Legal
Data processing addendum
How we process personal data on behalf of organisations that use Regimate Enterprise, in line with Article 28 of the UK GDPR.
In short. For your organisation's asset register you're the controller and we're your processor. We only use that data to provide Regimate to you, keep it secure, use the sub-processors we list, help you meet your obligations, tell you promptly about breaches, and delete it when you ask. This addendum applies automatically; if you need a signed copy, email privacy@regimate.app.
1. Scope and roles
This Data processing addendum (DPA) forms part of our Business terms between Echo Thirteen Capital Ltd (Regimate, the processor) and the organisation using Regimate Enterprise (the Customer, the controller). It applies to personal data in Customer Data that we process on the Customer's behalf (Customer Personal Data). Terms such as controller, processor, personal data, data subject and personal data breach have the meanings given in the UK GDPR.
Regimate acts as an independent controller, not a processor, for: individuals' own Regimate accounts and sign-in data; billing and account administration; the safety, moderation and anti-abuse measures we apply across the platform; and alerts sent to item owners through the Finder API. Those are covered by our Privacy policy.
2. Processing on instructions
We'll process Customer Personal Data only on the Customer's documented instructions, which are this DPA, the Business terms and the Customer's use and configuration of the Service, unless the law requires otherwise. If the law requires other processing we'll tell the Customer first unless the law forbids it. We'll tell the Customer if we believe an instruction breaks data protection law.
3. Confidentiality
We'll make sure everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality and only accesses it as needed to provide, support or secure the Service.
4. Security
We'll implement and maintain the technical and organisational measures in Annex 2, appropriate to the risk. We may update them as long as the overall level of protection isn't reduced.
5. Sub-processors
- The Customer gives general authorisation for us to use sub-processors. Our current sub-processors are listed on our Sub-processors page.
- We'll update that page at least 30 days before a new sub-processor starts processing Customer Personal Data, and the Customer can ask to be notified by email of changes. The Customer may object on reasonable data protection grounds within that period. If we can't reasonably address the objection, the Customer may terminate the affected subscription and receive a refund of prepaid fees for the remaining period.
- We'll put a written contract in place with each sub-processor that imposes data protection obligations no less protective than this DPA, and we remain responsible for their performance.
6. Helping with data subject requests
Taking into account the nature of the processing, we'll help the Customer respond to requests from data subjects to exercise their rights, mainly through the tools in the Service. If we receive a request directly about Customer Personal Data, we'll pass it to the Customer and won't respond ourselves except to redirect the person, unless the law requires otherwise.
7. Personal data breaches
We'll notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We'll provide the information the Customer reasonably needs to meet its own reporting obligations, as it becomes available, and take reasonable steps to contain and remedy the breach.
8. Impact assessments and consultation
We'll give the Customer reasonable assistance with data protection impact assessments and any prior consultation with the Information Commissioner's Office that relate to the Service.
9. International transfers
We host the core platform, database and file storage in the UK and the European Economic Area. Where Customer Personal Data is transferred outside the UK, we'll make sure the transfer is covered by UK adequacy regulations or appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
10. Deletion and return
The Customer can update and delete Customer Personal Data in the Service at any time. When the Customer deletes its organisation, or within 30 days after the Business terms end, we'll delete Customer Personal Data from our live systems unless the law requires us to keep it. Deleted data may remain in point-in-time backups for up to 30 days. If the Customer needs a copy before deletion, it can ask us at privacy@regimate.app and we'll provide one in a common machine-readable format.
11. Information and audits
We'll make available the information reasonably necessary to demonstrate compliance with this DPA, including answers to reasonable security questionnaires. If that isn't enough, the Customer (or an independent auditor bound by confidentiality) may audit our compliance once a year on at least 30 days' notice, during business hours, at the Customer's cost and in a way that doesn't compromise other customers' data or our security.
12. The Customer's responsibilities
The Customer is responsible for having a lawful basis for the Customer Personal Data it gives us, for telling its staff, contractors and other data subjects how their data is used in Regimate, and for the accuracy of that data.
13. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Business terms. If this DPA conflicts with the Business terms, this DPA takes precedence for anything to do with Customer Personal Data.
Annex 1: Details of the processing
| Subject matter and duration | Providing Regimate Enterprise to the Customer for the term of the Business terms, plus the deletion period in section 10. |
|---|---|
| Nature and purpose | Hosting, storing, organising, displaying and transmitting Customer Data so the Customer can manage its assets, people, inspections and locations, receive contractor submissions, and be contacted by people who find its assets. |
| Categories of data subjects | The Customer's members and invitees; staff or others assets are assigned to; inspectors; contractors and their staff who submit assets; people who contact the Customer about a found asset. |
| Types of personal data | Names and email addresses; roles; names recorded against assets, inspections or locations; contractor organisation names and references; asset identifiers such as serial numbers, IMEIs and MAC addresses where they relate to an individual; photos and notes; messages from finders and any reply-to details they leave. |
| Special category data | None intended. The Customer shouldn't enter special category data into Regimate. |
Annex 2: Security measures
- Encryption in transit using TLS, with HTTP Strict Transport Security on all subdomains.
- Database and file storage encrypted at rest by our infrastructure providers; private files served only through HMAC-signed links that expire.
- Passwords, API keys, PINs and other secrets stored only as salted hashes, compared in constant time.
- Role-based access within each organisation (owner, admin, manager, viewer); sessions that can be revoked instantly.
- Isolated, non-root application containers on a private network behind a gateway that sets strict security headers.
- Input validation on every request, size limits, file-type checks on uploads, and re-encoding of images to remove metadata.
- Rate limiting, lockouts and automated moderation to prevent abuse.
- Logs that redact credentials, cookies and signed URLs.
- Automated daily deletion of data past its retention period, and point-in-time database backups.
- An automated test suite, including security regression tests, run before changes are released.
- Access to production systems limited to authorised personnel who need it.
- A published responsible disclosure policy.
Annex 3: Sub-processors
See our Sub-processors page, which forms part of this DPA.