DATA PROCESSING AGREEMENT (DPA)
Last Updated: 19 March 2026 ICO Registration Number: ZC107930
This Data Processing Agreement ("DPA") forms part of the Agreement between:
- Mark Dodson T/A We Sweep, of Lower Moorlands, Sherburn‑in‑Elmet, LS25 6DN ("Processor", "We Sweep"); and
- The Business User using the We Sweep Platform ("Controller").
This DPA governs the Processor's processing of Customer Data on behalf of the Controller in connection with the Services.
1. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Master Terms of Service.
- Applicable Law: means the UK GDPR, the Data Protection Act 2018, and all applicable UK data protection legislation.
- Customer Data: means personal data relating to Customers processed by the Processor on behalf of the Controller.
- Data Subject: means a Customer whose personal data is processed under this DPA.
- Personal Data Breach: means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
- Sub‑processor: means any third party engaged by the Processor to process Customer Data.
- TOMs: means the technical and organisational measures set out in Annex C.
2. Roles and Scope
2.1 Controller and Processor The Controller is the Data Controller and determines the purposes and means of processing Customer Data. We Sweep acts as the Data Processor.
2.2 Documented Instructions The Processor shall process Customer Data only:
- On the Controller's documented instructions.
- As necessary to provide the Services.
- As required by Applicable Law.
Instructions are limited to those provided through the Platform or in written form. The Processor may refuse instructions that are unlawful, infeasible, or outside the scope of the Services. The Processor shall inform the Controller if, in its opinion, an instruction infringes Applicable Law.
2.3 Details of Processing The subject matter, duration, nature, purpose, categories of data, and Data Subjects are set out in Annex A.
3. Processor Obligations
- 3.1 Confidentiality: The Processor shall ensure that all personnel authorised to process Customer Data are subject to binding confidentiality obligations, whether contractual or statutory. As a sole‑trader operation, the data protection contact (Mark Dodson) is personally bound by these obligations and ensures any future personnel are similarly bound before accessing Customer Data.
- 3.2 Security: The Processor shall implement appropriate technical and organisational measures ("TOMs") to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are set out in Annex C.
- 3.3 Sub‑processors: The Controller grants a general authorisation for the Processor to engage Sub‑processors listed in Annex B. The Processor shall:
- Notify the Controller at least 30 days before adding or replacing a Sub‑processor.
- Impose equivalent data protection obligations on each Sub‑processor by written contract.
- Remain fully liable for the performance of its Sub‑processors.
- Provide the Controller with the opportunity to object to a new Sub‑processor within 14 days of notification. If the Controller objects on reasonable data protection grounds, the parties shall discuss the concern in good faith. If no resolution is reached, the Controller may terminate the Agreement.
- 3.4 Data Subject Rights: The Processor shall assist the Controller, taking into account the nature of processing, in fulfilling the Controller's obligations to respond to Data Subject rights requests. This includes providing data export and erasure tools through the Platform.
- 3.5 Breach Notification: The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
- The name and contact details of the data protection contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
- The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
- 3.6 DPIAs: The Processor shall provide reasonable assistance to the Controller with Data Protection Impact Assessments and prior consultations with the Information Commissioner's Office, taking into account the nature of processing and the information available to the Processor.
- 3.7 Return and Deletion: Upon termination of the Agreement, the Controller has 60 days to export Customer Data via the Platform's data export tools. After 60 days, the Processor shall delete all Customer Data from active systems and confirm deletion in writing. Backup copies are purged in accordance with the retention schedule in Annex D.
- 3.8 Records: The Processor shall maintain records of processing activities carried out on behalf of the Controller, in accordance with Art. 30(2) of the UK GDPR.
4. International Transfers
The Processor shall not transfer Customer Data outside the UK unless appropriate safeguards are in place, including:
- The UK Addendum to the EU Standard Contractual Clauses.
- The UK–US Data Bridge (where applicable).
- Adequacy regulations issued by the UK Government.
The Processor has conducted transfer risk assessments for each international transfer. Details of international transfers by Sub‑processors are set out in Annex B.
5. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 of the UK GDPR. The Controller or its appointed auditor may conduct audits:
- Once per year under normal circumstances.
- Following a Personal Data Breach or a reasonable suspicion of non‑compliance.
- With 30 days' written notice.
- Provided audits do not unreasonably disrupt operations.
