This Data Processing Addendum (DPA) forms part of the Terms of Service between Gareth Williams t/a TradesOps.uk (TradesOps, 5 Barcote Close, Swindon SN25 2BH) (TradesOps, the Processor) and the Trader who subscribes to the Service (you, the Controller). It sets out the terms on which we process personal data relating to your own customers on your instructions.
Terms used in this DPA have the meanings given in the UK GDPR and the Data Protection Act 2018.
1. Roles and scope
- You are the Controller of your customers’ personal data.
- We are the Processor of that data and only process it on your documented instructions, as set out in this DPA and the Service you have signed up for.
- This DPA does not cover personal data for which we are the Controller (such as your account information as a Trader). That is covered by our Privacy Notice.
2. Subject matter, nature and purpose of processing
We process your customers’ personal data to provide the Service to you: to receive enquiries, draft replies, book quote visits, draft and send quotes, book jobs, draft and send stage invoices, and request reviews after final payment.
3. Duration
This DPA applies for as long as you have an active subscription with us, and for the 30-day post-termination retention window described in clause 9.
4. Categories of data and data subjects
4.1 Data subjects
- your prospective customers who submit an enquiry to your public link;
- your customers with whom you have entered into a booking, quote or job.
4.2 Categories of personal data
- contact details (name, email address);
- service address information (typically postcode, town, and free-text location);
- free-text enquiry content the customer submits;
- free-text site-visit notes you dictate to us;
- booking and job schedule details;
- quote and invoice details, including amounts and payment status.
We do not knowingly process special-category data (as defined by UK GDPR Article 9) or payment-card numbers on your behalf. You must not upload or input special-category data or card numbers through the Service. See clause 5 of the Terms of Service.
5. Our obligations as Processor
We will:
- process personal data only on your documented instructions, including any instructions given through your use of the Service, unless required to do otherwise by UK or EU law;
- ensure that persons authorised to process personal data have committed themselves to confidentiality;
- implement and maintain appropriate technical and organisational measures to protect the personal data — see clause 8;
- only engage sub-processors in accordance with clause 6;
- assist you with data subject requests, to the extent possible given the nature of the processing;
- assist you with data protection impact assessments and consultations with the ICO, where reasonably required;
- notify you of any personal data breach affecting your customers’ personal data without undue delay and in any event within 72 hours of becoming aware, with the information you need to notify the ICO;
- at your choice, delete or return all personal data to you at the end of the provision of services, and delete existing copies unless UK or EU law requires otherwise;
- make available to you information necessary to demonstrate compliance with this DPA and allow for reasonable audits at your cost.
6. Sub-processors
You give a general authorisation for us to engage the sub-processors listed in clause 7 to process your customers’ personal data. We remain fully liable to you for the performance of any sub-processor’s obligations.
We will give you at least 30 days’ notice by email of any intended change to the list of sub-processors. If you reasonably object to a new sub-processor on data protection grounds you may terminate your subscription on written notice within that 30-day window; refunds are pro-rata for any prepaid unused period.
7. Current sub-processors
- Supabase Inc. — hosted Postgres database, authentication and storage. Region: European Union.
- Vercel Inc. — application hosting and edge network.
- Cloudflare Inc. — DNS and edge protection.
- Anthropic PBC — large language model API used to draft customer-facing content. Anthropic does not train on API data by default.
- Resend, Inc. — outbound email delivery.
- Stripe Payments Europe, Ltd. — subscription billing. Stripe holds payment card data as an independent controller.
- Telegram FZ-LLC— messaging platform used to deliver trader notifications. Only your (the Trader’s) Telegram identifier is shared with Telegram — your customers’ personal data is not sent through Telegram.
8. Security measures
We implement and maintain the following technical and organisational measures. We will keep these under review and may update them from time to time provided they do not fall below the standard set here.
- encryption in transit (TLS 1.2 or higher) between clients and the Service and between the Service and its sub-processors;
- encryption at rest for the database and object storage layers, provided by Supabase;
- row-level security policies on every business-data table so that Traders can only access their own business’s data;
- service-role database access restricted to server-side webhook handlers, the Telegram bot, and AI workers — never exposed to browsers;
- authentication via email one-time code with anti-abuse rate limits;
- logical isolation of customer-facing token flows using hashed bearer tokens and idempotent state transitions;
- routine dependency updates and vulnerability monitoring;
- least-privilege access to production for our own personnel, with two-factor authentication required for administrative accounts;
- independent code review of user-facing surfaces before release.
9. Return and deletion of personal data
On termination of your subscription we retain your customers’ personal data for 30 days to allow you to export it. After 30 days we will delete the data from active production systems. Backups containing the data are retained for a further period consistent with our backup retention policy (currently up to 30 days) and are then deleted or overwritten in the ordinary course.
10. International transfers
Where any transfer of personal data outside the United Kingdom is required to provide the Service, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as appropriate. Copies are available on request.
11. Liability
Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA excludes or limits any liability that cannot be excluded or limited under English law.
12. Governing law
This DPA is governed by the laws of England & Wales and any dispute is subject to the exclusive jurisdiction of the courts of England & Wales.
13. Contact
Data protection contact: legal@tradesops.uk.
