Draft status
1. Roles and scope
The customer is controller and Digital Solutions Hub Limited is processor for customer personal data processed through DutyStack, except where either party acts as an independent controller for its own purposes. This DPA applies only to processor activities under the applicable agreement.
2. Documented instructions
The processor will process customer personal data only to provide, secure and support DutyStack, comply with the agreement and follow lawful documented customer instructions, unless law requires otherwise. The processor will notify the customer if an instruction appears to infringe applicable data-protection law.
3. Confidentiality and security
People authorised to process customer personal data must be bound by confidentiality. The processor will maintain measures appropriate to the risk, including authenticated access, role and tenant checks, protected file delivery, audit records, access revocation and service monitoring, subject to the service's documented boundaries.
4. Subprocessors
The customer gives general written authorisation for Digital Solutions Hub Limited to appoint subprocessors needed to provide, secure and support DutyStack.
Digital Solutions Hub Limited will impose appropriate data-protection obligations on each subprocessor and remains responsible for complying with its obligations under this DPA when using them.
Where required by the customer agreement or applicable data-protection law, affected customers will be informed of material additions or replacements and may raise a reasonable objection on genuine data-protection grounds. An objection is not an unconditional veto over operational supplier decisions.
The current register may be provided through the public Subprocessors page, a customer account, a contractual appendix or direct notice. Digital Solutions Hub Limited may replace a provider where reasonably necessary to continue securely delivering the service and will work in good faith to address a valid objection.
5. International transfers
The parties will not make a restricted transfer without a lawful transfer mechanism. Depending on the destination and provider, this may require UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses. The final agreement must identify the applicable mechanism.
6. Data-subject and compliance assistance
Taking account of the nature of processing, the processor will provide reasonable assistance for data-subject requests, security obligations, breach assessment, data-protection impact assessments and regulator consultations. The customer remains responsible for responding as controller.
7. Personal data breaches
The processor will notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data and will provide available information reasonably needed for the customer's assessment. A specific contractual deadline must not be inferred unless agreed in the final DPA.
8. Return and deletion
At the end of services, the processor will return or delete customer personal data as required by the agreement, subject to the customer's export choices, the implemented 30-day pending-deletion lifecycle, legal holds, backups and information that law requires to be retained. The final agreement must define how backup deletion is handled operationally.
9. Information, audit and liability
The processor will make information reasonably necessary to demonstrate compliance available, subject to confidentiality, security, proportionality and protection of other customers. The final DPA must define audit procedure, frequency, cost and independent-report alternatives. Liability is governed by the final customer agreement and must be solicitor-reviewed.
Appendix: processing details
- Data subjects: customer users, owners, administrators, workers, operatives, contractors, client contacts, support contacts and people recorded in operational evidence.
- Personal data: identity and contact details, memberships and roles, attendance, location/geofence evidence, photos, files, signatures, inspections, assets, training, competence, support, billing, diagnostic and audit information.
- Nature and purpose: hosting, organising, synchronising, securing, sharing under customer controls, generating reports and exports, communicating notifications, billing and supporting the service.
- Duration: for the subscription and applicable return, retention and deletion period, subject to lawful instructions and required retention.
- Frequency: ongoing or occasional according to the customer's use of DutyStack.
Privacy contact
Email support@dutystack.co.uk