Skip to content
SAR Portal
Received a DSAR? How It Works Features Pricing
Small Business
Restaurants & Hospitality Retail & E-commerce Professional Services
Mid-Size Business
Healthcare & Clinics Childcare & Education Financial Services Brokers & Intermediaries Property & Real Estate SaaS & Technology Recruitment Agencies
Enterprise
Enterprise Solutions
Docs Contact Sign Up Free Login

Quick links:

DSAR Response Guide DSAR Checklist Redaction Guide Documentation Pricing Sign Up
Press Esc to close

Data Processing Agreement

Last Updated: May 2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between SAR Portal (powered by Sekhon IT Consultants Ltd.) (“Processor”, “we”, “us”) and the customer (“Controller”, “you”) using our Service.

Processor Details:

  • Legal Name: Sekhon IT Consultants Ltd. (trading as SAR Portal)
  • Company Registration: Ireland
  • Registered Address: 1 Beaufield Crescent, Maynooth, Co. Kildare, Republic of Ireland
  • Data Protection Officer: dpo@sarportal.com

This DPA governs the processing of personal data by SAR Portal on behalf of the Controller in accordance with GDPR (Regulation (EU) 2016/679).

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data
  • Data Subject: The individual whose personal data is processed
  • Sub-processor: Third parties engaged by SAR Portal to process personal data
  • Data Breach: Security incident leading to unauthorized access, loss, or disclosure of personal data

3. Scope and Purpose

3.1 Subject Matter

SAR Portal processes personal data on behalf of the Controller for the purpose of providing DSAR management services.

3.2 Categories of Data Subjects

  • Data subjects submitting DSARs
  • Employees and staff of the Controller
  • Third parties mentioned in documents

3.3 Categories of Personal Data

  • Contact information (names, email addresses, phone numbers)
  • Documents uploaded by the Controller
  • Case notes and communications
  • Identity verification data

3.4 Duration

Processing continues for the duration of the subscription agreement plus data retention periods specified in our Terms.

4. Processor Obligations

SAR Portal agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure staff are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to data subject rights requests
  • Support the Controller in meeting GDPR obligations (security, breach notification, DPIAs)
  • Delete or return all personal data at the end of the service relationship
  • Make available information necessary to demonstrate compliance

4.1 Scope of Instructions

The Controller’s documented instructions are limited to:

  • Configuration of the Service via the user interface
  • Requests submitted via our support channels
  • Instructions documented in this DPA

SAR Portal is not obligated to follow instructions that would violate GDPR or other applicable laws. We will promptly notify the Controller if we believe an instruction infringes data protection law.

5. Sub-processors

5.1 Authorized Sub-processors

The Controller authorizes the use of the following sub-processors:

Sub-processorPurposeLocationDPA in Place
Microsoft Azure (Cosmos DB, Blob Storage)Data storageEEA — West Europe (Netherlands)Yes
Microsoft Azure Entra External IDAuthenticationEEA — West EuropeYes
Azure OpenAI ServiceAI features (not used for training)EEA — Sweden CentralYes
Azure AI Document IntelligencePDF text extractionEEA — Sweden CentralYes
Azure AI Language ServicePII entity detection (no data retained)EEA — Sweden CentralYes
Microsoft Graph APIUser provisioning (email + display name for invitations)Global (covered by Microsoft SCCs)Yes
Stripe (Stripe Payments Europe)Billing and payments (no card data held by us)EEA — Ireland / NetherlandsYes
Twilio SendGridEmail delivery (EU SMTP endpoint)EEAYes
Google reCAPTCHA EnterpriseBot protection (browser signals only, no case data)Global (Enterprise DPA)Yes

5.1.1 Development Tooling Sub-Processors

Customer production data and personal data are prohibited from general development assistants, coding tools and non-production AI services. Technical and organisational controls enforce separation between production data and non-production development environments.

Where AI assistance is applied to production personal data for occasional operational or support purposes, it is confined to the EU-resident, Article 28-governed service listed below, which processes data within the EEA with no international transfer. This is treated as a sub-processor with documented instructions, not as routine development.

Sub-processorPurposeLocationTransfer BasisDPA in Place
Anthropic, Inc. (via Microsoft Azure AI Foundry)EU-resident AI assistance for occasional operational or support tasks that may involve production data, under documented instructionsEEA — Sweden CentralAzure DPA Article 28; EU data residency (no international transfer)Yes

A separate US-based development assistant (Anthropic, Inc. — Max plan) is used for development, documentation and other non-production work only. It does not process customer personal data and is therefore not a sub-processor of customer data; production personal data and credentials are withheld from it by enforced technical access controls.

5.2 Changes to Sub-processors

We will notify the Controller 30 days before adding new sub-processors. The Controller may object within 14 days.

