Data Processing Agreement

Proofworks Ltd · standard form · version 1.0 · last updated 27 July 2026

How to read this. Proofworks builds and runs systems inside your own cloud environment. Your personal data stays in your environment and is not hosted on our infrastructure. Under UK GDPR we therefore act as a limited processor — our access is confined to building, deploying, monitoring and supporting the system within your account, on your documented instructions. This is our standard form; the operative version is the copy executed as a schedule to your engagement.

1. Parties and status

This Data Processing Agreement (DPA) is entered into between:

This DPA forms part of, and is subject to, the written services agreement between the parties (the Agreement). It applies wherever we process personal data on your behalf in connection with ProofSync or any other system we build, deploy or operate for you. Where you act as a processor for your own client, we act as your sub-processor and references to "Controller" are construed accordingly.

2. Definitions

Data Protection Legislation means the UK GDPR, the Data Protection Act 2018, and all applicable laws and regulations relating to the processing of personal data. UK GDPR, personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the Data Protection Legislation. Sub-processor means any third party engaged by us to process personal data on your behalf. Your Environment means the cloud account(s) and infrastructure that you own and control, within which the system is deployed.

3. Roles, scope and the deployment model

You are the controller of the personal data and we are your processor (or sub-processor). We process personal data only to provide the services and only on your documented instructions, including the instructions set out in this DPA and the Agreement.

Because the system is deployed inside Your Environment:

If we are ever required to process personal data outside Your Environment (for example to reproduce a support issue), we will do so only on your documented instructions and only to the extent necessary.

4. Our obligations as processor

We will:

  1. Instructions. Process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law — in which case we will inform you first, unless the law prohibits it.
  2. Confidentiality. Ensure that personnel authorised to process the personal data are bound by an appropriate duty of confidentiality.
  3. Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 UK GDPR.
  4. Sub-processors. Engage sub-processors only in accordance with clause 5.
  5. Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights.
  6. Assistance. Assist you in ensuring compliance with your obligations under Articles 32–36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to us.
  7. Deletion or return. At the end of the services, delete or return all personal data as set out in clause 8.
  8. Demonstrating compliance. Make available to you the information necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits, as set out in clause 9.
  9. Notify limits. Immediately inform you if, in our opinion, an instruction infringes the Data Protection Legislation.

5. Sub-processors

You give general written authorisation for us to engage sub-processors. For systems deployed inside Your Environment, no sub-processor processes your personal data by default — the system, and where applicable any AI model, run within your own cloud account. Our current sub-processor list for our hosted platforms is published at proof-works.co.uk/trust and summarised in Annex 3; that list does not apply to an in-Environment deployment except to the extent expressly agreed.

Where we propose to add or replace a sub-processor that would process your personal data, we will give you prior notice and a reasonable opportunity to object on reasonable data-protection grounds. Any sub-processor we engage will be bound by data-protection obligations no less protective than those in this DPA, and we remain fully liable to you for its performance.

6. International transfers

Because your personal data remains within Your Environment, you determine the region in which it is stored and processed, and we do not transfer it outside the UK. Where any transfer of personal data outside the UK is nonetheless required for the services, we will effect it only on your instructions and subject to an appropriate transfer mechanism under the Data Protection Legislation (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses).

7. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and in any event in time to support your own notification obligations. Our notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. We operate continuous monitoring across live systems and maintain a documented incident-response process; where a confirmed personal data breach engages the statutory threshold, we support notification to the ICO within 72 hours as required by law.

8. Deletion and return

Because the system and its data reside in Your Environment, you retain your personal data at all times and on termination — there is no Proofworks-held copy to hand back. On termination or expiry of the services, and at your choice, we will delete or return any personal data that happens to be in our possession or control (for example, extracts created for support), and delete existing copies unless retention is required by law.

9. Audit

We will make available to you the information reasonably necessary to demonstrate compliance with this DPA and Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, no more than once in any twelve-month period (save where required by a supervisory authority or following a personal data breach), subject to reasonable confidentiality and security conditions.

10. Liability, precedence and general

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is a conflict between this DPA and the Agreement on the processing of personal data, this DPA prevails. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction. This DPA continues for as long as we process personal data on your behalf.

Annex 1 — Details of the processing

Subject matterKeeping two operational systems in step — for ProofSync, the verified synchronisation of completed jobs, updates and related records between your system and your client's CAFM.
DurationThe term of the services under the Agreement.
Nature and purposeReading, matching, validating and writing job records between systems so that completed work is reflected in both, with read-back verification; plus the administration, monitoring and support of that system within Your Environment.
Types of personal dataTypically limited to business-context data on job and work-order records: names and contact details of staff, engineers/operatives and site contacts; site and property addresses; job references, notes, times, costs and status; and document metadata. No special-category data is intended to be processed. You remain responsible for the data you place into your systems.
Categories of data subjectYour personnel and contractors; your clients' personnel; and individuals named on the underlying job or work-order records.

Annex 2 — Technical and organisational measures

We operate to a certified security standard (Cyber Essentials) and maintain measures appropriate to the risk, including:

Annex 3 — Sub-processors

In-Environment deployments: none by default. The system, and where applicable the AI model (for example via Amazon Bedrock in your own cloud account), run inside Your Environment, so no third party processes your personal data on our behalf.

Our hosted platforms (not applicable to an in-Environment deployment unless expressly agreed) rely on a small number of sub-processors, published and kept current at proof-works.co.uk/trust. We give notice of material changes to sub-processors handling personal data on your behalf.

This is Proofworks' standard Data Processing Agreement, published for transparency. The version that governs a specific engagement is the one executed as a schedule to your services agreement, and may be adjusted to reflect your particular processing and requirements. Questions or a countersigned copy: admin@proof-works.co.uk.