Back to the Suite terms

Data Processing Agreement

The Suite keeps one record of each of your clients, built from the apps you use. This is what we hold, where it sits, who else touches it and how to get rid of it.

Ascendz Digital LimitedEffective 5 September 2026
Clause 1.0

Who this is between

This agreement is between Ascendz Digital Limited, registered in England and Wales with company number 17079053, whose registered office is Tudor House, Newport Road, Eccleshall ST21 6BG (“Ascendz”, “we”) and you, the member of The Suite.

It forms part of the Suite terms and takes precedence over them on anything to do with your clients’ personal data.

It is about a different set of people from the rest of our terms. Everywhere else, the person we hold information about is you. Here it is your clients.

Clause 2.0

Your clients’ information is yours

You are the data controller. We are your processor. You decide what goes in and what comes out; we hold it so your apps can agree about who somebody is and for no other reason.

We will never:

  • sell it, or give it to anyone outside the list in Annex C;
  • use it to train an artificial intelligence model;
  • contact your clients ourselves;
  • look at it, except where you have asked us for help and we need to.

Information about you is different: your name, your address, what you have paid. We are the controller of that and it is covered by our general terms rather than by this page.

Clause 3.0

What we process and why

Annex A lists exactly what is held. In short: who somebody is, how to reach them, which of your apps has met them, where they sit in your pipeline and a dated history of what has happened.

We process it to store, organise and show it back to you. Nothing else. It lasts as long as your membership, plus the deletion period in clause 11.

The apps send us what happened, not what was in it. A support ticket tells us that a ticket was opened and what it was called. It does not send us the conversation inside it.

Clause 4.0

Your instructions

We process only on your instructions. Using the product is an instruction. This page is an instruction. Anything else needs to be in writing.

You choose what feeds in. For every app you decide whether it may add new people, whether its activity is shown at all and whether it may move somebody along your pipeline. Turning something off stops it being recorded from that point.

If we think an instruction breaks UK data protection law we will tell you and we may pause that part until it is sorted out.

Clause 5.0

What we ask of you

Only put people into The Suite that you are entitled to hold information about and make sure they have been told what the law requires.

This matters most when you import a file. A list you bought, or one you have not touched in five years, is not something we can make lawful on your behalf.

Clause 6.0

How it is kept

Annex B is the full list. The short version:

  • Encrypted in transit and at rest.
  • Nothing reaches your clients’ records from a browser. Row level security is on, with no policy granting access to anyone but our server.
  • Every query is scoped to one member. Nobody can read another member’s clients.
  • Each connected app has its own credential and only a hash of it is stored. A copy of our database does not let anyone write to it.

What we do not have. We hold no SOC 2 or ISO 27001 certification, we have not commissioned an independent penetration test and we do not operate a formal information security management system. We would rather say so than imply otherwise. Annex B is honest about the rest.

Clause 7.0

Who else touches it

You give general authorisation for the sub-processors in Annex C. Each is bound by obligations no less protective than these.

We will email you at least 30 days before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may end your membership of The Suite.

Clause 8.0

Where it is held

Your clients’ records are stored in West Europe (London), in the United Kingdom.

Where any personal data is transferred outside the UK, we rely on the safeguards UK GDPR requires, which may include the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with each supplier’s own data protection terms. Ask us at clientsupport@ascendz.co for the specifics.

Note the difference from our other products. Some of them send content to AI providers in the United States. The Suite’s client record does not: nothing in it is sent to an AI provider.

Clause 9.0

When one of your clients asks

They are your clients, so you answer them. We will help and most requests need no help from us: the record shows you everything held about a person on one page and deleting them deletes their history with them.

If one of your clients writes to us directly we will not answer them substantively. We will point them at you and let you know they were in touch.

Clause 10.0

If something goes wrong

We will tell you about a personal data breach affecting your clients without undue delay and in any event within 24 hours of becoming aware of it. We will tell you what we know, what we are doing and what we think you should do.

