This Data Processing Agreement forms part of the Terms of Service and is the Article 28 agreement your compliance team will ask for. It is between:
- the Customer — the organisation subscribing to Conformiq, acting as controller; and
- Conformiq — [TO CONFIRM — registered company name], company number [TO CONFIRM], acting as processor.
It applies to personal data inside Customer content. It does not apply to account, billing or security data, where Conformiq is the controller in its own right — see the Privacy Policy.
No signature is needed: it takes effect when you accept the Terms. If your procurement process needs a countersigned copy, email [TO CONFIRM — contact email].
1. Roles
| Data | Controller | Processor |
|---|---|---|
| Names, emails, roles of Conformiq users | Conformiq | — |
| Billing and subscription data | Conformiq | — |
| Security logs, usage analytics | Conformiq | — |
| Machines, certificates, projects, inspections, photographs | Customer | Conformiq |
| Personal data about the Customer's staff, operatives, examiners and contractors inside those records | Customer | Conformiq |
The Customer confirms it has a lawful basis for the personal data it puts into Conformiq, and has told the people concerned as UK GDPR requires — including where a certificate names an examiner who is not one of its own staff.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Conformiq equipment and inspection-certificate record service.
Duration: for as long as the subscription runs, plus the wind-down period in section 10.
Nature and purpose: hosting, storage, retrieval, indexing, optical/AI extraction of fields from uploaded images and PDFs, generation of PDF compliance packs, display of limited fields on the public QR portal, and delivery of reminder emails and SMS.
3. Categories of data subject
- The Customer's employees, workers and authorised users
- Operatives and site staff named in inspection or defect records
- Competent persons and examiners named on certificates
- Contacts at the Customer's suppliers, hire companies and main contractors
- Anyone incidentally captured in a photograph taken through the app
4. Categories of personal data
- Identification and contact data: name, work email, phone, employer, job role
- Employment context: which projects and machines a person is associated with
- Signatures and sign-off names on weekly inspection checklists
- Examiner name, employer and report number on certificates
- Images: photographs of machines, data plates, certificates and dockets, and any personal data visible in them
- Scan and access events: who viewed or scanned which machine, and when
No special category data is required by the service. The Customer must not upload it.
5. Conformiq's obligations
Conformiq will:
- Process personal data only on the Customer's documented instructions — using the service is such an instruction — unless required otherwise by law, in which case it will tell the Customer first unless prohibited.
- Ensure anyone authorised to process the data is under a duty of confidence.
- Implement the technical and organisational measures in section 8.
- Not engage a sub-processor except as set out in section 6.
- Assist the Customer, taking account of the nature of processing, in responding to data subject rights requests.
- Assist the Customer with security, breach notification and data protection impact assessments under Articles 32 to 36.
- Delete or return personal data at the end of the agreement, as set out in section 10.
- Make available the information needed to demonstrate compliance, and allow audits under section 11.
- Immediately tell the Customer if it thinks an instruction breaches data protection law.
6. Sub-processors
The Customer gives general authorisation for the sub-processors listed below. Conformiq imposes data protection terms on each of them no less protective than this DPA, and remains liable for their performance.
Conformiq will give at least 30 days' notice before adding or replacing a sub-processor, by email to account admins. If the Customer reasonably objects on data protection grounds within that period and it cannot be resolved, the Customer may terminate the affected part of the service without penalty for the remainder of the term.
Current sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase / AWS | Database, file storage, authentication | [TO CONFIRM — hosting region, e.g. eu-west-2 London] |
| Cloudflare | Content delivery, application hosting, bot protection | Global edge, UK/EU points of presence |
| Stripe Payments Europe | Subscription billing and payments | EU, with UK/US transfers under SCCs + UK Addendum [TO CONFIRM] |
| [TO CONFIRM — email provider, e.g. Resend] | Reminder and transactional email delivery | [TO CONFIRM] |
| Twilio | SMS reminders, where enabled by the Customer | EU/US, SCCs + UK Addendum [TO CONFIRM] |
| [TO CONFIRM — AI provider used for photo extraction] | Reading fields from uploaded photographs and PDFs | [TO CONFIRM] |
| Google Maps Platform | Project location lookup and map display | EU/US, SCCs + UK Addendum |
[TO CONFIRM] — verify this table against your actual live integrations before publishing, and keep it current; a stale sub-processor list is the single most common failure in a customer audit.
7. International transfers
Personal data is held at rest in [TO CONFIRM — hosting region]. Where a sub-processor processes data outside the UK, the transfer is covered by UK adequacy regulations, or by the EU Standard Contractual Clauses together with the ICO's International Data Transfer Addendum, plus a transfer risk assessment and supplementary measures where needed.
8. Security measures
- Encryption in transit (TLS 1.2+) and at rest
- Row-level access control in the database, so an organisation's data is isolated from every other organisation
- Role-based permissions: admin, manager, collaborator, and project-scoped access
- Optional multi-factor authentication for user accounts
- Signed, expiring links for document downloads rather than public file URLs
- Rate limiting and abuse protection on the public QR portal
- Audit trail of record changes, with who changed what and when
- Automated daily backups, retained for [TO CONFIRM — backup retention period]
- Least-privilege access for staff, with access logged [TO CONFIRM — describe your internal access control]
9. Personal data breaches
Conformiq will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer content, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. The Customer, as controller, is responsible for deciding whether to notify the ICO or data subjects.
10. Deletion and return
On termination, Customer content stays available for export for 30 days. After that it is deleted from live systems, and backups containing it age out within a further 30 days. Conformiq will confirm deletion in writing on request. It may retain data where the law requires, in which case this DPA continues to apply to it.
11. Audit
Conformiq will respond to a reasonable security questionnaire once per year at no cost. Where that is genuinely insufficient, the Customer may audit once per year on 30 days' notice, during business hours, without disrupting the service, subject to confidentiality, and at the Customer's cost unless material non-compliance is found.
12. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
13. Conflicts
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.