NGS CORE

Data Processing Agreement

Last updated: 20 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between NGS CORE Ltd (“Processor”, “we”) and the Customer using NGS CORE (“Controller”, “you”), and applies whenever we process personal data on your behalf as part of the service. It’s written to meet the requirements of Article 28 UK GDPR.

1. Roles

For personal data about your own staff (Users) that you upload or that’s generated through their use of the assistant, you are the Controller and NGS CORE is the Processor. We process this data only on your documented instructions, which are given by configuring and using the service.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the NGS CORE onboarding assistant service.
DurationFor as long as your account is active, plus the retention period described in our Privacy Policy.
Nature of processingStorage, retrieval, and AI-assisted question-answering over uploaded documents.
PurposeTo let your staff get accurate answers to policy questions from your own documentation.

3. Categories of data subjects and personal data

  • Data subjects: your employees who are invited as Users, and any individuals named within uploaded documents.
  • Categories of personal data: names, work contact details, questions and answers, usage information contained within Customer Data, and other personal data contained within documents uploaded by the Customer.

The Service is not designed to require the processing of special category data or criminal offence data. Customers must not intentionally upload such data unless NGS CORE has agreed appropriate safeguards in writing. If such data is nevertheless included in Customer Data, it remains subject to the protections and obligations of this DPA.

4. Sub-processors

You give general authorisation for us to engage the following sub-processors, each bound by data protection obligations equivalent to those set out in this DPA, to the extent applicable to the processing they carry out:

Sub-processorPurposeLocation
OpenAIDocument embeddings, OCR/transcription of uploaded documents, and answer generationUnited States
SupabaseDatabase and file storageEU
ClerkAuthentication and account managementUnited States
StripePayment processingUnited States / Ireland
ResendTransactional email deliveryUnited States
RailwayApplication hosting (background worker)United States / EU
VercelApplication hosting (web app)United States / Global CDN

We remain responsible to you for the performance of our sub-processors’ obligations in relation to the processing of your personal data.

We’ll give you reasonable notice of any intended change to this list so you can object on reasonable and documented data-protection grounds. If we’re unable to provide a commercially reasonable alternative or otherwise resolve your objection within 30 days, either party may terminate the affected service on reasonable written notice. Where a sub-processor’s processing involves a restricted transfer of personal data outside the UK, the transfer will be subject to an appropriate transfer mechanism in accordance with section 8.

5. Processor obligations

We agree to:

  • Process personal data only on your documented instructions
  • Ensure people authorised to process the data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data (see section 7)
  • Delete or return personal data at the end of the relationship, at your choice, subject to legal retention requirements
  • Make available information reasonably necessary to demonstrate compliance with this DPA

We will reasonably assist you, taking into account the nature of the processing and the information available to us, with:

  • responding to requests from data subjects exercising their rights;
  • ensuring compliance with obligations relating to security of processing;
  • notification of personal data breaches to the ICO and, where applicable, communication of breaches to affected individuals;
  • data protection impact assessments; and
  • consultations with the ICO or another supervisory authority where required.

We’ll allow for audits on reasonable notice, during normal business hours, in a way that doesn’t unreasonably disrupt our operations or compromise the confidentiality or security of other customers. Before requesting a full audit, please first consider the security documentation and audit information we make available to Customers on request.

6. Security measures

Data is encrypted in transit and at rest. Access to Customer data is restricted by organisation-scoped access controls enforced both in application logic and at the database level, and administrative access to production systems is limited to those who need it. A more detailed description of our technical and organisational measures, including our current security testing and penetration-testing position, is maintained in a separate Security & Technical Organisational Measures document available to Customers on request.

7. Data breach notification

NGS CORE will notify you without undue delay and, where reasonably practicable, within 24 hours after becoming aware of a personal data breach affecting your data.

That notification will include, to the extent reasonably available to us at the time: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences of the breach; and the measures taken or proposed to address it and mitigate its effects. We’ll provide further information as it becomes available and will reasonably assist you in complying with your own obligations under applicable data protection law, including any obligation to notify the ICO or affected individuals.

8. International transfers

Where processing involves a restricted transfer of your personal data outside the UK, we will ensure that an appropriate transfer mechanism is in place under applicable UK data protection law. Depending on the circumstances, this may include an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism.

9. Liability

Except to the extent otherwise expressly provided in our Terms of Service, liability arising under or in connection with this DPA is subject to the liability provisions in our Terms of Service.

10. Contact

Data protection queries: help@ngs-core.com.