Data Processing Agreement
Proofworks Ltd · standard form · version 1.0 · last updated 27 July 2026
1. Parties and status
This Data Processing Agreement (DPA) is entered into between:
- Proofworks Ltd, a company registered in England and Wales (company number 16940700), registered office 63 Archer Drive, Mickleover, Derby, DE3 0AG, ICO registration ZC167703 (the Processor, "we", "us"); and
- the Customer identified in the engagement to which this DPA is attached (the Controller, "you").
This DPA forms part of, and is subject to, the written services agreement between the parties (the Agreement). It applies wherever we process personal data on your behalf in connection with ProofSync or any other system we build, deploy or operate for you. Where you act as a processor for your own client, we act as your sub-processor and references to "Controller" are construed accordingly.
2. Definitions
Data Protection Legislation means the UK GDPR, the Data Protection Act 2018, and all applicable laws and regulations relating to the processing of personal data. UK GDPR, personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the Data Protection Legislation. Sub-processor means any third party engaged by us to process personal data on your behalf. Your Environment means the cloud account(s) and infrastructure that you own and control, within which the system is deployed.
3. Roles, scope and the deployment model
You are the controller of the personal data and we are your processor (or sub-processor). We process personal data only to provide the services and only on your documented instructions, including the instructions set out in this DPA and the Agreement.
Because the system is deployed inside Your Environment:
- your personal data remains within Your Environment and is not copied to, hosted on, or stored on Proofworks' own infrastructure in the ordinary course of the services;
- our processing consists of administering, configuring, deploying, monitoring, maintaining and supporting the system within Your Environment, under access that you grant and can revoke; and
- you retain control of where the data lives, who may reach it, and the credentials and keys to it.
If we are ever required to process personal data outside Your Environment (for example to reproduce a support issue), we will do so only on your documented instructions and only to the extent necessary.
4. Our obligations as processor
We will:
- Instructions. Process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law — in which case we will inform you first, unless the law prohibits it.
- Confidentiality. Ensure that personnel authorised to process the personal data are bound by an appropriate duty of confidentiality.
- Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 UK GDPR.
- Sub-processors. Engage sub-processors only in accordance with clause 5.
- Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights.
- Assistance. Assist you in ensuring compliance with your obligations under Articles 32–36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to us.
- Deletion or return. At the end of the services, delete or return all personal data as set out in clause 8.
- Demonstrating compliance. Make available to you the information necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits, as set out in clause 9.
- Notify limits. Immediately inform you if, in our opinion, an instruction infringes the Data Protection Legislation.
5. Sub-processors
You give general written authorisation for us to engage sub-processors. For systems deployed inside Your Environment, no sub-processor processes your personal data by default — the system, and where applicable any AI model, run within your own cloud account. Our current sub-processor list for our hosted platforms is published at proof-works.co.uk/trust and summarised in Annex 3; that list does not apply to an in-Environment deployment except to the extent expressly agreed.
Where we propose to add or replace a sub-processor that would process your personal data, we will give you prior notice and a reasonable opportunity to object on reasonable data-protection grounds. Any sub-processor we engage will be bound by data-protection obligations no less protective than those in this DPA, and we remain fully liable to you for its performance.
6. International transfers
Because your personal data remains within Your Environment, you determine the region in which it is stored and processed, and we do not transfer it outside the UK. Where any transfer of personal data outside the UK is nonetheless required for the services, we will effect it only on your instructions and subject to an appropriate transfer mechanism under the Data Protection Legislation (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses).
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and in any event in time to support your own notification obligations. Our notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. We operate continuous monitoring across live systems and maintain a documented incident-response process; where a confirmed personal data breach engages the statutory threshold, we support notification to the ICO within 72 hours as required by law.
8. Deletion and return
Because the system and its data reside in Your Environment, you retain your personal data at all times and on termination — there is no Proofworks-held copy to hand back. On termination or expiry of the services, and at your choice, we will delete or return any personal data that happens to be in our possession or control (for example, extracts created for support), and delete existing copies unless retention is required by law.
9. Audit
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA and Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, no more than once in any twelve-month period (save where required by a supervisory authority or following a personal data breach), subject to reasonable confidentiality and security conditions.
10. Liability, precedence and general
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is a conflict between this DPA and the Agreement on the processing of personal data, this DPA prevails. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction. This DPA continues for as long as we process personal data on your behalf.
Annex 1 — Details of the processing
| Subject matter | Keeping two operational systems in step — for ProofSync, the verified synchronisation of completed jobs, updates and related records between your system and your client's CAFM. |
|---|---|
| Duration | The term of the services under the Agreement. |
| Nature and purpose | Reading, matching, validating and writing job records between systems so that completed work is reflected in both, with read-back verification; plus the administration, monitoring and support of that system within Your Environment. |
| Types of personal data | Typically limited to business-context data on job and work-order records: names and contact details of staff, engineers/operatives and site contacts; site and property addresses; job references, notes, times, costs and status; and document metadata. No special-category data is intended to be processed. You remain responsible for the data you place into your systems. |
| Categories of data subject | Your personnel and contractors; your clients' personnel; and individuals named on the underlying job or work-order records. |
Annex 2 — Technical and organisational measures
We operate to a certified security standard (Cyber Essentials) and maintain measures appropriate to the risk, including:
- Access control — unique accounts, least-privilege access, and multi-factor authentication on every account and cloud service touching customer data; documented joiners/movers/leavers with revocation within 24 hours of departure.
- Deployment in Your Environment — the system runs in your own cloud account under your credentials and keys; our access is scoped, logged and revocable by you.
- Encryption — data encrypted in transit; encryption at rest per your environment's configuration.
- Segregation and least data — only the fields necessary for the sync are read and written; matching is on unique reference, never a guess.
- Logging and monitoring — automated health checks and audit logging across live systems, with out-of-hours alerting.
- Secure engineering — version-controlled code in private repositories; encrypted, access-controlled backups; supported, auto-patched systems and encrypted devices.
- Resilience and response — a documented incident-response process; breach assessment and notification as set out in clause 7.
- Governance — security policies, an asset register and a shared-responsibility review owned by a director and reviewed at least annually.
Annex 3 — Sub-processors
In-Environment deployments: none by default. The system, and where applicable the AI model (for example via Amazon Bedrock in your own cloud account), run inside Your Environment, so no third party processes your personal data on our behalf.
Our hosted platforms (not applicable to an in-Environment deployment unless expressly agreed) rely on a small number of sub-processors, published and kept current at proof-works.co.uk/trust. We give notice of material changes to sub-processors handling personal data on your behalf.