Data Processing Agreement
About this document: This is the standard Data Processing Agreement ("DPA") template for organisations entering into a Corporate Programme with Expat183 ("Processor"). The Processor operates TheWILL.ai (estate planning), Expat183 (tracking the days you spend in each country) and Orchard72 (portfolio tracking). This DPA covers Personal Data processed through whichever of those services the Corporate Programme includes. It supplements the Terms of Service and Privacy Policy and is entered into between the organisation ("Controller") and the Processor.
1. Definitions
- "Controller" means the organisation that enters into a Corporate Programme agreement with the Processor.
- "Processor" means the operator of TheWILL.ai, Expat183 and Orchard72.
- "Data Subject" means the employee or individual whose personal data is processed under this DPA.
- "Personal Data" means any information relating to an identified or identifiable Data Subject, as defined in Article 4(1) of the UK GDPR.
- "Processing" means any operation performed on Personal Data, as defined in Article 4(2) of the UK GDPR.
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "UK GDPR" means the United Kingdom General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018.
2. Scope and Data Categories
This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller in connection with the Corporate Programme. The categories of data processed and their purposes are set out below.
Outbound will-file disclosure requests are outside this DPA. A legal professional using the Platform for their own practice may ask the Processor to send a will-file disclosure request to a firm outside the Platform. That is a feature of the legal professional's own relationship with the Processor, governed by the Legal Professional Terms and the Privacy Policy, and it is stated here so that it is not read into this agreement by silence. It involves no Employee Data, no Personal Data originating from the Controller and no instruction from the Controller, the Controller is not a controller of anything processed on it, and nothing in this DPA authorises the Processor to send such correspondence on the Controller's behalf. Where a Controller also holds a legal professional account, that account is governed separately and is not brought within this DPA by the overlap.
| Data Category | Examples | Processing Purpose | Controller |
|---|---|---|---|
| Employee identity data | Email address, display name, employee identifier | Programme enrolment, licence assignment, SSO authentication | Employer (Controller) |
| Organisational data | Department, employment start/end dates | Programme administration, HRIS synchronisation | Employer (Controller) |
| Programme participation status | Invited email address, account name once accepted, activation status, assignment and activation dates and times | Showing the Controller which invitations have been activated, on its dashboard, by bulk export and through the read-only Corporate Reporting API | Expat183 (independent controller); the Employer is controller of any copy it exports |
| Will and estate content | Will text, beneficiary details, asset records | Will creation and management services | Expat183 (independent controller) |
| Documents and media | Uploaded identity documents, video messages | Document vault, identity verification | Expat183 (independent controller) |
| Subscription and billing | Plan type, billing interval, payment status | Subscription management, invoicing | Expat183 (independent controller) |
| Mirror Will partner data | Partner email, shared jurisdiction, residence address, children details | Mirror Will creation involving two data subjects per engagement | Expat183 (independent controller) |
3. Controller Obligations
The Controller shall:
- Ensure it has a lawful basis for providing employee Personal Data to the Processor, including obtaining any necessary consents in accordance with Article 7 of the UK GDPR.
- Provide accurate and up-to-date employee data and promptly notify the Processor of any changes, corrections, or deletions required.
- Ensure that consent to participate in the Corporate Programme is freely given, specific, informed, and unambiguous, and is collected separately from employment terms and conditions.
- Inform Data Subjects of the processing carried out by the Processor by providing appropriate privacy notices.
- Where the Controller exports programme participation status, whether by bulk download or programmatically, treat the exported copy as Personal Data for which the Controller is solely responsible. The Controller shall keep the export secure, use it only to administer the programme, keep it no longer than it needs to for that purpose, and include this processing in the privacy notices it gives to Data Subjects. An export never contains will content, documents, beneficiary details or other estate records, and the Processor does not act on the Controller's behalf once the export has been delivered.
- Where the Controller creates reporting API keys for its own systems, keep each key confidential and use it only to administer the programme. Grant each key only the access its integration needs (aggregate reporting, the employee roster, or both). Revoke a key without delay if it may have been exposed or is no longer needed. The Controller is responsible for the systems it connects with a key and for any copy of Personal Data those systems retrieve, on the same terms as an export. A key reads only aggregate programme statistics, invoices and the roster data the Controller itself provided, with seat status and dates. It never reads will content, documents, beneficiary details or other estate records.
4. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by UK law.
- Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR.
- Assist the Controller in responding to requests from Data Subjects exercising their rights under Chapter III of the UK GDPR.
- Assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of processing and the information available to the Processor.
