Legal
Data Processing Agreement
Last updated 16 August 2026.
Recovery Agent is a trading name and product of Proja AI Ltd, Company No. 16963746, registered in England and Wales ("we", "us"). These terms apply to the Recovery Agent platform and services.
1. Roles
For customer records processed under an engagement, the customer is the controller and Proja AI Ltd is the processor. This document forms part of the engagement terms.
2. Subject matter and duration
Processing is limited to the delivery of the agreed recovery engagement and continues for the engagement term plus any agreed retention period.
3. Nature and purpose
Ingestion, validation, analysis, evidence linking, case preparation, controlled counterparty engagement, reporting and audit logging.
4. Categories of data and data subjects
Business contact details of customer personnel, supplier and counterparty personnel, and any personal data incidentally contained in transactional records, correspondence, site records or evidence supplied by the customer. Special category data is not requested and should not be supplied.
5. Processor obligations
We process only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist with data subject requests, security incidents and impact assessments; and delete or return data at the end of the engagement.
We do not use customer data to train public models, do not use one customer's data for another, and do not create cross-customer benchmarks without explicit rights and effective anonymisation.
6. Sub-processors
We engage sub-processors for hosting, database, storage, transactional email and model inference under written terms no less protective than these. A current list is provided on request, and we give notice of intended changes so the customer may object.
7. Security measures
Tenant separation, row-level security, private storage with segregated paths, expiring signed URLs, encryption in transit and at rest, multi-factor authentication for privileged users, session timeouts, least-privilege access and append-only audit logging.
8. Transfers and audit
Transfers outside the UK rely on adequacy or the UK International Data Transfer Addendum. The customer may audit compliance on reasonable notice, subject to confidentiality and the security of other customers' data.