In plain English
We process your data only on your instructions, under UK GDPR. Our sub-processors are listed, our security controls are documented, and you can audit us.
01Parties & roles
This Data Processing Agreement ("DPA") is between the customer ("Controller") and Perpetually Limited, company number 16482921 ("Processor"). It applies to all personal data processed by TradesInvo on the Controller's behalf to provide the service under our Terms & Conditions.
02Subject matter & duration
Subject matter: processing of personal data necessary to provide the TradesInvo service. Duration: for the term of the underlying subscription, plus a 90-day data return / deletion window after termination.
03Nature & purpose of processing
Hosting, storing, displaying, transmitting, analysing, backing up and otherwise processing personal data to provide lead management, customer records, quotes, jobs, calendar, invoicing, payments, reviews, reporting and AI-assisted features.
04Categories of data subjects & data
Data subjects: Controller's customers, prospects, suppliers, employees and contractors.
Personal data: name, address, email, phone, job and property details, photographs, notes, invoice and payment metadata, and any other personal data the Controller chooses to upload.
Special-category data: not intended to be processed. Controller must not upload special-category data without first agreeing additional safeguards in writing with TradesInvo.
05Processor obligations
The Processor will:
06Security measures
The Processor implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and least-privilege for staff.
- Mandatory MFA for all staff access to production.
- Centralised audit logging with tamper protection.
- Documented incident response, business continuity and disaster recovery plans.
- Annual penetration test by an independent third party.
- Security training for all staff at induction and annually.
Full details in our Security overview.
07Sub-processors
The Processor uses the following sub-processors. We will notify Controllers of any addition or change at least 30 days in advance.
- Supabase Inc. — application database & auth (EU / UK regions).
- Amazon Web Services EMEA SARL — cloud infrastructure (London, eu-west-2).
- Stripe Payments UK Ltd — payment processing.
- Resend / Postmark — transactional email delivery.
- PostHog Inc. — product analytics (EU region).
- OpenAI Ireland Ltd / Anthropic PBC — AI processing for in-product features.
- Cloudflare Inc. — CDN, WAF and DDoS protection.
08International transfers
Where personal data is transferred outside the UK, the Processor relies on UK adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary measures.
09Data subject requests
The Processor will, to the extent legally permitted, promptly notify the Controller of any data subject request received directly. The Processor will assist the Controller in fulfilling its obligations to respond within statutory time limits.
10Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, and will provide all information reasonably required to enable the Controller to meet its own notification obligations.
11Audits
The Processor will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, on reasonable prior notice and during normal business hours.
12Return & deletion
On termination of the underlying subscription, the Processor will, at the Controller's choice, return or delete all personal data within 90 days, except where retention is required by law.
13Liability
Liability under this DPA is governed by the limitation of liability provisions in our Terms & Conditions.
14Governing law
This DPA is governed by the laws of England and Wales.
Questions about this document? Email legal@tradesinvo.com or write to Perpetually Limited, 66 Paul Street, London, England, EC2A 4NA, United Kingdom.