Back to buffcrm.co.uk

Buff CRM — Data Processing Agreement

DASE Systems Limited 45 Main Street, Leeds, West Yorkshire, LS25 1DS Company Number: 17333059

Version 1.0 — Effective date: 22 July 2026


Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between DASE Systems Limited ("DASE", "Processor") and the Subscriber ("Controller") and sets out the terms on which DASE processes personal data on behalf of the Subscriber in connection with the Buff CRM Platform.

This DPA is entered into in accordance with Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.


Part 1 — Definitions

"Controller" means the Subscriber, who determines the purposes and means of processing of personal data.

"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any successor legislation.

"Personal Data" means any information relating to an identified or identifiable natural person processed by DASE on behalf of the Controller under this DPA.

"Processing" has the meaning given in the Data Protection Legislation.

"Processor" means DASE Systems Limited, which processes personal data on behalf of the Controller.

"Sub-processor" means any third party engaged by DASE to process personal data on behalf of the Controller.


Part 2 — Details of processing

2.1 Nature and purpose

DASE processes personal data for the purpose of providing the Buff CRM Platform to the Controller, including storing customer records, job records, vehicle records, booking information, and communications data inputted by the Controller and its Staff Users.

2.2 Types of personal data

The categories of personal data processed under this DPA include: names, contact details (email address, telephone number, postal address), vehicle registration numbers, job and booking history, payment records, and any other personal data the Controller chooses to input into the Platform.

2.3 Categories of data subjects

The data subjects are the Controller's customers and any individuals whose personal data the Controller inputs into the Platform.

2.4 Duration

DASE processes personal data for the duration of the Subscription Period and for 90 days following termination, after which personal data is deleted or anonymised in accordance with the Terms of Service.


Part 3 — DASE's obligations as Processor

DASE shall:

(a) process personal data only on the documented instructions of the Controller, which are set out in the Terms of Service and this DPA, unless required to do so by applicable law;

(b) ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations;

(c) implement appropriate technical and organisational security measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage;

(d) not engage any Sub-processor without the Controller's general authorisation as set out in Part 4, and ensure that Sub-processors are bound by equivalent data protection obligations;

(e) assist the Controller in responding to data subject rights requests, to the extent reasonably practicable given the nature of the processing;

(f) assist the Controller in meeting its obligations in relation to security, breach notification, data protection impact assessments, and prior consultation with the ICO;

(g) at the Controller's election, delete or return all personal data to the Controller on termination of the subscription, and delete existing copies unless retention is required by law;

(h) make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA.


Part 4 — Sub-processors

4.1 General authorisation

The Controller provides general authorisation for DASE to engage Sub-processors. DASE will inform the Controller of any intended changes to Sub-processors, giving the Controller the opportunity to object.

4.2 Current Sub-processors

Sub-processor Role Location
Hetzner Online GmbH Server hosting and infrastructure Germany (EU)
Stripe, Inc. Payment processing United States
Twilio Inc. SMS delivery United States
Resend Inc. Transactional email delivery United States
Cloudflare, Inc. Security, CDN, DNS United States
Sentry (Functional Software, Inc.) Error monitoring (EU servers, no PII) United States

4.3 Sub-processor obligations

DASE imposes equivalent data protection obligations on all Sub-processors by contract and remains fully liable for the acts and omissions of its Sub-processors.


Part 5 — Security measures

DASE implements the following technical and organisational security measures:


Part 6 — Data subject rights

Where DASE receives a data subject rights request that relates to personal data processed on behalf of the Controller, DASE will forward that request to the Controller without undue delay. The Controller is responsible for responding to data subject rights requests in relation to data it controls.

DASE provides tools within the Platform to assist Controllers in responding to data subject rights requests, including the ability to export, correct, and delete customer records.


Part 7 — Security incidents and breach notification

DASE shall notify the Controller without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will include, to the extent available: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and measures taken or proposed to address the breach.


Part 8 — Data transfers

Where DASE transfers personal data outside the UK in connection with the use of Sub-processors, DASE shall ensure that appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or reliance on an adequacy decision.


Part 9 — Audit rights

The Controller may, on reasonable notice and at its own cost, audit DASE's compliance with this DPA no more than once per year. DASE may satisfy audit requests by providing relevant certifications, third-party audit reports, or other reasonable evidence of compliance.


Part 10 — Term and termination

This DPA remains in force for the duration of the Terms of Service and terminates automatically on termination of the Subscriber's subscription. The obligations in this DPA that by their nature should survive termination (including obligations relating to the return or deletion of personal data) shall survive.


Part 11 — Governing law

This DPA is governed by the laws of England and Wales.


Contact

For data protection matters: [email protected]

This Data Processing Agreement was last updated on 22 July 2026 and is effective from 22 July 2026.