Legal

Data Processing Agreement

The short version

When you quote a customer through TradeDraft, their name, address and job details pass through our hands. The law calls you the controller of that information and us your processor, and it requires a written contract between us saying what we may do with it. This is that contract. In plain terms: we only use your customers' data to run the service for you, we keep it confidential and encrypted, only three companies ever touch it, we tell you quickly if anything goes wrong, and we delete it when you're done — except the accepted-quote records you may need as evidence, which we hold for six years. If we ever close the service, you get notice and time to take your copies first. It forms part of your Terms of Use, so there is nothing to sign.

1. What this agreement is, and who it binds

This Data Processing Agreement forms part of, and is subject to, the TradeDraft Terms of Use between TradeDraft (the processor — "we", "us") and the customer who accepts those Terms (the controller — "you"). It takes effect when you accept the Terms and applies for as long as we process personal data on your behalf. Where it conflicts with the Terms on anything to do with data protection, this agreement prevails.

"Data protection law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" carry the meanings given in the UK GDPR.

2. Which data this covers

You are the controller of your own customers' personal data that you enter into, or generate through, the service: their names, postal addresses, email addresses, phone numbers, job and site details, the contents of quotes and invoices, and the acceptance record captured when a customer accepts a quote online (their typed name, the date and time, their device's IP address and browser). We are your processor for all of it.

This agreement does not cover your own account data — your login, billing, usage and contact preferences. We are an independent controller of that, and it is governed by our Privacy Policy instead.

3. What we do with it

Subject matterProviding the TradeDraft quoting, acceptance, invoicing and payment-facilitation features to you.
DurationFor as long as you hold an account, plus the retention periods in clause 8.
Nature of the processingStoring, structuring, displaying, rendering into documents, transmitting by email at your instruction, and retaining.
Types of personal dataName, postal address, email, phone, job and site details, quote and invoice contents, and the e-signature record described in clause 2.
Categories of data subjectYour customers, and any individual you name on a quote or invoice.

4. What we undertake to do

We shall:

  • Process only on your instructions. Your instructions are these Terms, this agreement, and your use of the features. That includes any transfer of data outside the UK. If the law ever requires us to process the data otherwise, we will tell you before doing so unless the law prohibits us from telling you.
  • Keep it confidential. Anyone authorised to work on the service is bound by a duty of confidentiality.
  • Secure it with appropriate technical and organisational measures, as set out in clause 5.
  • Help you answer your customers. If one of your customers exercises a right — access, correction, erasure, restriction, portability or objection — we will assist you in responding, so far as it is possible for us to do so.
  • Help you meet your own duties on security, breach notification and data protection impact assessments, taking account of what the processing involves and what information is available to us.
  • Return or delete it at the end of the service, at your choice, and delete existing copies — subject to the evidence and financial records described in clause 8, which we keep for the periods that clause sets out. If the service itself comes to an end, clause 8 says what happens to those records.
  • Show our working. We will make available the information reasonably necessary to demonstrate that we meet these obligations, and allow for audits as described in clause 9.
  • Tell you if an instruction looks unlawful. If we consider that something you ask us to do would breach data protection law, we will say so.

5. Security

We maintain security appropriate to the risk. In practice that means: encryption in transit (HTTPS) and at rest (AES-256); per-account isolation enforced at the database level, so no customer can reach another customer's data; write access to money and evidence records restricted to the server, never the browser; least-privilege access to systems; and infrastructure from the established providers named in clause 6. We will not materially reduce the overall security of the service during your subscription.

6. Who else touches this data

You give general authorisation for us to use sub-processors. We remain responsible for what they do with your customers' data, and each is bound by data-protection terms no less protective than this agreement. Four companies process your customers' data:

Sub-processorWhat it doesWhere
SupabaseDatabase, accounts and server functions — the primary store for your quotes, customers and evidence recordsUnited Kingdom (London region)
StripeCard payments, only where your customer chooses to pay a deposit or invoice by cardUK / EU / US, under Stripe's data protection terms and UK transfer safeguards
ResendSending acceptance links, invoices and related emails to your customerUS, under the provider's data protection terms and UK transfer safeguards
Ideal PostcodesAddress lookup — when you search a postcode while building a quote, that postcode is sent to find the matching addresses, together with the technical details every web request carries: your device's IP address and the page the request came from. No name, email, customer detail or job detail is sent. They keep a record of requests made against our accountUnited Kingdom

The other providers named in our Privacy Policy — Netlify (hosting), Cloudflare (cookieless analytics), Payhip (the template-shop checkout) and Google (sign-in, only if you choose the Google button) — support our own business and do not process your customers' quote data.

