Cookies that sign you in and keep your session need no consent. Choose what else we may use. Privacy Policy

Heed, International Tax Intelligence
PricingFAQThe Circle
Terms of Service

Data Processing Addendum

Version 1.0, 5 September 2026 · Heed

This Data Processing Addendum (the "Addendum") forms part of the Terms of Service between Heed (the "Company"), and the customer that accepts the Terms (the "Customer"). It applies whenever the Customer enters or uploads personal data about people other than itself into the Service, which is typically an advisor firm or a family office recording data about its clients. It takes effect when the Customer first does so.

1. Definitions

  • Applicable Data Protection Law means the laws that apply to the processing of Customer Personal Data, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as it forms part of the law of the United Kingdom ("UK GDPR") and the Data Protection Act 2018, and the Swiss Federal Act on Data Protection ("FADP").
  • Customer Personal Data means personal data that the Customer, or a person acting on its behalf, enters into or uploads to the Service about data subjects other than the Customer's own users, as described in Annex I.
  • Sub-processor means a third party engaged by the Company to process Customer Personal Data on the Company's behalf.
  • EU SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914.
  • UK Addendum means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
  • "Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in Applicable Data Protection Law.

2. Roles and Scope

For Customer Personal Data, the Customer is the controller and the Company is the processor. Where the Customer itself acts as a processor for its own client, the Customer is the Company's instructing party and warrants that its instructions reflect those of the relevant controller. The Company processes Customer Personal Data only to provide, secure, maintain and improve the Service as described in the Terms and Annex I, for the duration of the Customer's use of the Service and the deletion period in section 10.

For personal data about the Customer's own users (account holders, staff who sign in) and for the Customer's billing and marketing data, the Company is an independent controller, as described in the Privacy Policy.

3. Instructions

The Company processes Customer Personal Data only on the Customer's documented instructions. The Terms, this Addendum and the Customer's use of the Service's features (for example entering a client, running a scenario, asking a question about a client, sending an alert to a client) are those instructions. The Company will not process Customer Personal Data for its own purposes, sell it, or use it to train artificial-intelligence models. Where a law of the European Union, a Member State, the United Kingdom or another jurisdiction to which the Company is subject requires the Company to process Customer Personal Data otherwise, the Company informs the Customer of that requirement before processing, unless the law prohibits that on important grounds of public interest. If the Company believes an instruction infringes Applicable Data Protection Law, it informs the Customer without undue delay and may suspend the instruction until it is confirmed or withdrawn.

4. Confidentiality

The Company ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality and receives access only to the extent needed for their role.

5. Security

The Company implements and maintains the technical and organisational measures in Annex II, and any further measures required by Applicable Data Protection Law, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risk to data subjects. The Company may update those measures provided the overall level of protection does not fall below what Annex II describes.

6. Sub-processors

The Customer gives the Company general written authorisation to engage the Sub-processors on the list the Company provides under Annex III and to replace or add Sub-processors as follows. The Company gives the Customer's account owner at least 30 days' written notice by email before a new Sub-processor first processes Customer Personal Data. The Customer may object on reasonable, documented data-protection grounds within that period. The parties will then discuss in good faith; if the objection is not resolved within 30 days, the Customer may terminate the affected Services on written notice, and the Company refunds any prepaid fees for the period after termination. The Company imposes on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this Addendum, and remains liable to the Customer for the Sub-processor's performance.

7. Data Subject Requests

The Service lets the Customer view, correct, export and delete the Customer Personal Data it holds, which is the primary way it answers requests from data subjects. Taking into account the nature of the processing, the Company assists the Customer with appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data-subject rights. If the Company receives such a request directly and can identify the Customer, it forwards the request to the Customer within five business days and does not respond to the data subject except to refer them to the Customer, unless the law requires otherwise.

8. Personal Data Breaches

The Company notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, and is updated as further information becomes available. The Company cooperates with the Customer and takes reasonable steps to contain and remedy the breach. The Company's notice is not an admission of fault or liability.

9. Impact Assessments and Prior Consultation

Taking into account the nature of the processing and the information available to it, the Company assists the Customer in carrying out data protection impact assessments and in prior consultation with a supervisory authority, where those relate to the Company's processing of Customer Personal Data.

10. Deletion and Return

During the term, the Customer can export Customer Personal Data through the Service. Within 30 days after the end of the Customer's use of the Service, or earlier on the Customer's written instruction, the Company deletes all Customer Personal Data, including copies at Sub-processors, except where Applicable Data Protection Law or another law requires it to be kept, in which case the Company continues to protect it under this Addendum and processes it for no other purpose. Backups are overwritten in the normal cycle of the database provider.

11. Demonstrating Compliance and Audits

The Company makes available to the Customer the information necessary to demonstrate compliance with this Addendum, including this Addendum, the Annexes, and the current independent audit reports or certifications of its hosting providers. Once in any period of twelve months, or following a personal data breach or a demand from a supervisory authority, the Customer may audit the Company's compliance: first by written questionnaire, and where the written answers do not resolve a documented concern, by an audit conducted by the Customer or an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, at the Customer's cost, limited to the processing of Customer Personal Data and without access to other customers' data. The Company contributes to such audits.

