DATA PROCESSING AGREEMENT (DPA)
Last Updated: 27 August 2026 ICO Registration Number: ZC107930
This Data Processing Agreement ("DPA") forms part of the Agreement between:
- Mark Dodson T/A We Sweep, of Lower Moorlands, Sherburn‑in‑Elmet, LS25 6DN ("Processor", "We Sweep"); and
- The Business User using the We Sweep Platform ("Controller").
This DPA governs the Processor's processing of Customer Data on behalf of the Controller in connection with the Services.
1. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Master Terms of Service.
- Applicable Law: means the UK GDPR, the Data Protection Act 2018, and all applicable UK data protection legislation.
- Customer Data: means personal data relating to Customers processed by the Processor on behalf of the Controller.
- Data Subject: means a Customer whose personal data is processed under this DPA.
- Personal Data Breach: means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
- Sub‑processor: means any third party engaged by the Processor to process Customer Data.
- TOMs: means the technical and organisational measures set out in Annex C.
2. Roles and Scope
2.1 Controller and Processor The Controller is the Data Controller and determines the purposes and means of processing Customer Data. We Sweep acts as the Data Processor.
2.2 Documented Instructions The Processor shall process Customer Data only:
- On the Controller's documented instructions.
- As necessary to provide the Services.
- As required by Applicable Law.
Instructions are limited to those provided through the Platform or in written form. Instructions to send messages to Data Subjects are limited to transactional service communications relating to a specific booking or transaction (such as booking confirmations, appointment reminders, certificate delivery, and payment requests); marketing communications are outside the scope of the Services. The Processor may refuse instructions that are unlawful, infeasible, or outside the scope of the Services. The Processor shall inform the Controller if, in its opinion, an instruction infringes Applicable Law.
2.3 Details of Processing The subject matter, duration, nature, purpose, categories of data, and Data Subjects are set out in Annex A.
2.4 Controller‑Directed Integrations The Platform allows the Controller to connect its own accounts with certain third‑party services — currently Google Calendar and the accounting packages Xero, QuickBooks Online, and Sage Accounting ("Connected Services"). Where the Controller connects a Connected Service:
- Transmitting Customer Data to that Connected Service is a documented instruction under clause 2.2. For calendar synchronisation this comprises the Customer's name, address, and booking details; for accounting synchronisation it comprises the Customer's contact details (name, email address, phone number, address) and the related sales invoice, payment, and credit note records.
- The Connected Service processes that data under the Controller's own agreement with the relevant provider. Connected Services are engaged by the Controller, not by the Processor, and are not Sub‑processors of the Processor; clause 3.3 does not apply to them.
- The Controller is responsible for ensuring its own arrangements with each Connected Service satisfy Applicable Law, including any international transfer requirements arising from the provider's hosting locations.
- Disconnecting a Connected Service through the Platform withdraws the instruction with immediate effect: no further Customer Data is transmitted, and the stored connection credentials are deleted. Data already transmitted remains in the Connected Service under the Controller's own arrangement with that provider.
3. Processor Obligations
- 3.1 Confidentiality: The Processor shall ensure that all personnel authorised to process Customer Data are subject to binding confidentiality obligations, whether contractual or statutory. As a sole‑trader operation, the data protection contact (Mark Dodson) is personally bound by these obligations and ensures any future personnel are similarly bound before accessing Customer Data.
- 3.2 Security: The Processor shall implement appropriate technical and organisational measures ("TOMs") to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures are set out in Annex C.
- 3.3 Sub‑processors: The Controller grants a general authorisation for the Processor to engage Sub‑processors listed in Annex B. The Processor shall:
- Notify the Controller at least 30 days before adding or replacing a Sub‑processor.
- Impose equivalent data protection obligations on each Sub‑processor by written contract.
- Remain fully liable for the performance of its Sub‑processors.
- Provide the Controller with the opportunity to object to a new Sub‑processor within 14 days of notification. If the Controller objects on reasonable data protection grounds, the parties shall discuss the concern in good faith. If no resolution is reached, the Controller may terminate the Agreement.
