Restated

Data processing terms.

Version 1.0, effective 17 August 2026. Questions: hello@foundationcollective.co.uk

These terms are incorporated into the subscriber terms and apply automatically to every subscription. No signature is needed for them to bind us. If your procurement requires a countersigned copy on your own template, email hello@foundationcollective.co.uk.

1. Parties and roles

1.1
These terms are between the subscribing organisation ("Controller", "you") and Restated Ltd (company number SC790998), whose registered office is 13 Corskie Park, Dunecht, AB32 7AE ("Processor", "we").
1.2
For the personal data contained in the materials, briefs, brand content, images and outputs you process through the service ("Customer Personal Data"), you are the controller and we are the processor. You determine the purposes and means; we act only on your instructions.
1.3
For account, authentication, billing, support and service security data, we are a controller in our own right, as described in the privacy notice. These terms do not apply to that processing.
1.4
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and, where applicable to your processing, the EU GDPR, in each case as amended or replaced. Terms such as controller, processor, personal data, processing, personal data breach and supervisory authority have the meanings given in that law.

2. Our obligations as processor

2.1
Instructions only. We will process Customer Personal Data only to provide, secure, support and maintain the service in accordance with the subscriber terms and your instructions, and as Annex 1 describes. Your use of the service, including the briefs and materials you submit, constitutes your instructions. If we believe an instruction breaches Data Protection Law, we will tell you and may pause that processing.
2.2
No AI model training. We will not use Customer Personal Data to train, fine-tune or evaluate artificial intelligence models, and we will not permit any subprocessor to do so. Our AI provider processes submitted content under a paid API agreement solely to return the output requested, and does not retain it for training.
2.3
No other use. We will not sell Customer Personal Data, use it for advertising, or disclose it to any third party except as these terms permit or the law requires. If we are legally compelled to disclose it, we will tell you first unless we are prohibited from doing so.
2.4
Confidentiality of personnel. We will ensure that anyone we authorise to process Customer Personal Data is subject to a duty of confidence, is given access only where needed for their role, and has been made aware of the obligations in these terms.
2.5
Security. We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, the cost of implementation and the risks involved. The measures in place are described in Annex 2. We may change them, provided the level of protection is not reduced.
2.6
Assistance with data subject rights. We will notify you without undue delay if we receive a request from a person exercising their rights in relation to Customer Personal Data, and we will not respond to it ourselves except to direct them to you. We will give you the assistance you reasonably need, through the service's own features where possible, to answer such a request.
2.7
Breach notification. We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken or proposed. We will cooperate with you and take reasonable steps to mitigate it.
2.8
Impact assessments. We will give you reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that relates to the service.
2.9
Records and audit. We will keep records of our processing sufficient to demonstrate compliance with these terms, and will make available to you the information you reasonably need to verify it. Where that information is not enough, you may audit our compliance no more than once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without access to other customers' data or to our systems in a way that risks their security, and at your own cost. Where a regulator requires an audit, this frequency limit does not apply.
2.10
Deletion and return. On termination of your subscription, or on your written request, we will delete Customer Personal Data in accordance with the retention periods in the privacy notice, except where we are required by law to keep it. Attached generation materials are purged within 48 hours of the generation completing as part of normal operation. You can export your library from the app at any time before your access ends.

3. Your obligations as controller

3.1
You warrant that you have a lawful basis for the Customer Personal Data you put into the service, that you have given the people concerned any privacy information they are entitled to, and that your instructions to us comply with Data Protection Law.
3.2
You warrant that you hold all consents, releases and permissions needed for any identifiable individual appearing in material you upload, including photography, film and voice recordings, and for the use you intend to make of the outputs.
3.3
You will not put special category personal data, criminal offence data, payment card data or children's data into the service without our prior written agreement. The service is not designed for those categories, and the measures in Annex 2 are calibrated to business content.
3.4
You are responsible for the accuracy of the data you submit and for keeping your own record of processing.