12. International Transfers

The Company stores Customer Personal Data with its database provider in the European Union (Ireland) and accesses it from outside the European Economic Area; certain Sub-processors process it in the United States, as Annex III describes. The Company does not transfer Customer Personal Data outside the country where the Customer is established except under the safeguards below or where Applicable Data Protection Law otherwise permits.

12.1 EU GDPR

Where Customer Personal Data protected by the EU GDPR is transferred to the Company or a Sub-processor in a country without an adequacy decision, the EU SCCs are incorporated into this Addendum by reference, with the Customer as data exporter and the Company as data importer, and completed as follows: Module Two (controller to processor) applies; Clause 7, the docking clause, applies; under Clause 9(a), Option 2 (general written authorisation) applies with the notice period in section 6; the optional language in Clause 11(a) does not apply; under Clause 13, the supervisory authority is the authority of the EU Member State in which the Customer is established, or, where the Customer is not established in the EU, the authority of the Member State of its representative or of the data subjects concerned; under Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland; under Clause 18(b), disputes are resolved by the courts of Ireland; Annexes I, II and III of the EU SCCs are completed by Annexes I, II and III of this Addendum. Where the Customer is itself a processor, Module Three applies with the same selections.

12.2 UK GDPR

Where Customer Personal Data protected by the UK GDPR is transferred to the Company or a Sub-processor outside the United Kingdom without adequacy regulations, the EU SCCs as completed above apply together with the UK Addendum, which is incorporated by reference. Table 1 is completed by the parties' details in Annex I, Table 2 by the selections in section 12.1, Table 3 by Annexes I to III, and in Table 4 the Importer may end the UK Addendum as set out in its section 19.

12.3 Switzerland

Where the FADP applies, the EU SCCs apply with these adjustments: references to the EU GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent supervisory authority; data subjects in Switzerland may enforce their rights in Switzerland; and the term personal data includes data relating to legal persons where the FADP still protects them.

12.5 Government access

The Company has not received, as at the version date above, any order from a public authority for access to Customer Personal Data. If it receives one, it will, where the law allows, inform the Customer, challenge unlawful or disproportionate requests, and disclose only the minimum required.

13. Liability

Each party's liability under or in connection with this Addendum is subject to the exclusions and limitations in the Terms, which apply in aggregate across the Terms and this Addendum. Nothing in this section limits either party's liability to data subjects under the EU SCCs or the UK Addendum where they apply, or any liability that Applicable Data Protection Law does not allow to be limited.

14. Term, Precedence and General

This Addendum lasts as long as the Company processes Customer Personal Data. Sections 8, 10, 12 and 13 survive its end. If there is a conflict, the EU SCCs and the UK Addendum prevail over this Addendum, and this Addendum prevails over the Terms, in each case only for the processing of Customer Personal Data. The Company may update this Addendum to reflect changes in law, the Service or its Sub-processors; material changes take effect 30 days after notice by email to the Customer's account owner, and the Customer may end the affected Services before then if it objects. Otherwise the general provisions and the governing-law clause of the Terms apply to this Addendum.

15. Acceptance and Signed Copies

The Customer accepts this Addendum by creating an advisor or family-office account, or by entering Customer Personal Data into the Service, whichever happens first. No signature is needed for it to bind both parties. A Customer that requires a countersigned copy, or a copy with its own details completed in Annex I, can request one from privacy@heed.finance; the Company returns it within ten business days.

Annex I: Description of the Processing

Parties

Data exporter (controller): the Customer, identified by the account details it provides in the Service, represented by the account owner.

Data importer (processor): Heed; contact privacy@heed.finance.

Data subjects

The Customer's clients and prospective clients; people connected to those clients whose details the Customer records, such as family members, beneficial owners and officers of client entities; and, for the purposes of usage records only, the Customer's own staff who use the Service.

Categories of personal data

  • Identity and contact details: name, email address, and other contact details the Customer enters.
  • Tax and residency profile: tax residency, citizenships, jurisdictions of interest, income types, asset classes, wealth bracket, life events and horizons, and offshore or corporate entity holdings.
  • Presence records: days spent by country and date, travel notes, and identity or travel document details where the Customer records them.
  • Entity records: company names, jurisdictions, registration numbers, fiscal year ends, compliance obligations and related documents.
  • Working records: notes, tasks, messages between the Customer and its clients, scenario inputs and results, reports and files the Customer creates or uploads.

Special categories of data

None are required by the Service. The Customer must not enter special categories of personal data (such as health, religious or political data) or criminal-offence data unless it has a lawful basis to do so and has told the Company in writing beforehand.

Nature and purpose of the processing

Hosting and storage; matching client profiles against verified tax-law changes and sending the resulting alerts; counting days of presence against residency thresholds; comparing scenarios; producing reports and briefs; answering the Customer's questions about a client with AI-assisted research, sending only the fields the feature needs; messaging between the Customer and its clients; and the security, maintenance and support of the Service.