- 3.4 Data Subject Rights: The Processor shall assist the Controller, taking into account the nature of processing, in fulfilling the Controller's obligations to respond to Data Subject rights requests. This includes providing data export and erasure tools through the Platform.
- 3.5 Breach Notification: The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
- The name and contact details of the data protection contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
- The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
- 3.6 DPIAs: The Processor shall provide reasonable assistance to the Controller with Data Protection Impact Assessments and prior consultations with the Information Commissioner's Office, taking into account the nature of processing and the information available to the Processor.
- 3.7 Return and Deletion: Upon termination of the Agreement, the Controller has 60 days to export Customer Data via the Platform's data export tools. After 60 days, the Processor shall delete all Customer Data from active systems and confirm deletion in writing. Backup copies are purged in accordance with the retention schedule in Annex D.
- 3.8 Records: The Processor shall maintain records of processing activities carried out on behalf of the Controller, in accordance with Art. 30(2) of the UK GDPR.
4. International Transfers
The Processor shall not transfer Customer Data outside the UK unless appropriate safeguards are in place, including:
- The UK Addendum to the EU Standard Contractual Clauses.
- The UK–US Data Bridge (where applicable).
- Adequacy regulations issued by the UK Government.
The Processor has conducted transfer risk assessments for each international transfer. Details of international transfers by Sub‑processors are set out in Annex B.
5. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 of the UK GDPR. The Controller or its appointed auditor may conduct audits:
- Once per year under normal circumstances.
- Following a Personal Data Breach or a reasonable suspicion of non‑compliance.
- With 30 days' written notice.
- Provided audits do not unreasonably disrupt operations.
The Processor may charge reasonable costs for on‑site audits. The Processor may satisfy audit requests by providing relevant compliance certifications, audit reports, or documentation from its Sub‑processors.
6. Controller Obligations
The Controller shall:
- Ensure Customer Data is collected lawfully, with a valid lawful basis, and that appropriate privacy notices are provided to Data Subjects.
- Provide lawful, documented instructions to the Processor.
- Not upload excessive or irrelevant personal data beyond what is necessary for the Services.
- Respond to Data Subject rights requests directed to the Controller.
- Notify the Processor promptly of any Data Subject request that requires the Processor's assistance.
The Controller indemnifies the Processor for losses arising from unlawful instructions or the Controller's breach of its obligations under Applicable Law.
7. Liability
Liability under this DPA is governed by the limitation of liability in the Master Terms. In the event of conflict between this DPA and the Master Terms on data protection matters, this DPA prevails.
8. Term and Termination
This DPA remains in force for the duration of the Agreement and until all Customer Data has been deleted or returned. The obligations in this DPA that by their nature should survive termination shall continue to apply.
9. Governing Law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
ANNEX A — DETAILS OF PROCESSING
- Subject Matter: Provision of a SaaS platform for chimney sweep businesses, including online booking, customer management, job documentation, certificate generation, and payment processing.
- Duration: The duration of the Agreement plus 60 days following termination.
- Nature and Purpose: Facilitating bookings, generating safety certificates, storing job documentation (photos and inspection records), sending transactional notifications by email and — where enabled by the Controller — transactional service messages by SMS (e.g. appointment reminders), deriving geographic coordinates from postcodes for scheduling and route planning, processing card payments, recording payments made directly to the Controller (cash or bank transfer), and — where the Controller connects accounting software under clause 2.4 — transmitting customer contact details and sales invoice, payment, and credit note records to the Controller's own Xero, QuickBooks Online, or Sage account. Where the Controller enables its customer referral scheme, processing also comprises generating Customer referral codes, recording referrals between Customers, notifying the referring Customer of a successful referral (without naming the referred Customer), and applying reward credits as discounts to bookings.
