This Data Processing Agreement ("DPA") forms part of, and is subject to, the Conformiq Terms of Service between Conformiq ("Processor") and the customer organisation ("Controller") that uses the Service. It reflects the parties' agreement on processing of personal data under UK GDPR and EU GDPR (Article 28).
1. Subject matter and duration
The Processor processes personal data submitted by the Controller through the Service for the duration of the Controller's subscription and any wind-down period specified in the Terms.
2. Nature and purpose of processing
Hosting, storage, retrieval, transmission and reminder notifications relating to equipment and inspection-certificate records maintained by the Controller.
3. Categories of data subjects
- The Controller's employees and authorised users of the Service.
- Named contacts recorded by the Controller in equipment or certificate records.
4. Categories of personal data
- Identification data: name, work email, organisation, role.
- Equipment metadata that may include names or identifiers.
- Certificate documents that may include names of inspectors or approvers.
- Support and communication records.
5. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures under Article 32 (see Annex 1).
- Assist the Controller with data-subject requests and DPIAs where reasonably required.
- Notify the Controller without undue delay upon becoming aware of a personal data breach.
- On termination, delete or return personal data within 90 days, subject to statutory retention.
6. Sub-processors
The Controller authorises the following sub-processors:
- Lovable Cloud (Supabase) — application hosting, database and file storage (EU).
- Stripe Payments Europe, Ltd. — subscription billing.
- Google LLC — optional Sign in with Google (identity only).
- Lovable Email — transactional and reminder email delivery.
The Processor will give at least 30 days' notice of any intended change of sub-processor. The Controller may object on reasonable grounds.
7. International transfers
Where personal data is transferred outside the UK/EEA, the parties rely on the UK IDTA and/or EU Standard Contractual Clauses as appropriate.
8. Audit
The Processor will make available all information reasonably necessary to demonstrate compliance with Article 28. Audits will be at the Controller's expense, with reasonable notice and confidentiality safeguards.
Annex 1 — Security measures
- TLS 1.2+ for all data in transit.
- Encryption at rest for database storage and uploaded documents.
- Role-based access, least-privilege engineering access.
- Row-level security policies scoping data to the owning organisation.
- Automated backups with tested restoration procedures.
- Vulnerability management via ongoing security scanning of the platform.
Contact
Questions or requests under this DPA: info@conformiq.co.uk.
Note. This DPA is provided as a starting template. Enterprise customers requiring a countersigned copy should contact us.