1. Parties and how this addendum applies
1.1 This Data Processing Addendum ("DPA") is between the business that has signed up to The Job Planner ("you", the controller) and Matt Rooney, a sole trader trading as "The Job Planner", of the address shown on our invoices (available on request) ("we", the processor).
1.2 It forms part of our terms of service (the "Terms") and takes effect when you accept them. It meets the requirements of Article 28(3) of the UK GDPR.
1.3 Definitions. "UK GDPR", "Data Protection Act 2018", "controller", "processor", "personal data", "data subject", "processing" and "personal data breach" have the meanings given in UK data protection law, as amended by the Data (Use and Access) Act 2025. "Customer Personal Data" means personal data we process on your behalf in providing the service. "Sub-processor" means another processor we engage to process Customer Personal Data.
1.4 What's not covered. This DPA doesn't cover personal data we process as a controller — for example the account details of your users, sign-in and security logs, billing details and website enquiries. That's covered by our privacy notice.
1.5 If this DPA and the Terms conflict on a data protection point, this DPA wins.
2. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing The Job Planner job-management service to you under the Terms |
| Duration | For as long as you use the service, plus the deletion period in section 11 |
| Nature of processing | Collecting (through the app, imports and the customer portal), storing, organising, displaying, updating, sending (email and SMS on your instructions), generating documents (quotes, invoices, certificates, job sheets), AI-assisted drafting, exporting, anonymising and deleting |
| Purpose | Letting you manage customers, sites, jobs, visits, quotes, invoices, payments records, certificates and communications, as you choose to use the service |
| Types of personal data | Names; contact details (phone, email, postal address); site addresses and site access notes; details of properties and equipment (assets); job descriptions and notes; photos taken on site; signatures; certificates and job sheets; quotes, invoices and records of payments (amounts, dates, methods — no card numbers); the content and delivery records of emails and SMS messages sent through the service; timestamps of engineer visits (on my way, arrived, left) |
| Special category data | Not required by the service. You may choose to record information that reveals health or disability (for example "vulnerable customer — elderly, allow extra time" or access needs) in notes. If you do, you're responsible for having a lawful basis and condition for it, and for recording only what's necessary. Signatures are stored as images and are not used to identify anyone by biometric means |
| Categories of data subjects | Your customers and their contacts; occupiers, tenants, landlords, agents and other people at the sites you work on; people who sign job sheets or certificates; people who appear in photos or are named in job notes; recipients of messages sent through the service |
3. Your instructions
3.1 We process Customer Personal Data only on your documented instructions, including about transfers outside the UK, unless UK law requires us to do otherwise (in which case we'll tell you before processing, unless the law forbids it).
3.2 The Terms, this DPA and your use of the service's settings and features (for example sending a message, running an import, using an AI feature, exporting or deleting records) are your documented instructions.
3.3 We'll tell you promptly if we believe an instruction breaks UK data protection law. We aren't required to follow it until it's confirmed or changed.
3.4 You're responsible for making sure your instructions and your collection of Customer Personal Data are lawful, including telling your customers how their data is used and, where needed, getting their consent (for example for marketing messages).
4. Confidentiality
We make sure that anyone we authorise to access Customer Personal Data is bound by a duty of confidentiality (by contract or by law) and only accesses it where needed — for example to provide support you've asked for, or to investigate a technical or security problem.
5. Security
5.1 We take appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the UK GDPR, taking into account the nature of the data and the risks. These currently include:
- encryption in transit (TLS) for all connections, and encryption at rest by our database provider;
- separation of each company's data, with automated tests run whenever we change the software to confirm one company can't access another's data;
- passwords stored as scrypt hashes; optional two-factor authentication, which owners can make compulsory for their team;
- rate limiting on sign-in and other sensitive actions; audit logging of sign-ins and security events;
- security headers on the website and app; automated dependency updates;
- daily automated deletion of data that has passed its retention period;
- backups with point-in-time restore provided by our database provider.
5.2 More detail is on our security page. We may update these measures over time, but won't reduce the overall level of protection.
6. Sub-processors
6.1 General authorisation. You authorise us to use the sub-processors listed on our sub-processors page.
6.2 Contract terms. We put a written contract in place with each sub-processor that imposes data protection obligations giving at least the same level of protection as this DPA, as far as relevant to the service it provides. We remain responsible to you for our sub-processors' performance of those obligations.
