Data processing agreement
Between your company as the controller and the operator as the processor, covering the personal data you process in this service. It supplements the terms of use.
This document is incomplete until the operator has entered their details. It is assembled from a single source and completes itself the moment that is filled in.
1. Subject matter, duration and purpose
The subject matter is the processing of personal data you enter or upload in order to use this service. The purpose is solely to provide that service: quotes, jobs, invoices, scheduling and the communication that goes with them.
It runs for as long as your account exists and ends when the account is deleted.
2. Types of data and data subjects
What is processed is what the service provides fields for — in essence:
- Customers and enquirers: name, address, telephone, e-mail, access notes for the site, notes, jobs, quotes, invoices, payments.
- Staff: name, contact details, assignments, hours recorded, tools signed out.
- Suppliers and their contacts: name, contact details, orders.
- Your own user accounts: name, e-mail, password hash, sign-in times.
3. Processing only on your instructions
We process this data only on your documented instructions. Your use of the service is the standing instruction; anything beyond it must be given in writing. We do not use your data for our own purposes, do not pass it on, and do not train any model on it.
If we consider an instruction unlawful we will tell you, and may suspend it.
4. Confidentiality
Everyone with access to this data is bound to confidentiality. Access exists only as far as running and supporting the service requires; when we act on your account from the admin screen it is recorded in the log you can read.
5. Technical and organisational measures
We apply the measures required by Article 32 GDPR. Annex 1 describes them individually, and describes them as they are actually implemented.
6. Sub-processors
You consent to the following sub-processors. Each is bound by contract to the same standard. We will tell you before that list changes; you may object on reasonable grounds and terminate if it cannot be resolved.
- Cloudflare, Inc. — Running the service: hosting, database, file storage and AI models.
- Resend, Inc. bzw. MailChannels — Sending email: quotes, invoices, reminders, invitations, password links.
- OpenStreetMap Foundation (Nominatim) — Turning an address into coordinates for the job schedule.
- Anthropic PBC — Language model for quote estimates and text drafts — only where an API key is configured. Without one, the AI runs on Cloudflare. (only where configured)
- Google (News-RSS) und Reddit — Fetching public headlines for the daily industry digest.
7. Transfers outside the EEA
Cloudflare, Resend and Anthropic are established in the United States. Those transfers rely on the European Commission’s standard contractual clauses or on certification under the EU-US Data Privacy Framework. The database is run by Cloudflare; where the data physically sits is determined by their infrastructure.
8. Helping you answer data subjects
If a data subject comes to us directly we refer them to you and answer nothing ourselves. For access, rectification, erasure and portability the service gives you the means: the complete export under “Data”, and the delete actions in each area. Where that is not enough we help you as far as is reasonable.
9. Reporting a breach
If we become aware of a personal data breach affecting your data we tell you without undue delay and within 48 hours of becoming aware, with what we know of the details listed in Article 33(3). Reporting to the supervisory authority is yours to do; we supply what you need for it.
10. Deletion and return
When this ends we delete all of your company’s data. Deletion is requested and carried out after 30 days; within that window you can cancel it and take the full export. After that it cannot be undone. Backups held by Cloudflare expire within 30 days.
11. Evidence and audits
On request we provide the information needed to demonstrate compliance with this agreement, and allow audits. In the first instance that means answering in writing and passing on our sub-processors’ own certifications. An on-site audit is possible with reasonable notice.
Annex 1 — Technical and organisational measures
What follows is what is implemented. Where something is not implemented, that is here too — a list of measures claiming more than the service does is worse than no list.
- Access control: passwords are stored only as a PBKDF2 hash (SHA-256, 100,000 iterations, random salt), never in the clear. One-time tokens for password resets, address verification and invitations are held only as a SHA-256 hash.
- Two-step sign-in by e-mailed code is available to every account and is switched on per person.
- Tenant separation: every business table carries a company identifier and every query filters on it. The session proves membership on each request.
- Roles: costs, billing details, prices, the plan and anything that voids a document are limited to owner and admin.
- In transit: TLS only. Session cookies are httpOnly and sameSite, and secure over HTTPS.
- Logging: security-relevant changes are recorded with the value before and after, including access from the admin screen.
- Availability and recovery: the database runs on Cloudflare D1 with point-in-time recovery over 30 days.
- Data minimisation: the service does not collect special categories under Article 9 and provides no fields for them.
- Not implemented: application-level encryption of individual business data fields. That data has to be searched, sorted and summed; encryption happens at the sub-processor’s infrastructure level.
- Not implemented: external certification such as ISO 27001, and regular third-party penetration testing.
This agreement is a complete draft against Article 28(3) GDPR and has not been reviewed by a lawyer. It needs that review before it is put in front of customers.