Legal
Data processing agreement
Last updated: 20 July 2026
1. Parties and background
This data processing agreement (“DPA”) forms part of the agreement between Mohamed Zahir Ibrahim, trading as BrushDesk (“BrushDesk”, the “processor”) and the business holding a BrushDesk account (the “firm”, the “controller”) under the BrushDesk terms of service. It governs BrushDesk's processing of personal data the firm enters into the service and for which the firm is the controller (“firm data”).
This DPA is incorporated into the terms and applies automatically from the date the firm opens an account, accepts an order form, or otherwise uses the service in circumstances where BrushDesk processes firm data as processor. No separate signature is needed.
2. Definitions
“UK GDPR”, “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018. “Sub-processor” means a third party engaged by BrushDesk to process firm data.
3. Roles and scope
- The firm is the controller of firm data; BrushDesk is its processor.
- BrushDesk is an independent controller of the data it holds about the firm itself (account, billing, support and service-usage data), as described in the privacy policy. That processing is outside this DPA.
- This DPA applies for as long as BrushDesk processes firm data.
4. Details of processing
- Subject matter: provision of the BrushDesk job-management service.
- Duration:the term of the firm's account, plus the 30-day post-closure period in section 10.
- Nature and purpose: hosting, storage, display, transmission (including sending quotes, invoices, receipts and reminders the firm triggers), backup and deletion of firm data, solely to provide the service under the terms.
- Data subjects:the firm's customers and prospective customers; its employees, workers and subcontractors; other contacts the firm records (suppliers, site contacts).
- Personal data: names, postal addresses, email addresses, phone numbers; job, quote, invoice and payment records; timesheet and scheduling records; CIS/UTR details for subcontractors; site photographs; correspondence sent through the service.
- Prohibited and high-risk data:the service is not designed for special category data, criminal offence data, children's data, government identifiers or cardholder data outside Stripe-hosted payment flows. The firm agrees not to enter such data unless BrushDesk has agreed in writing and any extra protections the law requires are in place.
5. BrushDesk's obligations as processor
BrushDesk shall:
- process firm data only on the firm's documented instructions (the terms, this DPA, and the firm's use of the service's features), unless required to do otherwise by law, in which case BrushDesk will inform the firm unless the law prevents it;
- inform the firm if, in its opinion, an instruction infringes UK data protection law;
- ensure persons authorised to process firm data are bound by confidentiality obligations;
- implement appropriate technical and organisational measures as required by Article 32 UK GDPR, including those in Annex C;
- assist the firm, taking into account the nature of the processing, in responding to data subject rights requests; if a data subject contacts BrushDesk directly about firm data, BrushDesk will refer them to the firm without undue delay;
- assist the firm with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, impact assessments and prior consultation), taking into account the nature of the processing and the information available to BrushDesk;
- make available the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, as set out in section 9.
Where assistance goes beyond the product's standard functionality (bespoke exports, restoration from backups, extensive audit or regulator support), BrushDesk may charge a reasonable, quoted fee, unless the assistance is needed because BrushDesk broke this DPA.
6. Sub-processors
- The firm gives general written authorisation for BrushDesk to engage the sub-processors listed in Annex B.
- BrushDesk will give the firm at least 30 days' notice (by email to the account owner or by updating the published sub-processor list and emailing account owners) before adding or replacing a sub-processor that processes firm data. If the firm reasonably objects on data protection grounds and no resolution is found, the firm may terminate the affected service and receive a pro-rata refund of prepaid fees.
- BrushDesk will impose data protection obligations on each sub-processor equivalent to those in this DPA and remains liable to the firm for the sub-processor's performance.
7. Personal data breach
BrushDesk will notify the firm without undue delay after becoming aware of a personal data breach affecting firm data, and will provide (as it becomes available) the information the firm needs to meet its own notification obligations: the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and the measures taken or proposed. BrushDesk's notification is not an admission of fault.
8. International transfers
Firm data is stored in the EU (an adequate territory for UK transfers). BrushDesk will not transfer firm data outside the UK, the EEA or a territory covered by UK adequacy regulations unless the transfer is safeguarded by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
9. Audit and information
BrushDesk will, on reasonable written request (no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach), make available information reasonably necessary to demonstrate compliance with this DPA: summaries of security measures, sub-processor agreements' data protection terms, and relevant third-party certifications or audit reports of its hosting providers. Where this is insufficient, BrushDesk will allow an audit by the firm or its independent auditor, on at least 30 days' notice, during business hours, at the firm's cost, under confidentiality, and without access to other firms' data.
Audits must not unreasonably disrupt BrushDesk's business, weaken security, expose another customer's data or reveal confidential supplier information, and may only touch production systems where strictly necessary under agreed security controls. BrushDesk may decline or narrow requests that are excessive, repetitive or insufficiently scoped.
10. Return and deletion
During the term, the firm can export firm data using the service's export features. After account closure, BrushDesk retains firm data for 30 days (during which the firm may request an export), then deletes it, except where law requires longer retention (in which case the data is retained only as required and remains protected by this DPA). Deletion from encrypted backups occurs as those backups expire in the ordinary rotation.
11. Liability, precedence and term
- The liability provisions of the terms apply to this DPA. If this DPA conflicts with the terms on data protection matters, this DPA prevails.
- This DPA takes effect when the firm's account is opened and ends when BrushDesk ceases to process firm data under section 10.
Annex A — processing details
As set out in section 4.
Annex B — approved sub-processors
- Supabase — database, authentication and file storage (EU, eu-west region).
- Stripe— subscription billing and payment processing (the firm's own connected Stripe account is governed by the firm's direct agreement with Stripe).
- Resend — transactional email delivery.
- Vercel — application hosting and content delivery.
- PostHog — product analytics (EU-hosted, configured without device storage; see the privacy policy).
- Upstash — rate limiting and abuse prevention (processes IP addresses).
Annex C — technical and organisational measures (summary)
- Encryption in transit (TLS) and at rest.
- Multi-tenant isolation enforced at the database layer with row-level security, tested on every release.
- Role-based access control within each workspace (office and field roles; financial data hidden from field roles).
- Restricted, logged access to production systems; secrets held in managed environment configuration, not in code.
- Passwords stored as secure hashes; email verification before sending on a firm's behalf; rate limiting on authentication and signup endpoints.
- Daily encrypted backups; documented restore capability.
- Vulnerability management via dependency monitoring and pre-release security review.