Upliftby WealthSteer

WealthSteer · last updated 19 August 2026

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the agreement between Steer Financial Ltd ("the Processor") and each advice firm using WealthSteer ("the Controller"). It sets out the terms on which the Processor processes personal data on the Controller's behalf, as required by Article 28 UK GDPR. A signed copy is available on request to privacy@wealthsteer.com.

Roles and scope

The Controller determines the purposes and means of processing its clients' personal data. The Processor processes that data only to provide the WealthSteer services and only on the Controller's documented instructions, which include the functionality the Controller uses and configures in the products.

Nature of the processing

  • Subject matter: client engagement — confidence questionnaires and scores, financial fact-finds and statements, calculators, adviser notes, and reports.
  • Duration: the term of the Controller's agreement plus the deletion period below.
  • Data subjects: the Controller's clients and prospective clients; the Controller's own staff.
  • Categories of data: identity and contact details; questionnaire responses; financial information the data subject chooses to share (income, outgoings, assets, liabilities, protection); adviser notes; engagement and sign-in events.
  • Special category data: none is requested. Where a data subject volunteers it in free text, it is processed on the same terms.

Processor obligations

  • Process only on documented instructions and inform the Controller if an instruction appears to infringe data protection law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see Security).
  • Assist the Controller with data subject requests, security, breach notification and impact assessments.
  • Delete or return all personal data at the end of the services within 30 days of the Controller's instruction, unless law requires retention.
  • Make available the information necessary to demonstrate compliance and allow for audits, on reasonable notice and no more than once a year unless required by a supervisory authority.

Security

Data is hosted in the United Kingdom with encryption in transit and at rest; tenant isolation is enforced at the database layer (row-level security) so one firm can never read another's data; passwordless single-use sign-in links; append-only records for scores and statements; role-based access for the Processor's own staff with an audit trail of administrative actions; and regular backups with point-in-time recovery.

Sub-processors

The Controller gives general authorisation to the sub-processors below. The Processor will give at least 30 days' notice of any intended change, during which the Controller may object on reasonable grounds.

  • Supabase — Database, authentication and file storage — London, United Kingdom (AWS eu-west-2).
  • Vercel — Application hosting and content delivery — EU / UK edge; primary region United Kingdom.
  • Resend — Transactional email (sign-in links, invitations, reports) — United States (SCCs / UK IDTA in place).
  • Plausible Analytics — Cookieless, aggregate website analytics (marketing pages only) — European Union.
  • Sentry — Application error monitoring (marketing pages only, where enabled) — European Union.

International transfers

Platform data is stored in the United Kingdom. Where a sub-processor processes data outside the UK (currently transactional email), transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or an adequacy decision.

Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification duties.

Aggregated statistics

The Controller permits the Processor to derive anonymised, aggregated statistics from engagement data — for example a published financial confidence index or anonymised benchmarks — provided no Controller, client or individual is identifiable and small groups are suppressed. Such statistics are not personal data and fall outside this DPA.

Liability and precedence

Liability under this DPA is subject to the limitations in the Controller's agreement with the Processor. Where this DPA conflicts with that agreement on data protection matters, this DPA prevails.

Steer Financial Ltd is registered in England and Wales, company number TODO-COMPANY-NUMBER. Registered office: TODO Registered office address, United Kingdom.

Data protection enquiries: privacy@wealthsteer.com · ICO registration TODO-ICO-REF