← Back to vault-hire.com Legal & Compliance Library · public artefacts

Everything your procurement team needs.
In one place.

The four documents banking procurement and DPO teams ask for in week one of a vendor review. Each one is publicly accessible, versioned, and printable. Where a question requires confidential mechanism detail, the public document signposts to our NDA-gated security briefing — that boundary is intentional.

I

Instructions for Use

EU AI Act Article 13 — purpose, capabilities, limitations, human oversight, lifetime, performance metrics. The first artefact a deployer's AI-governance team will ask for.

8 sections · v1.0 · Feb 2026
D

Data Processing Agreement

UK GDPR Article 28 — controller / processor obligations, sub-processors, transfer mechanisms, return / deletion, audit rights. Ready to counter-sign.

12 clauses · v1.0 · Feb 2026
S

Sub-processor list

Every third party that processes personal data on our behalf — purpose, region, transfer mechanism, replacement notice. Re-published when anything changes.

Live list · last updated Feb 2026
P

DPIA template (for deployers)

UK GDPR Article 35 + EU AI Act Article 27 — pre-filled Data Protection Impact Assessment template the deploying customer can adapt. Mapped to ICO guidance.

11 sections · fillable

Need something more specific?

For our SOC 2 Type I readiness statement, pen-test summary, region map, or signed SCC / UK IDTA — request our full trust pack from trust@vault-hire.com. Replies typically within 1 working day.