Skip to content

Legal

Data Processing Agreement

Last updated 16 August 2026.

Recovery Agent is a trading name and product of Proja AI Ltd, Company No. 16963746, registered in England and Wales ("we", "us"). These terms apply to the Recovery Agent platform and services.

1. Roles

For customer records processed under an engagement, the customer is the controller and Proja AI Ltd is the processor. This document forms part of the engagement terms.

2. Subject matter and duration

Processing is limited to the delivery of the agreed recovery engagement and continues for the engagement term plus any agreed retention period.

3. Nature and purpose

Ingestion, validation, analysis, evidence linking, case preparation, controlled counterparty engagement, reporting and audit logging.

4. Categories of data and data subjects

Business contact details of customer personnel, supplier and counterparty personnel, and any personal data incidentally contained in transactional records, correspondence, site records or evidence supplied by the customer. Special category data is not requested and should not be supplied.

5. Processor obligations

We process only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist with data subject requests, security incidents and impact assessments; and delete or return data at the end of the engagement.

We do not use customer data to train public models, do not use one customer's data for another, and do not create cross-customer benchmarks without explicit rights and effective anonymisation.

6. Sub-processors

We engage sub-processors for hosting, database, storage, transactional email and model inference under written terms no less protective than these. A current list is provided on request, and we give notice of intended changes so the customer may object.

7. Security measures

Tenant separation, row-level security, private storage with segregated paths, expiring signed URLs, encryption in transit and at rest, multi-factor authentication for privileged users, session timeouts, least-privilege access and append-only audit logging.

8. Transfers and audit

Transfers outside the UK rely on adequacy or the UK International Data Transfer Addendum. The customer may audit compliance on reasonable notice, subject to confidentiality and the security of other customers' data.

Questions about this document can be sent to legal@recoveryagent.co.uk.