Reporting to the ICO and to the people affected is yours to do, because you are the controller. We will give you what you need to do it.

Clause 11.0

Deleting it

One client. Deleting a contact deletes their record, their whole history, any testimonial they gave and any reminder about them. It happens immediately and cannot be undone.

All of it. When your membership ends we delete your clients’ personal data within 30 days. Ask before then and we will export it to you first.

Backups expire on their own cycle. We will not restore deleted data from one except to recover from an incident.

Clause 12.0

Checking we are doing this

We will give you the information reasonably needed to show we are meeting this agreement. To protect other members’ confidentiality that will normally be documentation and written answers.

An on-site inspection is limited to once a year, on reasonable notice, in business hours, unless a regulator requires otherwise or a breach has happened.

Clause 13.0

How this sits with the products

Zenitro, Relavo, Kestry, Advoro and Draftd are each sold on their own and each has its own data processing agreement. Those cover what happens inside each product.

This one covers the shared client record in The Suite: the copy of who your clients are, assembled from those apps. Where the two overlap, the product’s own agreement governs what that product does and this one governs what The Suite does with what it is told.

Ending your Suite membership does not delete anything held inside a product you keep using. Ending a product does not delete what The Suite has already recorded. Both are deleted on request.

Clause 14.0

Liability and law

Liability is subject to the limits in the Suite terms.

This agreement is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction.

Annex A

Annex A · What is held

Whose information

Your leads, your current and former clients, your referral partners and anybody who gets in touch with you through an app in The Suite.

Who they are
Name and the business they work for.
How to reach them
Email address and a phone number if you have one.
Their relationship to you
Which of your apps has met them, where they sit in your pipeline and who referred them.
What has happened
A dated history: quizzes and scores, conversations, proposals and their values, invoices and payments, support tickets, notes you write and reminders you set.
Testimonials
What a client wrote, any rating they gave and the permission they chose for how it may be used.
Free text
Notes you write and anything an app chooses to include when it tells us something happened.

Special category data. We do not ask for it and no field is designed to hold it. You can type it into a note and if you do, the extra conditions the law attaches are yours to meet.

The Suite is sold to businesses and is not intended for holding information about children.

Annex B

Annex B · Security measures

What is in place

In transit
TLS on every connection, to the site and to the database.
At rest
Encrypted at rest by the database provider.
Isolation
Row level security is on for every table holding your clients’ data, with no policy for anonymous or ordinary signed-in roles. Only our server can read them.
Scoping
Every query is limited to a single member. One member cannot read another’s clients.
App credentials
One token per app, stored only as a SHA-256 hash and revocable individually.
Sign-in to an app
Tokens that identify you to an app are signed, expire in ninety seconds, are bound to one app and pin their signing algorithm.
Links
Any web address an app sends is checked before it is ever shown, so a connected app cannot inject a script into your record.
Deletion
Removing a member removes every contact, event, testimonial and reminder with them. There is no orphaned copy.
Access
Administrative access is limited to named individuals at Ascendz and granted only where it is needed to run or support the service.

What is not

  • No SOC 2, ISO 27001 or equivalent certification.
  • No independent penetration test has been carried out.
  • No formal information security management system.
  • No customer-managed encryption keys.
  • Audit logging is limited to what our providers record as standard.
Annex C

Annex C · Sub-processors

Supabase
Database, file storage and sign-in. Holds everything in Annex A. West Europe (London), United Kingdom.
Railway
Runs the application. Handles everything in Annex A in transit and in memory and stores none of it.
Resend
Sends email to you. Handles your address, not your clients’.
Stripe
Takes payment from you. Handles your billing information, not your clients’.

No AI provider appears on this listand none receives anything from your client record. If that ever changes we will tell you thirty days beforehand under clause 7.

Questions about any of this go to clientsupport@ascendz.coand reach a person rather than a queue.