Legal
Data Processing Addendum
Last updated 14 August 2026 · Forms part of the Terms
This Addendum (“DPA”) applies where you use OnPoint to process personal data about your own customers, staff, sites and contacts. It forms part of the Terms and is the written contract required by Article 28(3) of the UK GDPR. Where this DPA conflicts with the Terms on data protection, this DPA wins.
1Parties and roles
“Processor”, “we” or “us” means OnPoint Business, of London, United Kingdom.
“Controller”, “you” means the organisation that holds the OnPoint subscription.
For Customer Data — the records you create in OnPoint about your customers, sites, jobs, appointments, certificates, quotes and invoices — you are the controller and we are your processor. For data about you and your team as OnPoint users (your account, billing, support history, product usage) we are the controller in our own right; that processing is governed by our Privacy Policy, not this DPA.
2Subject matter, duration, nature and purpose
3Our obligations — Art. 28(3)(a)–(h)
(a) Documented instructions
We process Customer Data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we'll tell you first unless the law forbids it. Your instructions are: the Terms, this DPA, your configuration of the product, and the actions you and your users take in it. We will tell you if we consider an instruction infringes data protection law.
(b) Confidentiality
Everyone we authorise to process Customer Data is under a binding duty of confidentiality and is granted access on a least-privilege basis. This includes our support and engineering staff, whose administrative access is logged. Where diagnosing a fault requires viewing the product as one of your users sees it, that capability is restricted to the platform developer, every use is recorded in an audit log (actor, subject, time, IP, device), access is refused if it cannot be recorded, and the session is revoked on exit. We will provide you with the audit record for your organisation on request.
(c) Security
We implement appropriate technical and organisational measures under Art. 32 — set out in Annex B.
(d) Sub-processors
You give general written authorisation for us to engage sub-processors. The current list is published in our Privacy Policy. We will give at least 30 days' noticebefore adding or replacing one, and you may object on reasonable data-protection grounds within that period; if we can't resolve the objection you may terminate the affected services without penalty. We impose data-protection terms on each sub-processor no less protective than these, and remain fully liable for their performance.
(e) Assisting with data subject rights
Taking account of the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests to exercise rights under Chapter III. In practice you can access, correct, export and delete Customer Data yourself in the product; where you can't, contact us and we'll help. If a data subject contacts us directly about Customer Data, we will not respond substantively — we'll refer them to you and tell you.
(f) Assisting with Arts. 32–36
We assist you in ensuring compliance with the security, breach-notification and data-protection-impact-assessment obligations in Arts. 32–36, taking into account the nature of processing and the information available to us.
(g) Deletion or return
On termination you may export your Customer Data. After the period in clause 9 we delete it, except where UK law requires us to keep it.
(h) Information and audits
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy this with documentation and written responses where that reasonably demonstrates compliance; on-site audits are limited to once in any 12 months absent a breach or regulator requirement, on reasonable notice and subject to confidentiality.
4Personal data breaches
We notify you without undue delayafter becoming aware of a personal data breach affecting Customer Data, with the information available to us: the nature of the breach, categories and approximate numbers of records and data subjects affected, likely consequences, and the measures taken or proposed. We'll provide further detail as it becomes available. You remain responsible for deciding whether to notify the ICO and affected data subjects, since you are the controller.
5International transfers
Customer Data is primarily stored in the UK and EU. Some sub-processors operate outside the UK. Where we transfer Customer Data outside the UK we rely on UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with additional safeguards (encryption in transit and at rest, access controls, contractual use restrictions).
6Your obligations
You warrant that you have a lawful basis for the Customer Data you put into OnPoint; that you have given your data subjects the information Arts. 13–14 require, including that you use a third-party platform; and that your instructions to us will not put us in breach of data protection law. You are responsible for the accuracy of Customer Data and for honouring opt-outs on any messaging you send through the product.
7Our own processing as controller
We process limited data as controller to run and improve the Service — account and billing records, support interactions, security logs and aggregate usage analytics. We do not sell personal data, and we do not use Customer Data to train machine learning models.
8AI features
Where you use an AI feature, the content you submit is sent to our AI sub-processor to generate a response. Those providers are contractually prohibited from using your prompts or outputs to train their public models. AI features are optional and only process what you actively submit to them.
9Retention and deletion
Customer Data is retained for the life of your subscription. After closure we retain it for up to 90 days so you can recover or export it, then delete it, except where a legal obligation (for example HMRC record-keeping) requires longer. Backups are overwritten on a rolling cycle, typically within 35 days.
10Contact
Data protection queries, audit requests and breach correspondence: privacy@onpointbusiness.co.uk.
AAnnex A — Processing details
As set out in clause 2 above.
BAnnex B — Technical and organisational measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256) on managed infrastructure.
- Passwords stored only as salted hashes; we cannot read them.
- Row-level security in the database so each organisation reaches only its own records, with server-side membership checks on every service-role API route.
- Object storage served only through an authorising proxy that resolves each file back to its owning organisation; customer-portal links are scoped to the specific document they were issued for.
- Least-privilege internal access; administrative and impersonation actions logged.
- Card data handled solely by Stripe (PCI DSS Level 1); bank access via TrueLayer (FCA-authorised). We store neither card numbers nor bank credentials.
- Segregated environments, code review, dependency scanning and periodic security review.
- Automated backups with defined restore procedures.
CAnnex C — Sub-processors
Maintained at onpointbusiness.co.uk/privacy#sub-processors, which forms part of this DPA. Changes are notified under clause 3(d).