Data Processing Agreement

Version 0.1 draft · 7 September 2026

Draft - not yet in force. Prepared for review by a solicitor. It must not be relied on or published as binding until that review is complete. The Data (Use and Access) Act came into force in February 2026 and changed controller and processor duties, so any template written before 2026 is out of date.

This agreement applies where StockRoom processes personal data on your behalf - for example a supplier contact name stored against a purchase order. For your own account details we are the controller, and the privacy notice applies instead.

[A data processing agreement is legally mandatory for B2B SaaS. This draft reflects the Data (Use and Access) Act 2026, including the complaint-handling duties that took effect on 19 June 2026. Solicitor review required before use.]

1. Roles

You are the controller. We are the processor. You are responsible for having a lawful basis for the personal data you put into StockRoom.

2. Scope

3. Our obligations

4. Sub-processors

[Current list to be published and kept up to date: hosting and database, payment provider, transactional email, error monitoring. Named at deployment.]

5. International transfers

Where personal data is transferred outside the UK, we will rely on adequacy regulations or the UK International Data Transfer Addendum.

6. Security measures

7. Liability

Liability under this agreement is subject to the limits in the terms of service, except where the law does not allow it to be limited.