Data Processing Addendum

Last Updated: 31 August 2026

Tarian Data Processing Addendum (UK) (Standalone)

Last Updated: 31 August 2026


This Data Processing Addendum (this "DPA") sets out the terms on which RAMSGen Ltd processes Personal Data on behalf of a business customer in connection with Tarian, its software-as-a-service platform (the "Service").

Naming. Tarian is a product of RAMSGen Ltd. RAMSGen Ltd is the Processor under this DPA, whether the product is referred to as Tarian or as RAMSGen.


1. Parties

1.1 Processor

RAMSGen Ltd (company number 16458298) of 4th Floor, 14 Museum Place, City Centre, Cardiff, CF10 3BH ("RAMSGen", "Processor").

Privacy contact: support@tariansystems.com

1.2 Controller

The business customer that (a) has an account/workspace for the Service and (b) accepts or enters into this DPA ("Customer", "Controller").

1.3 Effective date

This DPA is effective from the earlier of (a) the date the Customer accepts it (including electronically) or (b) the date RAMSGen first processes Customer Personal Data on the Customer's behalf ("Effective Date").


2. Background and Scope

2.1 This DPA applies only to Personal Data that RAMSGen processes as Processor on behalf of the Customer in connection with the Service ("Customer Personal Data").

2.2 This DPA does not apply to personal data that RAMSGen processes as Controller, for example for account administration, billing, marketing, and security logs relating to RAMSGen's own business operations (those activities are covered by RAMSGen's privacy notice).

2.3 This DPA is intended to satisfy the requirements of Article 28(3) UK GDPR.


3. Definitions and Interpretation

3.1 In this DPA, the terms "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the UK GDPR.

3.2 "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable UK data protection and privacy laws, as amended from time to time.

3.3 "Customer Data" means the content and data submitted to or stored in the Service by or on behalf of the Customer or its users within the Customer's workspace (including project data and generated RAMS documents), which may include Customer Personal Data.

3.4 "Subprocessor" means any third party appointed by or on behalf of RAMSGen to process Customer Personal Data.

3.5 "UK Transfer Mechanism" means a valid transfer safeguard recognised under the Data Protection Legislation for transfers of Personal Data outside the UK, including (as applicable):

(a) UK adequacy regulations (including where applicable the UK extension to the EU-US Data Privacy Framework / UK-US data bridge); and/or

(b) the UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses; and/or

(c) any other valid mechanism under the Data Protection Legislation.

3.6 Order of precedence. If there is any conflict between this DPA and any other terms agreed between the parties relating to the Processing of Customer Personal Data, this DPA will prevail to the extent of the conflict.


4. Roles of the Parties

4.1 The Customer is the Controller of Customer Personal Data.

4.2 RAMSGen is the Processor of Customer Personal Data.

4.3 The Customer determines the purposes and means of Processing of Customer Personal Data and instructs RAMSGen to process Customer Personal Data on the terms of this DPA.


5. Details of Processing (Article 28(3))

5.1 The subject matter, nature, purpose, duration of Processing, types of Customer Personal Data and categories of Data Subjects are set out in Annex 1 (Details of Processing).

5.2 The Customer confirms that it has provided (and will provide) all required notices to, and obtained all required rights/consents from, Data Subjects (where required) to allow RAMSGen to process Customer Personal Data as contemplated by this DPA.


6. Processor Obligations

6.1 Instructions

RAMSGen will process Customer Personal Data only on the Customer's documented instructions, including as set out in this DPA and the Customer's configuration and use of the Service, unless Processing is required by applicable law. In that case, RAMSGen will (to the extent permitted by law) inform the Customer of that legal requirement before processing.

6.2 Unlawful instructions

RAMSGen will notify the Customer if, in RAMSGen's opinion, an instruction infringes the Data Protection Legislation.

6.3 Confidentiality

RAMSGen will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations (statutory or contractual). Confidentiality obligations continue for the period stated in the Terms.

6.4 Security

RAMSGen will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The baseline measures are described in Annex 2 (Security Measures).

6.5 Data minimisation

RAMSGen will only access and process Customer Personal Data as necessary to provide, secure, and support the Service in accordance with the Customer's instructions.


7. Subprocessors

7.1 General authorisation

The Customer provides a general authorisation for RAMSGen to engage Subprocessors to process Customer Personal Data in connection with the Service.

7.2 Current Subprocessors

As at the Last Updated date, RAMSGen's key Subprocessors are listed in Annex 3.

7.3 Subprocessor terms

Where RAMSGen engages a Subprocessor, RAMSGen will enter into a written agreement with the Subprocessor which imposes data protection obligations on the Subprocessor that are no less protective than those set out in this DPA (as required by Article 28(4) UK GDPR), in respect of the Processing of Customer Personal Data.

