This Data Processing Agreement ("DPA") forms part of the Terms of Service between Certio Software Ltd, a company registered in England and Wales under company number 17450320, whose registered office is at 565 Green Lanes, London, England, N8 0RL ("Certio", "we", "the Processor"), and the customer who has accepted those Terms ("you", "the Controller"). It applies whenever we process personal data on your behalf, and gives effect to Article 28 of the UK GDPR.
We process personal data on your behalf only to provide the Service described in the Terms — producing certificates, quotes, invoices and job records, handling enquiries and messages, and the related features you switch on. Processing lasts for as long as your account is active, and ends as set out in section 9. The subject matter, nature, purpose, data types and categories of data subject are set out in Annex 1.
We process your customers' personal data only on your documented instructions, including as to international transfers, unless we are required to do otherwise by law — in which case we will tell you before processing, unless that law prohibits us from doing so. Your use of the Service, and the settings and features you enable, constitute your instructions. If we consider an instruction to infringe data protection law, we will tell you.
We ensure that anyone authorised to process this data is subject to an appropriate duty of confidentiality, and that access is limited to those who need it to provide or support the Service.
We implement appropriate technical and organisational measures under Article 32 of the UK GDPR. These currently include: transmission over encrypted connections (HTTPS/TLS); authenticated, role-restricted access to backend systems, including a role separation that prevents team members from reaching the account owner's financial data; encryption at rest of sensitive credentials such as connected-account tokens, using authenticated encryption; hosting within the United Kingdom; and routine backups. We keep these measures under review and may update them, provided the level of protection is not reduced.
You give us general authorisation to engage sub-processors. The sub-processors we currently use, and what each one receives, are listed in the Privacy Policy, which forms part of this DPA. Several are engaged only if you switch on the corresponding optional feature.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance. If we intend to add or replace a sub-processor we will update that list and give you reasonable notice; if you reasonably object on data protection grounds, you may raise it with us at support@certio.uk and, if we cannot resolve it, you may terminate the affected part of the Service.
Your customers' requests should come to you, as Controller. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, in responding to requests to exercise rights of access, rectification, erasure, restriction, portability and objection. The Service also lets you access, correct, export and delete the records you hold, directly and without needing to ask us. If a data subject contacts us directly about data you control, we will not respond substantively; we will refer them to you and tell you.
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the information reasonably available to us so you can meet your own reporting duties. We will also provide reasonable assistance with data protection impact assessments and any prior consultation with the ICO, taking into account the nature of the processing and the information available to us.
Certio is hosted in the United Kingdom. Where a sub-processor processes data outside the UK, we rely on an appropriate safeguard — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision — as described in the Privacy Policy.
You may export your data at any time while your account is active. On termination, or at your written request, we will delete or irreversibly anonymise your customers' personal data, except to the extent we are required by law to retain it. Deleting your account in the app (Account → Delete account) triggers this. Data may persist in routine backups for a limited period before being overwritten on the normal backup cycle; it remains protected by this DPA until it is.
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits must be on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach, and conducted so as not to compromise the security or confidentiality of other customers' data.
You confirm that you have a lawful basis for the personal data you put into Certio, that you have given your customers the information they are entitled to, and that your instructions to us comply with data protection law. You are responsible for the accuracy of the data you enter and for the content of messages you send. Certio includes AI features that generate drafts and read documents; as stated in the Terms, their output is not warranted to be accurate and you remain responsible for checking anything before you rely on or send it.
The limitations and exclusions of liability in the Terms of Service apply to this DPA. If there is a conflict between this DPA and the Terms in relation to the processing of your customers' personal data, this DPA prevails. This DPA is governed by the laws of England & Wales, and the courts of England & Wales have exclusive jurisdiction.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Certio certification, quoting, invoicing, scheduling and messaging service. |
| Duration | For as long as your account is active, plus the limited backup period described in section 9. |
| Nature of processing | Collection, recording, organisation, storage, retrieval, use, transmission, backup, erasure — by automated means. |
| Purpose | Producing electrical certificates and job records; preparing and sending quotes and invoices; scheduling; handling enquiries and messages; optional AI drafting and document reading; optional payment, calendar, email and bank-reconciliation connections you enable. |
| Categories of data subject | Your customers and prospective customers; site contacts; and, where you use team features, your workers. |
| Types of personal data | Names; postal addresses and site addresses; phone numbers; email addresses; message and enquiry content; job, certificate and inspection records relating to a property; quote, invoice and payment records; photographs taken on site; and, where you enable it, worker location during working hours. |
| Special category data | None is requested or required. You should not enter special category data into the Service. |
Terms of Service · Privacy Policy · Privacy & Terms (combined)