UK GDPR / DPA 2018
LiveDPA in place with all sub-processors. Privacy policy published. Data subject rights procedures implemented.
FCA Regulatory Sandbox
AppliedApplication submitted to the FCA Regulatory Sandbox. Covers ADC loan monitoring under PS 1/26 and UK CRR.
Cyber Essentials (UK)
In ProgressApplication in progress. Controls are aligned with Cyber Essentials requirements.
ISO 27001
In ProgressControls aligned with ISO 27001 Annex A. Formal certification on our roadmap.
SOC 2 Type II
PlannedOn our roadmap as customer base scales. Available on request for Enterprise customers.
AI Sub-processor DPAs
LiveData Processing Agreements in place with OpenAI and Anthropic covering GDPR-compliant AI usage and data handling obligations.
Penetration Testing
In ProgressThird-party penetration test planned prior to Enterprise customer onboarding.
Terms of Service
Governs all use of the Mintstone platform, including user obligations, IP, liability limitations, and acceptable use.
View Terms βPrivacy Policy
How Mintstone collects, uses, stores, and protects personal data in accordance with UK GDPR and DPA 2018.
View Privacy Policy βData Processing Agreement
Article 28 UK GDPR compliant DPA. Covers sub-processor list, security measures, breach notification, and data subject rights.
View DPA βExecuted version available on request for customers
Master Services Agreement
Enterprise contract template covering service scope, SLAs, IP ownership, confidentiality, liability, and termination.
View MSA Template βExecuted version provided at contract stage
Information Security Policy
Mintstone's security controls: encryption, access controls, vulnerability management, incident response, and infrastructure security.
View Security Policy βBusiness Continuity Policy
RTO/RPO targets, backup procedures, disaster recovery scenarios, and incident severity classification.
View BCP βData Retention & Erasure Schedule
How long each category of personal data is retained, the legal basis, and deletion methods. Covers all ROPA processing activities.
View Retention Schedule βLegitimate Interests Assessments
ICO three-part test (purpose, necessity, balancing) for all processing activities relying on Article 6(1)(f) lawful basis.
View LIAs βData Protection Impact Assessments
Article 35 DPIAs for Open Banking transaction processing and AI document analysis. Completed before first customer data processed.
View DPIAs βEncryption everywhere
TLS 1.2+ in transit. AES-256 at rest across database (AWS RDS) and file storage (AWS S3, eu-west-2).
Tenant isolation
All data scoped by organisation ID at the database layer. Cross-tenant access is architecturally prevented.
Access controls
Role-based access (RBAC), MFA enforced for admin access, least-privilege principles throughout.
UK data residency
Primary infrastructure in AWS eu-west-2 (London). Data does not leave the UK/EEA without contractual safeguards.
Rate limiting & CSRF protection
All API endpoints protected against abuse, brute force, and cross-site request forgery.
Audit logging
All significant user actions logged with timestamps. Infrastructure logs retained for a minimum of 90 days.
| Provider | Service | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, database, file storage | π¬π§ UK (eu-west-2, London) |
| Vercel | Application hosting, edge compute | πΊπΈ USA (EU edge nodes available) |
| TrueLayer | Open banking, bank connection and transaction data | π¬π§ UK (FCA regulated) |
| OpenAI | AI document analysis (zero data retention API) Β· DPA in place | πΊπΈ USA (SCCs in place) |
| Anthropic | AI analysis tasks Β· DPA in place | πΊπΈ USA (SCCs in place) |
| PropertyData | Property market data | π¬π§ UK |
Regulatory status: Mintstone Ltd (Company No. 17105543) is not authorised or regulated by the Financial Conduct Authority or Prudential Regulation Authority. Mintstone provides software tools to FCA/PRA-regulated firms. All regulatory capital calculations, risk-weighted asset determinations, and submissions to the PRA remain the sole responsibility of the regulated firm. Mintstone has applied to the FCA Regulatory Sandbox; that application is currently in progress.
All enquiries
contact@mintstone.co.ukDPA, MSA, vendor questionnaires, security incidents, product questions