Data Processing Agreement
Last updated — to be confirmed
Handled is in private testing. Some details below are marked as to be confirmed, including the legal entity that would be party to this agreement. Questions are welcome at privacy@handledproperty.co.uk.
This Data Processing Agreement (DPA) forms part of the Terms of Service between you and Legal entity — to be confirmed, trading as Handled (we, us). It governs personal information that we process on your behalf. It does not need to be signed separately: it applies automatically whenever you use Handled to record information about other people.
It is required by Article 28(3) of the UK GDPR, which obliges a controller and a processor to have a contract containing the terms below. That obligation falls on both of us: you are not permitted to give personal information to a processor without one.
1. Which information this covers
Our Privacy Policy explains that there are two different roles in Handled, and this DPA covers only one of them.
| Information | Who is the controller | Covered by this DPA? |
|---|---|---|
| Your own account — your name, email, role, firm details, tax references, audit and security records | We are. We decide how and why it is used. | No. The Privacy Policy governs it. |
| What you record about other people — tenants, contacts, property ownership, financial records, uploaded documents | You are. We act only on your instructions. | Yes. This is the subject of this DPA. |
If you are an accountancy firm
Where you use Handled to manage records for your own clients, you may be acting as a processor for those clients rather than as a controller in your own right. In that case we act as your sub-processor, this DPA applies between us as though references to “controller” were references to you in that capacity, and you confirm that you have the authority from your clients to appoint us. We deal only with you, not with your clients, in respect of those records.
2. Definitions
Data Protection Law means the UK GDPR and the Data Protection Act 2018, and any legislation that replaces or amends them. Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given to them in that law. Customer Personal Data means personal data within the second row of the table in clause 1. Terms defined in the Terms of Service — including Account, Plan and Service — have the same meaning here.
3. Subject matter, duration, nature and purpose
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. Processing continues for as long as your Account is open, and then for the deletion window described in clause 10.
4. Our obligations: processing only on your instructions
We process Customer Personal Data only on your documented instructions, including in relation to transfers outside the UK, unless we are required to process it by law — in which case we will tell you before doing so, unless the law prohibits us from telling you.
Your instructions are:
- this DPA and the Terms of Service;
- your use of the features of the Service — entering, editing, importing, exporting, sharing and deleting records, granting access to an accountancy firm or a co-owner, and setting reminders are all instructions to process accordingly; and
- any further written instruction you send to privacy@handledproperty.co.uk, which we will follow where it is technically feasible and lawful.
We do not use Customer Personal Data for our own purposes. We do not sell it, do not use it for advertising, do not use it to train machine-learning models, and do not use it to build profiles of tenants or any other data subject.
If we consider an instruction to infringe Data Protection Law, we will tell you without undue delay. We are not obliged to give you legal advice, and telling you does not make us responsible for the lawfulness of your instructions.
5. Confidentiality
We ensure that anyone authorised to process Customer Personal Data is under an appropriate duty of confidentiality — whether a contractual obligation or a statutory one — and that the duty survives the end of their engagement. Access is limited to those who need it to provide, secure or support the Service.
6. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR. Those measures are described in Annex 2.
We may update the measures in Annex 2 as the Service develops, provided that we do not materially reduce the overall level of security. The measures in Annex 2 are the ones actually in place; they are not aspirations.
7. Sub-processors
You give us general written authorisation to appoint sub-processors. Those currently appointed are listed in Annex 3.
- We impose on each sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA.
- We remain fully liable to youfor the performance of each sub-processor’s obligations.
- We will give you at least 30 days’ notice by email before adding or replacing a sub-processor.
- You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate your subscription and receive a refund of Fees covering the period after termination, as your sole remedy.
8. Helping you respond to data subjects
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests to exercise data subject rights.
In practice the Service is built so that you can do this yourself, immediately and without asking us: you can search, view, correct, export and delete any record in your Account at any time, and export your records to CSV. For most access, rectification, erasure and portability requests this is faster than any process we could operate on your behalf.
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will tell them to contact you, and pass the request to you without undue delay, unless you have instructed us otherwise.
9. Personal data breaches, and helping you with your other duties
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notification will describe, so far as we know it at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases as it becomes available.
Notifying you is not an admission of fault by either of us. Reporting a breach to the ICO is your decision, because you are the controller — and the 72-hour clock in Article 33 runs from when you become aware.
Taking into account the nature of the processing and the information available to us, we also assist you with your obligations under Articles 32 to 36 — security, breach notification to the ICO and to data subjects, data protection impact assessments, and prior consultation with the ICO.
10. Deletion and return
At the end of the provision of the Service, we delete or return Customer Personal Data at your choice, and delete existing copies unless Data Protection Law requires us to keep them. Specifically:
- Return — you can export your records at any time, including throughout the read-only period after a subscription ends or is cancelled. Exporting is how return happens; we do not need to prepare anything for you.
- Deletion — when you close your Account, or 60 days after a cancelled subscription ends, your Account and the records in it are permanently deleted. Deleting an individual record deletes it at the time you delete it.
- Backups — copies held in routine backups are overwritten in the ordinary course of the backup cycle rather than being deleted individually. Until they are, they remain protected by the measures in Annex 2 and are not used for any purpose other than restoring the Service.
11. Information and audits
We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice:
- we will answer reasonable written questions about our processing, security measures and sub-processors, and provide any certifications or reports we hold;
- where that is not sufficient, you may audit us on reasonable notice of at least 30 days, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach;
- audits take place during business hours, must not unreasonably disrupt the Service, and are subject to confidentiality; and
- we may charge our reasonable costs for audits beyond the first in any 12-month period.
