VERSION 2026-08-25 · EFFECTIVE 25 August 2026
This Data Processing Addendum (‘DPA’) forms part of the Chasd Terms of Service between Chasd (‘Processor’) and Customer (‘Controller’) whenever Processor handles Customer Personal Data on Controller’s behalf. It is effective when Customer accepts the Terms or this DPA.
‘Data Protection Law’ means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and binding amendments or replacement law applicable to the processing. ‘Customer Personal Data’, ‘Controller’, ‘Processor’, ‘Data Subject’, ‘Personal Data Breach’ and ‘Processing’ have the meanings in Data Protection Law.
Capitalised terms not defined here have the meaning in the Terms. If this DPA conflicts with the Terms about Customer Personal Data, this DPA controls. It does not govern personal data for which Chasd acts as controller under its Privacy Notice.
Subject matter: the B2B credit-control workflow. Duration: the service term plus the deletion and backup-expiry period. Nature: collection from Xero, import, storage, organisation, retrieval, reminder delivery, reply receipt, deterministic classification, reconciliation, support, export and deletion. Purpose: providing, securing and supporting management of Controller-selected overdue B2B invoices.
Data Subjects may include Customer users; sole traders; and staff, directors or representatives of Controller’s debtors and business contacts. Data types may include business identity and contact details; account role; invoice identifier, dates, currency, totals and payment state; reminder and reply content; promises, disputes, notes, delivery events, audit data and technical identifiers.
Processing locations and subprocessors are described in the public Subprocessor Register. Controller may provide further documented instructions through service settings, support requests and agreed written directions, provided they are lawful and within the service scope.
Controller determines the purpose and means of the Customer Personal Data processing and remains responsible for its lawfulness. Controller must provide lawful, fair and documented instructions; have a lawful basis; give required privacy information; maintain accurate and proportionate data; respond to Data Subjects; and avoid unnecessary special-category, criminal-offence, children’s or highly sensitive information.
Controller may access, correct, export and delete Customer Personal Data using service controls and may give additional lawful instructions through the privacy contact. Controller is responsible for deciding whether the service and its security measures meet Controller’s legal and risk requirements.
Processor will process Customer Personal Data only to provide, secure, maintain and support Chasd; follow Controller’s documented settings and instructions; and make transfers documented by this DPA. If UK law requires other processing, Processor will notify Controller before processing unless the law prohibits notice on important public-interest grounds.
Processor will immediately inform Controller if, in its opinion, an instruction infringes Data Protection Law. Processor may suspend the affected instruction while the parties resolve the issue and is not required to perform an instruction that is unlawful or outside the service scope.
Processor will ensure people authorised to process Customer Personal Data are subject to an appropriate contractual or statutory duty of confidentiality, receive access only as needed and are informed of relevant data-protection and security duties.
Taking account of the state of the art, implementation cost, processing nature and risks, Processor will maintain appropriate technical and organisational measures under UK GDPR Article 32. Measures include encrypted transport; encrypted Xero tokens; signed provider webhooks; role-based and tenant access controls; service-credential separation; restricted production secrets; data-minimised logs; reminder stop rules; audit records; dependency management; backups; incident procedures; and tested export and deletion paths.
Processor regularly evaluates relevant controls and may update measures without materially reducing overall protection. Controller acknowledges that no internet service eliminates all risk.
Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, likely consequences, affected data and people, contact point and measures taken or proposed. Processor may provide information in phases and will reasonably assist Controller’s investigation, mitigation and notifications.
Processor’s notice is not an admission of fault. Controller remains responsible for deciding whether notice to the ICO, another regulator or affected people is required, with Processor’s reasonable assistance.
Taking account of the processing, Processor will use appropriate technical and organisational measures to help Controller respond to requests for access, correction, erasure, restriction, portability, objection and automated-decision safeguards. If Processor receives a request relating to Customer Personal Data, it will not respond substantively except on Controller’s instruction or as law requires and will route it to Controller where identifiable.
Taking account of the processing and information available, Processor will reasonably assist Controller with security, breach notification, data-protection impact assessments and prior consultation obligations under UK GDPR Articles 32 to 36.
Controller gives general written authorisation for the subprocessors in the Subprocessor Register. Processor will impose written data-protection obligations that provide materially equivalent protection for the relevant processing and remains responsible for a subprocessor’s performance as required by Data Protection Law.
Processor will give at least 14 days’ notice before a new subprocessor begins processing Customer Personal Data where practicable. Controller may object during that period on reasonable, documented data-protection grounds. The parties will seek a reasonable alternative; if none is available, Controller may stop the affected feature or terminate the service before the change takes effect.
Processor will not make a restricted transfer of Customer Personal Data without a lawful mechanism. Depending on destination and provider, this may be UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, supported where required by the UK data protection test and supplementary measures.
Controller authorises transfers described in the Subprocessor Register and provider safeguards. On request, Processor will provide relevant safeguard information or a copy subject to necessary commercial and security redactions.
During the term, Controller can export Customer data using service controls. At Controller’s choice after the services end, Processor will delete or return Customer Personal Data and delete remaining copies, unless UK law requires retention. A permanent workspace deletion is Controller’s instruction to delete rather than return, so Controller must export first if return is wanted.
Deletion from live systems does not immediately remove isolated backups. Backup copies remain protected, are not restored for ordinary use and expire under documented schedules unless law requires retention. Processor may retain separate controller-side billing, complaint, security and legal records under its Privacy Notice.
Processor will make available information reasonably necessary to demonstrate compliance with UK GDPR Article 28 and allow and contribute to proportionate audits and inspections by Controller or an independent auditor mandated by Controller.
Processor may first satisfy a request with current security, compliance and subprocessor documentation. If that is insufficient, Controller may conduct one audit per year on reasonable written notice during business hours, plus an additional audit after a material breach or where a regulator requires it. Audits must protect other customers, confidentiality and security. Controller bears its costs unless the audit identifies Processor’s material breach.
Processor will cooperate with the ICO or another competent supervisory authority as Data Protection Law requires.
This DPA continues while Processor processes Customer Personal Data. Liability under it is subject to the Terms to the extent permitted by Data Protection Law; nothing limits a Data Subject’s rights or a regulator’s powers.
Data-protection contact: privacy@chasd.co.uk. Processor registered office: Not configured — production launch blocked.