Data processing addendum
Effective 25 September 2026 · Last updated 2 October 2026
This addendum is part of the terms of use (the agreement) between the company or other organisation named in a Philofounder workspace (the customer) and GRANDPOINT LTD, company number 16498233, 50 Princes Street, Ipswich, IP1 1RJ, United Kingdom (GRANDPOINT). It applies whenever GRANDPOINT processes personal data on the customer’s behalf in providing Philofounder. If it conflicts with the agreement on data protection, this addendum prevails. Our privacy policy covers the data we hold as controller, such as sign-in identities and security logs.
1. Definitions
Data protection law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law replacing them. Customer personal data means personal data in the customer’s workspace that GRANDPOINT processes on the customer’s behalf, described in Annex 1; it excludes account data (sign-in identities, memberships, security and activity logs, rate-limit counters, platform logs and HMRC fraud-prevention data), which GRANDPOINT processes as controller under its privacy policy. Sub-processor means a third party GRANDPOINT engages to process customer personal data. Controller, processor, data subject, processing and personal data breach have the meanings in the UK GDPR.
2. Roles and instructions
2.1 The customer is the controller and GRANDPOINT the processor of customer personal data.
2.2 GRANDPOINT processes customer personal data only on the customer’s documented instructions, which are the agreement, this addendum, and the customer’s configuration and use of the service (including connecting accounts, uploading files, asking Philo questions and confirming actions). GRANDPOINT will tell the customer if it believes an instruction infringes data protection law and may decline it.
2.3 GRANDPOINT will not use customer personal data for its own purposes, sell it, use it for advertising, or use it (or allow a sub-processor to use it) to train general artificial intelligence or machine learning models.
2.4 If the law requires GRANDPOINT to process customer personal data other than on instructions, it will tell the customer first unless the law forbids it.
2.5 GRANDPOINT keeps its own records about the service, as controller: for each use of an AI model, the workspace, feature, model, token counts, cost and outcome, used to apply the customer’s AI allowance, cost and run the service and prevent misuse. These records contain no customer content and do not identify the person who made the call, and are kept for thirteen months.
3. The customer’s obligations
3.1 The customer is responsible for having a lawful basis and for giving privacy information to its directors, staff, advisers and the people whose data enters the workspace, including correspondents in a connected mailbox and counterparties in a bank feed.
3.2 The customer warrants that each mailbox, Drive, ledger, bank account and HMRC account it connects belongs to the customer or is one it is entitled to process, and that the person connecting it is authorised to do so.
3.3 The customer will not intentionally upload special category or criminal offence data except where incidental to a business record, and will ask people to remove such data from a CV before upload.
3.4 Where the customer connects Gmail or Google Drive, the customer will not instruct any use of Google user data that the Google API Services User Data Policy (including its Limited Use requirements) prohibits, and GRANDPOINT may refuse such an instruction.
4. Confidentiality
GRANDPOINT ensures that everyone it authorises to process customer personal data is bound by confidentiality. No one at GRANDPOINT reads the content of a connected mailbox unless the customer’s user has agreed to it for a specific support request, it is needed for security, or the law requires it.
5. Security
GRANDPOINT implements the measures in Annex 2 and keeps them appropriate to the risk (UK GDPR Article 32). It may update them provided the overall level of security is not reduced.
6. Sub-processors
6.1 The customer gives general authorisation for the sub-processors listed in Annex 3, which is the published list.
6.2 GRANDPOINT will give at least 30 days’ notice of a new or replacement sub-processor by email to each workspace owner and by updating Annex 3. The customer may object on reasonable data protection grounds within 15 days of the notice; the parties will discuss the objection in good faith and, if it is not resolved, the customer may end the affected part of the service and receive a pro-rata refund of any fees paid in advance for it.
6.3 GRANDPOINT imposes data protection terms on each sub-processor that are, in substance, no less protective than this addendum, and remains responsible to the customer for its sub-processors.
6.4 Providers the customer chooses are not sub-processors: the customer’s own mailbox and Drive provider (Google or Microsoft), its accounting software (for example FreeAgent), its bank and TrueLayer, HMRC, Companies House, and any assistant provider account the customer supplies itself (“bring your own key”). Data sent to or received from them is at the customer’s instruction and under the customer’s own terms with them.
7. Assistance
7.1 Data subject rights. The service lets the workspace owner find, export and delete data. GRANDPOINT will forward any request it receives about customer personal data to the customer within five working days and will otherwise assist the customer, taking into account the nature of the processing.
7.2 Impact assessments. GRANDPOINT will provide reasonable information, including its own data protection impact assessment, to help the customer with impact assessments and any prior consultation with the Information Commissioner.
8. Personal data breaches
8.1 GRANDPOINT will notify the customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting customer personal data, to each workspace owner’s email and to any security contact the customer has given.
8.2 The notice will describe, as far as is known, the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. GRANDPOINT will update the customer as more becomes known. It will not notify the customer’s data subjects or the Information Commissioner on the customer’s behalf without the customer’s agreement, except where the law or a provider’s terms require GRANDPOINT itself to report (for example HMRC’s terms for Making Tax Digital data).
9. Deletion and return
9.1 During the agreement the workspace owner can export all customer personal data (except secrets such as access tokens) and can permanently erase the workspace from Settings. Erasure withdraws connected accounts at the provider where the provider allows it, deletes stored files and logos, deletes every workspace record including its activity log, and deletes the requesting person’s account if they belong to no other workspace.
