UK GDPR Article 28 Compliant Agreement between AgencySoftware.io (Data Processor) and the Customer (Data Controller)
Effective Date: January 2025 | Version 1.0
In this Data Processing Agreement ("DPA"):
2.1. Subject Matter: The Data Processor shall process Personal Data on behalf of the Data Controller for the purpose of providing foster care management software services as described in the main service agreement.
2.2. Nature and Purpose: Processing includes the collection, storage, organisation, retrieval, use, and erasure of data for:
2.3. Types of Personal Data:
2.4. Categories of Data Subjects:
AgencySoftware.io operates under a strict "Anonymisation-by-Design" policy for sensitive placement data.
3.1. The system is designed to encourage and facilitate the use of pseudonymised identifiers rather than directly identifiable information for children and young people in placement records.
3.2. Daily observations, incident reports, and notes relating to placements should be recorded using pseudonyms or initials as configured by the Data Controller.
3.3. The Data Controller retains the key to re-identify individuals and remains responsible for the security of this mapping.
The Data Processor shall:
4.1. Process Personal Data only on documented instructions from the Data Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.
4.2. Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
4.4. Assist the Data Controller in ensuring compliance with obligations under Articles 32-36 of UK GDPR (security, breach notification, impact assessments, and prior consultation).
4.5. At the choice of the Data Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless storage is required by applicable law.
4.6. Make available to the Data Controller all information necessary to demonstrate compliance with Article 28 of UK GDPR and allow for and contribute to audits.
5.1. The Data Controller provides general written authorisation for the Data Processor to engage Sub-processors, subject to the conditions in this section.
5.2. The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Data Controller the opportunity to object.
5.3. Current Authorised Sub-processors:
| Sub-processor | Purpose | Location | DPA Status |
|---|---|---|---|
| Stripe, Inc. | Payment processing | USA (EU SCCs) | Active DPA |
| Clerk | Authentication services | USA (EU SCCs) | Active DPA |
| Amazon Web Services (AWS) | Cloud infrastructure (UK Region) | UK (London) | Active DPA |
| Cloudflare, Inc. | CDN and security | Global (UK processing) | Active DPA |
| Mailgun (Sinch) | Transactional email | EU | Active DPA |
| MongoDB Atlas | Database hosting | UK (London Region) | Active DPA |
5.4. All Sub-processors are bound by data protection obligations no less protective than those set out in this DPA.
The Data Controller shall:
7.1. The Data Processor shall assist the Data Controller in responding to requests from data subjects exercising their rights under Chapter III of UK GDPR, including:
7.2. If the Data Processor receives a request directly from a data subject, it shall promptly notify the Data Controller and shall not respond to the request without the Data Controller's prior written authorisation, unless legally required to do so.
8.1. The Data Processor shall notify the Data Controller without undue delay (and in any event within 24 hours) after becoming aware of a Personal Data breach.
8.2. Such notification shall include:
8.3. The Data Processor shall cooperate with the Data Controller and provide reasonable assistance in the investigation, mitigation, and remediation of any breach.
9.1. Upon termination or expiration of the service agreement, the Data Processor shall:
Safeguarding Exception
Where a LADO (Local Authority Designated Officer) safeguarding lock or active investigation is in place, data preservation shall be maintained for the duration required by the relevant authority, overriding standard retention periods.
9.2. The Data Processor shall provide written certification of data deletion upon request.
10.1. All primary data storage and processing occurs on servers physically located within the United Kingdom.
10.2. Where Sub-processors are located outside the UK (such as payment processors), appropriate safeguards are in place including:
11.1. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with this DPA and UK GDPR Article 28.
11.2. The Data Controller (or an appointed third-party auditor) may conduct audits upon reasonable notice (minimum 30 days), subject to:
12.1. Each party shall be liable for any breaches of this DPA caused by its own acts or omissions.
12.2. Liability under this DPA is subject to the limitations and exclusions set out in the main service agreement, except that such limitations shall not apply to the extent prohibited by applicable law.
13.1. This DPA shall remain in effect for the duration of the main service agreement.
13.2. Obligations relating to confidentiality, data deletion, and cooperation with audits shall survive termination.
For all data protection inquiries, Subject Access Requests (SARs), data portability requests, or privacy concerns:
Data Protection Contact
Email: privacy@agencysoftware.io
Data Controller
Tarquin Barnsby (Sole Trader)
Trading as AgencySoftware.io
Little Waterham Farm, Highstreet
Faversham, Kent, ME13 9EJ
This DPA shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over any dispute arising from this DPA.
AgencySoftware.io is officially registered with the Information Commissioner's Office (ICO)
Registration Reference: ZC136598
Verify on ICO RegisterWe use essential cookies to make our site work. We would also like to set optional analytics cookies to help us improve it. We will not set optional cookies unless you enable them. Read our Cookie Policy for more details.