Data processing agreement
How SYSTMS processes personal data on behalf of the businesses that use it, under Article 28 of the UK GDPR.
This agreement forms part of the terms of service between SYSTMS ("Processor") and the business using SYSTMS ("Controller"). It meets Article 28 of the UK GDPR and, where it applies, the EU GDPR. If it conflicts with the terms on data protection, this agreement prevails.
1. Scope
| Subject matter | Hosting and processing of the Controller's data in SYSTMS |
|---|---|
| Duration | For as long as the Controller has an account, plus the 30-day export period and deletion afterwards |
| Nature and purpose | Storage, organisation, retrieval, display, analysis (including by AI models), transmission to services the Controller connects, and deletion — to provide the Service |
| Types of personal data | Names, contact details, addresses, job and service history, vehicle and property details, communications, notes, photos, signatures, voice recordings and transcripts, staff records (role, pay rate, working pattern, leave, documents, time records, location at clock-in where enabled), and any other data the Controller chooses to enter |
| Data subjects | The Controller's customers and their contacts, staff and contractors, suppliers, and prospects |
| Special category data | Not required by the Service. The Controller is responsible for any it chooses to enter, such as health information in leave or incident records |
2. Processor obligations
- Instructions. The Processor processes personal data only on the Controller's documented instructions — these terms, and the Controller's use of the Service — unless the law requires otherwise, in which case it will tell the Controller first unless the law forbids that. It will tell the Controller if it believes an instruction breaks data protection law.
- Confidentiality. Everyone authorised to process the data is bound by confidentiality.
- Security. The Processor maintains the measures in Annex 1, appropriate to the risk.
- Sub-processors. The Controller authorises the sub-processors listed on our sub-processors page. The Processor will give at least 30 days' notice of a new sub-processor there and by email; the Controller may object on reasonable data protection grounds, and if the objection cannot be resolved may end the affected service with a pro-rata refund of prepaid fees. The Processor imposes data protection terms on each sub-processor equivalent to these and remains responsible for them. Services the Controller chooses to connect (such as its own Zoho, Google or Microsoft account) are the Controller's own processors or controllers, not our sub-processors.
- Data subject requests. The Processor will help the Controller respond to requests to exercise data subjects' rights, mainly through the Service's own tools, and will pass on any request it receives directly.
- Assistance. The Processor will help the Controller with security, breach notification, data protection impact assessments and consultation with the regulator, taking into account the information available to it.
- Breaches. The Processor will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, with the information it has and updates as it learns more.
- Deletion and return. At the end of the service the Controller can export its data for 30 days; the Processor then deletes it from the live service, and from backups as they are overwritten, unless the law requires it to be kept.
- Audit. The Processor will make available the information needed to show compliance with this agreement and allow for audits, primarily by answering written questions and providing its providers' security certifications; on-site audits by agreement, on reasonable notice, at the Controller's cost, and no more than once a year unless a breach has occurred.
3. International transfers
Where personal data is transferred outside the UK or EEA, the Processor ensures a lawful transfer mechanism: adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), or the ICO's International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.
4. Liability
Liability under this agreement is subject to the limitations in the terms of service.
Annex 1 — Security measures
- Encryption in transit (TLS) for all traffic; encryption at rest provided by the hosting platform.
- Tenant isolation: every read and write of a business's records goes through server-side gateways that check the requester's membership and role; records are locked to their company at the database level.
- Role-based access: management-only data (finance, automations, forecasts, marketing, staff administration) is refused to field and office roles on the server, whatever the browser shows.
- Secrets management: API keys, OAuth tokens and webhook secrets are held in the backend secret store or service-role-only tables and never returned to a browser.
- Webhook signature verification for inbound integrations.
- Least-privilege access by our own staff, only to support a customer or maintain the Service.
- Authentication by the hosting platform, with salted password hashing.
- Logging of access and errors for security monitoring.
- Backups maintained by the hosting platform.