DRAFT — for solicitor review; not yet in force.
Property Inspector — Data Processing Agreement
1. Parties and purpose
1.1 This Data Processing Agreement (DPA) is between MBGW Limited (company number [TBC]; registered office [TBC]) (MBGW or the Processor) and the subscriber identified in the subscriber account (the Customer or the Controller).
1.2 It forms part of the Terms of Service and sets out the terms required by Article 28 of the UK GDPR on which MBGW processes personal data on behalf of the Customer in providing the Property Inspector service (the Service).
1.3 Capitalised terms not defined here have the meaning given in the Terms of Service. Data Protection Law means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003, each as amended. "Controller", "processor", "data subject", "personal data", "personal data breach" and "processing" have the meanings given in the UK GDPR.
2. Roles
2.1 The Customer is the controller of personal data contained in Customer Data. MBGW is the processor of that data.
2.2 MBGW is an independent controller of the Customer's own account data (subscriber identity, billing and agreement records) as described in the Privacy Notice. That processing is outside this DPA.
2.3 Where the Customer itself acts as a processor for a third party (for example carrying out inspections under contract to a landlord or managing agent), MBGW acts as the Customer's sub-processor, and the Customer warrants that its instructions to MBGW are consistent with its own obligations to that third party.
3. Details of the processing (Article 28(3))
| Subject matter | Provision of the Property Inspector service: a hosted office workspace, mobile field app, customer portal and messaging service for property inspection and maintenance businesses. |
| Duration | The term of the Customer's subscription, plus the export and deletion period in section 11. |
| Nature and purpose | Hosting, storage, backup, display, transmission, synchronisation to field devices, generation of PDF reports, optional synchronisation to the Customer's own Google or Microsoft services, and deletion, all at the Customer's direction, to enable the Customer to run its business. |
| Categories of data subjects | The Customer's staff and contractors (office users, field engineers); the Customer's customers, tenants, landlords, occupiers and other site contacts; any individuals who appear in inspection records, photographs or messages. |
| Categories of personal data | Names, job titles, email addresses, telephone numbers, postal addresses; user account identifiers and privileges; engineer device identifiers and location during work; site addresses and access notes; inspection forms, findings, signatures and photographs (which may incidentally show people or personal property); work orders and appointments; chat messages between the Customer's teams; documents and reports uploaded or generated. |
| Special category data | None is required by the Service. The Customer must not enter special category or criminal offence data unless it has a lawful basis and has told MBGW in writing. |
4. Customer's instructions (Article 28(3)(a))
4.1 MBGW will process Customer Data only on the Customer's documented instructions, including with regard to transfers of personal data outside the UK, unless required to do otherwise by UK law, in which case MBGW will inform the Customer before processing unless the law prohibits it.
4.2 The Customer's instructions are: the Terms of Service, this DPA, the configuration the Customer makes in its workspace (including which integrations to connect, which users to create and what privileges to give them), and the actions the Customer and its Users take in the Service (including creating, editing, sharing, exporting and deleting data). Further written instructions may be given to [TBC: support/privacy contact email]; MBGW may charge for instructions that require work outside the normal operation of the Service.
4.3 MBGW will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality (Article 28(3)(b))
5.1 MBGW will ensure that persons authorised to process Customer Data are bound by contractual or statutory obligations of confidentiality, and that access is limited to those who need it to provide, support and secure the Service.
6. Security (Article 28(3)(c) and Article 32)
6.1 MBGW will implement and maintain appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current measures are described in the Security Overview and include:
- each Customer workspace held in its own database, its own application container, its own object-storage prefix and its own messaging domain, isolated from other subscribers;
- API access fenced to the workspace identified in the user's signed token, so that one workspace's users cannot read another's records;
- encryption of data in transit (TLS) between users, the mobile app, the workspace and the API;
- authentication through MBGW's identity broker with single sign-on (Microsoft or Google) or email and password with a minimum length, account lockout and rate limiting;
- role- and privilege-based access control within each workspace, configured by the Customer;
- encrypted and signed backups and exports, held on MBGW's UK estate;
- logging and monitoring of access and errors.
6.2 MBGW may update these measures from time to time provided the overall level of protection is not reduced.
6.3 MBGW does not claim any external security certification. [TBC: whether a certification such as Cyber Essentials will be pursued; do not state one until achieved.]
7. Sub-processors (Article 28(2) and (4))
7.1 The Customer gives general written authorisation for MBGW to engage sub-processors to process Customer Data, subject to this section.