Audit rights extend to our own systems and records. They do not extend to the systems of our sub-processors, or to any information about other customers.
12. International transfers
Customer Personal Data is stored in the United Kingdom — the database, file storage and the application itself. We will not transfer Customer Personal Data outside the UK without ensuring an appropriate safeguard under Data Protection Law is in place, such as UK adequacy regulations or the International Data Transfer Addendum to the EU standard contractual clauses.
Annex 3 records where each sub-processor holds data and where its parent company is incorporated. The distinction matters: a US-incorporated company hosting your data in London may still be capable of accessing it from the US, which counts as a transfer.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in section 15 of the Terms of Service. Nothing in this DPA limits either party’s liability to a data subject, or relieves either party of any liability imposed directly by Data Protection Law.
14. Changes to this DPA
We may update this DPA where Data Protection Law changes, where our processing changes, or to add or replace a sub-processor under clause 7. If a change materially affects your rights we will give you at least 30 days’ notice by email before it takes effect. This DPA is governed by the law of England and Wales.
Where this DPA and the Terms of Service conflict on the processing of Customer Personal Data, this DPA takes precedence.
Annex 1 — Details of the processing
| Subject matter | Provision of the Handled property record-keeping service. |
| Duration | For as long as your Account is open, and then for the deletion window in clause 10 — 60 days after closure or after a cancelled subscription ends. |
| Nature of the processing | Collection, storage, organisation, structuring, retrieval, aggregation, export and erasure, by automated means. |
| Purpose | Keeping records of properties, tenancies, rent, expenses and compliance dates; producing quarterly and annual tax figures; generating reminders; allowing you to share records with an accountancy firm or a co-owner; and exporting records at your request. |
| Types of personal data | Tenant names, email addresses, phone numbers, tenancy dates, rent and deposit amounts, deposit scheme and reference, and notes you add. Contact details for contractors, agents and suppliers — name, company, phone, email, website, postal address, trade, notes. Property addresses, purchase and sale details, and ownership shares, which can identify individual owners. Financial transaction records, references and descriptions. The contents of documents you upload — tenancy agreements, safety certificates, EPCs, receipts and invoices — which are chosen by you and may contain personal data beyond the categories listed here. |
| Categories of data subject | Tenants and prospective tenants; your contractors, agents, suppliers and other contacts; co-owners of properties you record; and, where you are an accountancy firm, your clients and the individuals in their records. |
| Special category data | Not required by the Service, and not requested by any field in it. If you choose to upload documents containing special category data or criminal offence data, you do so as controller and must have a condition under Article 9 or 10 for it. We do not process it for any purpose other than storing and returning the document you uploaded. |
Annex 2 — Technical and organisational measures
These are the measures actually in place, not a general description of good practice.
Access control
- Row-level security is enforced in the database itself, on every table holding customer records — not only in application code. A request authenticated as one account cannot read or write another account’s rows even if the application layer were bypassed or defective.
- Access to a client’s records by accountancy firm staff is controlled by per-staff permissions and per-client restrictions that you and the firm control.
- Destructive database operations are not executable by the role the application runs as; they are reserved to a separate privileged role that user requests never hold.
- Authentication and session management are provided by our database and authentication provider. Passwords are stored hashed and salted, and we never see them.
Storage and transmission
- All data is stored in the United Kingdom (London region), in a database and file storage hosted there.
- Data is encrypted in transit using TLS, and at rest by our hosting provider.
- Uploaded documents are held in private, non-public storage. They are never served from a public URL. Access is granted through time-limited signed links that expire after five minutes.
- Uploads are restricted by file type and size, and the type is checked on the server rather than trusted from the browser.
Application security
- Security headers are set on every response, including a Content-Security-Policy that forbids the site being framed, restricts form submission to our own origin, and blocks plugin content; X-Frame-Options; X-Content-Type-Options; a referrer policy that stops record identifiers leaking in the Referer header; and a permissions policy that denies camera, microphone and geolocation.
- Scheduled maintenance endpoints require a secret and fail closed if it is absent, so they cannot run unauthenticated.
- Exported CSV files are escaped against formula injection, so an exported record cannot execute when opened in a spreadsheet.
Logging and accountability
- Changes to records are written to an audit log recording who made the change, when, and the values before and after. Audit records are retained for 12 months.
- Access to production systems is limited to personnel who need it, and is protected by multi-factor authentication where the provider supports it.
Resilience
- Backups are taken by our database provider and are held in the same region as the primary data.
- The application is hosted on infrastructure that is redundant across availability zones within the London region.
Annex 3 — Sub-processors
| Sub-processor | What they do | Where data is held | Incorporated |
|---|---|---|---|
| Supabase | Database, authentication and file storage | London, United Kingdom (AWS eu-west-2) | United States |
| Vercel | Hosting and delivery of the application, and anonymous page-speed and page-view measurement | Served from London, United Kingdom (lhr1); measurements are aggregated by Vercel's analytics infrastructure | United States |
| Resend | Sending service emails — confirmation, password reset, invitations | Sent via Ireland (eu-west-1); delivery logs, which include recipient email addresses, are held in the United States | United States |
Service emails are sent to account holders, and to people you invite to Handled. We do not send email to tenants, and no tenant record is transmitted to our email provider.
Contact
Questions about this agreement, or a request to exercise the audit rights in clause 11, go to privacy@handledproperty.co.uk, or by post to Postal address — to be confirmed.
We are registered with the Information Commissioner’s Office under registration number ICO registration number — to be confirmed.