Data Processing Addendum

Data Processing Addendum

Data Processing Addendum

Effective Date: 9 May 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Full-Tilt Computing Limited, trading as True Holder (“Processor”, “we”) and the customer (“Controller”, “you”) and applies to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Service. Capitalised terms not defined here have the meanings set out in UK GDPR and the Data Protection Act 2018.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Full-Tilt Computing Limited, trading as True Holder (“Processor”, “we”) and the customer (“Controller”, “you”) and applies to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Service. Capitalised terms not defined here have the meanings set out in UK GDPR and the Data Protection Act 2018.

1. Roles and scope

1. Roles and scope

For the purposes of UK GDPR, Controller determines the purposes and means of the processing of Personal Data within the customer’s account; Processor processes Personal Data on Controller’s documented instructions. Where the EU GDPR applies, the corresponding roles under that regulation apply.

For the purposes of UK GDPR, Controller determines the purposes and means of the processing of Personal Data within the customer’s account; Processor processes Personal Data on Controller’s documented instructions. Where the EU GDPR applies, the corresponding roles under that regulation apply.

2. Subject-matter, duration, nature and purpose

2. Subject-matter, duration, nature and purpose

Subject-matter: provision of the True Holder family-office software-as-a-service. Duration: the term of the Service plus any retention period set out in the Privacy Policy or required by law. Nature and purpose: hosting, storing, organising, transmitting and otherwise processing Personal Data so that Controller and its authorised users can manage entities, ownership, family members, valuations, KYC documents, dividends, succession plans and related records. Categories of data subjects: Controller’s authorised users, family members and beneficial owners, advisors, officers, counterparties, and other individuals whose details Controller chooses to record. Categories of Personal Data: identification data (name, date of birth, nationality, address, contact details), images and copies of identity documents, financial data (holdings, valuations, dividends, loans, remuneration), employment data, family relationships, and free-text notes Controller may upload.

Subject-matter: provision of the True Holder family-office software-as-a-service. Duration: the term of the Service plus any retention period set out in the Privacy Policy or required by law. Nature and purpose: hosting, storing, organising, transmitting and otherwise processing Personal Data so that Controller and its authorised users can manage entities, ownership, family members, valuations, KYC documents, dividends, succession plans and related records. Categories of data subjects: Controller’s authorised users, family members and beneficial owners, advisors, officers, counterparties, and other individuals whose details Controller chooses to record. Categories of Personal Data: identification data (name, date of birth, nationality, address, contact details), images and copies of identity documents, financial data (holdings, valuations, dividends, loans, remuneration), employment data, family relationships, and free-text notes Controller may upload.

3. Processor obligations

3. Processor obligations

Processor will: (a) process Personal Data only on documented instructions from Controller, including with regard to international transfers, except where required by law (in which case Processor will, where lawful, inform Controller); (b) ensure that persons authorised to process Personal Data are bound by confidentiality; (c) implement appropriate technical and organisational measures (see Section 6); (d) assist Controller, taking into account the nature of processing, in responding to data-subject requests and complying with Articles 32–36 UK GDPR; (e) at Controller’s choice, delete or return all Personal Data after the end of the Service, save to the extent retention is required by law.

Processor will: (a) process Personal Data only on documented instructions from Controller, including with regard to international transfers, except where required by law (in which case Processor will, where lawful, inform Controller); (b) ensure that persons authorised to process Personal Data are bound by confidentiality; (c) implement appropriate technical and organisational measures (see Section 6); (d) assist Controller, taking into account the nature of processing, in responding to data-subject requests and complying with Articles 32–36 UK GDPR; (e) at Controller’s choice, delete or return all Personal Data after the end of the Service, save to the extent retention is required by law.

4. Sub-processors

4. Sub-processors

Controller authorises Processor to engage sub-processors to deliver the Service. The current list of sub-processors includes: Supabase (database, authentication, storage, edge compute), Resend (transactional email), and Lovable (development infrastructure / AI gateway). Processor will impose data-protection obligations on sub-processors that are no less protective than those in this DPA. Processor will give reasonable prior notice of new sub-processors and Controller may object on reasonable data-protection grounds; if the parties cannot agree a resolution, Controller may terminate the affected portion of the Service.

Controller authorises Processor to engage sub-processors to deliver the Service. The current list of sub-processors includes: Supabase (database, authentication, storage, edge compute), Resend (transactional email), and Lovable (development infrastructure / AI gateway). Processor will impose data-protection obligations on sub-processors that are no less protective than those in this DPA. Processor will give reasonable prior notice of new sub-processors and Controller may object on reasonable data-protection grounds; if the parties cannot agree a resolution, Controller may terminate the affected portion of the Service.

5. International transfers

5. International transfers

Where Processor or its sub-processors transfer Personal Data outside the UK or EEA, the transfer will be made under an appropriate transfer mechanism, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, supplemented where necessary by additional safeguards.

Where Processor or its sub-processors transfer Personal Data outside the UK or EEA, the transfer will be made under an appropriate transfer mechanism, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, supplemented where necessary by additional safeguards.

6. Security measures

6. Security measures

Processor maintains technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access, including: encryption in transit (TLS 1.2+); encryption at rest of database backups and object storage; row-level security tenant isolation; least-privilege access controls; audit logging; secret management; security testing of code prior to release; incident response procedures; and supplier due diligence.

Processor maintains technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access, including: encryption in transit (TLS 1.2+); encryption at rest of database backups and object storage; row-level security tenant isolation; least-privilege access controls; audit logging; secret management; security testing of code prior to release; incident response procedures; and supplier due diligence.

7. Personal Data breach notification

7. Personal Data breach notification

Processor will notify Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Controller’s data, providing the information required to enable Controller to meet its own obligations under Article 33 UK GDPR.

Processor will notify Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Controller’s data, providing the information required to enable Controller to meet its own obligations under Article 33 UK GDPR.

8. Audits

8. Audits

Processor will make available to Controller, on reasonable written request and subject to confidentiality, the information necessary to demonstrate compliance with this DPA, including third-party audit reports where available. On-site audits are permitted no more than once per twelve-month period, on at least 30 days’ notice, during business hours, and at Controller’s cost (save where the audit reveals material non-compliance).

Processor will make available to Controller, on reasonable written request and subject to confidentiality, the information necessary to demonstrate compliance with this DPA, including third-party audit reports where available. On-site audits are permitted no more than once per twelve-month period, on at least 30 days’ notice, during business hours, and at Controller’s cost (save where the audit reveals material non-compliance).

9. Liability and conflicts

9. Liability and conflicts

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in relation to Personal Data, this DPA prevails.

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in relation to Personal Data, this DPA prevails.

10. Contact

10. Contact

Data-protection enquiries: privacy@trueholder.org. To execute a counter-signed copy of this DPA, contact legal@trueholder.org.

Data-protection enquiries: privacy@trueholder.org. To execute a counter-signed copy of this DPA, contact legal@trueholder.org.