Data Processing Summary
/data-processing·Effective from: [go-live date]·Version 0.1 (draft)
This document is written for people who need a plain-English answer to “where does our data actually live, and who touches it?” — trustee co-directors, professional-indemnity insurers, corporate clients doing their own due diligence, and internal auditors. It is a summary; the full processor contracts are held with the CRM change file and are available on request.
4.1 Roles
| Data controller | Acer Prime Law Limited, in respect of matter, party and CRM-user data. |
|---|---|
| Joint controller | Premier Trust Corporation Ltd, in respect of data held about beneficiaries and third parties of the trusts it acts as trustee for. |
| Processors (see 4.4) | Supabase Inc., Vercel Inc., Resend Inc., Deepgram Inc. |
| DPO / privacy contact | Alan McAloon (interim). privacy@acerprimelaw.co.uk. |
4.2 What data lives where
| Data set | Where it is stored | How long | Who can see it |
|---|---|---|---|
| Log-in credentials & session tokens | Supabase Auth (EU-region project) | Session lifetime + 90-day audit | Automated access only; developers via masked logs |
| User profiles (name, role, tenancy) | Supabase Postgres (EU region) | Life of engagement + 12 months | Firm administrators only |
| Trust register & party dossiers | Supabase Postgres (EU region) | Life of trust + 12 years | Users in the same tenancy, subject to role checks |
| Trust ledger entries & fee notes | Supabase Postgres (EU region) | Life of trust + 12 years (audit); 7 years post-close for fee history | Users in the same tenancy |
| KYC / identity documents | Supabase Storage, encrypted | 5 years from end of business relationship (MLR 2017) | Fee earners and MLRO |
| Attendance notes & voice recordings | Supabase Storage / Postgres | Life of matter + 7 years | Users in the same tenancy |
| Voice transcriptions (raw) | Deepgram (temporary — see 4.4) | Discarded after transcription returns | None once returned |
| Outbound emails (transactional) | Resend (delivery logs) | 30 days delivery logs | Firm administrators via Resend dashboard |
| CRM code, images, static assets | Vercel edge network | Life of deployment | Public HTTPS |
| Backup snapshots | Supabase managed backups (EU region) | 7-day point-in-time recovery (Pro tier); monthly cold archives 12 months | Restricted admin access with 4-eyes control |
| Audit log | Supabase Postgres (EU region), append-only | Life of trust + 12 years | Firm partners and auditor |
4.3 Encryption and key management
- Data is encrypted in transit using TLS 1.2 or higher.
- Data is encrypted at rest by Supabase using AES-256, with keys held in Supabase’s managed KMS.
- Sensitive columns (NI number, passport number) are also encrypted at the column level using pgsodium.
- Application-layer secrets (service-role keys, API tokens) are stored only in Vercel encrypted environment variables. They are never exposed to the browser.
4.4 Sub-processors
| Sub-processor | What they do | Where hosted | Transfer safeguards |
|---|---|---|---|
| Supabase Inc. | Postgres database, authentication, object storage, backups | Europe (Ireland/Frankfurt) region | UK-EU Adequacy Regulations; SCCs + UK IDTA for US corporate access |
| Vercel Inc. | Static hosting, edge functions, DNS | Global CDN with EU-preferred region | SCCs + UK IDTA; no client data is stored on Vercel — only application code and public assets |
| Resend Inc. | Transactional email (magic-link log-in, alerts, fee-note delivery) | US region | SCCs + UK IDTA; content limited to notification body and recipient email |
| Deepgram Inc. | Voice-to-text transcription (triggered by fee earner) | US region | SCCs + UK IDTA; audio deleted from Deepgram after transcription is returned |
We will update the sub-processor list here before adding any new sub-processor that touches client data. Trustees or clients who want to be notified in advance can subscribe by emailing privacy@acerprimelaw.co.uk.
4.5 Access model inside the CRM
- Every table is protected by row-level security keyed on the tenancy of the logged-in user.
- Roles are: org_admin (Acer Prime Law — user administration only, no client data), manager, director, trust_officer and mlro. Each role has explicit write permissions.
- Directors and MLRO are the only roles who can approve CDD.
- Every write is captured in an append-only audit log with actor, timestamp, tenancy and record identifier.
- Firm partners can review the audit log; auditors are given read-only access to the tables they need.
4.6 Backup and disaster recovery
- Supabase performs daily automated backups (point-in-time recovery to any minute within 7 days on the Pro tier we operate).
- We take a manual monthly cold snapshot and store the encrypted export on Acer Prime Law-controlled storage.
- Recovery Time Objective (RTO): 4 hours for a full-service restore; Recovery Point Objective (RPO): 1 hour.
- We rehearse a restore-to-scratch at least once every twelve months and document the result.
4.7 Breach notification
- Any suspected personal-data breach is reported to Alan McAloon within 24 hours of detection.
- We assess risk to individuals within 48 hours.
- If the risk threshold is met, we notify the ICO within 72 hours of becoming aware, and affected individuals without undue delay.
4.8 Right to inspect
Trustee co-directors, professional-indemnity insurers and clients whose data lives inside the CRM may ask to inspect: (a) the current sub-processor list, (b) a summary of security controls, (c) the most recent restore-rehearsal log, and (d) our data-retention schedule. Email privacy@acerprimelaw.co.uk to arrange. We will normally respond within ten working days.
4.9 Deletion on request
Where we no longer have a lawful reason to hold your data, we will delete it. Deletion is soft-first (the record is hidden and access-locked) and hard-purged after our next retention review, subject to any legal-hold obligation.