We will give you at least 30 days' notice before adding or replacing a sub-processor that handles your customers' data. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may close your account and we will refund any period you have paid for in advance.

7. Sending data outside the UK

Your customers' data is stored in the United Kingdom. Where a sub-processor in clause 6 processes it outside the UK, we rely on an appropriate safeguard under Chapter V of the UK GDPR — an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or the UK extension to the EU–US Data Privacy Framework, as applicable to that provider.

8. How long we keep it, and what we delete

We hold your customers' data as described in the Privacy Policy. In summary: quotes that were never accepted are deleted 90 days after they expire, and the data of closed accounts within 90 days of closure.

The exception, and it matters to you. Accepted quotes, the acceptance and signature records that go with them, the record of what was sent and when, and paid-invoice records are kept for six years. That is deliberate: an accepted quote is a formed contract, and those records are the evidence you would rely on if a customer later disputed what was agreed. We keep them under Article 6(1)(c) and (f) and the Article 17(3) exception to erasure, which is why they survive an erasure request. When you close your account we delete your personal data and de-identify what remains, so the evidence is held only for the establishment or defence of legal claims.

This is a policy we operate, not a result we warrant. We will take reasonable care to hold these records for these periods and to keep them retrievable, but we do not promise that a particular record will be available at a particular moment: the service is provided "as is" and "as available" under the Terms of Use, and liability is limited as they set out. Download and keep your own copies of anything you would need in a dispute.

If TradeDraft itself ends. If we stop providing the service, clause 4 governs what happens to your customers' data and this clause does not extend it. We will give you at least 30 days' notice, unless something outside our control makes that impossible, and during that period you can download your quotes, acceptance records and send log, or ask us for a copy of them. After that period we delete the data we hold on your behalf. We cannot promise to keep a six-year archive of a service that has closed, and we are not going to pretend otherwise: once the records are back with you, you hold your own evidence and you are the controller of it. The only things we keep are what the law requires us to keep (our own financial and tax records), and anything we need to defend a claim already made or threatened against us, for as long as that claim is live.

9. Audits and information

On reasonable written notice, and no more than once in any twelve months unless a breach or a regulator requires otherwise, we will provide the information you need to satisfy yourself — or your regulator — that your customers' data is handled as this agreement says. Where that information is not enough, we will contribute to an audit conducted by you or an auditor you appoint, at your cost, at a mutually agreed time, subject to confidentiality and to not compromising the security or data of any other customer.

10. Personal data breaches

If there is ever a personal data breach affecting your customers' data, we will tell you without undue delay once we become aware of it, and give you what you reasonably need to meet your own obligations: what happened, the categories and approximate number of people affected so far as known, the likely consequences, and what we have done about it. Notifying you is not an admission of fault. Reporting the breach to the Information Commissioner, and to the individuals affected where required, is your decision as controller — we will support it.

11. What stays your responsibility

You remain responsible for having a lawful basis to hold your customers' data, for the accuracy and lawfulness of what you enter, for telling your customers how their data is used, and for handling their requests — with our help under clause 4.

12. Liability, changes and term

Liability under this agreement is subject to the limits in the Terms of Use, except for liability that cannot be limited under data protection law. If we change this agreement materially we will give you at least 14 days' notice, in line with the Terms, and the "last updated" date below will move. This agreement ends when we no longer process personal data on your behalf.

13. Getting in touch

For anything to do with data protection — a question, a customer's request, or a concern — email hello@tradedraft.co.uk. You can also complain to the Information Commissioner's Office at ico.org.uk.

Last updated: 25 August 2026