Data Processing Agreement
Version: 2026-09-17 · Effective: 17 September 2026
This DPA forms part of the BrakerBase agreement between the subscribing business (“Controller”) and LBM Developments Ltd (“Processor”) where the Processor handles personal data for the Controller.
1. Definitions and precedence
“Data Protection Law” means the UK GDPR, Data Protection Act 2018 and applicable UK privacy law. Statutory data-protection terms have their statutory meanings. This DPA prevails over the Terms for processing personal data.
2. Instructions
The Processor will process only on documented Controller instructions, including the Terms, integrations and authorised user actions, unless UK law requires otherwise. It will inform the Controller before legally required processing unless prohibited. It will notify the Controller if an instruction appears to infringe Data Protection Law and may pause it while resolved.
3. Processing details
- Subject: BrakerBase stock, vehicle, order, invoice, user, dispatch, audit, AI, vehicle-data and integration functions.
- Duration: subscription plus stated export, retention and backup periods.
- Nature: collecting, storing, organising, retrieving, transmitting, securing, backing up and deleting data to provide the Service.
- Data subjects: Controller customers, prospects, users, staff, suppliers, recipients and contacts.
- Data: names, contact and delivery details, orders, invoices, accounts, vehicles, stock, photographs and support data.
The Service is not intended for unnecessary special-category or criminal-offence data. Contact us before intentionally using it for such data.
4. Personnel and confidentiality
Access is limited to authorised personnel who need it and are bound by confidentiality and security duties.
5. Security
The Processor will maintain measures appropriate to risk, including Schedule 1, and assess their suitability. The Controller is responsible for secure user administration and lawful configuration.
6. Subprocessors
The Controller gives general written authorisation for the Subprocessor Schedule. The Processor will impose equivalent duties, remain responsible and give at least 15 days’ notice of a material new subprocessor where practicable. The Controller may object on reasonable data-protection grounds. The parties will seek an alternative; if none is reasonably available, either may terminate the affected Service without penalty.
7. Rights
The Processor will reasonably assist with access, correction, deletion, restriction, portability, objection and automated-decision requests. Direct requests about Controller data will be directed to the Controller unless law requires a response.
8. Incidents
The Processor will notify the Controller without undue delay after becoming aware of a breach affecting Controller data, provide available information and take reasonable containment, recovery and prevention steps. Notification is not an admission of fault.
9. Compliance assistance
The Processor will reasonably assist with security, breach notifications, impact assessments and prior consultation. Additional work outside normal support may be chargeable at an agreed reasonable rate.
10. Transfers
No restricted transfer will occur without a UK adequacy regulation or safeguard such as the UK IDTA or Addendum, plus supplementary measures where required. Relevant information is available subject to confidentiality.
11. Return and deletion
At the Controller’s choice, data will be returned or deleted after the Service unless law requires retention. Principal records have self-service export. Active data follows the Terms deletion period; isolated encrypted backups expire within 90 days.
12. Audits
The Processor will provide information reasonably necessary to demonstrate compliance and permit reasonable audit. Audits require notice, protect other customers and security, use existing reports first and avoid unreasonable disruption. Each party bears its costs unless material non-compliance is found.
13. Controller obligations
The Controller is responsible for lawful collection, transparency, accuracy, minimisation, retention, lawful bases, rights handling and instructions.
14. Liability and term
The Terms’ liability provisions apply. This DPA ends when Controller data has been returned or deleted, except provisions intended to survive.
Schedule 1 — Technical and organisational measures
- Logical tenant separation and business-scoped database access.
- Individual authentication, password hashing, roles and session expiry.
- Secure HTTP-only same-site cookies and CSRF protection.
- Encryption in transit and encrypted integration credentials.
- Audit logging, monitoring and controlled administrator access.
- Need-based provider access and confidentiality duties.
- Backup, export, recovery and restoration procedures.
- Secure development review, dependency maintenance and incident response.
- Data minimisation, retention and deletion controls.
Contact
Processor: LBM Developments Ltd. Privacy contact: sy@lbmdevelopments.com.