This DPA forms part of the Terms of Service between Type on Data Ltd ("Processor") and the customer ("Controller") and applies where we process personal data on your behalf (e.g. your clients' contact details, tickets, documents).
You are the Controller; we are the Processor. Each party complies with UK GDPR and the Data Protection Act 2018.
Subject matter: provision of the TOD-OPS platform. Duration: term of the subscription, plus the retention period in clause 8. Nature and purpose: hosting, storage and processing of Controller data so the Controller can run its business operations. Full particulars are in Annex 1.
We process personal data only on your documented instructions; ensure persons authorised to process are under confidentiality; implement appropriate technical and organisational security measures; assist with data subject requests and breach notification; and delete or return data at the end of the contract.
You authorise our use of the sub-processors listed in Annex 2. We remain responsible for their compliance with this DPA, and will give you reasonable notice before adding or replacing one so you may object.
Transfers outside the UK/EEA are made under appropriate safeguards (UK IDTA / SCCs).
We will notify you without undue delay after becoming aware of a personal data breach affecting your data.
We will make available information necessary to demonstrate compliance and allow for reasonable audits.
You can export your data at any time from within the platform, and we recommend doing so before you cancel. After cancellation your account's data is retained for 3 months so the account can be reinstated, and is then permanently deleted. We email a warning before that happens. Backups taken before deletion age out on their own cycle.
| Subject matter | Provision of the TOD-OPS business operations platform. |
|---|---|
| Duration | The term of the subscription, plus the post-cancellation retention period in clause 8. |
| Nature and purpose | Hosting, storage, organisation, retrieval, transmission and deletion of Controller data, so the Controller can manage clients, work and billing. |
| Categories of data subject | The Controller's own staff and platform users; the Controller's clients and their contacts; suppliers and their contacts; job applicants and other people the Controller records; recipients of documents sent for signature. |
| Categories of personal data | Identity and contact details (name, job title, email, telephone, postal address); account credentials and access logs; correspondence sent to or from the platform, including support emails and their attachments; calendar entries and meeting records; documents uploaded or generated, and their contents; signature images, signer names, IP addresses and timestamps captured as an e-signature audit trail; time, task and project records; invoices, payment status and bank details recorded for payment purposes; HR records the Controller chooses to keep, which may include absence and holiday. |
| Special category data | Not required by, and not requested by, the platform. Sickness absence recorded in the HR module may amount to health data. The Controller decides what it enters and is responsible for having a lawful basis and an Article 9 condition for it. |
| Frequency | Continuous, for the duration of the subscription. |
Those marked optional process data only if you switch that feature on or connect that account.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| 20i Ltd | Hosting, database, file storage, and the mailboxes used to send and receive platform email | All Controller data | United Kingdom |
| Stripe | Subscription billing and payment processing | Billing contact name, email and address; subscription records. Card details are entered on Stripe's own checkout and are never seen or stored by us | EEA / USA |
| Google LLC | Web fonts on our public pages | IP address and browser details of visitors to those pages. No cookie, no account data | USA |
| jsDelivr | Delivery of the in-platform calendar component | IP address and browser details. No cookie, no account data | Global CDN |
| Companies House (GOV.UK) | Company lookups you request when adding a client | The company name or number you search for. No personal data of your contacts is sent | United Kingdom |
| Anthropic or OpenAI — optional | AI drafting, where enabled. Each account supplies its own API key; nothing is sent until one is set | The text of the prompt and any document content included in it | USA |
| Xero / Intuit QuickBooks — not currently available | Accounting sync is on our roadmap and is not offered today. No data reaches either provider. Listed here so the position is on the record; this row becomes live only when the feature ships, and we will tell you before it does | None at present | — |