Data Processing Agreement
Sponsor Licence Compliance Guru, operated by Nara Solicitors Ltd, Spaces Canary Wharf, 25 Cabot Square, London E14 4QZ, United Kingdom. Authorised and regulated by the Solicitors Regulation Authority (SRA No. 8006464). Company number 15219728.
Version 1.0 · Last updated: 29 July 2026.
This Data Processing Agreement (“DPA”) reflects UK GDPR Article 28, forms part of our Terms and Conditions (the “Main Agreement”) and binds both parties automatically from the moment you accept the Main Agreement (for example at account creation) — no separate signature is needed. It applies to the personal data you enter or upload into the platform (“Customer Data”).
1. Roles
For Customer Data, your organisation is the controller and Nara Solicitors Ltd is the processor, processing it only to provide and support the Sponsor Licence Compliance Guru platform. For your account, security and billing data, we act as an independent controller under our Privacy & Cookies Policy. Where you separately engage Nara Solicitors for legal services, that work is carried out by the firm as your solicitor under its own terms, not under this DPA.
2. Details of the processing
- Subject matter: hosting and management of UK sponsor-licence compliance records on your behalf.
- Duration: the term of the Main Agreement, plus a 30-day export window, after which data is deleted.
- Nature & purpose: storage, organisation, reminder generation and export of compliance records. No automated decision-making with legal effect.
- Types of data: identity & contact; immigration & right-to-work (passport, visa/BRP, CoS, RTW/ECS evidence); employment; financial (payroll evidence); attendance & absence. The platform does not solicit special-category data.
- Data subjects: your sponsored workers, prospective workers, their emergency contacts and your key personnel.
3. Our obligations as processor
- Documented instructions. We process Customer Data only on your documented instructions (the Main Agreement, this DPA, and your use of the platform), unless required by law. If we consider an instruction infringes data-protection law, we will tell you and may pause or decline it until you confirm or amend it.
- Confidentiality. Our personnel are bound by confidentiality, and by our professional obligations as solicitors.
- Security (Art. 32). Encryption in transit (TLS) and at rest (AES-256, including backups); mandatory two-factor authentication; application-level tenant isolation verified by automated deployment checks; private document storage served only via short-lived signed links; least-privilege access; append-only audit logs retained at least 12 months; rate-limiting and brute-force protection on sign-in; and daily encrypted backups (recovery point objective of no more than 24 hours; restoration after data loss targeted within one working day on a reasonable-endeavours basis), with documented disaster-recovery and business-continuity procedures.
- Sub-processors. You authorise the sub-processors listed below. We impose equivalent data-protection terms on each, remain liable for them, give you prior notice of changes, and — if you reasonably object on data-protection grounds within 14 days — will not appoint that sub-processor or will let you terminate the affected service without penalty.
- Data-subject rights. We assist you in responding to access, rectification, erasure, restriction, portability and objection requests (the platform’s export and delete features support this in the ordinary course). A request we receive directly is forwarded to you within 5 working days. Assistance beyond the self-service features may be provided at your reasonable cost.
- Assistance. We assist you with UK GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation), given the nature of the processing and the information available to us; assistance beyond our existing documentation may be at your reasonable cost.
- Breach notification. We notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data, and where feasible within 48 hours, with the information then available. Such notice is not an admission of fault.
- Deletion or return. On termination, at your choice, we delete or return Customer Data and delete existing copies (subject to legal retention and routine backup cycles, from which data is purged within the documented window, currently up to 7 days). You may request return or export within 30 days of termination. A customer-initiated account deletion removes Customer Data immediately from the live system. On request, we will provide written confirmation that deletion is complete, including when the backup purge window ends.
- Audits. We make available our security documentation and any certifications to demonstrate compliance, which you agree to rely on first. Where that does not address a specific reasonable concern, you (or an independent, non-competitor auditor bound by confidentiality) may audit on at least 30 days’ notice, no more than once a year (or after a breach), during business hours, without compromising other customers, and at your own cost.
