Data Processing Agreement

Version: 2026-09-17 · Effective: 17 September 2026

This DPA forms part of the BrakerBase agreement between the subscribing business (“Controller”) and LBM Developments Ltd (“Processor”) where the Processor handles personal data for the Controller.

1. Definitions and precedence

“Data Protection Law” means the UK GDPR, Data Protection Act 2018 and applicable UK privacy law. Statutory data-protection terms have their statutory meanings. This DPA prevails over the Terms for processing personal data.

2. Instructions

The Processor will process only on documented Controller instructions, including the Terms, integrations and authorised user actions, unless UK law requires otherwise. It will inform the Controller before legally required processing unless prohibited. It will notify the Controller if an instruction appears to infringe Data Protection Law and may pause it while resolved.

3. Processing details

The Service is not intended for unnecessary special-category or criminal-offence data. Contact us before intentionally using it for such data.

4. Personnel and confidentiality

Access is limited to authorised personnel who need it and are bound by confidentiality and security duties.

5. Security

The Processor will maintain measures appropriate to risk, including Schedule 1, and assess their suitability. The Controller is responsible for secure user administration and lawful configuration.

6. Subprocessors

The Controller gives general written authorisation for the Subprocessor Schedule. The Processor will impose equivalent duties, remain responsible and give at least 15 days’ notice of a material new subprocessor where practicable. The Controller may object on reasonable data-protection grounds. The parties will seek an alternative; if none is reasonably available, either may terminate the affected Service without penalty.

7. Rights

The Processor will reasonably assist with access, correction, deletion, restriction, portability, objection and automated-decision requests. Direct requests about Controller data will be directed to the Controller unless law requires a response.

8. Incidents

The Processor will notify the Controller without undue delay after becoming aware of a breach affecting Controller data, provide available information and take reasonable containment, recovery and prevention steps. Notification is not an admission of fault.

9. Compliance assistance

The Processor will reasonably assist with security, breach notifications, impact assessments and prior consultation. Additional work outside normal support may be chargeable at an agreed reasonable rate.

10. Transfers

No restricted transfer will occur without a UK adequacy regulation or safeguard such as the UK IDTA or Addendum, plus supplementary measures where required. Relevant information is available subject to confidentiality.

11. Return and deletion

At the Controller’s choice, data will be returned or deleted after the Service unless law requires retention. Principal records have self-service export. Active data follows the Terms deletion period; isolated encrypted backups expire within 90 days.

12. Audits

The Processor will provide information reasonably necessary to demonstrate compliance and permit reasonable audit. Audits require notice, protect other customers and security, use existing reports first and avoid unreasonable disruption. Each party bears its costs unless material non-compliance is found.

13. Controller obligations

The Controller is responsible for lawful collection, transparency, accuracy, minimisation, retention, lawful bases, rights handling and instructions.

14. Liability and term

The Terms’ liability provisions apply. This DPA ends when Controller data has been returned or deleted, except provisions intended to survive.

Schedule 1 — Technical and organisational measures

Contact

Processor: LBM Developments Ltd. Privacy contact: sy@lbmdevelopments.com.