Data processing agreement
Template under UK GDPR Article 28 · Last updated 1 October 2026
Template wording. This page is a starting draft and has not been reviewed by a solicitor. The operator must replace it with final legal wording before relying on it.
1. Parties and roles
This agreement is between the organisation that holds a Quality Tracker workspace (the controller) and Mercer Materials ([Registered company name, company number and registered office address]) (the processor). It forms part of the terms of service.
2. The processing
| Subject matter | Hosting and operating the controller's quality records workspace |
|---|---|
| Duration | For as long as the controller has a workspace, plus the deletion period in section 9 |
| Nature and purpose | Storing, displaying, checking, reporting on and exporting records entered by the controller's users |
| Personal data | Names and work email addresses of the controller's users; names of people at suppliers, customers and labs where entered; names in notes and uploaded documents |
| Data subjects | The controller's staff and contacts at its suppliers, customers and laboratories |
3. Processor's obligations
- Process personal data only on the controller's documented instructions, which include using the service as configured by the controller.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply appropriate technical and organisational security measures (section 5).
- Assist the controller, so far as possible, with data subject requests, security obligations, and data protection impact assessments.
- Notify the controller without undue delay after becoming aware of a personal data breach.
- Make available the information needed to demonstrate compliance and allow for audits on reasonable notice.
4. Sub-processors
The controller gives general authorisation for the sub-processors listed in the privacy policy (Supabase, Vercel, Stripe, Resend, Sentry). The processor will give notice of any intended change so the controller can object, and remains responsible for its sub-processors.
5. Security measures
- Each organisation's records are isolated by database row level security, covered by automated tests.
- Encryption in transit (TLS) and at rest; passwords stored only as salted hashes.
- Role-based access within each workspace and an audit trail of changes.
- Daily backups; rate limiting on sign-in; security headers on all pages.
6. Location and transfers
Workspace data is stored in London, United Kingdom. Where a sub-processor processes personal data outside the UK, the processor ensures an appropriate transfer mechanism is in place, such as the UK International Data Transfer Addendum.
7. Controller's obligations
The controller is responsible for having a lawful basis for the personal data it enters, for the accuracy of that data, and for managing its users' access.
8. Liability
Liability under this agreement is subject to the limits in the terms of service.
9. Return and deletion
The controller can export its records at any time. When the workspace is deleted, or on the controller's written request after the service ends, the processor deletes the controller's data from live systems within 30 days and from backups within a further 30 days, unless the law requires it to be kept.
To request a countersigned copy, contact sebastian@mercermaterials.uk.