DASE Systems Limited 45 Main Street, Leeds, West Yorkshire, LS25 1DS Company Number: 17333059
Version 1.0 — Effective date: 22 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between DASE Systems Limited ("DASE", "Processor") and the Subscriber ("Controller") and sets out the terms on which DASE processes personal data on behalf of the Subscriber in connection with the Buff CRM Platform.
This DPA is entered into in accordance with Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
"Controller" means the Subscriber, who determines the purposes and means of processing of personal data.
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any successor legislation.
"Personal Data" means any information relating to an identified or identifiable natural person processed by DASE on behalf of the Controller under this DPA.
"Processing" has the meaning given in the Data Protection Legislation.
"Processor" means DASE Systems Limited, which processes personal data on behalf of the Controller.
"Sub-processor" means any third party engaged by DASE to process personal data on behalf of the Controller.
DASE processes personal data for the purpose of providing the Buff CRM Platform to the Controller, including storing customer records, job records, vehicle records, booking information, and communications data inputted by the Controller and its Staff Users.
The categories of personal data processed under this DPA include: names, contact details (email address, telephone number, postal address), vehicle registration numbers, job and booking history, payment records, and any other personal data the Controller chooses to input into the Platform.
The data subjects are the Controller's customers and any individuals whose personal data the Controller inputs into the Platform.
DASE processes personal data for the duration of the Subscription Period and for 90 days following termination, after which personal data is deleted or anonymised in accordance with the Terms of Service.
DASE shall:
(a) process personal data only on the documented instructions of the Controller, which are set out in the Terms of Service and this DPA, unless required to do so by applicable law;
(b) ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations;
(c) implement appropriate technical and organisational security measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage;
(d) not engage any Sub-processor without the Controller's general authorisation as set out in Part 4, and ensure that Sub-processors are bound by equivalent data protection obligations;
(e) assist the Controller in responding to data subject rights requests, to the extent reasonably practicable given the nature of the processing;
(f) assist the Controller in meeting its obligations in relation to security, breach notification, data protection impact assessments, and prior consultation with the ICO;
(g) at the Controller's election, delete or return all personal data to the Controller on termination of the subscription, and delete existing copies unless retention is required by law;
(h) make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA.
The Controller provides general authorisation for DASE to engage Sub-processors. DASE will inform the Controller of any intended changes to Sub-processors, giving the Controller the opportunity to object.
| Sub-processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting and infrastructure | Germany (EU) |
| Stripe, Inc. | Payment processing | United States |
| Twilio Inc. | SMS delivery | United States |
| Resend Inc. | Transactional email delivery | United States |
| Cloudflare, Inc. | Security, CDN, DNS | United States |
| Sentry (Functional Software, Inc.) | Error monitoring (EU servers, no PII) | United States |
DASE imposes equivalent data protection obligations on all Sub-processors by contract and remains fully liable for the acts and omissions of its Sub-processors.
DASE implements the following technical and organisational security measures:
Where DASE receives a data subject rights request that relates to personal data processed on behalf of the Controller, DASE will forward that request to the Controller without undue delay. The Controller is responsible for responding to data subject rights requests in relation to data it controls.
DASE provides tools within the Platform to assist Controllers in responding to data subject rights requests, including the ability to export, correct, and delete customer records.
DASE shall notify the Controller without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will include, to the extent available: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and measures taken or proposed to address the breach.
Where DASE transfers personal data outside the UK in connection with the use of Sub-processors, DASE shall ensure that appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or reliance on an adequacy decision.
The Controller may, on reasonable notice and at its own cost, audit DASE's compliance with this DPA no more than once per year. DASE may satisfy audit requests by providing relevant certifications, third-party audit reports, or other reasonable evidence of compliance.
This DPA remains in force for the duration of the Terms of Service and terminates automatically on termination of the Subscriber's subscription. The obligations in this DPA that by their nature should survive termination (including obligations relating to the return or deletion of personal data) shall survive.
This DPA is governed by the laws of England and Wales.
For data protection matters: [email protected]
This Data Processing Agreement was last updated on 22 July 2026 and is effective from 22 July 2026.
Drop your email and we will let you know the moment Buff opens its doors.