independent payment purposes or the browser-only free validator.

1 Parties and instructions

The customer is the controller and Dali AI GmbH is the processor. The Business Terms, the customer's use of the workspace and saved support instructions are documented instructions. Dali AI processes personal data only on those instructions and to provide, secure or support UK Filing, unless applicable law requires otherwise. Where legally permitted, Dali AI informs the customer before processing required by law and immediately reports an instruction it reasonably believes infringes applicable data-protection law.

2 Processing details

Subject and purposeStorage, mapping, generation, structural pre-check, review workflow, download, support and security for monthly framework-management-information files.
DurationFor the subscription and the deletion period below. Individual stored files automatically expire after 90 days unless deleted sooner.
Personal-data typesBusiness contact and authority names or identifiers, invoice and transaction references, dates, products, quantities, values, contract references, file metadata and workspace activity. Special-category and criminal-offence data are prohibited.
Data subjectsThe customer's personnel, business contacts, suppliers, customers and participating-authority contacts whose ordinary business information appears in source records.
Controller rights and dutiesThe customer decides the lawful purpose and content, minimises the upload, keeps source data accurate, controls authorised users, reviews outputs, submits returns and may download or delete files and workspace data.

3 Confidentiality and security

Dali AI limits access to persons who need it for service or support and who are bound by confidentiality. Measures include TLS in transit; Cloudflare-managed AES-256 encryption for stored file values; one-way hashing of private workspace credentials; tenant-specific database and storage keys; encrypted platform secrets; same-origin mutation controls; file-type and 20-MB limits; workflow event records; automatic file expiry; and customer-controlled deletion. The customer acknowledges that the private link is a bearer credential and must be protected like a password.

4 Sub-processor authorisation

The customer gives general written authorisation for the sub-processor below. Dali AI imposes materially equivalent data-protection obligations, remains responsible for its sub-processor's performance of those obligations and will notify the checkout business email of an intended replacement or additional customer-file sub-processor at least 14 days beforehand where practicable. The customer may object on reasonable data-protection grounds during that period; if no reasonable alternative is available, either party may end the affected service.

Sub-processorPurposeProcessing locations and safeguards
Cloudflare, Inc. and listed Cloudflare group/sub-processing entitiesPages Functions, D1 workflow database, KV file storage, delivery and securityD1 primary location: Cloudflare Eastern Europe region. KV and network services use Cloudflare's global infrastructure, including the United States. Cloudflare's Data Processing Addendum and applicable transfer safeguards apply.

5 Rights requests and compliance assistance

Taking account of the processing and information available, Dali AI will provide reasonable assistance with data-subject requests, security duties, breach notifications, data-protection impact assessments and regulator consultations. If Dali AI directly receives a request concerning customer-controlled data, it forwards the request and does not respond substantively unless instructed or legally required.

6 Personal-data incidents

Dali AI notifies the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data and provides available information reasonably needed for the customer's assessment and notification duties. Notice is sent to the checkout business email or another recorded security contact. The customer remains responsible for notifications required of it as controller.

7 Return and deletion

During the subscription, the customer can download outputs and delete individual files or the complete workspace. On termination, Dali AI will, at the customer's written choice, return available customer data or delete it, unless law requires retention. Stored file values expire no later than 90 days after upload. Dali AI may retain minimal contract, billing, security and deletion evidence where legally necessary; it will not use retained material for another purpose.

8 Information and audits

Dali AI provides information reasonably necessary to demonstrate compliance, including this addendum, current security information and relevant sub-processor documentation. With reasonable notice and confidentiality safeguards, the customer may conduct one proportionate audit per year, first using documents and remote questions. On-site or additional audits are limited to a substantiated incident, regulator requirement or material unresolved concern; the customer bears reasonable costs unless the audit identifies a material Dali AI breach.

9 International transfers

Dali AI is established in Switzerland. The parties may rely on an applicable UK adequacy regulation for transfer to Switzerland. Cloudflare processing outside an adequate destination is governed by the transfer mechanism and supplementary measures in Cloudflare's Data Processing Addendum. Dali AI will reasonably assist with information needed for the customer's transfer assessment.

10 Order of precedence and contact

This addendum prevails over conflicting Business Terms for processor obligations. Otherwise the Business Terms, including governing law and liability provisions to the extent legally permitted, apply. Data-protection instructions and incident notices: [email protected]; do not attach customer files to ordinary email.