Legal

Data Processing Agreement

Last updated: 26 June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Controller”) and SusDevOS Ltd (“Processor”) and applies where the use of the SusDevOS platform involves the processing of personal data on your behalf. It is required by Article 28 of UK GDPR and EU GDPR.

By using SusDevOS on a paid plan, you accept this DPA. Enterprise customers requiring a countersigned copy should contact dpo@susdevos.com.

1. Definitions

Terms not otherwise defined here have the meanings given in UK GDPR and EU GDPR. “Personal Data” means any information relating to an identified or identifiable natural person that you upload to or process via the SusDevOS platform. This includes — but is not limited to — named employee travel records, user account details of your staff, and any individually identifiable data in emissions records.

Most emissions data (fuel consumption figures, energy use totals, activity quantities) is not personal data. This DPA applies only where personal data is involved.

2. Roles and responsibilities

You (“Controller”) determine the purposes and means of processing personal data that you upload to SusDevOS. SusDevOS (“Processor”) processes that data only on your documented instructions and only to provide the platform services described in the Terms of Service.

SusDevOS is independently a Controller for user account data (login details, authentication logs, billing information). That processing is governed by the Privacy Policy, not this DPA.

3. Subject matter and duration

The subject matter of processing under this DPA is the provision of the SusDevOS GHG reporting and ecosystem tracking platform. Processing begins when you start using the platform and continues until your account is terminated, after which personal data is retained or deleted per Section 8 below.

4. Nature and purpose of processing

We process personal data for the following purposes, and only to the extent necessary for each:

  • Storing and calculating GHG emissions data that contains personal identifiers (e.g. named business travel)
  • Maintaining audit log records of user actions for inventory integrity and regulatory compliance
  • Sending platform notifications and alerts to named users
  • Providing data export and GDPR data subject access request responses on your behalf

5. Types of personal data and data subjects

The personal data we may process on your behalf includes:

Data typeData subjects
User names and work email addressesYour employees, contractors, consultants
Employee commuting journey data (Scope 3 Category 7)Your employees (if individually identifiable)
Named business travel recordsYour employees or travellers
Supplier contact data (if entered)Your suppliers' named contacts
Audit log entries containing user identityYour platform users

6. Obligations of the Processor (SusDevOS)

SusDevOS agrees to:

  • Process personal data only on your documented instructions and not for any other purpose
  • Ensure all persons with access to the personal data are bound by appropriate confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 7)
  • Not engage a sub-processor without your prior consent (given by accepting this DPA for the sub-processors listed in Section 9)
  • Notify you within 24 hours of becoming aware of a personal data breach involving your data
  • Assist you in fulfilling your GDPR obligations: data subject rights, DPIAs, breach notifications to supervisory authorities
  • Return or delete personal data at termination (see Section 8)
  • Make available all information necessary to demonstrate compliance with this DPA and permit audits on reasonable notice

7. Security measures

SusDevOS implements and maintains the following technical and organisational measures to protect personal data:

  • Encryption at rest: AES-256 encryption for all database storage and file storage
  • Encryption in transit: TLS 1.3 (minimum TLS 1.2) for all data transmission
  • Access control: Role-based access control with least-privilege principle; SuperAdmin MFA required
  • Tenant isolation: Row-level data isolation — each entity's data is architecturally separated
  • Authentication: JWT with 15-minute expiry and server-side token revocation; Argon2id password hashing
  • Audit logging: Immutable logs of all access to personal data with user identity and timestamp
  • Monitoring: AWS GuardDuty, application error monitoring with PII scrubbing, 24/7 alerting
  • Patch management: Critical security patches applied within 14 days; automated dependency updates via Dependabot
  • Penetration testing: Annual third-party penetration test; findings remediated before production deployment
  • Certification: Cyber Essentials certified; ISO 27001 in progress

8. Return and deletion of data

On termination of your account or on your written request, SusDevOS will, at your election:

  • Provide a complete export of your data in JSON or CSV format within 30 days; or
  • Delete all personal data from live systems within 30 days, and from backup systems within 90 days

SusDevOS may retain personal data that is required to be kept by applicable law (e.g. billing records for 7 years under UK financial regulations) or that is necessary to defend legal claims. Audit log entries for verified GHG inventories are retained per the retention tier of your plan even after deletion, as these records may be required for regulatory compliance.

9. Sub-processors

You consent to SusDevOS engaging the following sub-processors. SusDevOS will notify you 30 days before adding any new sub-processor, giving you the right to object.

Sub-processorPurposeLocationTransfer mechanism
Amazon Web ServicesCloud infrastructure, database, file storageUK/EU regionsUK/EU adequacy
StripePayment processing (billing data only)UK/EUUK/EU adequacy
SentryError monitoring (PII scrubbed before upload)United StatesStandard Contractual Clauses (EU SCCs Module 2 + UK IDTA)

10. International transfers

Personal data is primarily processed within the UK and EU. Where transfers to third countries occur (e.g. Sentry in the US), SusDevOS relies on appropriate safeguards: EU Standard Contractual Clauses (Module 2: controller-to-processor) and, for UK personal data, the UK International Data Transfer Agreement (IDTA) approved by the ICO.

11. Audit rights

You may audit SusDevOS's compliance with this DPA on reasonable written notice of at least 30 days and no more than once per year, at your cost. As an alternative, SusDevOS will provide its most recent third-party penetration test executive summary and Cyber Essentials certification on request under NDA. Enterprise customers may negotiate additional audit rights in a bespoke agreement.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for losses that cannot be excluded under applicable data protection law.

13. Governing law

This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.

14. Contact

For questions about this DPA, to request a countersigned copy, or to exercise your rights as a controller, contact our Data Protection Officer at dpo@susdevos.com.