Legal

Data Processing Agreement

Last updated: 13 August 2026

This Data Processing Agreement ("DPA") applies automatically to every customer of MyDirector-OS and forms part of our Terms of Service. No signature is required: it takes effect when you create an account and remains in force for as long as you use the Service. You may download a copy for your own records at any time.

1. Parties and roles

  • Controller - you, the director (or the entity you act for), in respect of the board and company information you upload: minutes, board packs, agendas, resolutions, contact details of fellow directors and officers, and correspondence.
  • Processor - Ian Fordyce Smith trading as MyDirector-OS, a sole trader established in Guernsey, in respect of that content.
  • Separately, we are a controller of your own account data (name, email, authentication records, billing references, security logs). That processing is governed by our Privacy Policy, not by this DPA.

2. Subject matter, duration and nature of processing

We process your content only to provide the Service: storing and displaying directorships, meetings and documents; generating AI reviews, summaries and voice briefs on your instruction; sending calendar and email notifications; producing invoices and board papers; and maintaining audit and security logs. Processing lasts for the term of your account.

3. Categories of data and data subjects

  • Data subjects - you, fellow directors and officers, company secretaries, advisers and other people named in the documents you upload.
  • Personal data - names, roles, business contact details, meeting attendance and conflict disclosures, signature images, and any personal data contained in documents, emails or messages you choose to store.
  • We do not ask for, and ask you not to upload, special category data (health, biometric identification, political opinions) unless it is genuinely necessary for a board matter.

4. Our obligations as processor

  • We process your content only on your documented instructions, which the Service's features constitute.
  • We keep your content confidential and limit access to what is necessary to operate and support the Service.
  • We do not sell your content and we do not use it to train AI models.
  • We assist you, so far as reasonably practicable, with data subject requests, security incidents and data protection impact assessments.
  • We notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your content.

5. Security measures

These are the measures actually in place today:

  • Encryption in transit (TLS 1.3) and at rest (AES-256) at the infrastructure layer.
  • Row-level security enforced on every application table, so records are readable only by their owner.
  • All file storage buckets are private; documents are served through short-lived signed URLs.
  • Optional TOTP two-factor authentication, and re-authentication before password changes.
  • Append-only audit logging of workspace actions, and SHA-256 fingerprinting of signed documents.
  • Automated daily backups held by our hosting provider.
  • Administrative access is limited to the sole trader operating the Service.

6. Where your data is held

The application database, file storage and backups are hosted on Supabase infrastructure running on Amazon Web Services in the eu-central-1 region (Frankfurt, Germany). The web application is delivered through Cloudflare's global edge network, which routes and caches static assets only. Some sub-processors listed below process data outside the EEA; where they do, transfers rely on adequacy decisions, the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.

7. Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, file storage, authentication, backupsAWS eu-central-1 (Frankfurt)
CloudflareApplication delivery, edge compute, DDoS protectionGlobal edge
AI gateway (routing to Google Gemini)AI reviews, summaries, assistant replies, voice briefsEU / US
Paddle.com Market LtdMerchant of Record: payments, subscriptions, invoicesUK / EU
Email delivery providerTransactional and account email, inbound mailboxEU / US

We will give notice through the Service before adding or replacing a sub-processor. If you reasonably object, you may terminate your subscription and export your data.

8. AI processing - what is and is not stored

Model calls are stateless: the AI providers do not retain your prompts or documents for training. However, so the Service works as intended, the following are stored in your own workspace: extracted document text used for search and retrieval, AI review summaries and action points, assistant conversation history you save, and generated audio briefs. Deleting the underlying record deletes these alongside it.

9. Return and deletion

You can export everything we hold in your workspace as a single JSON file at any time from Settings, and you can delete individual records immediately. Deleting your account starts a 30-day grace period, after which your content and files are permanently erased. Audit log entries are retained for the life of the account and are erased with it. Billing records held by Paddle are retained by Paddle for statutory accounting purposes.

10. Audits

MyDirector-OS itself does not hold SOC 2 or ISO 27001 certification. Our infrastructure providers do, and we will supply their current reports or certificates on request, along with written answers to reasonable security questionnaires.

11. Liability and governing law

This DPA is subject to the limitations of liability in our Terms of Service and is governed by the law of the Bailiwick of Guernsey. Where the UK GDPR or EU GDPR applies to your processing, the equivalent obligations under Article 28 of that regime apply to us as processor.

12. Contact

Data protection queries: our contact page. Security reports: security@mydirector-os.com (see security.txt). Supervisory authority: the Office of the Data Protection Authority, Guernsey.