Skip to content
Our Stairwell
Overview
Features
All featuresExplore the shared workspaceMeetings and governanceKeep agendas, papers, attendance, proxies, minutes, decisions, and company records connected.Building recordsTrack works, quotes, certificates, insurance, assets, contractors, and the evidence behind each decision.Service charge recordsConnect demands, payments, credits, bills, funds, bank activity, reports, and unit ledgers.Document librarySearch file contents, filter by source, follow documents back to their records, and share evidence with control.Resident communicationPublish announcements, run discussions and polls, coordinate dates, and keep residents pointed to the right record.Resident accessConnect residents to units and roles while keeping finance, governance, and sensitive records appropriately controlled.Setup and prioritiesUse guided setup, dashboard priorities, invitations, notifications, controlled sharing, and exports to keep work moving.
How it worksPricingContactSupport
Sign in
Start free trial
Menu
OverviewFeaturesHow it worksPricingContactSupportSign inStart free trial

Legal and privacy

Data Processing Agreement

Pre-release draft ยท Version 2026-09-05

The UK GDPR Article 28 terms incorporated into every Our Stairwell customer subscription.

Legal and privacy
Privacy noticeCookies & storageSubscription termsData processingAcceptable useSupport & service levelsSubprocessorsSecurity measures

These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.

This Data Processing Agreement (DPA) is incorporated into the Master Subscription Terms. It applies when Our Stairwell processes personal data on behalf of Customer through the Service.

1. Scope and definitions

The parties to this DPA are the Customer and Supplier identified in the Master Subscription Terms. Terms such as controller, processor, personal data,processing, personal data breach and data subject have the meanings given in the UK GDPR and Data Protection Act 2018. Data Protection Lawmeans those laws and any replacement or amending UK data-protection legislation that applies to the processing.

Customer is controller and Supplier is processor for Customer Personal Data. If Customer processes for another controller, Customer is a processor and Supplier is its subprocessor. Each party remains a separate controller for personal data it determines how and why to use for its own account administration, billing, fraud prevention, security, contract evidence and legal compliance.

2. Customer instructions

Supplier will process Customer Personal Data only on Customer's documented instructions, including the instructions in the Agreement, Customer's configuration and authorised users' use of Service features, support requests and lawful written directions. This includes hosting, organising, retrieving, displaying, backing up, exporting, transmitting through enabled integrations, supporting and deleting the data.

Supplier may process otherwise only where UK law requires it. Unless legally prohibited on important public-interest grounds, Supplier will tell Customer about that requirement before processing. Supplier will promptly tell Customer if, in its reasonable opinion, an instruction infringes Data Protection Law and may pause that instruction while the parties resolve it.

3. Customer obligations

Customer must:

  • comply with Data Protection Law as controller and give lawful, fair and transparent instructions;
  • ensure it has a lawful basis for Customer Personal Data and provides required privacy information;
  • limit data and user access to what is necessary, maintain accurate records and configure permissions;
  • respond to data subjects and supervisory authorities, with Supplier's assistance under this DPA; and
  • not intentionally submit special-category or criminal-offence data unless necessary, lawful, documented and protected by appropriate controls.

4. Confidentiality and personnel

Supplier will ensure that each person authorised to process Customer Personal Data is bound by a statutory or contractual duty of confidentiality, receives access only as needed for their role, and is informed of applicable security and data-protection responsibilities.

5. Security

Taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and risks to individuals, Supplier will implement and maintain appropriate technical and organisational measures designed to protect confidentiality, integrity, availability and resilience. The current measures are described in the Security Measures Schedule.

Supplier may update measures as technology and risk change, provided it does not materially reduce the overall level of protection during the subscription.

6. Personal data breaches

Supplier will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, where feasible, target an initial notice within 24 hours. Notice will include available information about the nature of the breach, likely consequences, affected data and individuals, mitigation and a contact point. Information may be supplied in phases as the investigation progresses.

Supplier will take reasonable steps to contain, investigate, mitigate and remediate the breach and will reasonably assist Customer with any notification. A notice is not an admission of fault. Customer is responsible for deciding whether to notify the ICO or affected people unless law places that duty directly on Supplier.

7. Data-subject rights and compliance assistance

Taking account of the nature of processing, Supplier will use appropriate technical and organisational measures to help Customer respond to requests for access, rectification, erasure, restriction, portability, objection and rights concerning automated decision-making. If Supplier receives a request relating to Customer Personal Data, it will direct the person to Customer and will not independently respond unless authorised or legally required.