7.4 Responsibility

RAMSGen remains responsible to the Customer for the performance of each Subprocessor's obligations relating to the Processing of Customer Personal Data.

7.5 Changes; notice; objection

(a) RAMSGen may add or replace Subprocessors.

(b) Where reasonably practicable, RAMSGen will provide notice of any new Subprocessor by email to the Customer account email and/or by in-Service notice (at RAMSGen's discretion).

(c) The Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notifying RAMSGen at support@tariansystems.com within 14 days of notice.

(d) If the parties cannot resolve the objection within a reasonable period, RAMSGen will, acting reasonably, either (i) not appoint the new Subprocessor for the relevant Processing, or (ii) propose a commercially reasonable change to enable provision of the Service without that Subprocessor. If neither option is reasonably practicable, either party may terminate the affected part of the Service by written notice (and the parties will agree any pro-rata refund of prepaid fees due solely for the affected part, if applicable under the parties' commercial agreement).


8. International Transfers (UK)

8.1 Where Processing of Customer Personal Data involves a transfer of Customer Personal Data outside the UK, RAMSGen will ensure that the transfer is made in accordance with the Data Protection Legislation and is subject to a UK Transfer Mechanism.

8.2 The Customer acknowledges that certain Subprocessors may be located in, or may process Customer Personal Data from, the United States and other countries outside the UK (for example, where US-based service providers are used).


9. Assistance to the Customer

9.1 Data Subject requests

Taking into account the nature of the Processing, RAMSGen will provide reasonable assistance to the Customer to help the Customer respond to requests from Data Subjects to exercise their rights under the Data Protection Legislation, to the extent the Customer cannot fulfil such requests through self-service tools in the Service.

9.2 Regulatory compliance assistance

RAMSGen will provide reasonable assistance to the Customer with the Customer's obligations under Articles 32 to 36 UK GDPR (security, breach notification, DPIAs and prior consultation), taking into account the nature of Processing and the information available to RAMSGen.

9.3 Costs of assistance

Assistance under this Section 9 is included to the extent it is reasonable and proportionate. RAMSGen may charge a reasonable fee for assistance that is (a) exceptional in scope, (b) not required by the Data Protection Legislation, or (c) requires substantial technical effort, provided RAMSGen notifies the Customer in advance where practicable.

9.4 Direct requests to RAMSGen

If RAMSGen receives a request from a Data Subject relating to Customer Personal Data, RAMSGen will (unless prohibited by law) promptly direct the Data Subject to the Customer and notify the Customer.


10. Personal Data Breach

10.1 RAMSGen will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 RAMSGen's notification will include, to the extent available, information enabling the Customer to meet its obligations under the Data Protection Legislation, such as:

(a) the nature of the Personal Data Breach;

(b) the categories and approximate number of Data Subjects concerned;

(c) the categories and approximate number of Personal Data records concerned;

(d) likely consequences; and

(e) measures taken or proposed to address and mitigate.

10.3 RAMSGen will reasonably cooperate with the Customer's investigation, mitigation, and required notifications.


11. Return, Deletion and Retention of Customer Personal Data

11.1 During the term

The Customer may export/download Customer Data and outputs from the Service using available functionality.

11.2 Post-termination export window (Published RAMS PDFs)

Following termination/expiry of the Customer's access to the Service, Published RAMS PDF exports may be made available for download for 30 days, unless RAMSGen is legally prohibited from doing so or continued access would present a material security/fraud risk.

11.3 Deletion from live systems

Subject to Sections 11.4 and 11.5, RAMSGen will delete (or anonymise) Customer Personal Data from live systems within 30 days after termination/expiry of the Service, in accordance with the Customer's instructions in this DPA.

11.4 Retention of Published RAMS

The Customer instructs RAMSGen that RAMSGen may retain Published RAMS (and associated metadata) for up to 5 years after termination/expiry for legitimate business purposes such as compliance, audit trails, record-keeping, and establishing, exercising or defending legal claims. Where Published RAMS contains Customer Personal Data, that Customer Personal Data may be retained for the same period.

11.5 Backups

Customer Personal Data may be retained in backups and deleted in accordance with RAMSGen's backup cycles, typically within 90 days.

11.6 Legal retention

RAMSGen may retain Customer Personal Data to the extent required by applicable law and will ensure continued protection of such retained Customer Personal Data in accordance with this DPA.


