Data Processing Agreement
Last Updated: 09/08/2026
This Data Processing Agreement ("Agreement") forms part of the Terms and Conditions between TradeMartin Ltd ("Processor", "we", "us", "our") and the customer using the Service ("Controller", "you").
This Agreement applies whenever we process Personal Data on your behalf through the TradeMartin application.
1. Purpose
This Agreement sets out each party's obligations regarding the processing of Personal Data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and any applicable data protection legislation.
2. Definitions
Unless otherwise defined in this Agreement, capitalised terms have the meanings given in the UK GDPR.
Controller means the person or organisation determining the purposes and means of processing Personal Data.
Processor means the organisation processing Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means has the meaning given by Article 4 UK GDPR.
Subprocessor means a third party engaged by the Processor to process Personal Data.
3. Scope of Processing
We process Personal Data solely for the purpose of providing the Service.
Typical categories of processing include storing customer records, creating quotations, managing jobs, generating invoices, storing notes, scheduling work, processing expenses, storing uploaded documents, synchronising integrations, providing AI-powered assistance and customer support.
4. Categories of Personal Data
Depending on how the Service is used, Personal Data may include names, addresses, email addresses, telephone numbers, job addresses, appointment details, invoices, quotations, payment references, communications, uploaded documents, photographs and business contact details.
The Controller determines what Personal Data is entered into the Service.
5. Categories of Data Subjects
Processing may relate to customers, prospective customers, employees, subcontractors, suppliers, business contacts and authorised users.
6. Processor Obligations
We shall process Personal Data only on documented instructions from the Controller unless required by law.
We shall ensure persons authorised to process Personal Data are subject to confidentiality obligations.
We shall implement appropriate technical and organisational security measures.
We shall assist the Controller where reasonably required to comply with UK GDPR.
We shall notify the Controller without undue delay upon becoming aware of a Personal Data Breach.
We shall delete or return Personal Data upon termination unless retention is required by law.
We shall maintain records of processing activities where required.
7. Controller Obligations
The Controller shall comply with applicable data protection legislation.
The Controller shall ensure it has a lawful basis for processing Personal Data.
The Controller shall ensure Personal Data entered into the Service is accurate where reasonably practicable.
The Controller shall respond to Data Subject requests.
The Controller shall ensure its Users comply with applicable laws.
The Controller remains responsible for determining the purposes and lawful basis for processing.
8. Security Measures
We implement appropriate technical and organisational measures designed to protect Personal Data.
These may include encryption in transit, encryption at rest, secure authentication, role-based permissions, audit logging, regular security updates, infrastructure monitoring, secure backups and vulnerability management.
Security measures may evolve over time provided they maintain an appropriate level of protection.
9. Confidentiality
All personnel authorised to process Personal Data are subject to confidentiality obligations.
Access to Personal Data is restricted to personnel who require access in order to perform their duties.
10. Subprocessors
The Controller authorises us to appoint Subprocessors where necessary for providing the Service.
Examples include cloud infrastructure providers, payment processors, email delivery providers, AI providers, customer support providers, monitoring services, analytics providers and backup providers.
We shall ensure Subprocessors are subject to written agreements imposing data protection obligations substantially equivalent to those contained within this Agreement.
A current list of Subprocessors will be made available upon request or published on our website.
11. International Transfers
Where Personal Data is transferred outside the United Kingdom, we shall ensure appropriate safeguards are implemented including International Data Transfer Agreements, Standard Contractual Clauses, adequacy regulations and equivalent lawful safeguards.
12. AI Processing
Where the Controller chooses to use AI Features, Personal Data contained within prompts may be processed by approved AI service providers solely to generate responses.
We shall use commercially reasonable efforts to ensure AI providers implement appropriate security measures.
We do not intentionally use identifiable Controller data to train publicly available AI models without appropriate authorisation.
The Controller remains responsible for reviewing AI-generated outputs before acting upon them.
13. Data Subject Rights
Taking into account the nature of processing, we shall provide reasonable assistance to enable the Controller to fulfil obligations relating to access requests, rectification, erasure, restriction, portability and objections.
Where we receive a request directly from a Data Subject relating to Controller data, we shall promptly notify the Controller unless legally prohibited.
14. Personal Data Breaches
Upon becoming aware of a Personal Data Breach affecting Controller data, we shall notify the Controller without undue delay.
We shall provide available information regarding the breach, investigate the incident, take reasonable steps to mitigate its effects and cooperate with the Controller where appropriate.
15. Audits
Upon reasonable written notice, the Controller may request information demonstrating compliance with this Agreement.
Where additional audits are reasonably required, both parties shall cooperate in good faith.
Audits must be conducted during normal business hours, avoid disruption to other customers and protect confidential information.
We may satisfy audit requests through recognised independent security reports or certifications where appropriate.
16. Deletion and Return of Data
Upon termination of the Services, the Controller may export Customer Data during any applicable retention period.
Following expiry of the retention period, we shall securely delete Personal Data unless retention is required by law.
Backup systems may retain encrypted copies for a limited disaster recovery period before automatic deletion.
17. Liability
Each party remains liable for its own compliance with applicable data protection legislation.
Nothing within this Agreement limits or excludes liability where such limitation would be unlawful.
Liability relating to this Agreement shall otherwise be governed by the limitation of liability provisions contained within the Terms and Conditions.
18. Order of Precedence
If there is any conflict between this Agreement and the Terms and Conditions regarding the processing of Personal Data, this Agreement shall prevail.
19. Governing Law
This Agreement shall be governed by the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction regarding disputes arising under this Agreement.

