WealthSteer · last updated 19 August 2026

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the agreement between Steer Financial Ltd ("the Processor") and each advice firm using WealthSteer ("the Controller"). It sets out the terms on which the Processor processes personal data on the Controller's behalf, as required by Article 28 UK GDPR. A signed copy is available on request to privacy@wealthsteer.com.

Roles and scope

The Controller determines the purposes and means of processing its clients' personal data. The Processor processes that data only to provide the WealthSteer services and only on the Controller's documented instructions, which include the functionality the Controller uses and configures in the products.

Nature of the processing

Processor obligations

Security

Data is hosted in the United Kingdom with encryption in transit and at rest; tenant isolation is enforced at the database layer (row-level security) so one firm can never read another's data; passwordless single-use sign-in links; append-only records for scores and statements; role-based access for the Processor's own staff with an audit trail of administrative actions; and regular backups with point-in-time recovery.

Sub-processors

The Controller gives general authorisation to the sub-processors below. The Processor will give at least 30 days' notice of any intended change, during which the Controller may object on reasonable grounds.

International transfers

Platform data is stored in the United Kingdom. Where a sub-processor processes data outside the UK (currently transactional email), transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or an adequacy decision.

Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification duties.

Aggregated statistics

The Controller permits the Processor to derive anonymised, aggregated statistics from engagement data — for example a published financial confidence index or anonymised benchmarks — provided no Controller, client or individual is identifiable and small groups are suppressed. Such statistics are not personal data and fall outside this DPA.

Liability and precedence

Liability under this DPA is subject to the limitations in the Controller's agreement with the Processor. Where this DPA conflicts with that agreement on data protection matters, this DPA prevails.