Data Processing Agreement

UK GDPR Article 28 Compliant Agreement between AgencySoftware.io (Data Processor) and the Customer (Data Controller)

Effective Date: January 2025 | Version 1.0

Quick Summary

  • You (the Customer) are the Data Controller for all foster placement data.
  • AgencySoftware.io acts as the Data Processor, processing data only on your instructions.
  • All data is stored on secure UK-based servers.
  • We operate under a strict "Anonymisation-by-Design" policy.
  • We never sell, rent, or share your data with third parties for their own purposes.

1. Definitions and Interpretation

In this Data Processing Agreement ("DPA"):

  • "Data Controller" means the Customer (the Fostering Agency, Independent Fostering Agency, or Local Authority) who determines the purposes and means of processing Personal Data.
  • "Data Processor" means AgencySoftware.io, trading name of Tarquin Barnsby (Sole Trader), who processes Personal Data on behalf of the Data Controller.
  • "Personal Data" has the meaning given in UK GDPR Article 4(1).
  • "Processing" has the meaning given in UK GDPR Article 4(2).
  • "Sub-processor" means any third party engaged by the Data Processor to process Personal Data.
  • "UK GDPR" means the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
  • "DPA 2018" means the Data Protection Act 2018.

2. Scope of Processing

2.1. Subject Matter: The Data Processor shall process Personal Data on behalf of the Data Controller for the purpose of providing foster care management software services as described in the main service agreement.

2.2. Nature and Purpose: Processing includes the collection, storage, organisation, retrieval, use, and erasure of data for:

  • Foster carer recruitment and enquiry management
  • Compliance tracking and document management
  • Placement records and daily observations
  • Incident reporting and safeguarding notes
  • Communication management (SMS, email, notifications)

2.3. Types of Personal Data:

  • Foster carer contact details (name, address, phone, email)
  • Enquirer information (prospective foster carers)
  • Pseudonymised observations, incidents, and daily notes relating to foster placements
  • Compliance documentation and training records
  • Communication logs and correspondence

2.4. Categories of Data Subjects:

  • Prospective and approved foster carers
  • Agency staff and administrators
  • Referenced individuals in placement records (processed under pseudonymisation)

3. Anonymisation-by-Design Policy

AgencySoftware.io operates under a strict "Anonymisation-by-Design" policy for sensitive placement data.

3.1. The system is designed to encourage and facilitate the use of pseudonymised identifiers rather than directly identifiable information for children and young people in placement records.

3.2. Daily observations, incident reports, and notes relating to placements should be recorded using pseudonyms or initials as configured by the Data Controller.

3.3. The Data Controller retains the key to re-identify individuals and remains responsible for the security of this mapping.

4. Data Processor Obligations

The Data Processor shall:

4.1. Process Personal Data only on documented instructions from the Data Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.

4.2. Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication for system access
  • Regular security testing and vulnerability assessments
  • Access controls based on the principle of least privilege
  • Comprehensive audit logging

4.4. Assist the Data Controller in ensuring compliance with obligations under Articles 32-36 of UK GDPR (security, breach notification, impact assessments, and prior consultation).

4.5. At the choice of the Data Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless storage is required by applicable law.

4.6. Make available to the Data Controller all information necessary to demonstrate compliance with Article 28 of UK GDPR and allow for and contribute to audits.

5. Sub-processors

5.1. The Data Controller provides general written authorisation for the Data Processor to engage Sub-processors, subject to the conditions in this section.

