Legal

SERODIN Data Processing Agreement

This Data Processing Agreement governs the Controller and Processor relationship between the SERODIN customer and LEDUSTRA LTD in respect of personal data contained in documents submitted to SERODIN for anonymisation.

Last updated: 8 September 2026

Issued by

LEDUSTRA LTD

Company number: 16783014

Registered office: 49 New Road, Eastleigh, England, SO50 8EN

ICO registration number: ZC114830

LEDUSTRA LTD forms part of Legistra® Group Limited.

  1. 1.Parties

    This Data Processing Agreement (the “DPA”) is made between the SERODIN customer (the “Customer”) and LEDUSTRA LTD.

    • LEDUSTRA LTD
    • Company number: 16783014
    • Registered office: 49 New Road, Eastleigh, England, SO50 8EN
    • ICO registration number: ZC114830

    LEDUSTRA LTD forms part of Legistra® Group Limited.

    In relation to the processing governed by this DPA, the Customer acts as Controller and LEDUSTRA LTD acts as Processor. This DPA applies only to personal data contained in documents submitted to SERODIN for anonymisation.

  2. 2.Scope

    This DPA applies only to Customer Document Data processed through the SERODIN anonymisation service. It does not govern any other processing carried out by LEDUSTRA LTD.

    The Customer determines which document is submitted, what information that document contains, and the purpose for which the anonymisation is carried out.

    LEDUSTRA LTD processes the submitted document only in order to provide the anonymisation service to the Customer.

    Account data, billing data, support data and marketing data fall outside the scope of this DPA.

  3. 3.Definitions

    • “Controller” means the party that determines the purposes and means of the processing.
    • “Processor” means the party that processes personal data on behalf of the Controller.
    • “Personal Data” means any information relating to an identified or identifiable natural person.
    • “Processing” means any operation performed on personal data, whether or not by automated means.
    • “Data Subject” means the individual to whom personal data relates.
    • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
    • “Subprocessor” means a processor engaged by LEDUSTRA LTD to carry out processing activities on behalf of the Customer.
    • “Customer Document Data” means personal data and other identifying information contained in documents submitted by the Customer to SERODIN for anonymisation.
  4. 4.Subject matter and purpose of processing

    The sole purpose of the processing under this DPA is to provide the SERODIN document anonymisation service requested by the Customer.

    To that end, the processing comprises:

    • receipt of the Customer document
    • temporary technical storage
    • reading or extraction of content
    • optical character recognition (OCR) where required
    • transmission of extracted text between SERODIN processing components
    • detection of identifying information
    • replacement of detected information with [SERODIN]
    • generation of the protected document
    • return of the protected document to the Customer
  5. 5.Nature of processing

    The processing operations carried out are limited to those necessary to deliver the anonymisation service, namely:

    • receipt
    • temporary storage
    • access
    • reading
    • extraction
    • OCR
    • transmission between internal processing components
    • detection
    • replacement
    • transformation
    • generation
    • return
    • deletion
  6. 6.Duration and temporary storage

    The source document is stored temporarily while the anonymisation is performed. Temporary page images may be created where OCR or redaction requires them.

    Source documents and temporary processing files are deleted after processing. The protected output is stored temporarily so that the Customer can download it.

    Under the current configuration, temporary working files and downloadable output files are automatically cleaned up when older than one hour.

    Customer documents are not retained as long-term Customer records, and the six-year contractual and business retention period applied to other records does not apply to Customer Document Data.

  7. 7.Types of personal data

    Personal data and other identifying information contained in documents selected and submitted by the Customer for anonymisation.

    The exact content of the personal data processed depends entirely on the document chosen and submitted by the Customer, and is not determined by LEDUSTRA LTD.

  8. 8.Categories of data subjects

    Individuals whose personal data or identifying information is contained in documents submitted by the Customer.

  9. 9.Customer instructions

    Submission of a document to SERODIN constitutes a documented instruction from the Customer to process that document for the purpose of anonymisation.

    LEDUSTRA LTD processes Customer Document Data only on the instructions of the Customer. Processing for any other purpose is prohibited unless required by law.

    Where law requires LEDUSTRA LTD to process Customer Document Data differently, it will inform the Customer of that legal requirement before processing, unless the law prohibits such information.

  10. 10.Customer responsibilities

    As Controller, the Customer is responsible for:

    • establishing and maintaining a lawful basis for the processing
    • having the authority to submit the document to SERODIN
    • providing any privacy information required to Data Subjects
    • complying with its own obligations as Controller under applicable data protection law
    • deciding whether use of SERODIN is appropriate for a given document
  11. 11.Processor obligations

    LEDUSTRA LTD undertakes, in relation to Customer Document Data:

    • to process only on the documented instructions of the Customer
    • to maintain confidentiality
    • to implement appropriate technical and organisational measures
    • to put appropriate arrangements in place with any subprocessor
    • to assist with Data Subject rights requests where required
    • to assist in connection with Personal Data Breaches
    • to assist with Data Protection Impact Assessments and prior consultation with a supervisory authority where applicable
    • to make available information reasonably necessary to demonstrate compliance with this DPA
    • to delete or return Customer Document Data after processing
  12. 12.Confidentiality

    Access to Customer Document Data is limited to those authorised persons and systems required to operate, maintain, secure or provide the SERODIN service.

    Authorised personnel are subject to confidentiality obligations in respect of Customer Document Data.

  13. 13.Security

    Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of Data Subjects, LEDUSTRA LTD implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

    Those measures include:

    • authentication
    • access controls
    • restricted administrative access
    • secure transmission
    • secure handling of credentials and secrets
    • infrastructure security
    • monitoring
    • security logging
    • software maintenance and updates
    • incident-response procedures

    LEDUSTRA LTD does not claim any certification in respect of these measures, and no method of processing or transmission can be guaranteed to be absolutely secure.