7.2 The sub-processors engaged at the date of this DPA are listed in the Sub-processor List. Some are engaged for every workspace: Google (Firebase Cloud Messaging, which delivers push notifications to the mobile app), TomTom (live-traffic tiles and travel-time estimates from an en-route team's device position), Ideal Postcodes (postcode address lookup) and the OpenStreetMap Foundation (base map tiles and geocoding, requested directly from Users' browsers); the Sub-processor List states what each receives. Others (Google Workspace, Drive and Calendar; Microsoft 365 / Microsoft Graph) process Customer Data only if and when the Customer connects that integration in its workspace settings; connecting an integration is the Customer's instruction to share the relevant data with that provider.
7.3 MBGW will give the Customer at least 30 days' notice by email before adding or replacing a sub-processor, and will publish a new version of the Sub-processor List. The Customer may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Customer may close the affected workspace under the Terms of Service without penalty for the remainder of the notice period.
7.4 MBGW will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains liable to the Customer for the performance of its sub-processors' obligations.
8. Assistance with data subject rights (Article 28(3)(e))
8.1 Taking into account the nature of the processing, MBGW will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights.
8.2 The Service provides the Customer with direct access to search, correct, export and delete its Customer Data, which is the primary means of responding to such requests. MBGW will provide further assistance on request, and may charge a reasonable fee for assistance that goes beyond the functionality of the Service.
8.3 If MBGW receives a request directly from a data subject relating to Customer Data, it will not respond except to direct the data subject to the Customer, and will notify the Customer promptly.
9. Assistance with security, breaches and impact assessments (Article 28(3)(f))
9.1 MBGW will assist the Customer in ensuring compliance with Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to MBGW.
9.2 Personal data breach notification. MBGW will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and in any event within [TBC: e.g. 48 hours]. The notification will describe, so far as known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. MBGW may provide information in phases as it becomes available.
9.3 MBGW will not notify a supervisory authority or data subjects on the Customer's behalf unless instructed to do so or required by law.
10. Audit (Article 28(3)(h))
10.1 MBGW will make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR, including the Security Overview, the Sub-processor List and, on request, written responses to reasonable security questionnaires.
10.2 MBGW will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to: (a) at least 30 days' written notice; (b) no more than one audit in any 12-month period unless required by a supervisory authority or following a personal data breach; (c) the audit being conducted during business hours, with minimum disruption, and by a person bound by confidentiality; and (d) the Customer bearing its own costs and reimbursing MBGW's reasonable costs where the audit exceeds [TBC: e.g. one working day]. Where an audit would expose other subscribers' data or MBGW's security, MBGW may provide the information by alternative means.
11. Return and deletion on exit (Article 28(3)(g))
11.1 Throughout the subscription, and throughout any closure notice period, the Customer may request an export of all Customer Data using "Download my data" in the subscriber portal; MBGW produces the export and makes it, and its passphrase, available to the Customer as described in the Data Retention and Backup Policy. The export is a complete, machine-readable copy (CSV and JSON tables, photographs, documents and reports, and the workspace database records), encrypted and signed as described in the Data Retention and Backup Policy.
11.2 When a workspace is torn down (following closure, non-payment or termination under the Terms of Service), MBGW will: (a) produce a final export of the Customer Data; (b) permanently delete the workspace database, application container, file store, object-storage prefix and messaging domain; and (c) delete the Customer's data from the shared API database. The final export is retained for the Customer to collect for the period stated in the Data Retention and Backup Policy, after which it is deleted.
11.3 Backups containing Customer Data are deleted in accordance with the Data Retention and Backup Policy. Until deleted, they remain protected by this DPA and are not used for any other purpose.
11.4 MBGW may retain Customer Data to the extent required by UK law, and will continue to protect it under this DPA.
12. International transfers
12.1 MBGW hosts and processes Customer Data in the United Kingdom. MBGW will not transfer Customer Data outside the UK except: (a) to a sub-processor listed in the Sub-processor List, using the transfer mechanism stated there; or (b) on the Customer's instruction, including where the Customer connects an integration with a provider that processes data outside the UK.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent Data Protection Law does not permit such limitation.
14. Term and precedence
14.1 This DPA applies for as long as MBGW processes Customer Data on the Customer's behalf.
14.2 In the event of conflict between this DPA and any other part of the contract in relation to the processing of personal data, this DPA prevails.
14.3 This DPA is governed by the law of England and Wales.
Annex — Customer's standing instructions checklist
The Customer instructs MBGW to process Customer Data by:
- hosting the Customer's workspace and making it available to the Customer's Users;
- synchronising records to and from the mobile app on the Customer's devices;
- generating PDF reports from inspection data and storing them in the workspace and, if connected, the Customer's own Google Drive or Microsoft 365;
- synchronising work orders to and from the Customer's own Google Calendar or Microsoft 365 calendars, if connected;
- delivering chat messages between the Customer's teams;
- sending transactional emails (invitations, verification, notifications) to the Customer's Users;
- taking backups on the schedule the Customer or MBGW configures;
- producing exports on request and at teardown;
- deleting data as the Customer directs and at teardown.