5.2. The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Data Controller the opportunity to object.

5.3. Current Authorised Sub-processors:

Sub-processorPurposeLocationDPA Status
Stripe, Inc.Payment processingUSA (EU SCCs)Active DPA
ClerkAuthentication servicesUSA (EU SCCs)Active DPA
Amazon Web Services (AWS)Cloud infrastructure (UK Region)UK (London)Active DPA
Cloudflare, Inc.CDN and securityGlobal (UK processing)Active DPA
Mailgun (Sinch)Transactional emailEUActive DPA
MongoDB AtlasDatabase hostingUK (London Region)Active DPA

5.4. All Sub-processors are bound by data protection obligations no less protective than those set out in this DPA.

6. Data Controller Obligations

The Data Controller shall:

  • Ensure that it has all necessary rights and lawful bases to transfer Personal Data to the Data Processor for processing.
  • Provide clear and documented instructions regarding the processing of Personal Data.
  • Maintain appropriate records of processing activities as required by Article 30 of UK GDPR.
  • Ensure compliance with data subject rights requests and notify the Data Processor where assistance is required.
  • Inform the Data Processor without undue delay if any processing instruction infringes UK GDPR or other applicable data protection law.

7. Data Subject Rights

7.1. The Data Processor shall assist the Data Controller in responding to requests from data subjects exercising their rights under Chapter III of UK GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

7.2. If the Data Processor receives a request directly from a data subject, it shall promptly notify the Data Controller and shall not respond to the request without the Data Controller's prior written authorisation, unless legally required to do so.

8. Personal Data Breach

8.1. The Data Processor shall notify the Data Controller without undue delay (and in any event within 24 hours) after becoming aware of a Personal Data breach.

8.2. Such notification shall include:

  • A description of the nature of the breach
  • The categories and approximate number of data subjects affected
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach

8.3. The Data Processor shall cooperate with the Data Controller and provide reasonable assistance in the investigation, mitigation, and remediation of any breach.

9. Data Retention and Deletion

9.1. Upon termination or expiration of the service agreement, the Data Processor shall:

  • Provide the Data Controller with a complete export of all Personal Data in a commonly used, machine-readable format
  • Soft-delete all Personal Data within 30 days of account cancellation
  • Permanently purge all Personal Data after the 30-day recovery period

Safeguarding Exception

Where a LADO (Local Authority Designated Officer) safeguarding lock or active investigation is in place, data preservation shall be maintained for the duration required by the relevant authority, overriding standard retention periods.

9.2. The Data Processor shall provide written certification of data deletion upon request.

10. International Transfers

10.1. All primary data storage and processing occurs on servers physically located within the United Kingdom.

10.2. Where Sub-processors are located outside the UK (such as payment processors), appropriate safeguards are in place including:

  • UK International Data Transfer Agreement (IDTA)
  • Standard Contractual Clauses (SCCs) as approved by the ICO
  • Adequacy decisions where applicable

11. Audit Rights

11.1. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with this DPA and UK GDPR Article 28.

11.2. The Data Controller (or an appointed third-party auditor) may conduct audits upon reasonable notice (minimum 30 days), subject to:

  • Confidentiality obligations protecting other customers' data
  • Reasonable scope and duration limitations
  • Audits being conducted during normal business hours

12. Liability

12.1. Each party shall be liable for any breaches of this DPA caused by its own acts or omissions.

12.2. Liability under this DPA is subject to the limitations and exclusions set out in the main service agreement, except that such limitations shall not apply to the extent prohibited by applicable law.

13. Term and Termination

13.1. This DPA shall remain in effect for the duration of the main service agreement.

13.2. Obligations relating to confidentiality, data deletion, and cooperation with audits shall survive termination.

14. Contact Information

For all data protection inquiries, Subject Access Requests (SARs), data portability requests, or privacy concerns:

Data Protection Contact

Email: privacy@agencysoftware.io

Data Controller

Tarquin Barnsby (Sole Trader)

Trading as AgencySoftware.io

Little Waterham Farm, Highstreet
Faversham, Kent, ME13 9EJ

15. Governing Law

This DPA shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over any dispute arising from this DPA.

AgencySoftware.io is officially registered with the Information Commissioner's Office (ICO)

Registration Reference: ZC136598

Verify on ICO Register

Cookie Preferences

We use essential cookies to make our site work. We would also like to set optional analytics cookies to help us improve it. We will not set optional cookies unless you enable them. Read our Cookie Policy for more details.