Data Processing Agreement
This agreement forms part of the Terms of Service between Corley Marsh, trading as Upcraftly, 125 Rowney Avenue, Saffron Walden, CB10 2YE ("Processor") and the business using Upcraftly ("Controller"), and meets the requirements of Article 28 of the UK GDPR.
1. Scope
Subject matter: providing the Upcraftly booking service. Duration: the life of the subscription plus any deletion period. Nature and purpose: storing and processing booking, customer and form records, and sending booking emails. Data subjects: the Controller's customers and staff. Personal data: names, contact details, booking history, notes and form answers. Special-category data only if the Controller chooses to collect it.
2. Processor obligations
- Process personal data only on the Controller's documented instructions (including by using the service's features), unless the law requires otherwise.
- Make sure people authorised to process the data are bound by confidentiality.
- Keep appropriate technical and organisational security measures, including encryption in transit, hashed passwords, tenant separation, access controls and audit logs.
- Help the Controller respond to data subject requests, for example by providing export and deletion-request tools.
- Help the Controller with security, breach notification and data protection impact assessments, taking into account the information available to the Processor.
- Notify the Controller without undue delay, and within 48 hours where possible, after becoming aware of a personal data breach.
- At the end of the service, delete or return the personal data at the Controller's choice, unless the law requires it to be kept.
- Make available the information needed to show compliance with this agreement, and allow for reasonable audits.
3. Sub-processors
The Controller authorises the following sub-processors: Cloudflare, Inc. (hosting and database); Stripe Payments UK Ltd / Stripe, Inc. (payments); Resend (email delivery). The Processor will give at least 30 days' notice of new sub-processors, and the Controller may object. The Processor imposes data protection terms on each sub-processor that are no less protective than these.
4. International transfers
Where personal data is transferred outside the UK, the Processor makes sure an appropriate safeguard is in place, such as the UK International Data Transfer Addendum or an adequacy decision.
5. Controller obligations
The Controller is responsible for having a lawful basis for the processing, giving privacy information to its customers, and deciding what data to collect.
Contact for data protection matters: info@upcraftly.co.uk.