NextSaaS and the general data protection regulation (GDPR)

 

RAIZFLOW LTD

GDPR & Data Protection Compliance Policy

 

 

ENTITY

RaizFlow Ltd

UK Private Limited Company

THREATWATCH

Civil B2B + B2C

UK+EU Users · Full processor stack

HORIZON

Military — Planning

Pre-deployment · No live data yet

 

Version 2.0 · April 2026 · Based on confirmed operational parameters · CONFIDENTIAL

 

!

MANDATORY LEGAL REVIEW REQUIRED

This document is built on confirmed answers: UK Ltd entity, B2B+B2C customers, UK+EU users, Supabase+Google+OpenAI+Stripe+Apollo+Hunter+email tool processors, Horizon pre-deployment. It constitutes a binding internal framework. A qualified UK data protection solicitor must review and sign off before RaizFlow accepts any live user data. The B2C model creates PECR consent obligations requiring specific technical implementation before launch.

 


 

1. Legal Entity & Regulatory Framework

 

 

1.1 Confirmed Company Parameters

Parameter

Confirmed Detail

Legal entity

RaizFlow Ltd — private limited company, England and Wales, Companies Act 2006

Registration

Companies House registration required before processing personal data

Primary regulator

Information Commissioner’s Office (ICO) — ico.org.uk — registration mandatory, fee £40-60/year, criminal offence to process without

EU regulator (Latvia users)

Datu valsts inspekcija (DVI) Latvia — dvi.gov.lv — register before processing Latvian resident data

DPO

Designate Data Protection Officer — dpo@raizflow.io — before launch. Internal or external consultant.

Applicable laws

UK GDPR · UK DPA 2018 · EU GDPR (Art 3(2) extra-territorial) · PECR 2003 · Latvian PDPL · Consumer Rights Act 2015 · Consumer Contracts Regulations 2013

 

1.2 Dual Jurisdiction: UK GDPR + EU GDPR

Regime

Rule Applied to RaizFlow Ltd

UK GDPR

Primary regime. Applies to all processing by RaizFlow Ltd as UK-established entity. ICO lead authority. UK DPA 2018 supplements.

EU GDPR

Secondary regime. Applies because ThreatWatch offers services to Latvian (EU) data subjects — Article 3(2) extra-territorial effect. DVI relevant authority. EU SCCs required for US transfers.

UK-EU data flow

Currently covered by UK-EU adequacy decision (2021). Monitor ICO. If revoked: implement SCCs within 30 days.

Conflict rule

Where UK GDPR and EU GDPR conflict, apply the more restrictive standard. Document every conflict.

 


 

2. B2B + B2C Customer Model — Dual Compliance Regime

 

 

!

CONFIRMED: BOTH B2B AND B2C CUSTOMERS

ThreatWatch has confirmed both business subscribers and individual consumer subscribers. This creates two separate compliance regimes running simultaneously across marketing, consent, contract terms, consumer rights, and PECR. Every processing activity below is assessed against both.

 

2.1 The Critical Differences

Area

B2B Rule vs B2C Rule

PECR electronic marketing

B2B corporate email: legitimate interests, no prior consent needed. Functional opt-out required every email. | B2C personal email: PRIOR OPT-IN CONSENT required under PECR Regulation 22. Criminal offence to send without. No exceptions.

Cookie consent

Both B2B and B2C: PECR consent required for non-essential cookies. Recommendation: eliminate all non-essential cookies entirely by using server-side analytics only. Removes this obligation for both groups.

14-day cancellation right

B2C only: Consumer Contracts Regulations 2013 gives 14-day right to cancel any online subscription. Must be disclosed at purchase. Refund required. | B2B: no statutory cooling-off.

Consumer Rights Act 2015

B2C Terms of Service must pass unfairness test. Plain language required. Exclusion clauses restricted. Solicitor review of B2C terms essential. | B2B: commercial parties, standard contract law.

Data subject rights volume

B2C users significantly more likely to exercise rights (access, erasure, portability, objection). Build self-service rights tools into account settings to handle volume without manual DPO involvement.

Refund obligations

B2C: full refund within 14 days of cancellation within cooling-off period. Payment processing via Stripe must support this. | B2B: per contract terms.

Balancing test stringency

Legitimate interests balancing test is harder to pass for B2C consumers than B2B professionals. Every LIA must be assessed from a consumer perspective.