12. Audits and Information

12.1 RAMSGen will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, in accordance with Article 28(3)(h) UK GDPR.

12.2 Audit rights

The Customer may audit RAMSGen's compliance with this DPA:

(a) no more than once per 12-month period (unless required by a competent supervisory authority or following a Personal Data Breach);

(b) on at least 30 days' prior written notice;

(c) during normal business hours; and

(d) subject to reasonable confidentiality and security restrictions.

12.3 Alternative assurance

Where reasonably sufficient, RAMSGen may satisfy audit requests by providing written responses to security questionnaires and/or relevant summaries, policies, and available third-party assurance materials (if any), instead of permitting an on-site audit.

12.4 Costs

The Customer will bear its own audit costs and will reimburse RAMSGen's reasonable internal costs in supporting any audit requested by the Customer (unless the audit identifies a material breach of this DPA by RAMSGen).


13. Restricted Data (Special Category Data and Criminal Offence Data)

13.1 Prohibition

The Service is not designed for the Processing of:

(a) Special Category Personal Data (Article 9 UK GDPR); or

(b) Personal Data relating to criminal convictions and offences (Article 10 UK GDPR).

The Customer must not submit such data to the Service.

13.2 If prohibited data is submitted

If RAMSGen becomes aware that the Customer has submitted data prohibited by Section 13.1, RAMSGen may (acting reasonably):

(a) notify the Customer;

(b) delete, block, or restrict the affected data and/or Processing; and/or

(c) suspend the relevant feature(s) or the Customer's access to the extent necessary to protect RAMSGen, the Service, and Data Subjects.


14. AI / Third-Party AI Processing (Service Functionality)

14.1 The Customer acknowledges that certain Service features (document authoring, construction phase plan authoring, and RAMS review) transmit Customer Data (including any Customer Personal Data contained in the documents the Customer uploads or authors) to RAMSGen's AI model providers in order to generate the requested output. RAMSGen calls those providers directly. There is no routing intermediary, aggregator or broker in the path, and the providers are identified in Annex 3.

14.2 RAMSGen's account with OpenAI is configured for zero data retention: prompts and generated outputs are not retained by the provider after the request is served, and are not used to train or improve the provider's models. Supporting document-analysis features run on Google Vertex AI within RAMSGen's own Google Cloud project on the EU endpoint, where Google does not use the data to train its models. The Customer acknowledges that a third-party provider's systems are not wholly within RAMSGen's control, and that these commitments rest on the providers' contractual and technical undertakings to RAMSGen.

14.3 RAMSGen does not use Customer Data to train, fine-tune or otherwise improve any AI model, whether its own or a third party's.

14.4 Outputs generated by these features are produced by an automated system and are provided for the Customer's competent person to review and adopt. They are not a substitute for the Customer's own assessment, and RAMSGen does not carry out solely automated decision-making producing legal or similarly significant effects on Data Subjects within the meaning of Articles 22A to 22D UK GDPR (as inserted by the Data (Use and Access) Act 2025).


15. Liability

15.1 The parties' liability arising out of or in connection with this DPA will be subject to the limitation of liability and exclusion of losses agreed between the parties for the Service generally (if any). Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law.


16. Term and Termination

16.1 This DPA continues in effect from the Effective Date for as long as RAMSGen processes Customer Personal Data on behalf of the Customer, and will end once RAMSGen has deleted or anonymised Customer Personal Data in accordance with this DPA (subject to any permitted retention).


17. Governing Law and Jurisdiction

17.1 This DPA (and any dispute or claim arising out of or in connection with it) is governed by the laws of England and Wales.

17.2 The courts of England and Wales have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this DPA.


Annexes


Annex 1: Details of Processing (Article 28(3))

A. Subject matter

Provision of the Service to enable the Customer to create, store, manage and export RAMS documentation and related content, including generation of drafts/outputs using AI-enabled features.

B. Duration

For the term of the Customer's use of the Service, plus the post-termination export, deletion and retention periods described in this DPA (including Sections 11.2 to 11.5).

C. Nature and purposes of Processing

Processing activities may include: collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, using, disclosing by transmission, aligning/combining, restricting, erasing, and destroying Customer Personal Data, for the purposes of:

  • providing and operating the Service and its features;
  • generating requested outputs/documents;
  • enabling collaboration within the Customer's workspace;
  • providing support and troubleshooting;
  • ensuring security, monitoring, abuse prevention, and service integrity; and
  • complying with legal obligations applicable to RAMSGen.

D. Categories of Data Subjects

May include (depending on the Customer's use): the Customer's employees, workers, contractors, agency staff, client contacts, and other individuals whose personal data the Customer includes in Customer Data.

E. Types of Personal Data

Typically: names, email addresses, phone numbers, and role/job-related details included in RAMS documents and related project/workspace content.

