← Back to home

Data Processing Agreement

Last updated: 9 September 2026

This agreement satisfies Article 28(3) of the UK GDPR. It forms part of the Terms of Service and applies automatically whenever you use CertBox to record information about other people. You do not need to sign or request a separate copy; if your client or main contractor asks whether you have a processing contract with your software provider, this is it.

1. Who is who

This agreement is between you (“you”, the customer) and Paddy Dewhurst, sole trader, trading as CertBox (“CertBox”, “we”).

You are the controller of the personal data you put into CertBox about other people: the client who commissioned the work, the occupier of the property, a site contact, a tenant, anyone named on a certificate, quote, invoice or risk assessment, and any colleague you invite into your account. You decided to collect it and you decide what it is for. CertBox is your processor for that data and handles it only to run the service for you.

CertBox is a controller in its own right for your own account data — your name, email, login, billing record, and how you use the product. That is not covered by this agreement; it is covered by the Privacy Policy. The distinction matters because the rights and duties are different, and a document that blurs them protects neither of us.

2. What is being processed, and for how long

Article 28(3) requires these particulars to be written down.

  • Subject matter: our provision of the CertBox service to you.
  • Duration: for as long as your account is open, and then for the retention period in section 11.
  • Nature and purpose: collecting, storing, organising, formatting into documents, transmitting to recipients you choose, and making available to you again — so that you can produce and issue compliance certificates and related business records. We do not process this data for any purpose of our own.
  • Types of personal data: names; postal addresses, including the address of the property worked on; email addresses and telephone numbers; signatures; job, appliance and installation details tied to an identifiable property; photographs you take within the product; and any other personal data you choose to type into a free-text field.
  • Categories of data subject: your clients and customers; occupiers, tenants and landlords of the properties you work on; site contacts and other named third parties; and the colleagues you invite into your account.

CertBox is not designed for special category data or criminal offence data. Please do not enter it.

3. We act only on your instructions

We process the personal data described above only on your documented instructions, including where we transfer it out of the UK. Your instructions are: these terms, this agreement, the settings you choose in your account, and the ordinary operation of the features you use. If you need us to do something outside that, put it in writing to support@certbox.app and it becomes a documented instruction once we accept it.

If we think an instruction of yours breaks data protection law, we will tell you straight away and may pause that processing until it is resolved. We will also process data where UK law requires us to, in which case we will tell you first unless the law forbids it.

4. Confidentiality

Anyone we authorise to handle your data is bound to keep it confidential, whether by an employment contract, a written undertaking, or a contractor agreement. CertBox is currently operated by one person, and that person is bound by this clause.

5. Sub-processors

You give us general written authorisation to engage the sub-processors listed below. We remain fully liable to you for what they do with your data, and each is bound by written terms imposing obligations no weaker than the ones in this agreement.

Sub-processorWhat it doesWhere
HetznerServer hostingGermany
SupabaseDatabase, authentication and file storage, running on the aboveGermany
CloudflareContent delivery and DNSGlobal edge
StripePayment processing, if you subscribeUK / EU / US
MailgunSending the emails you send from CertBoxEU
SentryError monitoring; text is maskedEU
PostHogProduct analytics, only if you opt in; text and inputs are maskedEU
AnthropicReads the circuit labels in a consumer-unit photograph, only when you press Scan boardUnited States
Twilio, MessageBirdDelivering an SMS, only when you send oneEU / US
Postcodes.ioTurning a postcode you type into an addressUnited Kingdom

We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds within that period, tell us and we will either propose an alternative or you may close your account and receive a refund of any unused paid period.

6. Transfers out of the UK

Your data is stored in Germany, which benefits from a UK adequacy decision, so that is not a restricted transfer.

Two sub-processors above may handle personal data in the United States: Anthropic, when you use Scan board, and the payment and SMS providers in the course of delivering their service. Where personal data is transferred outside the UK to a country without adequacy, we rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, as incorporated into our contract with that provider.

7. Security

We take appropriate technical and organisational measures under Article 32. In plain terms, the measures in place are:

  • Data encrypted in transit using TLS, and at rest on the hosting provider's storage.
  • Access to your records restricted at the database level by row-level security, so one account's query cannot return another account's rows.
  • Authentication handled by a dedicated provider, with two-factor authentication on administrative access.
  • Administrative access to production limited to the proprietor, over key-based SSH.
  • Automated daily checks on database grants and access policies, and error monitoring with customer text masked.
  • Backups of the database, held in the same region as the primary.

We do not hold an ISO 27001 or SOC 2 certification and do not claim one. If you need evidence beyond this list, section 12 tells you how to ask.

8. Helping you answer your clients

If one of your clients exercises a data protection right — access, correction, erasure, portability, objection — that request is yours to answer, because you are the controller. We will help. If a request reaches us directly we will not answer it ourselves; we will pass it to you without undue delay. Taking into account the nature of the processing, we will provide the technical means to find, export, correct or remove the data in question, and the product's own export and deletion tools are provided for exactly this.

9. Helping you with breaches and assessments

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it. The notification will say what happened, which categories and roughly how many records and data subjects are affected, what the likely consequences are, and what we are doing about it. If we cannot establish all of that at once, we will send what we have and follow up rather than wait.

Reporting a breach to the ICO within 72 hours, and telling affected individuals where required, is your decision and your duty as controller. We will give you the information you need to make it. We will also give you reasonable help with data protection impact assessments and prior consultations under Articles 35 and 36.

10. Showing you what we do

On written request we will give you the information you reasonably need to show that we are meeting our obligations under Article 28. We will also allow an audit, by you or an auditor you appoint who is not a competitor of ours, on 30 days' written notice, no more than once in any twelve months unless a regulator requires otherwise or we have notified you of a breach. Audits happen during business hours, must not disrupt the service or expose another customer's data, and you cover your own costs.

11. Giving your data back, and deleting it

You can export your data yourself at any time while your account is open, and we recommend you do so before you close it.

When your account is deleted we delete the personal data we hold as your processor within 30 days, including from backups as they rotate, except where UK law requires us to keep something. Certificates already sent to a recipient are outside our reach — they are files in someone else's inbox — and a share link may keep a snapshot available until it expires or you revoke it.

Compliance certificates can be needed years after the work: injury claims and enforcement can arrive long after a job is finished, and claims relating to dwellings can now be brought up to fifteen years later. Our retention period is shorter than that. Keep your own copies of everything you issue.

12. Your side of it

You confirm that you have a lawful basis for the personal data you enter, that you have given your own clients the privacy information they are owed, and that your instructions to us will not put us in breach of data protection law. You are responsible for who you invite into your account and for what you do with a share link once you create one — anyone holding the link can open what it points at.

13. Liability, precedence and changes

Nothing in this agreement limits either party's liability to a data subject or to a regulator under Article 82 or the Data Protection Act 2018. Between us, the limits in Terms of Service §8 apply, except where the law does not permit them to.

Where this agreement and the Terms of Service conflict on a data protection question, this agreement wins.

We will give you at least 30 days' notice of material changes to this agreement, by email or in the app. Changes to the sub-processor list follow section 5.

14. Contact

Data protection questions, requests under section 10, and breach correspondence: support@certbox.app. CertBox is registered with the Information Commissioner's Office; the registration reference is in the Privacy Policy. You can complain to the ICO at any time.