 

2.2 B2C Registration Technical Requirements

1.    Separate, unchecked checkbox at registration: "I agree to receive marketing emails from ThreatWatch." Label must name marketing specifically. Cannot be bundled with Terms acceptance.

2.    Store consent record: timestamp, IP address, checkbox state (true/false), Privacy Policy version. Field: users.marketing_consent_record. Retain for customer lifetime plus 6 years.

3.    On checkout/subscription: display 14-day cancellation right with Model Cancellation Form link. Before early digital access: separate unchecked checkbox waiving cancellation right.

4.    Post-purchase confirmation email: must include full terms, cancellation right, Privacy Policy link. Sent within minutes of purchase.

5.    Account settings: self-service export (JSON/CSV), self-service marketing preference toggle, self-service account deletion. These reduce DPO workload significantly at scale.

 


 

3. Personal Data Processed — Confirmed Complete Map

 

 

!

CONFIRMED DATA SCOPE

All six confirmed data categories: email + name + company, payment details, location/postcode searches, usage patterns, passwords (hashed), API access logs. Plus B2C-specific: marketing consent records, cancellation records. Plus B2B-specific: sales CRM prospect data.

 

Data Category

Lawful Basis (B2B · B2C) · Retention · Notes

Email address

Collected at registration. Transactional use: CONTRACT. B2C marketing: CONSENT (PECR). B2B marketing: LEGITIMATE INTERESTS. Retained: contract duration + 30 days, then anonymised. Suppression list: indefinite.

Full name

Registration. Account personalisation and Duty of Care authorship. CONTRACT. 30 days post-deletion.

Company name

Registration. B2B: required. B2C: optional. CONTRACT + LEGITIMATE INTERESTS. 30 days post-deletion.

Payment details

Billing name/address/last 4 digits. Full card: Stripe only — RaizFlow never stores. CONTRACT. 7 years (HMRC legal obligation — overrides erasure right).

Postcode and location queries

UK postcodes and Riga district names entered during scans. Personal data when linked to user account. CONTRACT (product delivery). 12 months, automated pg_cron deletion.

Usage patterns

Session duration, features used, scan frequency, login times, IP address, browser/device. Pseudonymised (user hash not email). LEGITIMATE INTERESTS (product improvement, fraud prevention). B2C: balancing test documented. 12 months.

Hashed passwords

bcrypt hash minimum work factor 12 in Supabase Auth. Application never handles plaintext. CONTRACT. Deleted on account deletion.

API access logs

SHA-256 hashed key ID, timestamp, endpoint, territory, response code. No plaintext keys. LEGITIMATE INTERESTS (security, rate limiting, fraud). 12 months.

B2C marketing consent records

Timestamp, IP, checkbox state, Privacy Policy version. LEGAL OBLIGATION (PECR compliance evidence). Customer lifetime + 6 years. Cannot be deleted on erasure request.

B2C cancellation records

Purchase date, cancellation request date, refund status. LEGAL OBLIGATION (Consumer Contracts Regulations). 7 years.

Duty of Care assessments

Employee reference, journey, risk scores, PDF. B2B enterprise: employer is controller, RaizFlow is processor. Article 28 DPA governs. 7 years minimum.

Support communications

Email threads, in-app messages. CONTRACT + LEGITIMATE INTERESTS. 3 years.

B2B Sales CRM prospects

Business email, name, title, company, LinkedIn URL, company postcode. B2B ONLY — never B2C personal addresses. Source: Apollo, Hunter, LinkedIn public. LEGITIMATE INTERESTS. 24 months from last contact.

Trial access data

Activation timestamp, scans run, key hash, conversion status. CONTRACT. 6 months post-trial.

 

!

SPECIAL CATEGORY DATA — CONFIRMED ABSENCE

ThreatWatch does not collect health, biometric, racial, religious, political, sexual orientation, or criminal conviction data about its users. ThreatWatch processes area-level crime statistics, not individual crime records. If any future feature produces identifiable individual-level crime data, a full DPIA is mandatory before implementation and this section must be updated.

 


 

4. Lawful Basis Map — Complete

 

 

Processing Activity

Lawful Basis · B2B vs B2C Distinction · Key Requirement

Account creation and service delivery

Art 6(1)(b) CONTRACT. Both B2B and B2C. Do not use consent for core product delivery — withdrawal would prevent contract performance.