F. Special Category / criminal offence data

Not intended to be processed. The Customer is prohibited from submitting such data under Section 13.


Annex 2: Security Measures (Technical & Organisational Measures)

RAMSGen implements appropriate measures designed to protect Customer Personal Data. Measures may include (as appropriate):

MeasureDescription
Encryption in transitTLS for data transmitted between clients and the Service
Access controlsLeast-privilege access to systems and Customer Data
Authentication controlsVia third-party authentication services (passwords are not stored in plaintext by RAMSGen)
Logging and monitoringFor anomalous activity and security-related events
Backups and resilienceWith restoration processes and backup retention aligned to Section 11.5
Change managementSecure development practices, including deploying updates and fixes to maintain service security
Incident responseProcesses for handling suspected security incidents and Personal Data Breaches
Subprocessor securityContractual requirements for Subprocessors to maintain appropriate safeguards and process Customer Personal Data only in accordance with RAMSGen's instructions

RAMSGen may update these measures over time, provided that updates do not materially reduce the overall level of protection for Customer Personal Data.


Annex 3: Subprocessor List (Master)

The Customer authorises the engagement of the following Subprocessors (and any replacements/additions notified under Section 7.5). This Annex is the authoritative list of Subprocessors; the Terms and Privacy Policy reference this Annex rather than maintaining separate lists.

CategoryProviderLocation / RegionInternational Transfer?Notes
Infrastructure / hostingGoogle Cloud Platform (Google Cloud EMEA Limited)UK (europe-west2, London)No (UK hosting)The Service runs entirely on Google Cloud. Compute (Cloud Run), the primary database (Cloud SQL for PostgreSQL), document and file storage (Cloud Storage), secret storage (Secret Manager) and the private network (VPC) are all provisioned in europe-west2. All Customer Data at rest is held in the United Kingdom.
Application deliveryFirebase Hosting (Google)Google edge networkYes (static assets only)Serves the signed-in application's static bundle at app.tariansystems.com. Carries no Customer Data.
Network securityGoogle Cloud Armor and Cloud Load BalancingGoogle global networkIn transit only (global edge; the Service is served from europe-west2)Web application firewall, DDoS protection and TLS termination in front of the Service.
AuthenticationGoogle Cloud Identity PlatformGoogle (global)YesUser accounts, sign-in, email verification and password reset. Holds email addresses and authentication metadata only.
PaymentsStripeUSA / IrelandYesPayment processing and billing. Note: Stripe may act as an independent controller for payment card data. Customer Data within the Service is not intended to include payment card data, and RAMSGen never receives or stores card numbers.
Email deliveryResendUSAYesTransactional email delivery (invitations, trial and billing notices, review notifications, support correspondence).
AI model providerOpenAIUSAYesThe model provider for document authoring, construction phase plan authoring and RAMS review, the features a Customer uses day to day. Called directly; there is no routing intermediary. Configured for zero data retention (Section 14.2).
Google Vertex AI (Google Cloud EMEA Limited)EU multi-region endpointYes (EU, covered by UK adequacy regulations)Used by supporting document-analysis features. Runs inside RAMSGen's own Google Cloud project on the EU endpoint, under the same Google Cloud terms as the infrastructure row above, and Google does not use the data to train its models.

Not Subprocessors of the Service, listed here because earlier versions of this Annex named them or because a reader may encounter them on RAMSGen's public website:

ProviderWhy it is not in the list above
Firebase Hosting and Cloud Run (Google Cloud)Host the public marketing website tariansystems.com and its enquiry forms only, inside the same Google Cloud project as the Service. The Service runs at app.tariansystems.com; the website carries no Customer Data.
PostHogAnalytics on the public marketing website only. It is not deployed within the Service and processes no Customer Data.
Amazon Web Services, Cloudflare, Clerk, OpenRouterNamed in earlier versions of this Annex. None of them is used by the Service. They were removed on 13 August 2026.
AnthropicNamed in earlier versions as a model provider reached via OpenRouter. It is not used in that way. A Claude-on-Vertex code path exists but is not enabled in the deployed Service; were it enabled it would run inside RAMSGen's own Google Cloud project on the EU endpoint, and this Annex would be updated under Section 7.5 before it was.

Transfer safeguards

For Subprocessors located outside the UK, RAMSGen relies on appropriate UK Transfer Mechanisms as described in Section 8, which may include:

  • UK adequacy regulations (including the UK extension to the EU-US Data Privacy Framework where applicable);
  • the UK International Data Transfer Agreement (IDTA); and/or
  • contractual commitments from the Subprocessor.

Updates to this list

RAMSGen may update this Subprocessor list from time to time in accordance with Section 7.5 (notice and objection rights).