The Processor may charge reasonable costs for on‑site audits. The Processor may satisfy audit requests by providing relevant compliance certifications, audit reports, or documentation from its Sub‑processors.
6. Controller Obligations
The Controller shall:
- Ensure Customer Data is collected lawfully, with a valid lawful basis, and that appropriate privacy notices are provided to Data Subjects.
- Provide lawful, documented instructions to the Processor.
- Not upload excessive or irrelevant personal data beyond what is necessary for the Services.
- Respond to Data Subject rights requests directed to the Controller.
- Notify the Processor promptly of any Data Subject request that requires the Processor's assistance.
The Controller indemnifies the Processor for losses arising from unlawful instructions or the Controller's breach of its obligations under Applicable Law.
7. Liability
Liability under this DPA is governed by the limitation of liability in the Master Terms. In the event of conflict between this DPA and the Master Terms on data protection matters, this DPA prevails.
8. Term and Termination
This DPA remains in force for the duration of the Agreement and until all Customer Data has been deleted or returned. The obligations in this DPA that by their nature should survive termination shall continue to apply.
9. Governing Law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
ANNEX A — DETAILS OF PROCESSING
- Subject Matter: Provision of a SaaS platform for chimney sweep businesses, including online booking, customer management, job documentation, certificate generation, and payment processing.
- Duration: The duration of the Agreement plus 60 days following termination.
- Nature and Purpose: Facilitating bookings, generating safety certificates, storing job documentation (photos and inspection records), sending transactional notifications (booking confirmations, reminders, status updates), and processing payments.
- Categories of Personal Data: Name, address, email, phone number, appliance details, chimney type, inspection notes, photographs, certificate data, and payment transaction references.
- Data Subjects: Homeowners and Customers of the Controller who book or receive chimney sweeping or related services.
ANNEX B — AUTHORISED SUB‑PROCESSORS
| Sub‑processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Supabase | Database & infrastructure | All Customer Data | EU/UK/USA | UK Addendum to EU SCCs |
| Vercel | Frontend hosting | Encrypted session data only | Global | UK Addendum to EU SCCs |
| Postmark | Transactional email | Name, email, booking details | USA | UK–US Data Bridge |
| Stripe | Payment processing | Name, email, payment references | UK/USA | UK–US Data Bridge |
| Google Maps | Address lookup & routing | Address, postcode | Global | UK Addendum to EU SCCs |
| Google Calendar | Calendar synchronisation | Name, address, booking date/time, service type | Global | UK Addendum to EU SCCs |
ANNEX C — TECHNICAL & ORGANISATIONAL MEASURES (TOMs)
- Access Control: Role‑based access controls, multi‑factor authentication (MFA) for all administrative access, and principle of least privilege. Schema‑per‑tenant database isolation prevents cross‑tenant data access.
- Encryption: TLS 1.2+ for all data in transit. AES‑256 encryption for data at rest. Google OAuth refresh tokens encrypted with a dedicated encryption key.
- Logging & Monitoring: Continuous monitoring and audit logs for authentication events, data access, and administrative actions. Platform audit log retained for 2 years.
- Data Integrity: Input validation and sanitisation on all API endpoints. Checksums and validation for stored files.
- Backup: Regular encrypted backups with tested restoration procedures.
- Physical Security: Data centres operated by certified providers (ISO 27001, SOC 2 Type II).
- Development: Secure development lifecycle, dependency scanning, and code review. Rate limiting on all public endpoints.
- Incident Response: Documented data breach response plan with defined escalation procedures and 48‑hour notification commitment.
ANNEX D — DATA RETENTION SCHEDULE
| Data Category | Retention Period | Basis |
|---|---|---|
| Customer Data | Duration of Agreement + 60 days post‑termination | Contractual necessity |
| Business User Account Data | Duration of account | Contract |
| Financial Transaction Data | 7 years | HMRC legal obligation |
| Platform Audit Logs | 2 years | Legitimate interests / Legal obligation |
| Security Logs | 12 months | Legitimate interests |
| API Usage Logs | 90 days | Legitimate interests |
| Magic Link Tokens | 15 minutes (session) / 1 hour (auth) | Security necessity |
| Rate Limit Records | 24 hours | Legitimate interests |
| Data Export Files | 7 days | Data portability |
| Calendar Sync Tokens | Until integration removed by Controller | Contract |
Automated cleanup mechanisms enforce these retention periods. Details are documented in the internal Data Retention Policy.