6.3 Changes. We'll give at least 30 days' notice before adding or replacing a sub-processor, by emailing account owners and updating the sub-processors page.
6.4 Objecting. You can object to a change on reasonable data protection grounds by emailing privacy@localhost within that 30-day period. We'll discuss your concerns in good faith. If we can't resolve them, you can end the Terms by closing your account before the change takes effect, and we'll refund any fees paid in advance for the unused period.
6.5 Urgent changes. If we have to replace a sub-processor urgently (for example because it has failed or stopped providing its service), we'll tell you as soon as we can, and you'll have the same right to object.
7. International transfers
7.1 Some sub-processors process Customer Personal Data outside the UK, as shown on the sub-processors page. You authorise those transfers.
7.2 We'll only make, or allow, a transfer outside the UK where it is covered by UK adequacy regulations (for example for the European Economic Area, or the UK Extension to the EU–US Data Privacy Framework for certified US organisations), or by appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment where required. See the ICO's guidance on international transfers.
8. Helping with data subjects' requests
8.1 The service includes tools to help you respond to requests from your customers: you can search for a person, export their records, correct them, and anonymise them.
8.2 If those tools aren't enough, we'll give you reasonable help, taking into account the nature of the processing, to respond to requests to exercise rights under Chapter III of the UK GDPR (access, rectification, erasure, restriction, portability and objection).
8.3 If one of your customers contacts us directly about their data, we'll pass the request to you without undue delay and won't respond to it ourselves, except to tell them we've passed it on.
9. Helping with security, impact assessments and the ICO
Taking into account the nature of the processing and the information available to us, we'll give you reasonable help to meet your obligations on:
- security of processing (Article 32);
- notifying personal data breaches to the ICO and to data subjects (Articles 33 and 34);
- data protection impact assessments and prior consultation with the ICO (Articles 35 and 36) — for example by providing information about how the service works, our sub-processors and our security measures.
10. Personal data breaches
10.1 We'll tell you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by emailing the account owner.
10.2 We'll give you the information we have, and add to it as we learn more, including where possible: what happened; the categories and approximate numbers of people and records affected; the likely consequences; and what we've done or propose to do to deal with the breach and reduce its effects. We'll also tell you who to contact for more information.
10.3 We'll take reasonable steps to contain and investigate the breach and to reduce any harm.
10.4 As controller, you decide whether to notify the ICO (which, where required, must be done within 72 hours of becoming aware of the breach — see the ICO's report a breach page) and the people affected. Our notice to you isn't an admission of fault.
11. Deleting or returning data
11.1 Return. At any time, and before closing your account, the account owner can export all your company's data (JSON, plus invoices as CSV) from the settings page.
11.2 Deletion. When you close your account, we delete Customer Personal Data from our live database immediately. Copies in backups are overwritten within 30 days. If your subscription ends without the account being closed, we keep the data for 6 months and then delete it, as set out in the Terms.
11.3 We don't keep Customer Personal Data after deletion unless UK law requires us to, in which case we'll keep it protected and only use it for that purpose.
11.4 Our sub-processors may keep their own records as required by law (for example Stripe's payment records, which it keeps as a controller under its own terms).
12. Information and audits
12.1 We'll make available the information reasonably needed to show that we meet our obligations under Article 28 of the UK GDPR — for example, answers to a reasonable security questionnaire and a description of our controls.
12.2 If that information isn't enough to show compliance, or the ICO requires it, you (or an independent auditor you appoint who is bound by confidentiality and isn't a competitor of ours) may carry out an audit, including an inspection, on at least 30 days' written notice, no more than once in any 12 months (unless following a breach or at the ICO's request), during UK working hours and in a way that doesn't disrupt the service or put other customers' data at risk. You'll pay your own costs and our reasonable costs of supporting the audit.
12.3 Audits don't extend to our sub-processors' premises; we'll share the audit reports or certifications they make available to us where we're allowed to.
13. Liability and duration
13.1 Each party's liability under this DPA is subject to the limits and exclusions in the Terms, except where UK data protection law does not allow liability to be limited.
13.2 This DPA lasts as long as we process Customer Personal Data for you, and ends automatically when all of it has been deleted under section 11.
13.3 We may update this DPA to reflect changes in the law, ICO guidance or our service. We'll give account owners at least 30 days' notice of changes that materially affect you, and we won't reduce the protection it gives to Customer Personal Data.
13.4 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Questions about this DPA, or need a signed copy for your records? Email privacy@localhost.