Scan results and intelligence delivery

Art 6(1)(b) CONTRACT.

Payment processing

Art 6(1)(b) CONTRACT. Stripe as independent controller.

Usage analytics

Art 6(1)(f) LEGITIMATE INTERESTS. B2C: balancing test documented (pseudonymised data, product improvement benefits users). Opt-out available via account deletion.

Security and fraud prevention

Art 6(1)(f) LEGITIMATE INTERESTS. Protects all users. Strong justification.

B2B electronic marketing (corporate emails)

Art 6(1)(f) LEGITIMATE INTERESTS + PECR legitimate interests for B2B corporate addresses only.

B2C electronic marketing (personal emails)

Art 6(1)(a) CONSENT. PECR Regulation 22 prior opt-in required. Separate consent record. Withdrawal stops marketing within 24 hours.

Trial access provision

Art 6(1)(b) CONTRACT (trial agreement).

HMRC and tax record retention

Art 6(1)(c) LEGAL OBLIGATION. Overrides erasure right for 7 years.

Duty of Care assessments

Art 6(1)(b) CONTRACT (with employer) + Art 6(1)(c) LEGAL OBLIGATION (Corporate Manslaughter Act 2007).

14-day cancellation administration

Art 6(1)(c) LEGAL OBLIGATION (Consumer Contracts Regulations 2013).

Breach notification

Art 6(1)(c) LEGAL OBLIGATION (GDPR Art 33).

Agent training data (anonymised area-level)

Art 6(1)(f) LEGITIMATE INTERESTS. Postcode district data is not personal data per se. If combined with traceable session data: pseudonymise first.

 

4.1 Legitimate Interests Assessment — B2B Sales Outreach

LIA Stage

Analysis and Conclusion

Purpose test

Genuine legitimate interest? YES: contacting B2B professionals in security, compliance, and fintech roles with a genuinely relevant security intelligence product.

Necessity test

Is processing necessary? YES: name, business email, company, and title are the minimum required for personalised B2B outreach. No less invasive alternative.

Balancing test

Data subject interests override? NO, provided: (1) corporate email addresses only, never personal; (2) role is genuinely relevant to ThreatWatch; (3) functional unsubscribe in every email; (4) suppression list technically enforced; (5) data from legitimate B2B sources (Apollo, Hunter, LinkedIn public) only; (6) Sales Agent never contacts B2C individuals at personal addresses.

 


 

5. Data Subject Rights

 

 

Right

Implementation · B2B vs B2C

Right of access (Art 15)

30 days. Full export: account data, scan history, payment metadata, consent records. Self-service download in account settings. B2C: higher volume expected — automate.

Right to rectification (Art 16)

Self-service via account settings. Manual: 30 days. Log all corrections.

Right to erasure (Art 17)

On deletion: anonymise usage logs, delete account fields, delete scan history, instruct Stripe, add email to suppression list. EXCEPTIONS: 7-year payment records (legal obligation), Duty of Care assessments (employer’s legal requirements), B2C consent records (PECR compliance evidence).

Right to portability (Art 20)

JSON or CSV export of account data and scan history within 30 days. Applies to data processed on contract or consent basis.

Right to object (Art 21)

To marketing: absolute, no override. To legitimate interests processing: immediate cessation unless compelling grounds. B2C: lower threshold to accept objection than B2B.

Right to restrict (Art 18)

Mark record restricted during accuracy disputes or erasure challenges. Technical flag in users table checked before all processing.

Right against automated decisions (Art 22)

ThreatWatch does not score individual users. Area scores are not individual decisions. If any future feature categorises users with significant effects: DPIA required, human review mechanism required.

Consent withdrawal (B2C marketing)

One-click unsubscribe in every email. In-account marketing preference toggle. Process within 24 hours. No negative consequence for withdrawal. Cannot condition product features on marketing consent.

14-day cancellation (B2C only)

Consumer Contracts Regulations 2013. 14 calendar days from subscription to cancel, full refund. Disclosed at point of purchase. Model Cancellation Form provided. Refund within 14 days of cancellation request.

 


 

6. Sub-Processor Registry — Confirmed Full Stack

 

 

!

