Cookies that sign you in and keep your session need no consent. Choose what else we may use. Privacy Policy
Version 1.0, 5 September 2026 · Heed
This Data Processing Addendum (the "Addendum") forms part of the Terms of Service between Heed (the "Company"), and the customer that accepts the Terms (the "Customer"). It applies whenever the Customer enters or uploads personal data about people other than itself into the Service, which is typically an advisor firm or a family office recording data about its clients. It takes effect when the Customer first does so.
For Customer Personal Data, the Customer is the controller and the Company is the processor. Where the Customer itself acts as a processor for its own client, the Customer is the Company's instructing party and warrants that its instructions reflect those of the relevant controller. The Company processes Customer Personal Data only to provide, secure, maintain and improve the Service as described in the Terms and Annex I, for the duration of the Customer's use of the Service and the deletion period in section 10.
For personal data about the Customer's own users (account holders, staff who sign in) and for the Customer's billing and marketing data, the Company is an independent controller, as described in the Privacy Policy.
The Company processes Customer Personal Data only on the Customer's documented instructions. The Terms, this Addendum and the Customer's use of the Service's features (for example entering a client, running a scenario, asking a question about a client, sending an alert to a client) are those instructions. The Company will not process Customer Personal Data for its own purposes, sell it, or use it to train artificial-intelligence models. Where a law of the European Union, a Member State, the United Kingdom or another jurisdiction to which the Company is subject requires the Company to process Customer Personal Data otherwise, the Company informs the Customer of that requirement before processing, unless the law prohibits that on important grounds of public interest. If the Company believes an instruction infringes Applicable Data Protection Law, it informs the Customer without undue delay and may suspend the instruction until it is confirmed or withdrawn.
The Company ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality and receives access only to the extent needed for their role.
The Company implements and maintains the technical and organisational measures in Annex II, and any further measures required by Applicable Data Protection Law, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risk to data subjects. The Company may update those measures provided the overall level of protection does not fall below what Annex II describes.
The Customer gives the Company general written authorisation to engage the Sub-processors on the list the Company provides under Annex III and to replace or add Sub-processors as follows. The Company gives the Customer's account owner at least 30 days' written notice by email before a new Sub-processor first processes Customer Personal Data. The Customer may object on reasonable, documented data-protection grounds within that period. The parties will then discuss in good faith; if the objection is not resolved within 30 days, the Customer may terminate the affected Services on written notice, and the Company refunds any prepaid fees for the period after termination. The Company imposes on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this Addendum, and remains liable to the Customer for the Sub-processor's performance.
The Service lets the Customer view, correct, export and delete the Customer Personal Data it holds, which is the primary way it answers requests from data subjects. Taking into account the nature of the processing, the Company assists the Customer with appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data-subject rights. If the Company receives such a request directly and can identify the Customer, it forwards the request to the Customer within five business days and does not respond to the data subject except to refer them to the Customer, unless the law requires otherwise.
The Company notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, and is updated as further information becomes available. The Company cooperates with the Customer and takes reasonable steps to contain and remedy the breach. The Company's notice is not an admission of fault or liability.
Taking into account the nature of the processing and the information available to it, the Company assists the Customer in carrying out data protection impact assessments and in prior consultation with a supervisory authority, where those relate to the Company's processing of Customer Personal Data.
During the term, the Customer can export Customer Personal Data through the Service. Within 30 days after the end of the Customer's use of the Service, or earlier on the Customer's written instruction, the Company deletes all Customer Personal Data, including copies at Sub-processors, except where Applicable Data Protection Law or another law requires it to be kept, in which case the Company continues to protect it under this Addendum and processes it for no other purpose. Backups are overwritten in the normal cycle of the database provider.
The Company makes available to the Customer the information necessary to demonstrate compliance with this Addendum, including this Addendum, the Annexes, and the current independent audit reports or certifications of its hosting providers. Once in any period of twelve months, or following a personal data breach or a demand from a supervisory authority, the Customer may audit the Company's compliance: first by written questionnaire, and where the written answers do not resolve a documented concern, by an audit conducted by the Customer or an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, at the Customer's cost, limited to the processing of Customer Personal Data and without access to other customers' data. The Company contributes to such audits.
The Company stores Customer Personal Data with its database provider in the European Union (Ireland) and accesses it from outside the European Economic Area; certain Sub-processors process it in the United States, as Annex III describes. The Company does not transfer Customer Personal Data outside the country where the Customer is established except under the safeguards below or where Applicable Data Protection Law otherwise permits.
