Last updated: 9 September 2026
This agreement satisfies Article 28(3) of the UK GDPR. It forms part of the Terms of Service and applies automatically whenever you use CertBox to record information about other people. You do not need to sign or request a separate copy; if your client or main contractor asks whether you have a processing contract with your software provider, this is it.
This agreement is between you (“you”, the customer) and Paddy Dewhurst, sole trader, trading as CertBox (“CertBox”, “we”).
You are the controller of the personal data you put into CertBox about other people: the client who commissioned the work, the occupier of the property, a site contact, a tenant, anyone named on a certificate, quote, invoice or risk assessment, and any colleague you invite into your account. You decided to collect it and you decide what it is for. CertBox is your processor for that data and handles it only to run the service for you.
CertBox is a controller in its own right for your own account data — your name, email, login, billing record, and how you use the product. That is not covered by this agreement; it is covered by the Privacy Policy. The distinction matters because the rights and duties are different, and a document that blurs them protects neither of us.
Article 28(3) requires these particulars to be written down.
CertBox is not designed for special category data or criminal offence data. Please do not enter it.
We process the personal data described above only on your documented instructions, including where we transfer it out of the UK. Your instructions are: these terms, this agreement, the settings you choose in your account, and the ordinary operation of the features you use. If you need us to do something outside that, put it in writing to support@certbox.app and it becomes a documented instruction once we accept it.
If we think an instruction of yours breaks data protection law, we will tell you straight away and may pause that processing until it is resolved. We will also process data where UK law requires us to, in which case we will tell you first unless the law forbids it.
Anyone we authorise to handle your data is bound to keep it confidential, whether by an employment contract, a written undertaking, or a contractor agreement. CertBox is currently operated by one person, and that person is bound by this clause.
You give us general written authorisation to engage the sub-processors listed below. We remain fully liable to you for what they do with your data, and each is bound by written terms imposing obligations no weaker than the ones in this agreement.
| Sub-processor | What it does | Where |
|---|---|---|
| Hetzner | Server hosting | Germany |
| Supabase | Database, authentication and file storage, running on the above | Germany |
| Cloudflare | Content delivery and DNS | Global edge |
| Stripe | Payment processing, if you subscribe | UK / EU / US |
| Mailgun | Sending the emails you send from CertBox | EU |
| Sentry | Error monitoring; text is masked | EU |
| PostHog | Product analytics, only if you opt in; text and inputs are masked | EU |
| Anthropic | Reads the circuit labels in a consumer-unit photograph, only when you press Scan board | United States |
| Twilio, MessageBird | Delivering an SMS, only when you send one | EU / US |
| Postcodes.io | Turning a postcode you type into an address | United Kingdom |
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds within that period, tell us and we will either propose an alternative or you may close your account and receive a refund of any unused paid period.
Your data is stored in Germany, which benefits from a UK adequacy decision, so that is not a restricted transfer.
Two sub-processors above may handle personal data in the United States: Anthropic, when you use Scan board, and the payment and SMS providers in the course of delivering their service. Where personal data is transferred outside the UK to a country without adequacy, we rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, as incorporated into our contract with that provider.
We take appropriate technical and organisational measures under Article 32. In plain terms, the measures in place are:
We do not hold an ISO 27001 or SOC 2 certification and do not claim one. If you need evidence beyond this list, section 12 tells you how to ask.
If one of your clients exercises a data protection right — access, correction, erasure, portability, objection — that request is yours to answer, because you are the controller. We will help. If a request reaches us directly we will not answer it ourselves; we will pass it to you without undue delay. Taking into account the nature of the processing, we will provide the technical means to find, export, correct or remove the data in question, and the product's own export and deletion tools are provided for exactly this.
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it. The notification will say what happened, which categories and roughly how many records and data subjects are affected, what the likely consequences are, and what we are doing about it. If we cannot establish all of that at once, we will send what we have and follow up rather than wait.
Reporting a breach to the ICO within 72 hours, and telling affected individuals where required, is your decision and your duty as controller. We will give you the information you need to make it. We will also give you reasonable help with data protection impact assessments and prior consultations under Articles 35 and 36.
On written request we will give you the information you reasonably need to show that we are meeting our obligations under Article 28. We will also allow an audit, by you or an auditor you appoint who is not a competitor of ours, on 30 days' written notice, no more than once in any twelve months unless a regulator requires otherwise or we have notified you of a breach. Audits happen during business hours, must not disrupt the service or expose another customer's data, and you cover your own costs.
You can export your data yourself at any time while your account is open, and we recommend you do so before you close it.
When your account is deleted we delete the personal data we hold as your processor within 30 days, including from backups as they rotate, except where UK law requires us to keep something. Certificates already sent to a recipient are outside our reach — they are files in someone else's inbox — and a share link may keep a snapshot available until it expires or you revoke it.
Compliance certificates can be needed years after the work: injury claims and enforcement can arrive long after a job is finished, and claims relating to dwellings can now be brought up to fifteen years later. Our retention period is shorter than that. Keep your own copies of everything you issue.
You confirm that you have a lawful basis for the personal data you enter, that you have given your own clients the privacy information they are owed, and that your instructions to us will not put us in breach of data protection law. You are responsible for who you invite into your account and for what you do with a share link once you create one — anyone holding the link can open what it points at.
Nothing in this agreement limits either party's liability to a data subject or to a regulator under Article 82 or the Data Protection Act 2018. Between us, the limits in Terms of Service §8 apply, except where the law does not permit them to.
Where this agreement and the Terms of Service conflict on a data protection question, this agreement wins.
We will give you at least 30 days' notice of material changes to this agreement, by email or in the app. Changes to the sub-processor list follow section 5.
Data protection questions, requests under section 10, and breach correspondence: support@certbox.app. CertBox is registered with the Information Commissioner's Office; the registration reference is in the Privacy Policy. You can complain to the ICO at any time.