CONFIRMED PROCESSOR STACK

Seven sub-processors confirmed: Supabase (EU-hosted), Google Vertex AI (US), OpenAI (US), Stripe (US), Apollo.io (US), Hunter.io (EU/France), Email tool (Resend/Postmark/SendGrid — all US). Each requires a signed DPA and relevant transfer mechanism before processing begins.

 

Sub-Processor (Country)

Role · Transfer Mechanism · Key Requirements

Supabase Inc. (USA — data EU Frankfurt)

Database, auth, edge functions, cron. Data at rest: EU-West-1, covered by UK-EU adequacy. Supabase Inc. as entity: sign Supabase DPA (supabase.com/dpa) including SCCs. Review annually.

Google LLC — Vertex AI (US)

Gemini AI inference. Sign Google Cloud DPA + UK IDTA + EU SCCs. Transfer Impact Assessment: query data is postcodes/area names, low personal data sensitivity. Never include user identifiers in prompts.

OpenAI LLC (US)

GPT-4o inference. Sign OpenAI DPA + UK IDTA + EU SCCs. Business API: data not used for training (verify annually at openai.com/enterprise-privacy). No user identifiers in prompts.

Stripe Inc. (US)

Payment processing. Stripe is independent controller for payment data. Sign Stripe DPA (stripe.com/legal/dpa) + UK IDTA. RaizFlow never stores full card data.

Apollo.io (US)

B2B prospect database. B2B use only — never target B2C personal addresses via Apollo data. Sign Apollo DPA + UK IDTA + EU SCCs. Verify Apollo’s opt-out handling. 24-month data retention.

Hunter.io (France — EU)

Email verification, B2B only. EU-based, standard GDPR processor contract. No international transfer issue.

Email delivery tool — Resend / Postmark / SendGrid (all US)

Transactional + marketing email. All US-based. CRITICAL FOR B2C: processes B2C personal email addresses. Sign DPA + UK IDTA + EU SCCs with chosen provider. Mandatory technical configuration: suppression list enforcement, one-click unsubscribe insertion, bounce/complaint handling, B2C consent-gating. Consider EU-based alternative (Brevo) to reduce transfer complexity.

 

6.1 Transfer Mechanisms Summary

Transfer Route

Required Mechanism · Action

UK → EU (Supabase data in Frankfurt)

UK-EU adequacy decision. Monitor. If revoked: UK IDTA with Supabase within 30 days.

UK → USA (5 US processors)

UK International Data Transfer Agreement (IDTA) required for each. Template at ico.org.uk.

EU/Latvia → USA (same processors)

EU Standard Contractual Clauses (2021/914, Module 2) required for each. Sign EU SCC version separately.

Transfer Impact Assessment

Required for all UK→US transfers. Document: FISA 702 / EO 12333 risk assessment. Mitigating factor: prompts contain area codes not personal identifiers.

 

!

B2C EMAIL TOOL — TECHNICAL REQUIREMENTS BEFORE LAUNCH

The email tool processes B2C personal email addresses. Before first B2C marketing email: (1) Configure tool to block sends to any address where marketing_consent=false; (2) Insert functional unsubscribe link in every email automatically; (3) Process unsubscribes within 24 hours, sync to ThreatWatch suppression list; (4) Retain delivery logs 12 months; (5) Configure bounce and spam complaint handling to automatically suppress problematic addresses; (6) Never send to the suppression list regardless of application instruction.

 


 

7. PECR Compliance — Marketing & Electronic Communications

 

 

!

B2C MARKETING: PRIOR OPT-IN CONSENT IS MANDATORY

Confirmed B2C customers means PECR Regulation 22 applies to all marketing emails to individual consumers. This is law, not guidance. Sending one unsolicited marketing email to a B2C user without prior opt-in consent is a potential ICO enforcement action with fines up to £500,000. The technical consent mechanism must be built and tested before any B2C user receives a marketing email.

 

Communication Type

PECR Rule · Consent Required?

B2C marketing emails (personal addresses)

PRIOR OPT-IN CONSENT required. Separate unchecked checkbox at registration. Consent record stored. Withdrawal within 24 hours. Never override.

B2B marketing emails (corporate addresses only)

No prior consent under PECR for genuine B2B outreach. Legitimate interests. Functional unsubscribe every email. Suppression list enforced. Never personal addresses.