  14. 14.Subprocessors

    The Customer gives a general authorisation for LEDUSTRA LTD to engage subprocessors required to operate the SERODIN service.

    Where a subprocessor processes Customer Document Data, LEDUSTRA LTD ensures that appropriate contractual data protection obligations apply to that subprocessor, and remains responsible to the Customer for its performance.

    Engagement of a service provider does not imply that the provider processes Customer Document Data.

  15. 15.Relevant infrastructure providers

    • Railway — infrastructure used to host relevant SERODIN backend, OCR, analysis and anonymisation processing services.
    • Lovable — application and platform infrastructure used for relevant SERODIN application functions.

    Not every provider used by LEDUSTRA LTD receives Customer Document Data. Stripe is used for payments and subscriptions, Brevo is used for newsletter and communications, and GitHub is used for source-code hosting and development.

    These providers do not receive Customer Document Data merely because SERODIN uses them, and Customer documents are not intentionally stored in GitHub as part of the normal SERODIN document-processing workflow.

  16. 16.International transfers

    Where Customer Document Data is transferred outside the United Kingdom and a transfer safeguard is required, LEDUSTRA LTD will use an appropriate lawful transfer mechanism, which may include UK adequacy regulations, recognised contractual safeguards, Standard Contractual Clauses together with the UK International Data Transfer Addendum, or another lawful transfer mechanism.

  17. 17.Data subject assistance

    The Customer remains responsible for responding to Data Subject requests relating to Customer Document Data.

    LEDUSTRA LTD will provide reasonable assistance to the Customer, taking into account the nature of the processing, its technical capability and the information available to it.

  18. 18.Personal data breaches

    If LEDUSTRA LTD becomes aware of a Personal Data Breach affecting Customer Document Data, it will notify the Customer without undue delay where required by law, providing the information reasonably available to it at the time.

    The Customer remains responsible for deciding whether notification to the Information Commissioner's Office, another supervisory authority or affected individuals is required.

  19. 19.DPIA and regulatory assistance

    LEDUSTRA LTD will provide reasonable assistance to the Customer with Data Protection Impact Assessments and with prior consultation with a supervisory authority, where required and relevant to the processing performed through SERODIN.

  20. 20.Return and deletion

    Customer Document Data is not retained as long-term Customer records.

    Source documents and temporary processing files are deleted in accordance with the SERODIN processing workflow, and protected outputs are retained only temporarily to enable the Customer to download them.

    Any remaining Customer Document Data is deleted or returned after the relevant processing relationship ends, unless law requires its retention.

  21. 21.Audit and information rights

    LEDUSTRA LTD will make available to the Customer the information reasonably necessary to demonstrate compliance with its obligations under this DPA.

    Where an audit is legally required, it may be conducted subject to reasonable notice, confidentiality, system security, protection of the personal data and confidentiality of other customers, proportionality, and minimisation of disruption to the service.

    Where documentation provided by LEDUSTRA LTD is sufficient to demonstrate compliance, that documentation will be used in preference to intrusive access to systems.

  22. 22.Unlawful instructions

    If LEDUSTRA LTD considers that an instruction from the Customer infringes applicable data protection law, it will inform the Customer unless prohibited by law from doing so.

    LEDUSTRA LTD may suspend the affected processing until the issue is resolved.

  23. 23.Term and termination

    This DPA remains in force for as long as LEDUSTRA LTD processes Customer Document Data on behalf of the Customer.

    After processing ends, the obligations relating to deletion or return of Customer Document Data and to confidentiality continue for as long as necessary.

  24. 24.Precedence

    If this DPA conflicts with the SERODIN Terms of Use specifically in relation to Processor activities involving Customer Document Data, this DPA takes precedence.

  25. 25.Governing law

    This DPA is governed by the laws of England and Wales.

    The courts of England and Wales shall have jurisdiction, subject to mandatory provisions of applicable data protection law.

  26. 26.Contact

    LEDUSTRA LTD / SERODIN, 49 New Road, Eastleigh, England, SO50 8EN.

    • Company number: 16783014
    • ICO registration number: ZC114830
    • General: hello@serodin.com
    • Support: support@serodin.com
    • Privacy: privacy@serodin.com
  27. 27.Schedule 1 — Details of processing

    Controller: The SERODIN Customer.

    Processor: LEDUSTRA LTD.

    Subject matter: Processing of Customer Document Data for SERODIN document anonymisation.

    Purpose: To detect identifying information, replace detected information with [SERODIN], generate a protected document and return it to the Customer.

    Nature: Receipt, temporary storage, reading, extraction, OCR where necessary, transmission between SERODIN processing components, detection, replacement, transformation, generation, return and deletion.

    Duration: For the period technically necessary to perform the requested anonymisation. Under the current configuration, temporary working files and downloadable output files are automatically cleaned up when older than one hour.

    Personal Data: Personal data and identifying information contained in documents selected and submitted by the Customer.

    Data Subjects: Individuals whose personal data or identifying information is contained in documents submitted by the Customer.

  28. 28.Schedule 2 — Technical and organisational measures

    • controlled system access
    • authentication
    • restricted administrative privileges
    • secure transmission
    • secure credentials and secrets
    • infrastructure-level protections
    • technical monitoring
    • security-related logging
    • software maintenance and updates
    • confidentiality obligations
    • security incident procedures

Contact: hello@serodin.com · support@serodin.com · privacy@serodin.com