Taking account of the processing and information available, Supplier will reasonably assist Customer with security obligations, breach assessment and notification, data protection impact assessments and prior consultation with the ICO. Assistance beyond standard Service features or information may be charged at reasonable rates agreed in advance where the need was not caused by Supplier's breach.

8. Subprocessors

Customer gives general written authorisation for Supplier to use the subprocessors on the Subprocessor List. Supplier will impose written data-protection obligations that provide materially equivalent protection for Customer Personal Data and remains responsible for a subprocessor's performance of those obligations.

Supplier will give at least 30 days' prior notice of a new or replacement subprocessor that will process Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected feature or terminate the affected Service before the change takes effect and receive a pro-rata refund of prepaid fees for the unused affected period.

9. International transfers

Supplier will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless it complies with Data Protection Law. Where no UK adequacy regulation applies, Supplier will use an appropriate safeguard such as the ICO International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism, and will complete any required transfer risk assessment and supplementary measures. Customer authorises transfers made by the listed subprocessors under those safeguards.

10. Information and audits

Supplier will make available information reasonably necessary to demonstrate compliance with Article 28. Customer may audit once in any 12-month period and additionally after a material personal data breach or reasonable evidence of non-compliance. Customer must give at least 30 days' notice where practicable, keep audit information confidential, use an independent non-competitor, avoid disrupting the Service and first use current third-party reports or questionnaires where they reasonably address the request.

Supplier will contribute to a proportionate inspection. Customer pays its and Supplier's reasonable audit costs unless the audit identifies a material Supplier breach, in which case Supplier bears its own costs.

11. Return and deletion

During ordinary paid or trial access and the 90-day live retention period after that access ends following voluntary cancellation, Customer may use Service exports to retrieve Customer Personal Data. For qualifying non-payment, that period runs from the payment failure or mandate loss described in the Terms. At Customer's written choice made before the deletion date, Supplier will return available data through those exports or delete it. If Customer makes no choice, Customer instructs Supplier to delete live Customer Personal Data on the deletion schedule in the Master Subscription Terms.

Supplier will delete existing copies unless UK law requires storage. Backup copies that cannot reasonably be isolated are put beyond ordinary use, remain protected by this DPA and are deleted on the applicable cycle. Supplier may retain data as a separate controller only to the limited extent needed for its legal, tax, accounting, security, contract-evidence or legal-claim obligations.

12. Liability and ending this DPA

The liability provisions of the Master Subscription Terms apply to this DPA. This DPA starts with the Agreement and continues while Supplier processes Customer Personal Data. Duties concerning confidentiality, deletion, transfers, audit evidence and retained data survive termination for as long as relevant.

Schedule 1: processing details

Subject matterHosting and operating a shared resident-led building-management workspace and enabled support, communication, document, finance, meeting, building-work, export and integration features.
DurationFor the subscription and the deletion periods in the Agreement, plus protected backup cycles and any storage required by law.
Nature and purposeCollection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to authorised users and enabled providers, alignment, search, restriction, export, backup and deletion to provide and secure the Service.
Data subjectsCustomer representatives; committee members; directors, members and shareholders; owners, leaseholders, tenants, residents and invitees; suppliers, contractors and professional advisers; payees and contacts; meeting participants; support correspondents; and authorised users.
Personal dataNames, contact and address details; account and authentication identifiers; roles, permissions and unit relationships; company and association records; correspondence, announcements, meeting records and votes; documents and their metadata; repairs, compliance and contractor records; service-charge, transaction, payment-reference and bank-import data; support content; usage, device, IP, security and audit records; and other information Customer chooses to submit.
Sensitive dataThe Service is not designed to require special-category or criminal-offence data. Such data may appear incidentally in communications or documents uploaded by Customer and is processed only under Customer's documented instruction.
FrequencyContinuous and event-driven according to Customer's use of the Service.
Controller rightsCustomer determines purposes, users, permissions, content, enabled integrations, retention choices available in the Service, exports and lawful written instructions.

Schedule 2: contacts

Customer's data-protection contact is its administrator or other contact notified to Supplier. Supplier's privacy contact is [email protected]. Security incidents may also be reported to [email protected].

Our Stairwell

Block management software for UK resident-led buildings.

Explore
FeaturesPricingHow it worksContactSupportLegal