Transactional emails (both groups)

No PECR consent required: account activation, payment confirmation, security alert, password reset, trial expiry. Must not contain marketing.

Sales Agent automated outreach

B2B only. Never B2C personal addresses. Check B2B flag before every send. Corporate email addresses only.

Re-engagement emails (B2C lapsed trial)

Only if marketing consent was given at registration. If no consent on record: cannot send. B2B: one re-engagement attempt under legitimate interests, then suppress.

 

7.1 PECR Technical Checklist

6.    Unchecked marketing consent checkbox for B2C at registration. Not bundled with Terms.

7.    Consent record: timestamp, IP, state, Privacy Policy version. Retained customer lifetime + 6 years.

8.    Email tool: marketing list contains only users where marketing_consent=true (B2C) or business_email=true AND suppressed=false (B2B).

9.    Every email: prominent unsubscribe link, one click, no login required.

10.  Unsubscribe processed within 24 hours. sets marketing_consent=false, adds to suppression list, syncs to email tool.

11.  Suppression list checked before every outreach run. Cannot be overridden.

12.  Subject lines non-deceptive. Never fake RE: or FWD:.

13.  Sender name: real person name or "ThreatWatch Team". Never no-reply.

14.  RaizFlow Ltd physical address in every email footer.

15.  Delivery logs retained 12 months.

 


 

8. Data Retention Schedule

 

 

Data Category

Retention Period · Legal Justification

Active account data

Contract duration + 30 days grace. Then anonymise or delete.

B2C marketing consent records

Customer lifetime + 6 years. PECR compliance evidence. Cannot be deleted on erasure request.

B2C cancellation records

7 years. Consumer Contracts Regulations compliance.

Scan history and postcode queries

12 months. Automated pg_cron deletion.

Payment and billing records

7 years. HMRC legal obligation. Overrides erasure right.

Support communications

3 years from last message.

Duty of Care assessments

7 years minimum. Immutable once generated.

API and security access logs

12 months.

B2B sales CRM prospects

24 months from last contact. Immediate suppression on unsubscribe.

B2B outreach records (LIA evidence)

3 years. ICO may audit.

Rights request log

6 years. ICO may audit.

Breach log

5 years.

Trial access logs

6 months post-trial.

Email delivery and suppression logs

12 months.

Agent training data (anonymised area-level)

Indefinite. Not personal data — postcode district statistics only.

 


 

9. Technical & Organisational Security Measures

 

 

Security Measure

Implementation

Encryption at rest

AES-256-GCM for stored secrets. NEXUS_ENCRYPTION_KEY in Supabase Secrets only. PostgreSQL at-rest encryption via Supabase.

Encryption in transit

TLS 1.3. HSTS max-age 31536000 includeSubDomains. No HTTP permitted.

Password storage

bcrypt work factor 12 minimum. Supabase Auth. Application never handles plaintext passwords.

Access key hashing

SHA-256 one-way. Plaintext shown once. Irrecoverable from stored hash.

Row Level Security

Every Supabase table. Users access own data only. Admin: role verified at database JWT level.

Security headers

All Edge Functions: HSTS, X-Frame-Options DENY, X-Content-Type-Options nosniff, CSP, Referrer-Policy.

CORS

Allowlist only. ALLOWED_ORIGIN in Supabase Secrets. No wildcards.

Rate limiting

Per-tier limits enforced at Edge Function level before AI calls.

Automated security scanning

21-check security agent daily at 02:00 UTC. PDF report generated. Critical findings alerted immediately.

Prompt injection monitoring

Security agent scans AI prompts. User input sanitised before AI inclusion.

B2C payment security

No full card data ever stored by RaizFlow. Stripe tokenisation only. B2C payment forms load from Stripe.js — card data never touches RaizFlow servers.

Account takeover protection

Unusual login pattern detection for B2C accounts. User notification on suspicious access.

 


 

10. Data Breach Response

 

 

Timeline

Required Actions · B2B vs B2C Distinction

0–1 hour

Incident declared. DPO notified. Containment (revoke keys, isolate). All facts captured.

1–4 hours

Severity assessment. What data, how many subjects (B2B and B2C separately), probable harm. In doubt: notify ICO.

