Data Processing Agreement

Last updated: {{EFFECTIVE_DATE}}

This Data Processing Agreement ("DPA") forms part of the Terms of Service between {{COMPANY_LEGAL_NAME}} ("Processor", "we") and the Customer ("Controller", "you"). It governs our processing of personal data on your behalf when you use the Estate Ops Service, and is designed to meet Article 28 of the UK GDPR.

If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "special category data" have the meanings given in the UK GDPR. "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations, in each case as amended.

2. Roles and scope

2.1 You are the controller and we are the processor of the Customer Data described in Annex 1. For some account, billing and diagnostic data we act as a separate controller, as explained in our Privacy Policy; that data is outside this DPA.

2.2 We will process personal data only: (a) to provide and support the Service; and (b) on your documented instructions, which include the Terms, this DPA, and your configuration and use of the Service. If we believe an instruction breaches Data Protection Laws, we will tell you (unless legally prevented).

2.3 If we are required by law to process personal data otherwise than on your instructions, we will inform you first unless the law prohibits it.

3. Your obligations

You warrant that: (a) you have a lawful basis for the processing you instruct, including for any special category or safety data and for location and lone-worker monitoring; (b) you have given any notices and (where required) obtained any consents or conducted any consultation needed; and (c) your instructions comply with Data Protection Laws.

4. Confidentiality

We ensure that people authorised to process Customer Data are bound by appropriate confidentiality obligations and process the data only as needed to perform the Service.

5. Security

We implement and maintain the technical and organisational measures described in Annex 2, appropriate to the risk, taking into account the nature of the data (including safety and location data). We may update these measures provided protection is not materially reduced.

6. Sub-processors

6.1 You give general authorisation for us to engage sub-processors to deliver the Service. The current sub-processors are listed at Sub-processors, which is incorporated into this DPA.

6.2 We impose data protection obligations on each sub-processor that are substantially equivalent to those in this DPA, and we remain responsible for their performance.

6.3 We will give you reasonable advance notice (by updating the Sub-processors page and, where you subscribe, by notification) before adding or replacing a sub-processor, so you may object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the Service.

7. Assistance with data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects to exercise their rights. If a data subject contacts us directly, we will (unless legally required to act) refer them to you or forward the request.

8. Assistance with compliance

We will assist you, taking into account the nature of processing and the information available to us, with: security (clause 5); personal data breaches (clause 9); data protection impact assessments; and prior consultation with the ICO.

9. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will include the information reasonably available to help you meet your own breach obligations, and we will provide updates as more information becomes known and take reasonable steps to mitigate the breach.

10. Deletion and return

On termination or expiry of the Service, and on your written request, we will make Customer Data available for export for a limited period and then delete or anonymise it, unless Data Protection Laws require us to retain it. Backups are deleted in the ordinary course of our backup cycle.

11. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, no more than once a year (unless a regulator requires more, or following a breach), on reasonable notice, during business hours, subject to confidentiality, and without unreasonably disrupting our operations. We may satisfy audit requests by providing relevant third-party certifications and reports where available.

12. International transfers

We will not transfer Customer Data outside the UK except where a transfer mechanism recognised under Data Protection Laws is in place (for example the UK IDTA or the UK Addendum to the EU Standard Contractual Clauses) together with any supplementary measures needed. Current transfer locations are indicated on the Sub-processors page.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.


Annex 1 — Details of processing

clause 10.

and deletion of Customer Data to operate estate-management and field-safety features, including messaging, push notifications and SOS dispatch.

addresses, roles, department, estate); contact data (phone numbers of safety contacts); location data (map-pin coordinates and history, lone-worker session location, SOS location); safety/incident data (SOS events, lone-worker check-ins, fall alerts); photographs and media; device tokens and technical/usage data.

but safety and incident data may reveal information about a person's health or wellbeing. You are responsible for any Article 9 condition.

authorised family safety contacts, visitors, and other individuals whose data you choose to record.

Annex 2 — Security measures

devices.

access controls and monitoring.

Annex 3 — Sub-processors

The current list of sub-processors, their function and location is maintained at Sub-processors and forms part of this Annex.


Signing

This DPA takes effect on the date you accept the Terms or first use the Service. For a counter-signed copy, contact {{LEGAL_EMAIL}}.