Data Processing Agreement
This agreement applies where StockRoom processes personal data on your behalf - for example a supplier contact name stored against a purchase order. For your own account details we are the controller, and the privacy notice applies instead.
[A data processing agreement is legally mandatory for B2B SaaS. This draft reflects the Data (Use and Access) Act 2026, including the complaint-handling duties that took effect on 19 June 2026. Solicitor review required before use.]
1. Roles
You are the controller. We are the processor. You are responsible for having a lawful basis for the personal data you put into StockRoom.
2. Scope
- Subject matter: providing inventory management software.
- Duration: for as long as your account is open, plus the retention period.
- Categories of data subject: your staff, and any supplier or customer contacts you record.
- Categories of data: names, business contact details, and any free text you enter.
- StockRoom is not designed for special category data and you should not enter any.
3. Our obligations
- Process personal data only on your documented instructions, unless the law requires otherwise - in which case we will tell you first unless prohibited.
- Ensure everyone with access is under a duty of confidence.
- Apply appropriate technical and organisational measures (clause 6).
- Not engage a sub-processor without prior general authorisation and 30 days notice of any change, during which you may object and terminate.
- Help you respond to data subject requests, and with impact assessments and regulator consultations.
- Notify you without undue delay, and in any event within 24 hours, of a personal data breach.
- Handle complaints from data subjects and pass them to you promptly, as the 2026 duties require.
- Delete or return the data at the end of the contract, at your choice.
- Make available the information needed to demonstrate compliance, and allow audits on reasonable notice.
4. Sub-processors
[Current list to be published and kept up to date: hosting and database, payment provider, transactional email, error monitoring. Named at deployment.]
5. International transfers
Where personal data is transferred outside the UK, we will rely on adequacy regulations or the UK International Data Transfer Addendum.
6. Security measures
- Encryption in transit and at rest.
- Tenant isolation enforced by the database, not by application code alone.
- Least-privilege access to production, with access logged.
- Daily backups, with restores tested on every release.
- Automated security testing before every deployment.
- A written incident response process.
7. Liability
Liability under this agreement is subject to the limits in the terms of service, except where the law does not allow it to be limited.