4–24 hours

Draft ICO notification. Identify affected subjects. B2C: lower threshold for individual notification than B2B — consumer personal data breach causes higher personal harm.

24–72 hours

Submit ICO notification: ico.org.uk/report-a-breach. Also notify Latvian DVI if EU users affected — separate obligation. Partial notification acceptable; supplement later.

72 hours+

Individual notifications to affected data subjects where high risk. B2C: plain English, two paragraphs maximum. Explain what happened, what to do. B2B: professional communication, legal team involved.

 


 

11. Horizon — Pre-Deployment Legal Framework

 

 

!

HORIZON STATUS CONFIRMED: PRE-DEPLOYMENT — NO LIVE DATA

This is the optimal position. No immediate ICO reporting obligations. No current breach risk. No active processor agreements required for Horizon specifically. Use this window to build the complete legal and infrastructure framework before the first client contract is signed.

 

11.1 Required Before Horizon Processes Any Data

16.  Engage a qualified defence and national security solicitor. Confirm the specific legal gateway (Intelligence Services Act 1994, DPA 2018 Part 2/4, or statutory authority from the contracting government client).

17.  Confirm and obtain security clearances for all Horizon access staff. SC (Security Check) minimum. DV (Developed Vetting) for SECRET and above.

18.  Obtain signed Official Secrets Act 1989 declarations from all Horizon-cleared personnel before they access any classified data.

19.  Build Horizon on infrastructure completely separate from ThreatWatch. Separate Supabase project, separate API keys, separate repositories, separate deployments. Document the segregation architecture.

20.  Vertex AI and OpenAI must NOT be used for classified Horizon data. Build AI inference on government-approved infrastructure (AWS GovCloud UK, Azure Government, NCSC-approved private cloud, or on-premises).

21.  Draft the Article 28 Data Processing Agreement for use with government clients. Government client = data controller; RaizFlow = data processor.

22.  Apply Government Security Classification scheme to all Horizon outputs from day one.

23.  Complete a DPIA for every Horizon intelligence capability before any live processing.

24.  Assess EU AI Act classification for Horizon AI components. If deployed to law enforcement: likely high-risk AI under Annex III. Conformity assessment required.

25.  Confirm whether any Horizon capability involves communications interception or bulk data collection. If yes: Investigatory Powers Act 2016 warrants required before any such feature is built.

 

11.2 GDPR Exemptions Available to Horizon

Exemption

Application · Conditions

National security exemption (DPA 2018 Part 2, Ch 3)

Processing required for safeguarding national security may be exempt from most GDPR obligations including data subject rights and transparency. Must be applied case-by-case. Document every use. Cannot be used as blanket override.

Law enforcement processing (DPA 2018 Part 3)

If Horizon supports law enforcement (police, NCA): Part 3 — Law Enforcement Directive framework — governs instead of UK GDPR. Confirm applicable regime with legal adviser.

Individual rights restrictions

Access, erasure, portability rights may be restricted where applying them would prejudice national security or defence. Per-request basis. Specific exemption cited and documented. Rights not abolished, potentially restricted.

Classified data transfers

NATO, Five Eyes, and bilateral data sharing agreements may supersede standard GDPR transfer mechanisms for allied government data. Legal advice required on applicable agreements.

 


 

12. Latvia — EU-Specific Provisions

 

 

26.  Register with Datu valsts inspekcija (DVI) at dvi.gov.lv before processing any Latvian resident personal data.

27.  Latvian users have EU GDPR rights enforceable with the DVI. They may also complain to the DVI in addition to or instead of ICO.

28.  The Fintech Intelligence module monitors publicly available regulatory announcements. These are not personal data. Named individuals in enforcement actions (named directors, convicted officers): ARE personal data under Article 10 (criminal conviction data). Process only what is necessary; no searchable individual profiles.

29.  AML intelligence map: area and sector level only. No individual-level AML risk profiles. Named individuals from PEP lists or sanctions databases: Article 10 applies; specific official authority required.

30.  Bar scam blacklist: venue names only, no individual staff names.

31.  B2C Latvian users: same PECR-equivalent consent requirements apply under EU ePrivacy Directive.

 


 

13. AI Processing, EU AI Act & Transparency

 

 

Category

ThreatWatch Analysis · Action Required

Prohibited AI (Art 5)

ThreatWatch: no social scoring, no manipulation, no real-time biometric surveillance. Confirmed not prohibited.