- Inability to comply. We notify you promptly if we determine we can no longer meet our obligations under data-protection law; you may then suspend the affected processing and/or exercise your termination rights, and we take reasonable steps to stop and remediate any unauthorised processing.
- Public-authority requests. If we receive a legally binding request for Customer Data from a public authority, we notify you before disclosure unless legally prohibited, disclose only the minimum required, and where reasonable challenge overbroad or unlawful requests.
4. Your obligations as controller
You must ensure you have a lawful basis (and, for special-category data, a condition and the worker’s explicit consent) to process the Customer Data you upload; give only lawful instructions; be responsible for the accuracy, quality and legality of that data; keep your user accounts and credentials secure and use the two-factor authentication the platform provides; ensure only authorised personnel access the platform on your behalf and remove access promptly when no longer required; and notify us without undue delay if you know or suspect a credential has been compromised.
Immigration-law responsibility. You remain solely responsible for your compliance with UK immigration law, your sponsor-licence duties, Home Office guidance and your employment obligations. The Services support your record-keeping and monitoring activities but do not constitute legal or immigration advice and do not guarantee compliance, sponsor-licence retention or any Home Office outcome; automated indications, reminders and scores are aids only.
5. International transfers
Customer Data is hosted in the UK/EU region and will not be intentionally transferred or relocated outside the UK or EEA without prior notice to you and an appropriate transfer mechanism in place. Where any sub-processor processes Customer Data outside the UK, we ensure an appropriate transfer mechanism is in place — a UK adequacy decision, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses with a transfer risk assessment.
6. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & document storage | EU — Ireland (eu-west-1) |
| Vercel | Application hosting | UK — London (eu-west-2) |
| Amazon Web Services (Amazon SES) | Transactional email | UK — London (eu-west-2) |
| Functional Software, Inc. (Sentry) | Error monitoring (technical error reports; systems are designed not to include worker records in them) | EU / US (SCCs + UK Addendum) |
| postcodes.io | UK postcode lookup (no personal data sent) | UK |
| Cloudflare, Inc. (Turnstile) | Bot protection (CAPTCHA) on the public signup form — visitor IP/browser signals only; no worker records sent | Global edge (SCCs + UK Addendum) |
7. Liability, indemnity & governing law
Each party is liable for its own breaches of data-protection law and this DPA. Our total liability under this DPA is subject to, and counts towards, the limitations in the Main Agreement, except where the law does not permit limitation. You agree to indemnify us against claims, fines and reasonable costs arising from your own breach of your controller obligations — including a lack of lawful basis or valid consent for special-category data, or inaccurate or unlawfully collected data — except to the extent caused by our own breach or negligence. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
8. Precedence & changes to this DPA
This DPA forms part of the Main Agreement. If they conflict on a data-protection matter, this DPA prevails; on all other matters the Main Agreement prevails. We may update this DPA on reasonable notice to reflect a change in data-protection law, a new transfer mechanism, or a change of sub-processor, provided the protection of Customer Data is not materially reduced.
9. Anonymised data & notices
We may create and use aggregated, anonymised statistics derived from use of the platform that do not identify, and cannot reasonably be linked to, any person or customer; we will never attempt to re-identify them. Formal notices under this DPA go to the email address registered on your account (to you) and, to us, to privacy@narasolicitors.com (data protection), security@narasolicitors.com (security matters) or dpo@narasolicitors.com (our Data Protection Officer). We welcome good-faith reports of suspected security vulnerabilities to the security address and will not pursue researchers acting in good faith and within the law.
Download this DPA as a PDF (v1.0, 29 July 2026). This DPA applies automatically from acceptance of the Terms. Customers can optionally sign it inside their account (Dashboard → Docs → DPA) to generate a signed copy with a signature certificate for their records — questions to privacy@narasolicitors.com.
As the controller, you must tell your workers about this processing: we provide a fill-in worker privacy notice template to make that easy.