Where Customer Personal Data protected by the EU GDPR is transferred to the Company or a Sub-processor in a country without an adequacy decision, the EU SCCs are incorporated into this Addendum by reference, with the Customer as data exporter and the Company as data importer, and completed as follows: Module Two (controller to processor) applies; Clause 7, the docking clause, applies; under Clause 9(a), Option 2 (general written authorisation) applies with the notice period in section 6; the optional language in Clause 11(a) does not apply; under Clause 13, the supervisory authority is the authority of the EU Member State in which the Customer is established, or, where the Customer is not established in the EU, the authority of the Member State of its representative or of the data subjects concerned; under Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland; under Clause 18(b), disputes are resolved by the courts of Ireland; Annexes I, II and III of the EU SCCs are completed by Annexes I, II and III of this Addendum. Where the Customer is itself a processor, Module Three applies with the same selections.
Where Customer Personal Data protected by the UK GDPR is transferred to the Company or a Sub-processor outside the United Kingdom without adequacy regulations, the EU SCCs as completed above apply together with the UK Addendum, which is incorporated by reference. Table 1 is completed by the parties' details in Annex I, Table 2 by the selections in section 12.1, Table 3 by Annexes I to III, and in Table 4 the Importer may end the UK Addendum as set out in its section 19.
Where the FADP applies, the EU SCCs apply with these adjustments: references to the EU GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent supervisory authority; data subjects in Switzerland may enforce their rights in Switzerland; and the term personal data includes data relating to legal persons where the FADP still protects them.
The Company has not received, as at the version date above, any order from a public authority for access to Customer Personal Data. If it receives one, it will, where the law allows, inform the Customer, challenge unlawful or disproportionate requests, and disclose only the minimum required.
Each party's liability under or in connection with this Addendum is subject to the exclusions and limitations in the Terms, which apply in aggregate across the Terms and this Addendum. Nothing in this section limits either party's liability to data subjects under the EU SCCs or the UK Addendum where they apply, or any liability that Applicable Data Protection Law does not allow to be limited.
This Addendum lasts as long as the Company processes Customer Personal Data. Sections 8, 10, 12 and 13 survive its end. If there is a conflict, the EU SCCs and the UK Addendum prevail over this Addendum, and this Addendum prevails over the Terms, in each case only for the processing of Customer Personal Data. The Company may update this Addendum to reflect changes in law, the Service or its Sub-processors; material changes take effect 30 days after notice by email to the Customer's account owner, and the Customer may end the affected Services before then if it objects. Otherwise the general provisions and the governing-law clause of the Terms apply to this Addendum.
The Customer accepts this Addendum by creating an advisor or family-office account, or by entering Customer Personal Data into the Service, whichever happens first. No signature is needed for it to bind both parties. A Customer that requires a countersigned copy, or a copy with its own details completed in Annex I, can request one from privacy@heed.finance; the Company returns it within ten business days.
Data exporter (controller): the Customer, identified by the account details it provides in the Service, represented by the account owner.
Data importer (processor): Heed; contact privacy@heed.finance.
The Customer's clients and prospective clients; people connected to those clients whose details the Customer records, such as family members, beneficial owners and officers of client entities; and, for the purposes of usage records only, the Customer's own staff who use the Service.
None are required by the Service. The Customer must not enter special categories of personal data (such as health, religious or political data) or criminal-offence data unless it has a lawful basis to do so and has told the Company in writing beforehand.
Hosting and storage; matching client profiles against verified tax-law changes and sending the resulting alerts; counting days of presence against residency thresholds; comparing scenarios; producing reports and briefs; answering the Customer's questions about a client with AI-assisted research, sending only the fields the feature needs; messaging between the Customer and its clients; and the security, maintenance and support of the Service.
For the term of the Customer's use of the Service, then deletion under section 10.
As listed in Annex III, for the purposes stated there, for the same duration.
The Company engages the following categories of Sub-processor for Customer Personal Data. The identity, contact details and function of each named Sub-processor are provided to the Customer when its account is created, on request from privacy@heed.finance, and whenever the list changes under section 6. That named list is the agreed list for the purposes of Clause 9(a) of the EU SCCs. Providers of the Customer's own account, billing and marketing data are described in the Privacy Policy and are not Sub-processors of Customer Personal Data.
| Category | Function | Location of processing |
|---|---|---|
| Database and infrastructure provider | Database, authentication, file storage and server-side functions, on a major cloud provider's infrastructure | Ireland (data at rest); United States (the provider's support tooling) |
| Application platform | Application hosting, the gateway that routes AI requests, and transactional email delivery to the Customer's clients through its email delivery partner | European Union and United States |
| AI model provider (Google) | Gemini models that generate outputs for AI-assisted features on the Customer's request | United States and European Union |
| Internal notification tools | Operational notifications to the Company's team; a notification may contain the email address of a person who creates an account | Global and United States |
Workspaces the Customer connects itself, such as Slack or Microsoft Teams, receive alerts on the Customer's instruction under the Customer's own agreement with that provider and are not Sub-processors of the Company.
Questions about this Addendum: privacy@heed.finance.