Legal Documents - Organisations

This page contains the legal and technical documents relevant to deploying DebtRiot within your organisation. It is intended for procurement teams, data protection officers, and anyone responsible for evaluating third-party tools under UK GDPR. All documents are available to download. If you have questions before signing, contact hello@debtriot.co.uk.

Data Processing Agreement (DPA)

Required under UK GDPR Article 28 for any organisation deploying DebtRiot. This agreement sets out how DebtRiot (the processor) handles data on behalf of your organisation (the controller). Because DebtRiot does not collect personal data from end users, the DPA is brief and straightforward. A countersigned copy is provided to every client before deployment.

→ Download DPA (PDF)

B2B2C Terms & Conditions

Governs the relationship between DebtRiot and your organisation, including permitted use, access controls, liability, and termination. Covers both Discovery and paid subscription periods.

→ Download Terms & Conditions (PDF)

Pilot Agreement

Sets out the terms of the 3-month paid Discovery period: scope, pricing, exit clause, and the process for transitioning to an annual subscription. Includes data deletion obligations at end of Discovery if no subscription follows.

→ Download Discovery Agreement (PDF)

Data Architecture Summary

What DebtRiot collects, where it lives, and who can see it.

What is collected End users Nothing stored about them. No name, no email, no financial data, no device ID. End users interact with the tool anonymously. Their connection IP is used only briefly for abuse-prevention, held about 15 minutes, and is never logged or linked to them.

Org admin An admin recovery contact (email or phone) — used to verify a code-recovery request and for account correspondence. Dashboard login itself uses an admin code, stored only as a one-way hash.

Aggregate insight Anonymous event counters per organisation per month — usage patterns, strategy choices, completion journeys, and charity signposting effectiveness. No content, no user identity.
Where data is stored Anonymous aggregate counters are stored in Upstash Redis KV, UK region (London), namespaced under b2b2c: and logically isolated from all other DebtRiot data. Generated reports (anonymous aggregate snapshots) are stored in a private, access-gated Vercel Blob store for the life of the contract. No other data is stored on Vercel beyond ephemeral request processing.
Retention Anonymous aggregate counts are retained long-term to enable trend analysis and outcome reporting. As they contain no individual identifiers, they cannot be linked to any person. Org admin accounts and associated data are deleted within 30 days of contract end, or within 5 business days of a written deletion request, whichever comes first.
Who can access DebtRiot only. Data is never sold, shared, or disclosed to third parties. Org admins can view their own organisation's aggregate insight via their dashboard — they see no data from other organisations. No end-user personal identifiers exist or are accessible to anyone.
At contract end Your organisation's admin account is deleted within 30 days of contract end, or within 5 business days of a written request. Aggregate counts (anonymous) are retained for historical trend continuity unless deletion is specifically requested. Deletion is confirmed in writing. No data is retained after a deletion request.
ICO Registration: ZC115123 — registered with the Information Commissioner's Office under Miss Monika Pankiewicz, trading as DebtRiot.