Data processing agreement
The Article 28 terms under which Veilux processes a firm's customer data on its behalf: instructions, people, security, sub-processors, breaches and what happens at the end.
01Purpose and scope
This data processing agreement sets out the terms on which Veilux processes personal data on behalf of a subscribing firm, to satisfy Article 28 UK GDPR and, where it applies to the firm’s own processing, Article 28 EU GDPR. It applies to personal data the firm puts into Veilux about its own customers, contacts, leads and staff ("Customer Personal Data") — never to the data covered by the privacy notice, which is about the firm and its own people as Veilux’s own customer, where Veilux is the controller.
This agreement forms part of, and is incorporated into, the terms of service. Capitalised terms not defined here have the meaning given in the terms.
02Definitions
"UK GDPR" and "EU GDPR" mean the UK and EU General Data Protection Regulation respectively, each as amended or replaced from time to time, and "Data Protection Laws" means both of them together with the Data Protection Act 2018 and any other law that applies to the processing under this agreement. "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in the UK GDPR.
"Sub-processor" means a third party the Processor engages to process Customer Personal Data on the Controller’s behalf, as listed on the sub-processors page.
03Roles of the parties
For Customer Personal Data, the firm is the Controller and Veilux is the Processor. The firm determines why and how its customers’ and contacts’ personal data is processed; Veilux processes it only to provide the Veilux product to the firm, as this agreement and the firm’s own use of the product instruct.
Where the firm is itself a processor for one of its own clients — for example an accountant holding a client’s customer list on that client’s behalf — Veilux is a sub-processor at a further remove, and this agreement applies in the same way between the firm and Veilux; the firm remains responsible for its own agreement with its client.
04Duration
This agreement takes effect when the firm’s account is created and continues for as long as Veilux processes Customer Personal Data on the firm’s behalf, including during the 30-day grace period described in "Deletion or return of data" below, and ends when that processing ends.
05Subject matter, nature and purpose of processing
Subject matter: the hosting, storage and processing of Customer Personal Data as an inherent part of providing the Veilux product to the firm.
Nature of processing: collection, storage, organisation, retrieval, use, transmission (including by email and, where the firm switches it on, SMS), backup, and erasure or anonymisation of Customer Personal Data, carried out by automated means through the product and, exceptionally, by Veilux support staff signed in as a member of the firm’s own team for a limited, recorded support session.
Purpose of processing: to provide the Veilux product to the firm as its Controller instructs — running the firm’s customer records, sales ledger, projects, tickets and related functions — and for no purpose of Veilux’s own.
06Categories of data subjects and personal data
The categories of Data Subjects and the categories of Customer Personal Data Veilux may process on the firm’s behalf are set out in Annex 1. The firm decides which of these actually apply to its own account by what it chooses to put into the product — Annex 1 describes what the product is capable of holding, not a claim that every firm holds all of it.
Annex 1 — data subjects and data categories
- The firm’s customers and their contacts
- Name, email, phone, job title, billing and delivery address, VAT/tax number, invoices and payment history, project and ticket content, any file the firm attaches to their record, and any custom field the firm has defined.
- The firm’s leads and prospects
- Name, company, email, phone, source, pipeline value and stage, and notes the firm’s staff record about them.
- The firm’s own staff and contractors
- Name, work email, role and permissions, time recorded against projects, and audit trail of their actions in the product.
- Visitors to a public form the firm publishes (a booking page, an estimate request, an embedded contact form)
- Whatever the firm’s form asks for — typically name, email, phone and free-text content — submitted directly by the visitor.
- Anyone named in a support ticket, comment or attachment the firm creates
- Whatever personal data the firm’s own staff choose to enter in free text or attach as a file; Veilux cannot control the content of a field the product simply lets the firm fill in.
Veilux does not ask a firm to submit special category data (health, religion, sexual orientation and the rest) and has no field designed for it; a firm that chooses to put such data into a free-text field or attachment remains responsible for having a lawful basis for doing so, same as with any other data it enters.
07Processing only on instructions
Veilux will process Customer Personal Data only on the firm’s documented instructions — given by using the product as it is designed to be used (creating, changing, exporting, anonymising or deleting records) and by this agreement itself — unless required to do otherwise by Data Protection Laws or another law Veilux is subject to, in which case Veilux will tell the firm before processing, unless that law prohibits doing so.
If Veilux considers an instruction breaches Data Protection Laws, it will tell the firm promptly, and may suspend the instructed processing until the firm confirms or amends it.
08Confidentiality of personnel
Veilux ensures that anyone it authorises to process Customer Personal Data — its own staff, and a sub-processor’s staff — is subject to a binding duty of confidentiality, whether contractual or statutory, and is trained to handle personal data appropriately.
Only people who need to, to run and support the product, can reach a firm’s data. Support reaches it only by signing in as one of the firm’s own people, for a limited time, with a reason recorded at the time — never by a separate back door — and that access appears in the firm’s own audit log and access log, described on the security page and in docs/ACCOUNT.md.
09Security of processing
Veilux implements the technical and organisational measures set out in Annex 2, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purpose of the processing, and the risk to Data Subjects. Annex 2 names the mechanism behind each measure, and is kept in step with the security page, because the two must never disagree.
Veilux will not reduce the protection Annex 2 describes without telling the firm, and will keep Annex 2 and the security page accurate as the product changes.
