Data Processing Agreement
Last updated: 13 July 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between you (“Customer” or “Controller”) and JTWI Ltd (trading as ServeBusiness), 6 Bream, Tamworth, B77 1HR, United Kingdom (“ServeBusiness” or “Processor”). It sets out the terms on which we process personal data on your behalf under Article 28 of the UK GDPR. By accepting the Terms, you agree to this DPA.
1. Definitions
“UK GDPR”, “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018 (the “Data Protection Laws”). “Customer Personal Data” means personal data that ServeBusiness processes on the Customer’s behalf in providing the Service.
2. Roles of the parties
The Customer is the controller and ServeBusiness is the processor of the Customer Personal Data. Each party will comply with its obligations under the Data Protection Laws. The Customer is responsible for ensuring it has a lawful basis to collect and provide Customer Personal Data to ServeBusiness and for the accuracy and content of that data.
3. Scope & instructions
ServeBusiness will process Customer Personal Data only:
- to provide, maintain, secure and support the Service in accordance with the Terms;
- on the Customer’s documented instructions (including via use of the Service’s features); and
- as required by law, in which case we will inform the Customer unless prohibited.
The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are set out in Annex 1.
4. ServeBusiness’s obligations
ServeBusiness will:
- process Customer Personal Data only as described in Section 3;
- ensure that people authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Article 32), as described in Annex 2;
- engage sub-processors only in accordance with Section 6;
- taking into account the nature of processing, assist the Customer by appropriate measures to respond to data subject rights requests;
- assist the Customer with security, breach notification and, where applicable, data protection impact assessments and prior consultation (Articles 32 to 36);
- at the end of the provision of the Service, delete or return Customer Personal Data as described in Section 8; and
- make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 9.
5. Personal data breaches
ServeBusiness will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide reasonable information and cooperation to help the Customer meet its own notification obligations to the ICO and affected individuals.
6. Sub-processors
The Customer grants a general authorisation for ServeBusiness to engage the sub-processors listed in Annex 3 to provide the Service. ServeBusiness will impose data protection terms on each sub-processor that are no less protective than this DPA, and remains responsible for their performance. We will give the Customer reasonable notice of any intended addition or replacement of a sub-processor (for example by updating Annex 3 and/or by email), giving the Customer the opportunity to object on reasonable data-protection grounds.
7. International transfers
Where processing involves transferring Customer Personal Data outside the UK, ServeBusiness will ensure an appropriate transfer mechanism is in place (such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses). [Confirm the transfer mechanism for each sub-processor with your solicitor.]
8. Return & deletion
On termination or expiry of the Service, ServeBusiness will delete Customer Personal Data in accordance with the retention terms in our Privacy Policy. In summary, the Customer has a 2-month window to export its data, after which it is permanently deleted, except that ServeBusiness retains a pseudonymised record of its own fee income (with personal identifiers removed) for approximately 6 yearsto meet its legal and tax obligations. On the Customer’s request within the export window, we will return the data in a commonly used format or confirm deletion.
9. Audits
ServeBusiness will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Where the Customer reasonably requires further audit information, the parties will agree the scope, timing and cost of any audit in advance, and any audit will be conducted so as to minimise disruption and protect the confidentiality and security of other customers’ data.
10. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
11. Duration
This DPA takes effect when you accept the Terms and continues while ServeBusiness processes Customer Personal Data. Sections that by their nature should survive termination (including Sections 8 to 10) will survive.
Annex 1: Details of processing
- Subject matter: provision of the ServeBusiness platform (bookings, customers, invoicing, quotes, communications and payments).
- Duration:for the term of the Customer’s subscription, plus the retention periods in Section 8.
- Nature & purpose: hosting, storage, organisation, retrieval, use, transmission and deletion of Customer Personal Data to provide the Service.
- Types of personal data: contact details (name, email, phone, address), booking and appointment details, service and transaction details, and communications content.
- Categories of data subjects:the Customer’s own customers and, where applicable, the Customer’s staff.
Annex 2: Security measures
- Encryption of data in transit (TLS/HTTPS).
- Passwords stored using strong one-way hashing; card data handled by Stripe and not stored by us.
- Access controls and row-level security on the database, restricting access to a business’s data to that business.
- Rate limiting and abuse protection on public endpoints.
- Logging and monitoring for security and diagnostics.
- Regular application and dependency updates.
[Review and expand these measures with your security/legal advisor as the platform evolves.]
Annex 3: Approved sub-processors
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing |
| Supabase | Database, authentication & storage hosting |
| Vercel | Application hosting |
| Resend | Email delivery |
| The SMS Works | SMS delivery |
| Upstash | Rate limiting & caching |
Contact
Questions about this DPA? Email hello@servebusiness.co.uk.