9.2 On termination the customer may export within 30 days. GRANDPOINT then deletes customer personal data within a further 30 days, except copies in backups, which are overwritten within seven days on the backup schedule and are kept isolated and protected until then, and data the law requires GRANDPOINT to keep.
10. Audits and information
10.1 GRANDPOINT will make available the information necessary to demonstrate compliance with UK GDPR Article 28, including this addendum’s annexes, its register of sub-processors, its data protection impact assessment, and any third-party security report or certification it holds.
10.2 If that information is not enough, the customer, or an independent auditor bound by confidentiality, may audit once in any twelve months on 30 days’ notice, during business hours and at the customer’s cost, unless the audit follows a personal data breach or is required by the Information Commissioner.
11. International transfers
11.1 GRANDPOINT hosts the service in the United Kingdom. Some sub-processors process data outside the UK, as Annex 3 states.
11.2 GRANDPOINT will transfer customer personal data outside the UK only where UK adequacy regulations apply, or under the Information Commissioner’s International Data Transfer Agreement or International Data Transfer Addendum to the EU standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework, with a transfer risk assessment where required.
12. General
12.1 Liability under this addendum is subject to the limits in the agreement; nothing in it limits any liability that cannot be limited by law.
12.2 This addendum lasts as long as GRANDPOINT processes customer personal data.
12.3 It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: Details of processing
- Subject matter and duration
- Providing Philofounder for the term of the agreement and until deletion under clause 9.
- Nature
- Collection through the connections the customer chooses, storage, organisation, retrieval, automated filing, assistant analysis and drafting, notification, export and erasure.
- Purpose
- Helping the customer meet its company law, tax and record-keeping obligations and run its operations.
- Data subjects
- The customer’s directors, officers, persons with significant control, shareholders, founders, staff and advisers; third parties appearing in the customer’s mail, bank transactions, ledger, documents and websites.
- Categories of data
- Identity and contact details; officer and PSC data from the public register; mail sender, subject, date, text and attachments; bank accounts, balances and transactions; ledger balances, bills and invoices; VAT data and VAT numbers; director’s loan entries; CV and professional background; documents, minutes and letters; conversations with Philo.
- Special category data
- Not intended; may occur incidentally in documents, attachments or CVs.
- Frequency
- Continuous; automatic daily monitoring and mail filing once an account is connected.
Annex 2: Security measures
- Hosting in the United Kingdom: the application runs in London and the database is in London.
- Encryption: TLS in transit. Every stored file is encrypted by us with AES-256-GCM before it reaches storage, stored under a random name, and served only after a membership check. Access and refresh tokens for connected accounts are sealed the same way and are never sent to a browser or included in an export.
- Access control: every request is scoped to an active workspace membership. Roles are owner, member and accountant; permanent deletion, disconnection, export and erasure are for owners only; accountants read and cannot connect accounts.
- Database: row-level security is on and the public API roles are revoked on every table, so the only way to the data is through the application.
- Sign-in: single-use links sent to your email, rate limited, with a second step (a passkey or an authenticator app, with recovery codes) required for owners of a workspace that holds real data and available to everyone. A fresh second step within ten minutes is required for permanent deletes, erasure, export, disconnecting an account, removing a member and inviting one. Sessions last seven days, are listed per device, and can be revoked individually or all at once.
- Connected accounts: least-privilege scopes, read-only except Google Drive (copies saved into folders the customer chooses, on request or automatically if the customer turns that on) and the Microsoft 365 calendar (meetings the customer schedules, with invitations sent from the customer’s calendar); PKCE and a signed state bound to the person and the workspace; disconnecting revokes the grant at the provider where the provider allows it.
- The assistant: its tools read workspace data only; its two record-keeping actions ask you first; no tool sends email, makes a payment, submits a filing or deletes data; nothing a browser sends is treated as a tool result; dates and citations are checked against the record.
- Logging: an append-only activity log with actor, role, IP address and browser, which the workspace owner can read.
- Inputs: uploaded files are checked by their content as well as their name, and size limited; any web address you give us is fetched through a filter that cannot reach private networks.
- Development: every change passes type checks, tests (including tests that prove one company cannot read another), a dependency audit and secret scanning before it is deployed.
- Backups: a daily database backup kept for seven days, with a restore procedure that has been tested; a written access-control policy and an incident-response plan with the 72-hour deadlines for telling regulators.
Annex 3: Authorised sub-processors
This list is current as of the effective date above and is updated under clause 6.2.
| Sub-processor | Service | Location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting, serverless functions, encrypted file storage, logs | United Kingdom (London) for the application; storage and logs under the Vercel DPA | UK International Data Transfer Addendum in the Vercel DPA |
| Supabase Pte. Ltd | Database and daily backups | United Kingdom (London) | UK Addendum to the EU standard contractual clauses in the Supabase DPA (support access from Singapore) |
| Plus Five Five, Inc. (Resend) | Sign-in links, invitations and notification email | United States | UK Extension to the EU-US Data Privacy Framework; UK standard contractual clauses |
| Anthropic Ireland, Limited | The Philo assistant, reading documents on your instruction, drafting | United States | UK Addendum to the EU standard contractual clauses in the Anthropic DPA; no training on your content; inputs and outputs deleted within 30 days |
Contact
Data protection questions, rights requests and sub-processor objections go to privacy@grandpoint.uk. Security reports go to security@grandpoint.uk.