- Make available to the Controller all information necessary to demonstrate compliance with Article 28 of the UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
- Where the Controller is a professional firm using the platform's practice tools, act on the Controller's instruction to re-allocate a client internally from one of the Controller's professionals to another. On each such hand-over the Processor shall: restrict access to the client's special-category records (including health and mental capacity records) to the client's managing professional; re-point any document shares the client scoped to a matter so that they follow the new managing professional, and notify the client that it has done so; and keep an immutable log of the hand-over (who made it, from which professional, to which professional, and when), available to the Controller's owner and administrators.
5. Sub-Processors
The Controller provides general authorisation for the Processor to engage Sub-Processors. The current list of Sub-Processors is maintained at our Sub-Processor List page and is updated when Sub-Processors are added or removed.
The Processor shall notify the Controller of any intended changes to Sub-Processors at least 14 days before the change takes effect. The Controller may object to the change on reasonable grounds relating to data protection. If the objection cannot be resolved, the Controller may terminate the affected services.
The Processor shall impose on each Sub-Processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA.
The Processor shall remain fully liable to the Controller for the performance of each Sub-Processor's obligations under this DPA, in accordance with Article 28(4) of the UK GDPR. That assurance depends on the Processor continuing to operate; its limits where the Processor is insolvent are set out in Article 13.
6. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests under Chapter III of the UK GDPR, including rights of access, rectification, erasure, restriction of processing, data portability, and objection.
Where a Data Subject makes a request directly to the Processor, the Processor shall promptly inform the Controller and shall not respond to the request without the Controller's instructions, unless required to do so by UK law.
7. Security Measures
The Processor implements and maintains the following technical and organisational security measures:
- Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256).
- Envelope encryption of stored documents and other sensitive records: each record is sealed under its own data key, and those data keys are themselves encrypted under a key held and managed separately from the encrypted content, so that access to the stored data alone does not yield the plaintext.
- Access controls with role-based permissions and multi-factor authentication for administrative access.
- Least-privilege role-based access control for our own staff, under which administrative views are masked by default. Reading an unmasked record requires a time-limited, reason-bound break-glass elevation which is recorded internally against the incident or request that authorised it.
- Regular vulnerability assessments and penetration testing.
- Automated virus scanning of all uploaded documents.
- Logging and monitoring of access to Personal Data.
- Business continuity and disaster recovery procedures, including regular backups.
- Staff training on data protection and information security.
8. Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data breach affecting the Controller's data. This gives the Controller meaningful runway to meet its own 72-hour notification deadline to the Information Commissioner's Office under Article 33 of the UK GDPR. The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects affected.
- The name and contact details of the Processor's data protection point of contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to be taken to address the breach and mitigate its effects.
The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of each breach.
9. Data Deletion
Upon termination or expiry of the Corporate Programme agreement, the Controller shall elect, in accordance with Article 28(3)(g) of the UK GDPR, whether the Processor is to return or delete the Personal Data processed on the Controller's behalf. The Controller shall communicate its election within 30 days of termination or expiry. Where the Controller makes no election within that period, the Processor shall delete the data.
Where the Controller elects return, the Processor shall provide the employer-specific data in a structured, commonly used and machine-readable format within 30 days of the election, and shall then delete it on the timetable below.
Where the Controller elects deletion, or makes no election, the Processor shall:
- Delete all employer-specific data (organisation details, branding assets, assignment records, and aggregate programme statistics) within 30 days of termination.
- Purge all backup copies of employer-specific data within 90 days of termination.
- Employee personal data (wills, documents, digital asset records) is outside the scope of this DPA. As recorded in Article 2, Expat183 processes that data as an independent controller under its direct relationship with the individual employee, not on the Controller's behalf, and it is therefore neither returned to nor deleted at the direction of the Controller. It is retained, and erased, under the retention schedule in the Privacy Policy and on the individual's own instructions.
Deletion is retained by law where, and for as long as, UK or EU law requires the Processor to keep the data; in that case the Processor shall inform the Controller of the requirement and shall delete the data when it ends.
The Processor shall provide the Controller with written confirmation of deletion upon request, and shall provide it without a request where deletion is carried out as part of a discontinuation of the Service under Article 13.
10. Audit Rights
The Controller may conduct one audit per calendar year to verify the Processor's compliance with this DPA. The Controller shall provide at least 30 days' written notice of an audit. Audits shall be conducted during normal business hours and shall not unreasonably interfere with the Processor's operations.
The Processor may satisfy audit requests by providing the Controller with relevant third-party audit reports or certifications, where available. The Controller shall bear its own costs of the audit unless the audit reveals a material breach of this DPA by the Processor.
