1. Scope and roles
This DPA applies where we process personal data contained in the Customer's workspace on the Customer's behalf (Customer Personal Data). The Customer is the controller and LETLOGIC SOFTWARE LTD is the processor, except where either party acts as a separate controller under applicable law.
Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any legislation that replaces or supplements them. Controller, processor, data subject, personal data, personal data breach, process and supervisory authority have the meanings given by Data Protection Law.
2. Customer instructions
We will process Customer Personal Data only on the Customer's documented instructions, including those set out in the Agreement, the Customer's configuration and authorised users' use of the service, unless UK law requires otherwise. If law requires processing beyond those instructions, we will inform the Customer before processing unless the law prohibits notice.
We will promptly tell the Customer if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected processing while the parties resolve the issue.
3. Customer obligations
The Customer is responsible for:
- ensuring that its instructions and processing of Customer Personal Data comply with Data Protection Law;
- providing required privacy information and having a valid lawful basis;
- collecting only data that is adequate, relevant and necessary;
- configuring roles and permissions appropriately and managing authorised users; and
- notifying us before using the service for unusually high-risk processing so the parties can assess suitable safeguards.
4. Confidentiality and personnel
We will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate data-protection and security guidance, and access the data only as needed for their duties.
5. Security
Taking account of the state of the art, implementation costs, the nature and risks of the processing, we will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures include, as appropriate:
- encrypted transmission and managed encryption at rest provided by our infrastructure;
- role-based access controls, account authentication and administrative access restrictions;
- tenant separation controls and database policies designed to isolate agency workspaces;
- logging, monitoring, backups, vulnerability and dependency maintenance, and incident-response procedures;
- availability and recovery measures proportionate to the service; and
- periodic review of access and security measures.
6. Subprocessors
The Customer gives general written authorisation for us to use subprocessors to provide the service. Our current Subprocessor List identifies their functions and relevant processing locations.
We will impose data-protection obligations on each subprocessor that are no less protective in substance than those in this DPA, to the extent applicable to the service it provides. We remain responsible for a subprocessor's performance of those obligations.
We will notify the Customer's account administrator before appointing a new subprocessor that will process Customer Personal Data, where practicable giving at least 15 days' notice. The Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable solution; if none is available, either party may terminate the affected service without penalty before that subprocessor begins processing.
7. International transfers
We will not transfer Customer Personal Data outside the United Kingdom unless the transfer is permitted by Data Protection Law. Where no adequacy regulation applies, we will use an approved transfer mechanism, such as the UK International Data Transfer Agreement or UK Addendum to the EU standard contractual clauses, and apply supplementary measures where appropriate.
The Customer authorises us to enter those safeguards as its processor and to make reasonable updates needed to preserve their validity. Information about relevant provider locations is maintained on the Subprocessor List.
8. Assistance to the Customer
Taking account of the nature of processing and information available to us, we will provide reasonable assistance so the Customer can respond to data-subject requests and comply with duties relating to security, breach notifications, data-protection impact assessments and prior consultation with regulators.
If we receive a request directly concerning Customer Personal Data, we will not respond on the Customer's behalf unless authorised or legally required. We will direct the requester to the Customer where practical and notify the Customer.
9. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the incident, likely consequences, affected data and individuals, measures taken or proposed, and a contact for follow-up. We will take reasonable steps to contain, investigate and mitigate the incident.
Our notification or assistance is not an admission of fault or liability. The Customer remains responsible for deciding whether to notify a supervisory authority or affected individuals, unless law allocates that duty to us.
10. Return and deletion
During the subscription, the Customer may use available export functions or ask us for reasonable export assistance. Following termination, at the Customer's written choice, we will return or delete Customer Personal Data unless UK law requires retention. Data remaining in protected backups will be isolated from ordinary use and deleted in accordance with normal backup cycles, except where restoration is required for security or disaster recovery.
The Customer should make its return or deletion request before or promptly after access ends. Additional work to create a non-standard export may be chargeable where agreed in advance.
11. Information and audits
We will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer may request a remote audit no more than once in a 12-month period, unless a breach or regulator requires more frequent review. Audits must be on reasonable notice, during business hours, avoid disruption, protect other customers' data and use existing independent reports before requiring an on-site inspection.
The Customer bears its audit costs and our reasonable costs of substantial assistance, unless the audit identifies a material breach by us. Nothing requires us to disclose another customer's data, privileged material or information that would compromise security.
12. Records, regulators and legal requests
Each party will maintain records required by Data Protection Law and cooperate reasonably with the Information Commissioner's Office or another competent supervisory authority. Unless prohibited, we will notify the Customer of a binding legal demand for Customer Personal Data and will disclose only what is legally required.
13. Duration, order of precedence and liability
This DPA applies for as long as we process Customer Personal Data. If it conflicts with the Subscription Terms on a data-protection matter, this DPA takes priority. Liability under this DPA is subject to the liability provisions in the Subscription Terms, except to the extent Data Protection Law does not permit a limitation.
Schedule 1 — Processing details
Subject matter: provision, hosting, support and security of the LetLogic property operations service.
Duration: the subscription and the limited period afterwards required for return, deletion, backups and legal obligations.
Nature and purpose: collection, storage, organisation, retrieval, display, communication, export, backup, troubleshooting and deletion as needed to provide the service on the Customer's instructions.
Data subjects: Customer staff and applicants; tenants and prospective tenants; landlords; contractors and their staff; occupiers, guarantors and other property or tenancy contacts; and individuals mentioned in communications, documents or maintenance records.
Data types: names and contact details; account identifiers, roles and activity; property and tenancy information; dates of birth where entered; rent, deposit, invoice and landlord payment-reference data; maintenance, appointment and access information; messages, notifications, documents and portal records; and relevant technical and security data.
Special-category and criminal-offence data: the service is not designed to require these categories routinely. They may appear in free text or documents at the Customer's discretion. The Customer must enter them only where necessary, lawful and subject to appropriate safeguards.
14. Contact
Data-processing questions and subprocessor objections should be sent to chris.harris@letlogic.co.uk.