SimpliSite Data Processing Agreement
Draft for solicitor review. Not yet in force.
This agreement forms part of the SimpliSite Terms of Service between [Simplinet Ltd] trading as SimpliSite ("the Processor") and the Customer ("the Controller"). It sets out the terms required by Article 28 of the UK GDPR for the personal data the Controller stores in the SimpliSite service.
1. Definitions
"Data Protection Law" means the UK GDPR and the Data Protection Act 2018 and any law that replaces them. "Customer Personal Data" means personal data contained in Customer Data as defined in the Terms. Other capitalised terms have the meaning given in the Terms.
2. Details of processing
| Subject matter | Provision of the SimpliSite field-operations software |
| Duration | The subscription term plus the retention period in the Terms |
| Nature and purpose | Storage, retrieval, display, backup and transmission of records the Controller enters, to run its business |
| Types of personal data | Names, job titles, contact details, site addresses, job notes, photographs, signatures, engineer locations and timesheets, contractor onboarding details (which may include right-to-work documents, insurance and payment details) |
| Categories of data subject | The Controller's staff and contractors, its customers and their staff, site contacts, members of the public appearing incidentally in photographs |
| Special category data | Not intended. The Controller must not upload special category or criminal offence data unless a separate written agreement covers it |
3. Processor obligations
The Processor will:
3.1 process Customer Personal Data only on the Controller's documented instructions, which are the Terms, this agreement and the Controller's use of the service, unless required to do otherwise by law, in which case it will tell the Controller first where the law allows;
3.2 ensure that people authorised to process the data are bound by confidentiality;
3.3 implement the technical and organisational measures in Annex 1;
3.4 engage sub-processors only under 4 below;
3.5 taking into account the nature of the processing, help the Controller respond to data subject requests by providing the export and deletion tools in the service and, where those are insufficient, reasonable assistance;
3.6 help the Controller meet its obligations on security, breach notification, impact assessments and consultation with the ICO, taking into account the information available to the Processor;
3.7 at the Controller's choice delete or return all Customer Personal Data at the end of the service, and delete remaining copies, unless the law requires storage; the export tool in the service and the retention periods in the Terms satisfy this;
3.8 make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller, no more than once a year on 30 days' notice unless a supervisory authority requires otherwise or a breach has occurred; and
3.9 tell the Controller immediately if it believes an instruction infringes Data Protection Law.
4. Sub-processors
4.1 The Controller gives general authorisation for the sub-processors listed in Annex 2.
4.2 The Processor will give at least 30 days' notice by email before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection the Controller may terminate the affected service with a pro rata refund.
4.3 The Processor will impose data protection obligations on each sub-processor equivalent to those in this agreement and remains liable for their performance.
5. Personal data breach
5.1 The Processor will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, giving the information the Controller needs to meet its own notification duties, and will update as further information becomes available.
6. International transfers
6.1 Customer Personal Data is stored in the United Kingdom. Any transfer outside the UK will be made only under a lawful transfer mechanism as described in the Privacy Policy.
7. Liability
7.1 The liability of each party under this agreement is subject to the limitations and exclusions in the Terms.
Annex 1: Technical and organisational measures
- Data held in Supabase Postgres in the London region with encryption at rest and TLS in transit.
- Row Level Security isolates every organisation's records at the database layer; access tokens carry the organisation and are minted only by the authentication service.
- Multi-factor authentication available to all users and required for organisation owners and administrators.
- Role-based access within an organisation (owner, admin, office, engineer, customer portal).
- Audit log of changes to core records, retained for the life of the account.
- Daily backups with point-in-time recovery; restore procedure tested at least quarterly.
- File uploads limited to approved types and size, scanned on upload.
- Sign-in protection: rate limiting, bot detection on sign-up, disposable email domains blocked.
- Secrets held in the hosting provider's encrypted store, never in source control; service credentials restricted to server-side code.
- Vulnerability management: dependencies reviewed monthly, external penetration test before launch and annually thereafter.
- Staff access to production limited to named individuals with MFA and logged.
Annex 2: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | United Kingdom (London region); support from US and EU |
| Vercel, Inc. | Application hosting and serverless functions | United Kingdom / EU edge, US support |
| Stripe Payments UK Ltd | Subscription billing and payment processing | United Kingdom / EU / US |
| Resend, Inc. | Transactional email delivery | US |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | EU region |
| Xero (UK) Ltd | Accounting integration, only where the Controller connects it | UK / NZ / US |