High-risk AI (Annex III)

ThreatWatch sold to private companies: not high-risk. If ever sold to law enforcement for operational policing decisions: high-risk — conformity assessment, human oversight, technical documentation all required before EU deployment. Decide and document the sales policy.

Transparency obligation (limited risk)

AI-generated outputs: disclose that scores are AI-generated. Add to every scan result: "Intelligence generated by AI — review by qualified professional recommended before operational decisions."

GPAI deployer obligations

Deploying Gemini and GPT-4o: do not use to circumvent user rights, implement basic AI transparency, use only for stated purposes, maintain usage logs.

Horizon AI Act

If Horizon deployed for national security or law enforcement: Horizon AI components assessed separately. National security activities may be excluded from EU AI Act scope under Article 2(3). Confirm with legal adviser.

 


 

14. Privacy Policy & Consumer Terms Requirements

 

 

14.1 Privacy Policy — Must Be Published Before First User

32.  Identity of RaizFlow Ltd and DPO (dpo@raizflow.io).

33.  Dual jurisdiction: UK GDPR (ICO) and EU GDPR (DVI Latvia).

34.  Complete data categories with lawful basis for each. Distinguish B2B vs B2C where they differ.

35.  Explicit B2C marketing section: consent required, how to withdraw, what happens on withdrawal.

36.  Complete sub-processor list: all seven processors with data transferred, location, and transfer mechanism.

37.  All retention periods.

38.  All eight data subject rights plus 14-day B2C cancellation right.

39.  AI processing disclosure: scores generated by Gemini and GPT-4o, query postcodes sent to US processors, no user identifiers in prompts.

40.  Cookie policy: if server-side analytics only, state this clearly. Eliminates PECR obligation.

41.  Complaint rights: ICO (ico.org.uk) and DVI (dvi.gov.lv) with contact links.

42.  Date of last update.

 

!

B2C TERMS OF SERVICE — CONSUMER RIGHTS ACT 2015 REVIEW REQUIRED

B2C terms must pass the unfairness test. Plain language mandatory. Must include: 14-day cancellation right and Model Cancellation Form reference; clear description of what ThreatWatch does (area-level intelligence, not individual surveillance); limitation of liability that is prominent and not buried in small print; no terms excluding liability for death or personal injury; price and subscription terms clearly stated; how to complain. Engage a consumer law solicitor to review B2C-specific terms before launch.

 


 

15. Governance & Review

 

 

Item

Requirement

DPO designation

Designate before launch. May be internal (no conflict of interest) or external consultant. Reports to board. Contact: dpo@raizflow.io.

Annual review

DPO reviews and updates this policy every 12 months.

Triggered review

New feature involving personal data; new sub-processor; law changes; breach; ICO/DVI guidance.

ROPA

Records of Processing Activities: separate operational spreadsheet updated whenever processing changes. Available for ICO inspection on request.

Staff training

All staff: GDPR and PECR awareness at onboarding and annually. Sales team: specific PECR and LIA training. Horizon-cleared staff: OSA 1989 briefing. Records maintained.

Board accountability

Material policy changes require board sign-off. Documented in board minutes.

 


 

16. Pre-Launch Compliance Checklist

 

 

Complete every item before accepting live user data. Tick and date each.

 

ThreatWatch — All Items Mandatory Before First Live User

Compliance Item

Status

RaizFlow Ltd incorporated at Companies House

[ ] Date: ___________

ICO registration completed — ico.org.uk

[ ] Date: ___________

Latvian DVI registration — dvi.gov.lv

[ ] Date: ___________

DPO designated, dpo@raizflow.io active

[ ] Date: ___________

Privacy Policy at threatwatch.io/privacy

[ ] Date: ___________

B2C Terms of Service reviewed by consumer law solicitor

[ ] Date: ___________

B2C marketing consent checkbox — unchecked default, separate from Terms

[ ] Date: ___________

B2C consent records stored: timestamp, IP, state, PP version

[ ] Date: ___________

14-day cancellation disclosure at B2C checkout

[ ] Date: ___________

Model Cancellation Form accessible from checkout and account

[ ] Date: ___________

Self-service export, marketing toggle, account deletion in settings

[ ] Date: ___________

Functional unsubscribe in ALL outbound emails

[ ] Date: ___________

Suppression list technically enforced in email tool

[ ] Date: ___________

DPA signed: Supabase (supabase.com/dpa)

