These Data Processing Terms govern how SortedMate Ltd (“Processor”) processes personal data on behalf of users (“Controller”) when they enter their clients' data into the SortedMate platform. This document is an addendum to our Terms of Service and applies specifically to the processing of personal data belonging to your customers (the “Data Subjects”).
Scope & Definitions
Key Roles
Controller
You (the SortedMate user/tradesperson). You determine why and how your clients' personal data is processed in SortedMate.
Processor
SortedMate Ltd. We process personal data only on your documented instructions and for no other purpose.
Data Subjects
Your customers: homeowners, businesses, and other individuals whose personal data you upload to SortedMate.
Personal Data
Any information relating to an identified or identifiable natural person (name, email, phone, address, job site location, financial details, etc.).
Processing
Any operation performed on personal data, including collection, recording, storage, organisation, retrieval, transmission, use, and deletion.
Applicability: These Terms apply when you enter personal data of your clients into SortedMate. You remain the Controller and are responsible for the lawfulness of processing. SortedMate acts as your Processor.
Processing Details (UK GDPR Article 28)
Subject Matter
Provision of the SortedMate platform and its features to manage your business, including customer relationship management, quoting, invoicing, and communications.
Duration
For the term of your SortedMate subscription. Processing ceases when your subscription ends, subject to our data retention policy.
Nature of Processing
- Storage in our secure database
- Organisation and indexing for retrieval
- Transmission via email, SMS, and WhatsApp
- AI enhancement (quote improvement, enquiry parsing, suggestions)
- Access by you and your team members
- Backup and disaster recovery
- Audit logging for security purposes
Purpose
To provide the SortedMate service features as described in our Terms of Service, enabling you to manage your business and communicate with your clients.
Types of Personal Data
- Client names and contact details
- Email addresses
- Phone numbers
- Postal addresses (home/business)
- Job site addresses
- Financial data (quotes, invoices, payments)
- Job descriptions and photos
- Communication history
Categories of Data Subjects
The individuals whose data you input into SortedMate: homeowners, businesses, property managers, and other individuals for whom you provide services or with whom you communicate for business purposes.
Processor Obligations
SortedMate commits to the following obligations under UK GDPR Article 28:
Processing on Instructions Only
We process personal data only on your documented instructions. We do not process data for our own purposes (except where required by law or to defend legal claims).
Confidentiality of Personnel
All staff members and contractors who access personal data are subject to confidentiality obligations and have been trained on data protection.
Appropriate Security Measures
We implement technical and organisational security measures including: AES-256 encryption at rest, TLS encryption in transit, Row-Level Security on all database tables, multi-tenancy isolation via organization_id, Multi-Factor Authentication support, and Role-Based Access Control (RBAC).
Sub-processor Management
We only use sub-processors (third-party service providers) with your prior written consent. See our Sub-Processors page for details. We maintain a current list and notify you of changes.
Data Subject Rights Assistance
We assist you in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). We will respond to your request for assistance within 30 days.
Data Breach Notification
If we discover a personal data breach, we will notify you without undue delay, and in any case within 24 hours of discovery. You are responsible for notifying the ICO and affected individuals.
Data Deletion or Return on Termination
Upon termination of our relationship or at your request, we will delete or return all personal data within 30 days of active deletion, with backup copies purged within 90 days. Financial records required by HMRC will be retained for 7 years.
Audit Information Availability
We provide audit information as reasonably requested. SOC 2 reports and audit logs are available upon request. We allow audits by you or your appointed auditor.
Controller Obligations
As the Controller, you are responsible for:
Lawful Basis
Ensuring you have a lawful basis for processing your clients' personal data under UK GDPR (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
Privacy Notices
Providing any required privacy notices to your data subjects informing them how their data is used, including disclosure that it will be processed via SortedMate.
Special Category Data
Not uploading special category data (racial/ethnic origin, political opinions, religious beliefs, union membership, genetic/biometric data, health data, sex life data) unless you have an explicit lawful basis and have implemented appropriate safeguards.
Legal Compliance
Ensuring your instructions to us comply with applicable law. You must not instruct us to process data in a manner that violates UK GDPR or other legal requirements.
International Data Transfers
Data Storage Location
Your core business data is stored in the EU (AWS eu-west-1, Ireland) via Supabase. However, some service providers process data in the United States, including Clerk (authentication), Stripe (payments), Twilio (messaging), Resend (email), OpenAI (AI features), and Google (Maps, Calendar, reCAPTCHA).
Transfer Mechanisms
For transfers to countries without a UK adequacy decision, we rely on:
- EU-US Data Privacy Framework (UK Extension)
- UK International Data Transfer Agreement (IDTA)
- UK Addendum to the EU Standard Contractual Clauses
Transfer Impact Assessments
We have conducted Transfer Impact Assessments for all international transfers in accordance with UK GDPR Article 27. These assessments are available upon request.
For detailed information about sub-processors and their locations, please refer to our Sub-Processors page.
Liability
Our liability in relation to data processing is limited as set out in our Terms of Service. In particular:
- We are not liable for any losses arising from your failure to comply with UK GDPR or these Data Processing Terms.
- We are not liable for your instructions to process data unlawfully.
- We are not liable for losses caused by your failure to implement appropriate privacy notices or obtain required consents.
- Our total liability for any claim related to data processing is capped at the fees you have paid in the 12 months preceding the claim.
Standard Data Processing Agreement
These Data Processing Terms constitute the required Data Processing Agreement (DPA) under UK GDPR Article 28. By using SortedMate, you accept these terms. If you require a separate executed DPA, please contact us at privacy@sortedmate.com.
Contact Us
For questions about these Data Processing Terms, data subject requests, or to arrange an audit:
SortedMate Ltd
3rd Floor, 86-90 Paul Street
London, EC2A 4NE
United Kingdom
Company Registration No: 16880125
ICO Registration No: ZC090709