These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.
This Data Processing Agreement (DPA) is incorporated into the Master Subscription Terms. It applies when Our Stairwell processes personal data on behalf of Customer through the Service.
1. Scope and definitions
The parties to this DPA are the Customer and Supplier identified in the Master Subscription Terms. Terms such as controller, processor, personal data,processing, personal data breach and data subject have the meanings given in the UK GDPR and Data Protection Act 2018. Data Protection Lawmeans those laws and any replacement or amending UK data-protection legislation that applies to the processing.
Customer is controller and Supplier is processor for Customer Personal Data. If Customer processes for another controller, Customer is a processor and Supplier is its subprocessor. Each party remains a separate controller for personal data it determines how and why to use for its own account administration, billing, fraud prevention, security, contract evidence and legal compliance.
2. Customer instructions
Supplier will process Customer Personal Data only on Customer's documented instructions, including the instructions in the Agreement, Customer's configuration and authorised users' use of Service features, support requests and lawful written directions. This includes hosting, organising, retrieving, displaying, backing up, exporting, transmitting through enabled integrations, supporting and deleting the data.
Supplier may process otherwise only where UK law requires it. Unless legally prohibited on important public-interest grounds, Supplier will tell Customer about that requirement before processing. Supplier will promptly tell Customer if, in its reasonable opinion, an instruction infringes Data Protection Law and may pause that instruction while the parties resolve it.
3. Customer obligations
Customer must:
- comply with Data Protection Law as controller and give lawful, fair and transparent instructions;
- ensure it has a lawful basis for Customer Personal Data and provides required privacy information;
- limit data and user access to what is necessary, maintain accurate records and configure permissions;
- respond to data subjects and supervisory authorities, with Supplier's assistance under this DPA; and
- not intentionally submit special-category or criminal-offence data unless necessary, lawful, documented and protected by appropriate controls.
4. Confidentiality and personnel
Supplier will ensure that each person authorised to process Customer Personal Data is bound by a statutory or contractual duty of confidentiality, receives access only as needed for their role, and is informed of applicable security and data-protection responsibilities.
5. Security
Taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and risks to individuals, Supplier will implement and maintain appropriate technical and organisational measures designed to protect confidentiality, integrity, availability and resilience. The current measures are described in the Security Measures Schedule.
Supplier may update measures as technology and risk change, provided it does not materially reduce the overall level of protection during the subscription.
6. Personal data breaches
Supplier will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, where feasible, target an initial notice within 24 hours. Notice will include available information about the nature of the breach, likely consequences, affected data and individuals, mitigation and a contact point. Information may be supplied in phases as the investigation progresses.
Supplier will take reasonable steps to contain, investigate, mitigate and remediate the breach and will reasonably assist Customer with any notification. A notice is not an admission of fault. Customer is responsible for deciding whether to notify the ICO or affected people unless law places that duty directly on Supplier.
7. Data-subject rights and compliance assistance
Taking account of the nature of processing, Supplier will use appropriate technical and organisational measures to help Customer respond to requests for access, rectification, erasure, restriction, portability, objection and rights concerning automated decision-making. If Supplier receives a request relating to Customer Personal Data, it will direct the person to Customer and will not independently respond unless authorised or legally required.
Taking account of the processing and information available, Supplier will reasonably assist Customer with security obligations, breach assessment and notification, data protection impact assessments and prior consultation with the ICO. Assistance beyond standard Service features or information may be charged at reasonable rates agreed in advance where the need was not caused by Supplier's breach.
8. Subprocessors
Customer gives general written authorisation for Supplier to use the subprocessors on the Subprocessor List. Supplier will impose written data-protection obligations that provide materially equivalent protection for Customer Personal Data and remains responsible for a subprocessor's performance of those obligations.
Supplier will give at least 30 days' prior notice of a new or replacement subprocessor that will process Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected feature or terminate the affected Service before the change takes effect and receive a pro-rata refund of prepaid fees for the unused affected period.
9. International transfers
Supplier will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless it complies with Data Protection Law. Where no UK adequacy regulation applies, Supplier will use an appropriate safeguard such as the ICO International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism, and will complete any required transfer risk assessment and supplementary measures. Customer authorises transfers made by the listed subprocessors under those safeguards.
10. Information and audits
Supplier will make available information reasonably necessary to demonstrate compliance with Article 28. Customer may audit once in any 12-month period and additionally after a material personal data breach or reasonable evidence of non-compliance. Customer must give at least 30 days' notice where practicable, keep audit information confidential, use an independent non-competitor, avoid disrupting the Service and first use current third-party reports or questionnaires where they reasonably address the request.
Supplier will contribute to a proportionate inspection. Customer pays its and Supplier's reasonable audit costs unless the audit identifies a material Supplier breach, in which case Supplier bears its own costs.
11. Return and deletion
During ordinary paid or trial access and the 90-day live retention period after that access ends following voluntary cancellation, Customer may use Service exports to retrieve Customer Personal Data. For qualifying non-payment, that period runs from the payment failure or mandate loss described in the Terms. At Customer's written choice made before the deletion date, Supplier will return available data through those exports or delete it. If Customer makes no choice, Customer instructs Supplier to delete live Customer Personal Data on the deletion schedule in the Master Subscription Terms.
Supplier will delete existing copies unless UK law requires storage. Backup copies that cannot reasonably be isolated are put beyond ordinary use, remain protected by this DPA and are deleted on the applicable cycle. Supplier may retain data as a separate controller only to the limited extent needed for its legal, tax, accounting, security, contract-evidence or legal-claim obligations.
12. Liability and ending this DPA
The liability provisions of the Master Subscription Terms apply to this DPA. This DPA starts with the Agreement and continues while Supplier processes Customer Personal Data. Duties concerning confidentiality, deletion, transfers, audit evidence and retained data survive termination for as long as relevant.
Schedule 1: processing details
| Subject matter | Hosting and operating a shared resident-led building-management workspace and enabled support, communication, document, finance, meeting, building-work, export and integration features. |
|---|---|
| Duration | For the subscription and the deletion periods in the Agreement, plus protected backup cycles and any storage required by law. |
| Nature and purpose | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to authorised users and enabled providers, alignment, search, restriction, export, backup and deletion to provide and secure the Service. |
| Data subjects | Customer representatives; committee members; directors, members and shareholders; owners, leaseholders, tenants, residents and invitees; suppliers, contractors and professional advisers; payees and contacts; meeting participants; support correspondents; and authorised users. |
| Personal data | Names, contact and address details; account and authentication identifiers; roles, permissions and unit relationships; company and association records; correspondence, announcements, meeting records and votes; documents and their metadata; repairs, compliance and contractor records; service-charge, transaction, payment-reference and bank-import data; support content; usage, device, IP, security and audit records; and other information Customer chooses to submit. |
| Sensitive data | The Service is not designed to require special-category or criminal-offence data. Such data may appear incidentally in communications or documents uploaded by Customer and is processed only under Customer's documented instruction. |
| Frequency | Continuous and event-driven according to Customer's use of the Service. |
| Controller rights | Customer determines purposes, users, permissions, content, enabled integrations, retention choices available in the Service, exports and lawful written instructions. |
Schedule 2: contacts
Customer's data-protection contact is its administrator or other contact notified to Supplier. Supplier's privacy contact is [email protected]. Security incidents may also be reported to [email protected].