[ ] Date: ___________

DPA + UK IDTA + EU SCCs: Google Vertex AI

[ ] Date: ___________

DPA + UK IDTA + EU SCCs: OpenAI

[ ] Date: ___________

DPA + UK IDTA + EU SCCs: Stripe

[ ] Date: ___________

DPA + UK IDTA + EU SCCs: Apollo.io (B2B only use confirmed)

[ ] Date: ___________

DPA: Hunter.io

[ ] Date: ___________

DPA + UK IDTA + EU SCCs: Email delivery tool

[ ] Date: ___________

Transfer Impact Assessments completed for all 5 US processors

[ ] Date: ___________

UK-EU adequacy decision status confirmed operative

[ ] Date: ___________

Retention schedule automated in pg_cron deletion jobs

[ ] Date: ___________

RLS enabled on all Supabase tables

[ ] Date: ___________

AES-256 operational, NEXUS_ENCRYPTION_KEY in Secrets

[ ] Date: ___________

SHA-256 access key hashing — no plaintext keys stored

[ ] Date: ___________

24-hour security agent scan schedule active

[ ] Date: ___________

B2C PECR consent flow tested end-to-end

[ ] Date: ___________

B2B outreach suppression list operational and tested

[ ] Date: ___________

AI output disclosure text in Privacy Policy and scan results UI

[ ] Date: ___________

Staff GDPR + PECR training completed and documented

[ ] Date: ___________

Breach response procedure documented and tested

[ ] Date: ___________

ROPA initial version complete

[ ] Date: ___________

Solicitor sign-off on this document and B2C terms

[ ] Date: ___________

 

Horizon — Pre-Deployment Preparation

Compliance Item

Status

Defence and national security solicitor engaged and signed off

[ ] Date: ___________

Legal gateway for Horizon processing confirmed and documented

[ ] Date: ___________

Horizon infrastructure segregated from ThreatWatch — zero shared components

[ ] Date: ___________

AI infrastructure confirmed: no Vertex AI/OpenAI for classified data

[ ] Date: ___________

Security clearances confirmed: all Horizon access staff (SC minimum)

[ ] Date: ___________

OSA 1989 declarations signed by all Horizon personnel

[ ] Date: ___________

Article 28 DPA template drafted for government clients

[ ] Date: ___________

GSC classification applied to Horizon output templates

[ ] Date: ___________

DPIA completed for each Horizon intelligence capability

[ ] Date: ___________

EU AI Act high-risk assessment completed for Horizon AI components

[ ] Date: ___________

NCSC EUD guidelines applied to all Horizon access devices

[ ] Date: ___________

 

 

 

RaizFlow Ltd — UK Private Limited Company

dpo@raizflow.io · ThreatWatch (B2B+B2C Civil) · Horizon (Military, Pre-deployment)

GDPR & Data Protection Policy · Version 2.0 · April 2026

This document must be reviewed and signed off by a qualified UK data protection solicitor before live deployment.

Purpose of this document

At NextSaaS, we are fully committed to respecting your privacy. This page provides a clear overview of:

Conditions for refund

In simple terms, GDPR gives you greater control over your personal information. Service providers (like NextSaaS) must be transparent about what data they collect, how they use it, and how they share it — and users must have full rights to access, modify, or delete their data.

Although GDPR is an EU regulation, it affects any business that collects or processes the data of EU residents, including NextSaaS.

What is GDPR?

In simple terms, GDPR gives you greater control over your personal information. Service providers (like NextSaaS) must be transparent about what data they collect, how they use it, and how they share it — and users must have full rights to access, modify, or delete their data.

Although GDPR is an EU regulation, it affects any business that collects or processes the data of EU residents, including NextSaaS.

How NextSaaS Implements GDPR

NextSaaS has always prioritized user data privacy, even before GDPR came into effect. Our core practices naturally align with GDPR principles, and we've made further improvements to ensure full compliance.

We have updated our:

Data we collect

Why we collect your data

Third-Party services we use

Your data rights

How to manage or delete your data

Get started

Ready to start earning with NextSaaS?

If you have any questions, feel free to reach out to our team.