4. Subprocessors

4.1
You give us general authorisation to engage subprocessors to deliver the service. The current list, with the purpose and processing location of each, is published in the privacy notice and forms part of these terms.
4.2
We will give active subscribers at least 30 days' notice before adding or replacing a subprocessor, by email and by updating that page.
4.3
If you have a reasonable data protection objection to a new subprocessor, tell us within that notice period. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of your subscription and we will refund a proportionate part of any prepaid fees for service you will not receive.
4.4
We impose data protection obligations on each subprocessor that are materially equivalent to these terms, and we remain responsible to you for their performance.

5. International transfers

5.1
The service is hosted in the European Union, and our database, storage and rendering infrastructure is located in Germany. Payment processing is in the United Kingdom.
5.2
Content submitted for generation is transferred to our AI provider in the United States. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU standard contractual clauses, or the EU standard contractual clauses, together with a transfer risk assessment and the technical measures in Annex 2.
5.3
Ringfenced deliverables are designed so that the content typed into them never reaches our servers or any AI system, and therefore involve no transfer at all. Where that mode applies, the deliverable's own certificate records how you can verify it.

6. Liability and general

6.1
The limitations and exclusions of liability in clause 14 of the subscriber terms apply to these terms and to any claim under them, as a single aggregate cap across both documents.
6.2
These terms take effect on the date your subscription starts and continue for as long as we process Customer Personal Data.
6.3
If there is a conflict between these terms and the subscriber terms in relation to the processing of personal data, these terms prevail.
6.4
These terms are governed by the law of Scotland, and the Scottish courts have exclusive jurisdiction, in line with clause 16.7 of the subscriber terms.

Annex 1. Details of the processing

ItemDetail
Subject matterProvision of the Restated content and design generation service to the Controller.
DurationThe term of the subscription, plus the retention periods set out in the privacy notice.
Nature and purposeHosting, storage, text extraction, transmission to the AI provider, generation of outputs, rendering to PDF and other formats, sharing by link where the Controller chooses, support, security monitoring and backup.
Types of personal dataBusiness contact details of the Controller's personnel (name, work email, organisation, role); names, roles, quotations and biographical detail of individuals appearing in uploaded documents, briefs and brand material; images and film of identifiable individuals uploaded to the image bank; content of a user's private Spar conversations; support correspondence.
Categories of data subjectThe Controller's employees and contractors who use the service; individuals named or depicted in material the Controller uploads, including client and partner personnel, case study participants and quoted spokespeople; recipients of shared links.
Special category dataNone expected, and not permitted without prior written agreement under clause 3.3.
FrequencyContinuous, on the Controller's instruction, for as long as the subscription is active.

Annex 2. Technical and organisational measures

The measures below are the ones in place today. They are described at a level that a security reviewer can check against the service.

AreaMeasure
Tenant isolationEvery table carrying customer content enforces row level security scoped to the organisations a user belongs to. Application queries additionally pin the active organisation, so a user who belongs to more than one never sees a merged view.
Privileged functionsServer-side generation functions require a service key held only by the platform, in addition to authenticated access, and are probed after each deployment to confirm the lock holds.
StorageUploaded documents and the image bank live in private buckets. Access is by short-lived signed URL issued to an authorised member of the owning organisation. Public buckets are used only for assets the customer has chosen to publish, such as logos in a generated tool.
EncryptionTLS for all data in transit. Encryption at rest for the managed database and object storage.
Access controlPasswordless authentication by one-time code or single sign-on. Role-based access within an organisation. Least privilege for platform staff, with elevated keys held in environment configuration and never in client code.
Data minimisationText extracted from attached documents is purged within 48 hours of the generation completing. Only the extracted text needed for a job is sent to the AI provider.
LoggingSecurity-relevant and administrative events are written to an append-only audit log scoped to the organisation.
LocationDatabase, storage and rendering workers in Germany. Application hosting on EU compute with a global content delivery network for static assets.
Supplier controlSubprocessors are named publicly, engaged under data protection terms materially equivalent to these, and changed only after 30 days' notice.
Ringfenced modeWhere a deliverable is issued in ringfenced form, customer content is entered into a sealed, pinned runtime with an egress gate and content security policy, and does not reach our servers or any AI provider.

Contact

Data protection questions, subprocessor objections and audit requests: hello@foundationcollective.co.uk.

Version history

VersionEffectiveChange
1.017 August 2026First published version.