Data processing agreement

1. Scope

Subject matterHosting and processing of the Controller's data in SYSTMS
DurationFor as long as the Controller has an account, plus the 30-day export period and deletion afterwards
Nature and purposeStorage, organisation, retrieval, display, analysis (including by AI models), transmission to services the Controller connects, and deletion — to provide the Service
Types of personal dataNames, contact details, addresses, job and service history, vehicle and property details, communications, notes, photos, signatures, voice recordings and transcripts, staff records (role, pay rate, working pattern, leave, documents, time records, location at clock-in where enabled), and any other data the Controller chooses to enter
Data subjectsThe Controller's customers and their contacts, staff and contractors, suppliers, and prospects
Special category dataNot required by the Service. The Controller is responsible for any it chooses to enter, such as health information in leave or incident records

2. Processor obligations

  1. Instructions. The Processor processes personal data only on the Controller's documented instructions — these terms, and the Controller's use of the Service — unless the law requires otherwise, in which case it will tell the Controller first unless the law forbids that. It will tell the Controller if it believes an instruction breaks data protection law.
  2. Confidentiality. Everyone authorised to process the data is bound by confidentiality.
  3. Security. The Processor maintains the measures in Annex 1, appropriate to the risk.
  4. Sub-processors. The Controller authorises the sub-processors listed on our sub-processors page. The Processor will give at least 30 days' notice of a new sub-processor there and by email; the Controller may object on reasonable data protection grounds, and if the objection cannot be resolved may end the affected service with a pro-rata refund of prepaid fees. The Processor imposes data protection terms on each sub-processor equivalent to these and remains responsible for them. Services the Controller chooses to connect (such as its own Zoho, Google or Microsoft account) are the Controller's own processors or controllers, not our sub-processors.
  5. Data subject requests. The Processor will help the Controller respond to requests to exercise data subjects' rights, mainly through the Service's own tools, and will pass on any request it receives directly.
  6. Assistance. The Processor will help the Controller with security, breach notification, data protection impact assessments and consultation with the regulator, taking into account the information available to it.
  7. Breaches. The Processor will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, with the information it has and updates as it learns more.
  8. Deletion and return. At the end of the service the Controller can export its data for 30 days; the Processor then deletes it from the live service, and from backups as they are overwritten, unless the law requires it to be kept.
  9. Audit. The Processor will make available the information needed to show compliance with this agreement and allow for audits, primarily by answering written questions and providing its providers' security certifications; on-site audits by agreement, on reasonable notice, at the Controller's cost, and no more than once a year unless a breach has occurred.

3. International transfers

Where personal data is transferred outside the UK or EEA, the Processor ensures a lawful transfer mechanism: adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), or the ICO's International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.

4. Liability

Liability under this agreement is subject to the limitations in the terms of service.

Annex 1 — Security measures