Annex 2 — technical and organisational measures
- Tenant isolation
- Every record carries the identifier of the firm it belongs to. Reads and writes go through a client scoped to the signed-in firm, and a Postgres row-level security policy on every tenant-owned table refuses a row belonging to another firm at the database layer as well — so a mistake in the application code still cannot cross between firms. Cross-tenant access is tested as a deliberate attack in the automated test suite.
- Access control
- Permissions are checked again in every route handler, not only in the menu that shows or hides a link. Money-related permissions are separate from record-level permissions, so a contractor can be given access to a customer without seeing what they owe.
- Authentication
- Passwords are hashed with bcrypt at a cost factor of 12 and never stored or logged in the clear. Sign-in is rate-limited per address and per network. Two-factor authentication (authenticator app) is available to every staff user, required for roles that can change money, permissions or settings, and can be required firm-wide.
- Secrets and credentials
- API keys are stored only as a SHA-256 hash and last four characters; the full key is shown once and cannot be retrieved again. A firm’s own outgoing mail server password is encrypted with AES-256-GCM before it is stored.
- Audit trail
- Every change writes an append-only audit log entry in the same database transaction as the change itself, so a change without a record cannot happen; there is no code path that edits or deletes an audit entry.
- Transport security
- HTTPS with HTTP Strict Transport Security on every response, no content-type sniffing, and pages refuse to be displayed inside another site’s frame (with the single, deliberate exception of a firm’s own embeddable public form).
10Sub-processors
The firm gives Veilux general authorisation to engage the Sub-processors listed on the sub-processors page to process Customer Personal Data, subject to this section. Each Sub-processor is bound by written terms that impose data protection obligations equivalent to this agreement, and Veilux remains liable to the firm for a Sub-processor’s performance of those obligations.
Veilux will give the firm’s account owner at least 30 days’ notice by email before a new Sub-processor starts processing Customer Personal Data, or before an existing one changes what it processes. If the firm has a reasonable data-protection objection to the change, it may raise it within that notice period; if Veilux cannot reasonably address the objection, the firm may terminate the agreement for the affected part of the service and receive a refund of any pre-paid, unused fees for the terminated period.
11Assistance with data subject rights
The product lets a firm answer its own customers’ and contacts’ rights requests directly: a contact can be given a client-portal login that lets them view and correct their own record, and, where the firm switches these on, request an export or an erasure of their data without needing Veilux’s help at all. Where a firm’s privacy settings enable them, these tools sit at /portal/gdpr for the firm’s own customers to use.
Where a request needs more than the product does on its own — for example a request that reaches beyond what the client portal exposes — Veilux will give the firm reasonable assistance, at no additional charge, taking into account the nature of the processing and the information available to Veilux, so the firm can respond to the Data Subject within the time Data Protection Laws require.
12Data protection impact assessments and prior consultation
Where a firm reasonably needs information about Veilux’s processing to complete its own data protection impact assessment, or to consult a supervisory authority under Article 36 UK GDPR, Veilux will provide that information on request, to the extent it is available and the firm could not reasonably obtain it itself from this agreement, the security page and the sub-processors page.
13Personal data breach notification
Veilux will notify the firm’s account owner without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, with what is known at that time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. Where full information is not yet available within that window, Veilux will say so and provide it in phases as it becomes available, rather than delay the initial notice.
This notification is Veilux’s notice to the firm as Controller, and does not itself satisfy the firm’s own obligation to notify the Information Commissioner’s Office or affected Data Subjects, which remains the firm’s to assess and carry out; Veilux will assist with that assessment on request.
14International transfers
Veilux intends to host Customer Personal Data in the United Kingdom or the European Economic Area, and will name the hosting provider and region on the sub-processors page before any Customer Personal Data is hosted with it. Where processing a firm’s Customer Personal Data necessarily involves a transfer outside the UK and EEA — for example because the firm has switched on an integration whose provider is based elsewhere — that transfer is made subject to the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses for EU-originating data, or another transfer mechanism Data Protection Laws recognise as adequate, as stated for that Sub-processor on the sub-processors page.
15Deletion or return of data
At any time before the firm’s account closes, the firm can export the whole of its Customer Personal Data from Account → Data, in a structured, commonly-used format (CSV per table, or a full zip export of the account).
Once the firm closes its account, Customer Personal Data is kept unchanged for a 30-day grace period, during which the former owner may reopen the account or take a final export. At the end of that period, Customer Personal Data is permanently deleted from Veilux’s production systems, and that deletion is itself recorded (without the data it describes) so the firm can confirm it took place on request. Deletion from backups follows Veilux’s ordinary backup rotation once backups are in production, described on docs/DEPLOY.md and, once implemented, this agreement will be updated to state the exact rotation period.
This section does not require Veilux to delete Customer Personal Data it is required to retain by law, or that exists only inside a backup pending its ordinary rotation, and in either case Veilux will continue to protect it to the standard of this agreement until it is deleted.
16Audits and information
Veilux will make available to the firm the information reasonably necessary to demonstrate compliance with this agreement — principally this agreement, the security page and the sub-processors page — and will allow for, and contribute to, an audit or inspection conducted by the firm or an auditor it mandates, on reasonable notice, no more than once a year unless a Personal Data Breach or a supervisory authority gives cause for more, and subject to reasonable confidentiality and scheduling arrangements to avoid disrupting the service for other tenants.
17Liability
Each party’s liability arising out of or in connection with this agreement is subject to the limitation of liability in the terms of service, as if this agreement were part of them; nothing in this agreement is intended to give either party a greater or lesser liability than the terms already set.
Questions about this document: [email protected].