Duration and retention

For the term of the Customer's use of the Service, then deletion under section 10.

Transfers to Sub-processors

As listed in Annex III, for the purposes stated there, for the same duration.

Annex II: Technical and Organisational Measures

  • Storage location and encryption. Customer Personal Data is stored with the database provider in the European Union (Ireland), encrypted at rest by the provider and in transit with TLS.
  • Tenant isolation. Every table holding Customer Personal Data carries row-level security policies enforced inside the database, so a user can read only the rows of the firm, team or client they are authorised for. The applications that run in a browser never hold privileged credentials.
  • Authentication and access. Password authentication with rate limiting, optional time-based one-time-password multi-factor authentication, and role-based access within a firm (owner, administrator, analyst, viewer) with team scoping. Client portal access is granted per client and per scope by the Customer.
  • Privileged access. Access by the Company's own team is limited to a named allowlist, authenticated by magic link, and its actions are written to an audit log.
  • Secrets. Service credentials and integration keys are held in a vault or in server-side configuration, never in client code or version control.
  • Monitoring. A health check runs every five minutes and a data-integrity check runs daily; failures alert the Company's team.
  • Backups. Managed by the database provider; restores are tested when the provider's tooling changes.
  • Secure development. Changes pass automated type checks, tests, dependency audits and content guards in continuous integration before release; security-sensitive changes are reviewed before deployment.
  • Data minimisation for AI features. Only the fields a feature needs are sent to an AI provider, outputs are marked as AI-generated, and Customer Personal Data is never used to train models.
  • Sub-processor management. Written contracts with data-protection terms; the list in Annex III is reviewed whenever a provider changes.
  • Incident response. A documented process to contain, assess and notify within the period in section 8, with a single contact point at privacy@heed.finance.
  • Provider assurance. The hosting providers in Annex III maintain independent security certifications (including SOC 2 Type II reports), which the Company reviews and can make available on request.
  • Personnel. Confidentiality obligations and least-privilege access for everyone who can reach Customer Personal Data.

Annex III: Sub-processors

The Company engages the following categories of Sub-processor for Customer Personal Data. The identity, contact details and function of each named Sub-processor are provided to the Customer when its account is created, on request from privacy@heed.finance, and whenever the list changes under section 6. That named list is the agreed list for the purposes of Clause 9(a) of the EU SCCs. Providers of the Customer's own account, billing and marketing data are described in the Privacy Policy and are not Sub-processors of Customer Personal Data.

CategoryFunctionLocation of processing
Database and infrastructure providerDatabase, authentication, file storage and server-side functions, on a major cloud provider's infrastructureIreland (data at rest); United States (the provider's support tooling)
Application platformApplication hosting, the gateway that routes AI requests, and transactional email delivery to the Customer's clients through its email delivery partnerEuropean Union and United States
AI model provider (Google)Gemini models that generate outputs for AI-assisted features on the Customer's requestUnited States and European Union
Internal notification toolsOperational notifications to the Company's team; a notification may contain the email address of a person who creates an accountGlobal and United States

Workspaces the Customer connects itself, such as Slack or Microsoft Teams, receive alerts on the Customer's instruction under the Customer's own agreement with that provider and are not Sub-processors of the Company.

Contact

Questions about this Addendum: privacy@heed.finance.

Heed, international tax intelligence

Real-time tax intelligence for a borderless world.

Product
  • Change Feed
  • Ask Heed
  • Scenario Planner
  • Position Optimiser
  • Tax Rankings
  • Residency Tracker
  • Visa Match
  • Financial Navigator
  • Insurance
  • Structure Match
  • Mobile App
  • Marketplace
  • Relocation Brief
  • Concierge
For Who
  • Digital nomads
  • Expats
  • HNWIs
  • Advisors
Use cases
  • Tax residency
  • Capital gains tax
  • Crypto tax
  • Exit tax
  • Digital nomad tax
Resources
  • Tax RoastFree
  • Incorporation RoastFree
  • FAQ
  • Blog
  • Status
Company
  • About
  • Careers
  • Pricing
  • Apply as partner
Tax guidesEvery major jurisdiction tracked
  • Portugal
  • United Arab Emirates
  • Spain
  • Italy
  • United Kingdom
  • United States
  • Switzerland
  • Singapore
  • Malta
  • Greece
  • Cyprus
  • Andorra
  • Monaco
  • Liechtenstein
  • View all jurisdictions

Heed provides tax information and software tools for general informational purposes only. It is not tax, legal, financial or investment advice, and creates no adviser relationship. We hold no client funds and execute no transactions. Rates and legislative changes are compiled from public sources across multiple jurisdictions and may be incomplete or out of date. Always confirm your position with a qualified professional before acting.

Examples, rates and rule references shown on this website are illustrative and may not reflect the latest position. The live Heed product carries the current, source-verified data matched to your profile, that is always the source of truth.

© 2026 Heed. All rights reserved.
Privacy PolicyDPATerms of Service