In plain English
We process your data only on your instructions, under UK GDPR. Our sub-processors are listed, our security controls are documented, and you can audit us.
01Parties & roles
This Data Processing Agreement ("DPA") is between the customer ("Controller") and Perpetually Limited, company number 16482921 ("Processor"). It applies to all personal data processed by TradesInvo on the Controller's behalf to provide the service under our Terms & Conditions.
02Subject matter & duration
Subject matter: processing of personal data necessary to provide the TradesInvo service. Duration: for the term of the underlying subscription, plus a 90-day data return / deletion window after termination.
03Nature & purpose of processing
Hosting, storing, displaying, transmitting, analysing, backing up and otherwise processing personal data to provide lead management, customer records, quotes, jobs, calendar, invoicing, payments, reviews, reporting and AI-assisted features.
04Categories of data subjects & data
Data subjects: Controller's customers, prospects, suppliers, employees and contractors.
Personal data: name, address, email, phone, job and property details, photographs, notes, invoice and payment metadata, and any other personal data the Controller chooses to upload.
Special-category data: not intended to be processed. Controller must not upload special-category data without first agreeing additional safeguards in writing with TradesInvo.
05Processor obligations
The Processor will:
06Security measures
The Processor implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and least-privilege for staff.
- Mandatory MFA for all staff access to production.
- Centralised audit logging with tamper protection.
- Documented incident response, business continuity and disaster recovery plans.
- Annual penetration test by an independent third party.
- Security training for all staff at induction and annually.
Full details in our Security overview.
07Sub-processors
The Processor uses the following sub-processors. We will notify Controllers of any addition or change at least 30 days in advance.
- Supabase Inc. — application database, authentication & file storage (EU / UK regions).
- Lovable — application hosting and transactional email delivery (account, billing and notification emails).
- Amazon Web Services EMEA SARL — cloud infrastructure (London, eu-west-2).
- Cloudflare Inc. — CDN, WAF and DDoS protection.
- Stripe Payments UK Ltd — card payment processing.
- GoCardless Ltd — Direct Debit payment collection.
- Twilio Ireland Limited — SMS and voice calling (sending, receiving and routing).
- Meta Platforms Ireland Ltd — WhatsApp Business messaging, where a Controller enables it.
- ElevenLabs — AI voice receptionist: call handling, transcription and speech synthesis, where a Controller enables it.
- OpenAI Ireland Ltd — AI processing for in-product features (lead triage, quote drafts, review replies, voice-note transcription).
- PostHog Inc. — product analytics (EU region), only for visitors who consent to analytics cookies.
- Instantly.ai (Leadsy) — B2B website visitor identification, only for visitors who consent to analytics cookies.
Firecrawl and Sanity.io also support the service (competitor-comparison data and marketing content respectively) but do not process personal data a Controller uploads about their own customers, so they are not sub-processors under this DPA.
08International transfers
Where personal data is transferred outside the UK, the Processor relies on UK adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary measures.
09Data subject requests
The Processor will, to the extent legally permitted, promptly notify the Controller of any data subject request received directly. The Processor will assist the Controller in fulfilling its obligations to respond within statutory time limits.
10Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, and will provide all information reasonably required to enable the Controller to meet its own notification obligations.
11Audits
The Processor will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, on reasonable prior notice and during normal business hours.
12Return & deletion
On termination of the underlying subscription, the Processor will, at the Controller's choice, return or delete all personal data within 90 days, except where retention is required by law.
13Liability
Liability under this DPA is governed by the limitation of liability provisions in our Terms & Conditions.
14Governing law
This DPA is governed by the laws of England and Wales.
Questions about this document? Email legal@tradesinvo.com or write to Perpetually Limited, 66 Paul Street, London, England, EC2A 4NA, United Kingdom.