- Categories of Personal Data: Name, address, email, phone number (including mobile number where SMS is enabled), geographic coordinates derived from postcode, appliance details, chimney type, booking and inspection notes, photographs (taken by the Controller's technicians or uploaded voluntarily by the Customer when booking; embedded metadata such as GPS location is removed on upload), certificate data, payment method and payment status records, payment transaction references, referral data where the Controller enables its customer referral scheme (unique referral code, the link between a referred Customer and the Customer who referred them, referral counts, and reward credit records with amounts, status, and dates), and — where accounting software is connected — sales invoice, payment, and credit note records associating a Customer with services received and amounts paid.
- Data Subjects: Homeowners and Customers of the Controller who book or receive chimney sweeping or related services.
ANNEX B — AUTHORISED SUB‑PROCESSORS
| Sub‑processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Supabase | Database & infrastructure | All Customer Data | EU/UK/USA | UK Addendum to EU SCCs |
| Vercel | Frontend hosting | Encrypted session data only | Global | UK Addendum to EU SCCs |
| Postmark | Transactional email | Name, email, booking details | USA | UK–US Data Bridge |
| The SMS Works Ltd | Transactional SMS (service messages, e.g. appointment reminders) | Mobile number, appointment message content (business name, service, date and time) | UK | Not applicable (UK processing) |
| Stripe | Payment processing | Name, email, payment references | UK/USA | UK–US Data Bridge |
| Google Maps | Address lookup & routing | Address, postcode | Global | UK Addendum to EU SCCs |
The SMS Works retains message delivery reports on its own systems for 90 days, with archived records held for up to 7 years, under its own retention policy.
Connected Services that the Controller links to its own third‑party accounts — Google Calendar and the accounting packages Xero, QuickBooks Online, and Sage Accounting — are not Sub‑processors and are therefore not listed above. They receive Customer Data at the Controller's direction and process it under the Controller's own agreement with the relevant provider. See clause 2.4.
ANNEX C — TECHNICAL & ORGANISATIONAL MEASURES (TOMs)
- Access Control: Role‑based access controls, multi‑factor authentication (MFA) for all administrative access, and principle of least privilege. Schema‑per‑tenant database isolation prevents cross‑tenant data access.
- Encryption: TLS 1.2+ for all data in transit. AES‑256 encryption for data at rest. OAuth tokens for Connected Services (Google Calendar and accounting software) encrypted with dedicated encryption keys.
- Logging & Monitoring: Continuous monitoring and audit logs for authentication events, data access, and administrative actions. Platform audit log retained for 2 years.
- Data Integrity: Input validation and sanitisation on all API endpoints. Checksums and validation for stored files.
- Backup: Regular encrypted backups with tested restoration procedures.
- Physical Security: Data centres operated by certified providers (ISO 27001, SOC 2 Type II).
- Development: Secure development lifecycle, dependency scanning, and code review. Rate limiting on all public endpoints.
- Incident Response: Documented data breach response plan with defined escalation procedures and 48‑hour notification commitment.
ANNEX D — DATA RETENTION SCHEDULE
| Data Category | Retention Period | Basis |
|---|---|---|
| Customer Data | Duration of Agreement + 60 days post‑termination | Contractual necessity |
| Business User Account Data | Duration of account | Contract |
| Financial Transaction Data | 7 years | HMRC legal obligation |
| Platform Audit Logs | 2 years | Legitimate interests / Legal obligation |
| Security Logs | 12 months | Legitimate interests |
| API Usage Logs | 90 days | Legitimate interests |
| Magic Link Tokens | 1 hour (single use) | Security necessity |
| Geocoding Cache (coordinates only, no identifiers) | 30 days | Legitimate interests |
| Rate Limit Records | 24 hours | Legitimate interests |
| Data Export Files | 7 days | Data portability |
| Connected Service Tokens (calendar & accounting) | Until integration disconnected by Controller | Contract |
| Accounting sync document snapshots | Personal data removed 30 days after successful transmission; the transmission record (references, amounts, status) is retained for the duration of the Agreement | Contract / Legitimate interests |
Automated cleanup mechanisms enforce these retention periods. Details are documented in the internal Data Retention Policy.