Data Processing Agreement
Last updated: 29 July 2026
1. Introduction and scope
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, our Terms of Service between LBG Technology Group Ltd, trading as Renzo (“Renzo”, “we”, “us”) and the customer identified in the account (“you”). It applies whenever you use the Renzo platform (the “Service”) to process personal data relating to your own clients, their employees, or other individuals, and it reflects the requirements of Article 28 of the UK GDPR.
For that data, you are the controller (or, where you act for your own clients, a processor) and Renzo is your processor. Our Privacy Policy describes, separately, the data we collect as a controller in our own right (for example your account and billing details).
2. Details of the processing
- Subject matter and duration: the hosting and processing of Customer Data within the Service for the duration of your subscription, plus the wind-down period described in section 9.
- Nature and purpose: providing HR consultancy workspace features - client and client-work management, time tracking, documents, calendar and communications integrations, invoicing, reporting, and AI-assisted drafting - as configured and instructed by you through the Service.
- Categories of data subjects:your workspace users, your clients’ contacts, and employees or workers of your clients whose matters you manage in the Service.
- Types of personal data: contact and employment details, case and matter records, documents you upload, communications you sync, and related notes. HR case work may include special-category data (for example health information in welfare or absence cases) where you choose to record it.
3. Our obligations as processor
We will:
- process Customer Data only on your documented instructions (including as given through your use and configuration of the Service), unless required otherwise by law, in which case we will inform you unless prohibited;
- ensure that personnel with access to Customer Data are bound by confidentiality obligations;
- implement and maintain the technical and organisational measures described in section 7;
- assist you, taking into account the nature of the processing, in responding to data subject rights requests and in meeting your obligations under Articles 32 to 36 of the UK GDPR;
- notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, with sufficient information for you to meet your own notification obligations;
- delete or return Customer Data at the end of the agreement as described in section 9; and
- make available the information reasonably necessary to demonstrate compliance with this DPA, as described in section 10.
4. Your obligations as controller
You are responsible for the lawfulness of the personal data you process through the Service: having a lawful basis (and, for special-category data, an Article 9 condition), providing privacy information to your own clients and their employees, honouring their rights, and ensuring your instructions to us comply with data protection law. You are also responsible for the connected services you choose to authorise (section 5) and for managing access within your own workspace.
5. Sub-processors
You give general written authorisation for us to use the following sub-processors to provide the Service:
- Supabase - database, authentication, and file storage;
- Vercel - application hosting and delivery;
- Stripe - subscription billing and payments;
- Resend - transactional and (where you enable the outreach add-on) marketing email delivery;
- Anthropic - AI-assisted drafting features, only on the content you submit to those features.
In addition, the following connected services and lookups process data when - and only when - you or your Authorised Users choose to connect or use them. Each connection is authorised by you, exchanges data with the provider directly, is governed by your agreement with that provider, and can be disconnected by you at any time:
- Microsoft 365 - Outlook mailbox and calendar sync, and OneDrive / SharePoint file access;
- Google - Gmail mailbox sync (Google Drive file linking coming soon);
- Dropbox - file linking (coming soon);
- Xero and QuickBooks (Intuit) - accounting invoice sync (coming soon);
- Companies House - a public-register lookup when you use the company-search field while adding a client.
We will give you notice by email of any intended addition or replacement of a sub-processor, and you may object on reasonable data protection grounds. Each sub-processor is bound by data protection obligations materially equivalent to this DPA, and we remain responsible to you for their performance.
6. International transfers
Where a sub-processor processes personal data outside the UK or EEA, the transfer is protected by a recognised safeguard - a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses as applicable - under our agreement with that sub-processor.
7. Security measures
We apply the following technical and organisational measures (Article 32), reviewed and updated to reflect evolving risk:
- Encryption of personal data in transit using TLS, and encryption at rest for the database and file storage, provided by our infrastructure providers.
- OAuth tokens for all connected integrations encrypted at rest using AES-256-GCM before storage.
- Logical separation of each customer’s data in the multi-tenant environment: every request is bound to the authenticated tenant context and all data access is scoped to that tenant in the application layer, reinforced by database row-level security.
- Role-based access controls on a least-privilege basis. Administrative access is protected by multi-factor authentication, IP allow-listing, and step-up re-authentication for sensitive actions. Access to underlying infrastructure is restricted to authorised personnel.
- Multi-factor authentication required for all tenant users; rate limiting on repeated failed sign-ins; secure session management using HTTP-only cookies, with a 30-minute inactivity timeout applied by default (individual users may adjust or disable this in their personal settings).
- Audit logging of meaningful administrative and data-changing actions - including exports, deletions, and role or permission changes - in an append-only log retained for up to 7 years, in line with UK statutory retention for HR-related records.
- Recoverable soft-deletion with a grace period, followed by secure erasure of personal data. Right-to-erasure requests are fulfilled by anonymising or deleting the relevant records, with the action recorded in the audit log.
- Logging of application errors and events with administrative dashboards for health and incident tracking, and a documented incident-response process.
- Encrypted backups: the hosting provider’s automated daily backups with point-in-time recovery, plus an independent AES-256-encrypted daily backup on a 90-day rolling cycle, with documented recovery procedures.
- Automated dependency vulnerability scanning and a continuous-integration security gate that fails on high-severity issues in production dependencies, with security review of significant new features.
- Use of reputable infrastructure providers holding recognised security certifications such as ISO 27001 and SOC 2.
8. Data subject requests
If a data subject contacts us directly about data you control, we will not respond substantively but will refer them to you and notify you without undue delay. The Service’s export, correction, and deletion tools are the primary means by which we assist you in honouring data subject rights.
9. Deletion and return
On termination or expiry of your subscription you may export Customer Data from the Service for 30 days, after which we will delete it in line with our retention policy, unless retention is required by law. Deletion follows the soft-deletion and secure-erasure process described in section 7.
10. Audit and information
On written request, no more than once per year unless required by a supervisory authority or following a personal data breach, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security measures and relevant certifications of our sub-processors. Where this does not reasonably satisfy your obligations, we will discuss the scope and cost of any further audit with you in good faith.
11. Precedence and changes
If there is a conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails. Liability arising under or in connection with this DPA is subject to the exclusions and cap set out in clause 11 of the Terms of Service. We may update this DPA from time to time; the “last updated” date above reflects the most recent version, and material changes will be communicated by email to your workspace Owner where possible.
12. Contact
For any questions about this DPA, please contact:
LBG Technology Group Ltd t/a Renzo
Registered in England & Wales, company no. 17295467
Registered office: 82A James Carter Road, Mildenhall, IP28 7DE
Email: hello@renzohr.com
