Parties and scope
This data processing agreement (“DPA”) is between the customer that has accepted our terms of service (the “controller”) and BigThumb Digital Ltd, company number 11489879, Unit 8 The Courtyard, Gaulby Lane, Stoughton, Leicester, LE2 2FL (the “processor”). It forms part of the terms and applies whenever we process personal data on the customer’s behalf in providing Groundcuvva. It is intended to meet Article 28(3) of the UK GDPR and the Data Protection Act 2018. Words such as “personal data”, “processing”, “data subject” and “personal data breach” have the meaning given in the UK GDPR.
1. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Hosting and operating Groundcuvva, online software for grounds and garden maintenance companies. |
| Duration | The term of the customer’s subscription (or free trial), plus the deletion grace period and backup expiry described in section 9. |
| Nature and purpose | Storing, organising, displaying, transmitting (by email and the client portal), backing up and deleting customer data so the customer can schedule work, manage staff, record time, holidays and absence, keep compliance and health-and-safety records, monitor lone workers and report to its clients. |
| Data subjects | The customer’s employees, workers and contractors (current and former); the customer’s clients and their contacts (households, site contacts, managing agents); other people named in records, such as witnesses or injured persons in incident reports. |
| Personal data | Names, contact details, job titles, user accounts; employment details (start date, hours, working days, pay rate, holiday allowance); holiday and absence requests; time-clock entries and clock-in status; visit assignments, notes and photos; training records, licences and certificates; equipment use and vehicle checks; client names, addresses, site locations and coordinates, contract details and correspondence; activity logs. |
| Special category data | Health data: sickness absence and reasons; injury details in accident and incident reports; health surveillance and hand-arm vibration (HAVS) exposure records; any health information the customer records in notes. Processed only because the customer records it, for its employment, health and safety obligations (UK GDPR Art. 9(2)(b), DPA 2018 Sch. 1 para. 1). |
| Not processed | Device location (GPS). The lone-worker check uses only whether someone is still clocked in, or has a visit still in progress, after the customer’s daily check time. |
2. Processing on instructions
We process customer personal data only on the customer’s documented instructions. The terms, this DPA and the customer’s use and configuration of the service are those instructions. If the law requires us to process it otherwise, we will tell the customer first unless the law forbids it. We will tell the customer if we think an instruction breaks data protection law.
The customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis and an Article 9 condition for special category data, giving privacy information to its staff and clients, and deciding retention periods.
3. Confidentiality
Everyone we authorise to process customer personal data is under a contractual or statutory duty of confidentiality, and only has access where needed to run, secure or support the service. Our staff access a customer’s account only to support that customer, to keep the service secure, or where the law requires it; such access is recorded in an audit log.
4. Security
We implement the technical and organisational measures in Annex A, appropriate to the risk, as required by Article 32. We may update them so long as the overall level of security does not fall.
5. Sub-processors
- The customer gives general authorisation for us to use sub-processors. The current list is on our sub-processors page.
- We will give at least 30 days’ notice (by email to the account owner and on that page) before adding or replacing a sub-processor. The customer may object on reasonable data protection grounds within that period. We will then try to address the objection; if we cannot, the customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
- We impose data protection obligations on each sub-processor that are no less protective than this DPA, and remain liable to the customer for their performance.
6. Data subject rights
The service lets the customer find, correct, export and delete personal data itself. Where it cannot, we will help the customer, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects. If we receive a request directly, we will pass it to the customer without undue delay and will not answer it ourselves except to say we have done so.
7. Assistance with compliance
Taking into account the nature of processing and the information available to us, we will help the customer meet its obligations on security, breach notification, data protection impact assessments (DPIAs) and prior consultation with the ICO (Articles 32 to 36). We provide a DPIA template pre-filled for Groundcuvva on request.
8. Personal data breaches
- We will notify the customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting customer personal data.
- The notice will describe, as far as then known: the nature of the breach, the categories and approximate numbers of data subjects and records, likely consequences, and the measures taken or proposed. We will send further information as it becomes available.
- We will take reasonable steps to contain and remedy the breach and cooperate with the customer’s own notification to the ICO (within 72 hours of the customer becoming aware) and to data subjects.
- Notifying a breach is not an admission of fault.
9. Return and deletion
- The customer can export its data from the service at any time during the subscription.
- When a paid subscription ends, we keep customer data for 30 days so the customer can export it, then permanently delete the company, its records and its files from the live service. A free trial that ends without a subscription is deleted 60 days after it ends. The account owner is emailed a week before deletion, and can delete the company at any time from Settings.
- Deleted data leaves our database provider’s point-in-time backups as they expire, within [BACKUP RETENTION, e.g. 7 days]. Until then backups are encrypted, access-controlled and not used except for disaster recovery.
- We may keep data longer only where UK law requires us to, and then only for that purpose.
Records the customer must keep by law
The service doesn’t delete compliance records on its own. Employee records the customer needs for health and safety compliance are kept until the customer deletes them. Archiving an employee removes their access but keeps their incident, health surveillance (HAVS) and pesticide application records available to the customer for the periods the law requires (for example 40 years for vibration health surveillance, three years for accident records and pesticide applications). Likewise, deleting one of the customer’s clients removes that client’s details, jobs, visits, photos and documents but keeps pesticide application records, waste transfer notes and incident reports, with the client name and site address as recorded at the time, for the same periods (two years for waste transfer notes). The customer is responsible for deleting records once those periods have passed, and for exporting them before ending its subscription.
10. Information and audits
We will make available the information reasonably needed to demonstrate compliance with Article 28, such as this DPA, our security summary, sub-processor terms and any certifications. If that is not enough, the customer (or an independent auditor bound by confidentiality) may audit our compliance once a year on 30 days’ written notice, during business hours, at the customer’s cost, without access to other customers’ data. Audits required by the ICO or following a breach are not limited to once a year.
11. International transfers
We will not transfer customer personal data outside the UK except to a sub-processor listed on our sub-processors page and with a valid transfer mechanism: UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework for certified recipients, or the ICO’s International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
12. Liability and order of precedence
Liability under this DPA is subject to the limits in the terms, except where the law does not allow liability to be limited. If this DPA conflicts with the terms on the processing of personal data, this DPA wins. It is governed by the law of England and Wales.
Annex A: Security measures
- Encryption in transit: HTTPS only, with HSTS on every company web address.
- Encryption at rest: database (Neon, AWS London) and file storage (Cloudflare R2) are encrypted at rest by the providers. Gate codes, key-safe notes, right-to-work notes and accident-book injury details are additionally encrypted at field level by the application (AES-256-GCM, key held outside the database).
- Separation: each customer’s records carry its company identifier and every query is scoped to the signed-in user’s company; company web addresses are separate subdomains.
- Access control: role-based permissions (owner, admin, staff, client portal); password hashing; rate limits on sign-in and reset; short sessions (three days, one day without “keep me signed in”); email verification; optional two-step sign-in (authenticator app), mandatory for our own administrators.
- Files: uploads are type-checked, stored privately and served only to authorised users, never as executable content.
- Browser protections: Content Security Policy, frame blocking, no-sniff and strict referrer headers.
- Logging: an activity log of changes in each account; an access log of views of HR records and the accident book and of personal-data exports, visible to the customer’s owners and admins; an audit log of our administrators’ actions; platform logs for incident investigation.
- Backups: continuous point-in-time recovery by the database provider.
- People and process: least-privilege access to production, confidentiality obligations, a written breach response procedure, and dependency updates for known vulnerabilities.
Contact
Notices under this DPA: privacy@groundcuvva.com.