6. Security Measures

SAR Portal implements the following technical and organisational measures:

  • Encryption at rest (AES-256) and in transit (TLS 1.2+, HTTPS enforced with HSTS)
  • Authentication via Azure Entra External ID (OAuth 2.0 / OpenID Connect) with MFA support
  • Role-based access control (RBAC) with four defined roles (Admin, Case Manager, Reviewer, Read Only)
  • Secrets management via Azure Key Vault
  • Multi-tenant data isolation at the database level
  • Automated dependency scanning and mandatory code review
  • Rate limiting on all public-facing endpoints
  • PII sanitisation in application logs (personal data is masked, not stored in plaintext)
  • Point-in-time database backups; customer documents replicated across two EU regions (West Europe and North Europe) for durability
  • Security headers (CSP, HSTS, and others)

7. Data Breach Notification

In the event of a data breach, SAR Portal will:

  • Notify the Controller within 24 hours of becoming aware (Processor → Controller notification window, faster than the 72-hour Controller → DPC obligation under GDPR Article 33, to give Controllers time to fulfil their onward obligations)
  • Provide details of the breach, affected data, and remediation steps
  • Cooperate with the Controller’s investigation and notification obligations
  • Document all breaches and actions taken

8. Data Subject Rights

SAR Portal will assist the Controller in responding to data subject requests for:

  • Access to personal data
  • Rectification of inaccurate data
  • Erasure of personal data
  • Restriction of processing
  • Data portability
  • Objection to processing

9. International Transfers

All customer data is stored in EU data centers. Any transfers outside the EU are protected by:

  • Standard Contractual Clauses (SCCs): We use the European Commission’s 2021 SCCs (Decision 2021/914) for any transfers to third countries
  • Microsoft’s EU Data Boundary: Microsoft Azure services operate under their EU Data Boundary commitment
  • Adequacy Decisions: Where applicable, transfers may rely on adequacy decisions (e.g., UK, Switzerland)
  • UK Transfers: For customers subject to UK GDPR, restricted transfers are covered by the UK International Data Transfer Addendum to the EU SCCs, or the UK IDTA where applicable

9.1 Sub-Processor Transfers

All our sub-processors either:

  • Process data exclusively within the EU/EEA, or
  • Have signed SCCs with us and implement supplementary measures where required

You may request copies of relevant SCCs by contacting dpo@sarportal.com.

10. Data Retention and Deletion

Upon termination:

  • Customer data available for export for 90 days
  • All tenant data permanently deleted after 90 days
  • Audit logs retained per our documented retention policy (default 7 years), based on our legitimate interest in defending potential legal claims within the applicable limitation period
  • Billing records retained for at least 6 years, in line with Irish tax record-keeping requirements

11. Audits

The Controller may audit SAR Portal’s compliance with this DPA. We will provide:

  • Access to relevant documentation
  • Responses to compliance questionnaires
  • Third-party audit reports upon request

12. Liability

Liability for data protection breaches is governed by the Terms of Service and applicable law, including GDPR Article 82.

13. Contact

For DPA-related inquiries:

  • Data Protection Officer: dpo@sarportal.com
  • Legal: legal@sarportal.com
SAR Portal

Respond to GDPR data access requests correctly and on time. Step-by-step guidance, AI-powered redaction, and regulator-ready evidence.

support@sarportal.com
Product
  • How It Works
  • Features
  • Pricing
  • ROI Calculator
  • Documentation
Resources
  • Just Received a DSAR?
  • Missed Deadline Help
  • DSAR Response Guide
  • DSAR Checklist
  • Redaction Guide
  • Sample Evidence Pack
  • Blog
  • Use Cases
Industries
  • Restaurants & Hospitality
  • Retail & E-commerce
  • Professional Services
  • Healthcare & Clinics
  • Childcare & Education
  • Financial Services
  • Brokers & Intermediaries
  • Property & Real Estate
  • SaaS & Technology
  • Recruitment Agencies
  • Enterprise Solutions
Legal
  • Trust Center
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA
  • Security
  • Contact
  • Login
Need enterprise-grade DSAR management?

High-volume, fair-use processing, dedicated account manager, 99.5% SLA, and assisted onboarding.

Contact Sales Request a 20-Minute Demo
🇪🇺 EU Company
☁️ Hosted on Azure EU
🔒 256-bit Encryption
✅ Built for GDPR
Cyber Essentials Plus Operated by a Cyber Essentials Plus certified organisation

Disclaimer: The information provided on this website and through SAR Portal is for general informational purposes only and does not constitute legal advice. While we strive to provide accurate and up-to-date guidance on GDPR compliance, every situation is unique. You should consult with a qualified legal professional or data protection officer for advice specific to your circumstances. SAR Portal is a software tool to assist with DSAR management and does not replace professional legal counsel.

© Sekhon IT Consultants Ltd. All rights reserved.

We value your privacy

We use cookies to enhance your browsing experience and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Read our Cookie Policy

Cookie Preferences
Essential Cookies

Required for the website to function. Cannot be disabled.

Functional Cookies

Remember your preferences like theme and language settings.

Analytics Cookies

Help us understand how visitors use our website via Google Analytics.