11. International Transfers
Where Personal Data is transferred outside the United Kingdom, the Processor shall ensure that appropriate safeguards are in place in accordance with Chapter V of the UK GDPR. Transfer mechanisms include:
- Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner's Office.
- EU-US Data Privacy Framework certification, where the recipient is a certified participant.
The current list of Sub-Processors, including their locations and applicable transfer mechanisms, is available at our Sub-Processor List page.
12. Term and Termination
This DPA takes effect on the date the Corporate Programme agreement is signed and remains in force for as long as the Processor processes Personal Data on behalf of the Controller. The data deletion obligations set out in Article 9, and the discontinuation and insolvency provisions in Article 13, survive termination.
Either party may terminate this DPA by giving written notice if the other party materially breaches any provision of this DPA and fails to remedy the breach within 30 days of receiving written notice of the breach.
13. Processor Insolvency and Discontinuation of the Service
Articles 9 and 12 address the ending of the Corporate Programme agreement by one of the parties. This Article addresses the different case in which the Processor discontinues the Service, or enters administration, liquidation or receivership.
Notice. The Processor shall notify the Controller of a decision to discontinue the Service not less than 90 days before access ends, and shall notify the Controller without undue delay upon the appointment of an administrator, liquidator or receiver.
The Controller's Article 28(3)(g) election survives. The Controller's right to elect return or deletion of the Personal Data under Article 9 applies in full to a discontinuation or insolvency, and the Processor shall make the data available for return in a structured, commonly used and machine-readable format throughout the notice period.
Instructions cannot be expanded. Where an administrator, liquidator, receiver or other office-holder is appointed, processing of the Controller's Personal Data continues only in accordance with the Controller's existing documented instructions, as required by Article 28(3)(a) of the UK GDPR. An office-holder may not introduce new processing purposes, and the Personal Data processed on the Controller's behalf is not an asset that may be sold or transferred except to a transferee bound by obligations equivalent to this DPA and only where the Controller has been notified.
Deletion certificate is issued without a request. Where deletion is carried out as part of a discontinuation, the Processor shall issue written confirmation of deletion to the Controller proactively, at the time deletion completes, rather than on request. Deletion is completed before the Processor is dissolved.
Limits of the Processor's assurances. The Controller should be aware that the Processor's undertaking in Article 5 to remain fully liable for its Sub-Processors, and the security measures in Article 7, depend on the Processor continuing to operate and to pay its suppliers. The Processor cannot guarantee the continuity of Sub-Processor infrastructure during an insolvency, and a contractual liability owed by an insolvent company is of limited practical value. The Processor states this plainly rather than leaving it to be inferred, so that the Controller can take it into account in its own risk assessment and retain its own copy of any data it depends on. The disaster-recovery and business-continuity measures referred to in Article 7 address operational failures such as outage or data loss; they are not, and are not offered as, protection against the Processor's insolvency.
14. Liability
The liability of each party under or in connection with this DPA is governed by the limitation and exclusion of liability provisions of the Corporate Programme agreement between the parties (Terms of Service, Section 22). Where that agreement does not specify a cap applicable to data protection matters, each party's total aggregate liability arising out of or in connection with this DPA is limited, per contract year, to the greater of (a) the total fees payable by the Controller under the Corporate Programme agreement in that year, or (b) £50,000.
Nothing in this DPA limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any liability that cannot lawfully be limited or excluded; or (d) either party's obligations, or a Data Subject's rights, under applicable data protection law, including any liability under Article 82 of the UK GDPR to compensate a Data Subject for damage caused by processing.
The parties acknowledge that, under Article 82 of the UK GDPR, a controller or processor involved in processing may be held liable for the entire damage caused by that processing in order to ensure effective compensation of the Data Subject, and may then claim back from any other controller or processor the part of the compensation corresponding to that party's responsibility for the damage. This DPA does not limit a Data Subject's right to compensation.
15. Governing Law
This DPA is governed by the laws of England and Wales. Any dispute arising out of or in connection with this DPA is subject to the exclusive jurisdiction of the courts of England and Wales, subject to any mandatory rules of law conferring jurisdiction on the courts of a Data Subject's country of habitual residence.
Nothing in this Article limits the rights of a Data Subject under applicable data protection law, including any right to lodge a complaint with a supervisory authority in the country of their habitual residence.
Related Documents
Privacy Policy: How we collect, use, and protect your personal data.
Terms of Service: Our terms of service, including Corporate Programme terms (Section 22).
Sub-Processor List: Third-party sub-processors used to provide our services.

