Data processing agreement
Draft: under legal review. The version that applies to you is the one accepted in the app.
1. Parties
1.1 The Customer (the organisation named on the dpow.app order or account), the controller.
1.2 DPOW Group Ltd, company number 17276695, registered in England and Wales, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, trading as dpow.app, the processor.
1.3 This agreement forms part of the dpow.app terms between the parties and meets Article 28(3) of the UK GDPR and section 59 of the Data Protection Act 2018. If they conflict on personal data, this agreement wins.
2. What is processed
| Subject matter | Providing dpow.app: project registers, information management (ISO 19650), reports, chat answers about the Customer's projects, WhatsApp answers, links to the Customer's Microsoft 365 |
|---|---|
| Duration | While the Customer's account is active, then until deletion under clause 9 |
| Nature and purpose | Storing, organising, retrieving, displaying and analysing project information so the Customer can deliver its projects; producing documents and answers from it at the Customer's instruction |
| Types of personal data | Names, work email addresses, work phone and WhatsApp numbers, job roles, initials, capacity and hours, sign in records, the audit trail of who did what and when, the content of questions asked of the chat or over WhatsApp, names that appear in project documents and registers |
| Data subjects | The Customer's staff and members, its clients' and contractors' contacts, consultants, and other people named in project information |
| Special category data | None intended. The Customer should not put special category data into dpow.app |
The Customer's own documents stay in the Customer's own Microsoft SharePoint. dpow.app reads and writes them there with the signed in user's own Microsoft permissions. The files dpow.app holds itself are listed on our Security page.
3. DPOW Group Ltd's duties as processor
DPOW Group Ltd will:
- process the personal data only on the Customer's documented instructions (this agreement, the terms and the Customer's use of the app), unless UK law requires otherwise, and then tell the Customer first unless the law forbids it;
- make sure everyone authorised to process it is bound to confidentiality;
- keep the security measures in Annex 2 (Article 32);
- use sub-processors only as clause 5 allows;
- help the Customer, as far as it reasonably can, to answer requests from people using their data protection rights (the app's own data export and member removal tools are the main way);
- help the Customer with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36), taking into account what it knows;
- at the end of the service, return and delete the data under clause 9;
- make available the information needed to show it meets these duties, and allow and contribute to audits under clause 8;
- tell the Customer straight away if it thinks an instruction breaks data protection law.
4. The Customer's duties
The Customer is responsible for having a lawful basis for the personal data it puts into dpow.app, for giving any notices to the people concerned, and for the accuracy of what it enters. It controls who in its organisation can see and change what (Admin, Editor and Viewer roles).
5. Sub-processors
5.1 The Customer gives general authorisation to the sub-processors in Annex 3. DPOW Group Ltd will give at least 30 days' notice of any new or replacement sub-processor (by email to the Customer's admins and on the dpow.app site), and the Customer may object on reasonable data protection grounds.
5.2 Each sub-processor is bound by written terms that give the same protection as this agreement, and DPOW Group Ltd stays responsible for them.
6. International transfers
Some sub-processors are in, or may process data in, the United States (Annex 3). Transfers rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on the UK International Data Transfer Addendum to the EU standard contractual clauses in the provider's terms.
7. Personal data breaches
DPOW Group Ltd will tell the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, with what it knows and what it is doing, and will update the Customer as it learns more.
8. Audits
DPOW Group Ltd will answer reasonable written questions about its security and processing, once a year or after a breach, and will allow an audit by the Customer or an independent auditor bound by confidentiality, on 30 days' notice, at the Customer's cost, in working hours, without access to other customers' data.
9. Return and deletion
9.1 While the account is active, the Customer's project information is kept so the service can run.
9.2 When the Customer leaves, DPOW Group Ltd will give the Customer a full export of its information (the app's export, including the registers, logs and audit trail), and then delete it 90 days after the subscription ends, or sooner on the Customer's written request, except where UK law requires it to be kept. The audit trail and golden thread are kept for 6 years after a project closes, and billing records for 6 years. The full list of retention periods is in our privacy policy.
10. Liability
Liability under this agreement is as set out in the dpow.app terms.
11. Law
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: processing details
See clause 2.
Annex 2: security measures (Article 32)
- All traffic encrypted in transit (HTTPS, HSTS); the database encrypted at rest by the host.
- Every table that holds Customer data is separated by organisation with row level security in the database, so one organisation cannot read another's data; server routes check membership and role again.
- Roles: Admin, Editor (holds a seat) and Viewer (read only, enforced in the database and on the server).
- Microsoft tokens are sealed (encrypted) at rest and never sent to the browser.
- An append only audit trail that no role can edit or delete.
- Secrets held only in the hosting provider's encrypted settings, never in the code.
- Sign in through Microsoft or a one time email link; no passwords stored by dpow.app.
- WhatsApp: a phone number only answers once confirmed with a one time code; incoming messages are checked against a shared secret or Meta's signature.
- Errors are logged with personal data redacted.
More detail is on our Security page.
Annex 3: sub-processors
The sub-processors, what each one does and where, are listed on our sub-processor list, which forms this annex.
Not sub-processors: Microsoft (the Customer's own Microsoft 365 tenant, which the Customer controls and contracts with directly), and any AI provider used through the Customer's own key under the Customer's own contract with that provider.
Questions
Email pc at dpow.co.uk.