# Data Processing Terms

**Last updated: February 2026**

How SortedMate processes and protects your clients' personal data in accordance with UK GDPR Article 28.

---

These Data Processing Terms govern how SortedMate Ltd ("Processor") processes personal data on behalf of users ("Controller") when they enter their clients' data into the SortedMate platform. This document is an addendum to our [Terms of Service](https://sortedmate.com/legal/terms) and applies specifically to the processing of personal data belonging to your customers (the "Data Subjects").

## Scope & Definitions

### Key Roles

- **Controller** - You (the SortedMate user/tradesperson). You determine why and how your clients' personal data is processed in SortedMate.
- **Processor** - SortedMate Ltd. We process personal data only on your documented instructions and for no other purpose.
- **Data Subjects** - Your customers: homeowners, businesses, and other individuals whose personal data you upload to SortedMate.
- **Personal Data** - Any information relating to an identified or identifiable natural person (name, email, phone, address, job site location, financial details, etc.).
- **Processing** - Any operation performed on personal data, including collection, recording, storage, organisation, retrieval, transmission, use, and deletion.

**Applicability:** These Terms apply when you enter personal data of your clients into SortedMate. You remain the Controller and are responsible for the lawfulness of processing. SortedMate acts as your Processor.

## Processing Details (UK GDPR Article 28)

### Subject Matter

Provision of the SortedMate platform and its features to manage your business, including customer relationship management, quoting, invoicing, and communications.

### Duration

For the term of your SortedMate subscription. Processing ceases when your subscription ends, subject to our data retention policy.

### Nature of Processing

- Storage in our secure database
- Organisation and indexing for retrieval
- Transmission via email, SMS, and WhatsApp
- AI enhancement (quote improvement, enquiry parsing, suggestions)
- Access by you and your team members
- Backup and disaster recovery
- Audit logging for security purposes

### Purpose

To provide the SortedMate service features as described in our Terms of Service, enabling you to manage your business and communicate with your clients.

### Types of Personal Data

- Client names and contact details
- Email addresses
- Phone numbers
- Postal addresses (home/business)
- Job site addresses
- Financial data (quotes, invoices, payments)
- Job descriptions and photos
- Communication history

### Categories of Data Subjects

The individuals whose data you input into SortedMate: homeowners, businesses, property managers, and other individuals for whom you provide services or with whom you communicate for business purposes.

## Processor Obligations

SortedMate commits to the following obligations under UK GDPR Article 28:

### Processing on Instructions Only

We process personal data only on your documented instructions. We do not process data for our own purposes (except where required by law or to defend legal claims).

### Confidentiality of Personnel

All staff members and contractors who access personal data are subject to confidentiality obligations and have been trained on data protection.

### Appropriate Security Measures

We implement technical and organisational security measures including: AES-256 encryption at rest, TLS encryption in transit, Row-Level Security on all database tables, multi-tenancy isolation via organization_id, Multi-Factor Authentication support, and Role-Based Access Control (RBAC).

### Sub-processor Management

We only use sub-processors (third-party service providers) with your prior written consent. See our [Sub-Processors page](https://sortedmate.com/legal/sub-processors) for details. We maintain a current list and notify you of changes.

### Data Subject Rights Assistance

We assist you in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). We will respond to your request for assistance within 30 days.

### Data Breach Notification

If we discover a personal data breach, we will notify you without undue delay, and in any case within 24 hours of discovery. You are responsible for notifying the ICO and affected individuals.

### Data Deletion or Return on Termination

Upon termination of our relationship or at your request, we will delete or return all personal data within 30 days of active deletion, with backup copies purged within 90 days. Financial records required by HMRC will be retained for 7 years.

### Audit Information Availability

We provide audit information as reasonably requested. SOC 2 reports and audit logs are available upon request. We allow audits by you or your appointed auditor.

## Controller Obligations

As the Controller, you are responsible for:

### Lawful Basis

Ensuring you have a lawful basis for processing your clients' personal data under UK GDPR (consent, contract, legal obligation, vital interests, public task, or legitimate interests).

### Privacy Notices

Providing any required privacy notices to your data subjects informing them how their data is used, including disclosure that it will be processed via SortedMate.

### Special Category Data

Not uploading special category data (racial/ethnic origin, political opinions, religious beliefs, union membership, genetic/biometric data, health data, sex life data) unless you have an explicit lawful basis and have implemented appropriate safeguards.

### Legal Compliance

Ensuring your instructions to us comply with applicable law. You must not instruct us to process data in a manner that violates UK GDPR or other legal requirements.

## International Data Transfers

### Data Storage Location

Your core business data is stored in the EU (AWS eu-west-1, Ireland) via Supabase. However, some service providers process data in the United States, including Clerk (authentication), Stripe (payments), Twilio (messaging), Resend (email), OpenAI (AI features), and Google (Maps, Calendar, reCAPTCHA).

### Transfer Mechanisms

For transfers to countries without a UK adequacy decision, we rely on:

- EU-US Data Privacy Framework (UK Extension)
- UK International Data Transfer Agreement (IDTA)
- UK Addendum to the EU Standard Contractual Clauses

### Transfer Impact Assessments

We have conducted Transfer Impact Assessments for all international transfers in accordance with UK GDPR Article 27. These assessments are available upon request.

For detailed information about sub-processors and their locations, please refer to our [Sub-Processors page](https://sortedmate.com/legal/sub-processors).

## Liability

Our liability in relation to data processing is limited as set out in our [Terms of Service](https://sortedmate.com/legal/terms). In particular:

- We are not liable for any losses arising from your failure to comply with UK GDPR or these Data Processing Terms.
- We are not liable for your instructions to process data unlawfully.
- We are not liable for losses caused by your failure to implement appropriate privacy notices or obtain required consents.
- Our total liability for any claim related to data processing is capped at the fees you have paid in the 12 months preceding the claim.

## Standard Data Processing Agreement

These Data Processing Terms constitute the required Data Processing Agreement (DPA) under UK GDPR Article 28. By using SortedMate, you accept these terms. If you require a separate executed DPA, please contact us at [privacy@sortedmate.com](mailto:privacy@sortedmate.com).

## Contact Us

For questions about these Data Processing Terms, data subject requests, or to arrange an audit:

- Email: [privacy@sortedmate.com](mailto:privacy@sortedmate.com)
- SortedMate Ltd
- 3rd Floor, 86-90 Paul Street
- London, EC2A 4NE
- United Kingdom
- Company Registration No: 16880125
- ICO Registration No: ZC090709
