Legal

Data Processing Agreement

Last updated: 22 July 2026

This Data Processing Agreement is provided as part of Factorly's standard terms. It is being finalised with our legal advisers; the definitive, solicitor-reviewed version will be executed as part of onboarding before any resident personal data is processed for your firm.

This Data Processing Agreement (“DPA”) forms part of the agreement between Factorly Ltd (“Factorly”, “we”, the “Processor”) and the factor firm that uses the Factorly platform (the “Customer”, “you”, the “Controller”), and is incorporated into the Terms of Service. It governs the processing of personal data by Factorly on your behalf under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

1. Roles of the parties

For personal data relating to your residents, owners, tenants, properties and units that you enter into or generate through the platform (“Customer Personal Data”), you are the Controller and Factorly is the Processor. You determine the purposes and means of processing; Factorly processes Customer Personal Data only to provide the platform to you and only on your documented instructions.

Factorly acts as an independent Controller in respect of its own account, billing, security and marketing-analytics data, which is governed by our Privacy Policy rather than this DPA.

2. Subject-matter and details of processing

The processing Factorly carries out on your behalf is described below.

  • Subject-matter: provision of the Factorly property-management platform.
  • Duration: for the term of your agreement, plus the retention period in section 9.
  • Nature and purpose: storing, organising, transmitting and displaying Customer Personal Data to deliver charge management, payments, messaging, meetings, polls, compliance records, documents and related features.
  • Types of personal data: names, contact details (email, phone, address), unit/ownership details, financial balances and payment records, correspondence, and any personal data you choose to include in documents or messages.
  • Categories of data subjects: your staff, property owners, tenants, residents, and contractors.

3. Processing only on instructions

Factorly will process Customer Personal Data only on your documented instructions (including as set out in this DPA and your use of the platform's features), unless required to do otherwise by law — in which case we will inform you first, unless the law prohibits it. If we believe an instruction infringes data protection law, we will notify you.

4. Confidentiality

Factorly ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and have received appropriate data-protection training. Access is limited to those who need it to provide or support the platform.

5. Security

Taking into account the state of the art and the risks of processing, Factorly implements appropriate technical and organisational measures under Article 32 UK GDPR, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest;
  • Strict multi-tenant isolation — every record is scoped to your organisation;
  • Role-based access controls and least-privilege access;
  • UK-only data residency (see section 8);
  • Rate limiting, security headers, input validation and audit logging;
  • Continuous error and security monitoring.

6. Sub-processors

You provide a general authorisation for Factorly to engage sub-processors to help deliver the platform. Factorly imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains responsible for their performance. Our core infrastructure and AI are provided by:

  • Amazon Web Services (AWS) — cloud hosting, database, compute and file storage (UK, eu-west-2).
  • Anthropic (via AWS Bedrock) — AI features; processed within the AWS UK/EU region and not used to train third-party models.

We also use a small number of specialist providers, engaged under equivalent data-protection terms, for: transactional email delivery; real-time messaging and notifications; error and performance monitoring; and — only where you enable them — card and Direct Debit payment processing and accounting synchronisation.

A complete, current list of our named sub-processors is provided in the Data Processing Agreement executed at onboarding and is available on request. We will give you advance notice of any intended addition or replacement of a sub-processor so that you have the opportunity to object on reasonable data-protection grounds.

7. Assisting you

Taking into account the nature of the processing, Factorly will assist you by:

  • Providing appropriate technical and organisational measures to help you respond to data-subject requests (access, rectification, erasure, portability, restriction and objection) — the platform includes self-service export and deletion tools;
  • Assisting you in ensuring compliance with your security, breach-notification and data-protection-impact-assessment obligations under Articles 32–36 UK GDPR.

8. International transfers

Customer Personal Data is hosted in the United Kingdom (AWS eu-west-2). Factorly will not transfer Customer Personal Data outside the UK/EEA except where an appropriate safeguard under UK GDPR (such as an adequacy decision or the International Data Transfer Agreement / Addendum) is in place, or where you instruct such a transfer.

9. Personal data breach

Factorly will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for you to meet your notification obligations to the ICO and affected data subjects.

10. Return or deletion

On termination of your agreement, Factorly will, at your choice, delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. Standard deletion is completed within 90 days of termination, subject to backup rotation cycles.

11. Audit

Factorly will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice and subject to confidentiality.

12. Precedence

In the event of a conflict between this DPA and the Terms of Service in relation to the processing of Customer Personal Data, this DPA prevails.

13. Contact

For any data-protection matter, contact us at hello@factorly.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Data Processing Agreement — Factorly