Data Processing Agreement
Article 28 UK GDPR · ECET (processor) ↔ your Building (controller)
Action required by the Building. UK GDPR requires a written contract whenever a controller uses a processor. This page is the agreement ECET offers your Building. It takes effect when your Building accepts it (in onboarding or by signing a counterpart). Until accepted, it is a template for review.
1. Parties and roles
Processor:ECET Studios Ltd ("ECET"), which provides the booking and access software. Controller:your Building, which decides why and how its members', staff's and visitors' personal data is processed. ECET processes that data only on the Building's documented instructions and has no purpose of its own for it. Roles are determined by what each party actually does, not by any label.
2. Scope of the processing (Art 28(3))
- Subject matter: providing the ECET room-booking, building-access and communications platform.
- Duration: the term of the service, plus any agreed wind-down period.
- Nature & purpose: hosting, booking management, access-control logging, notifications, invoicing & payment reminders, and reporting, on the controller's behalf.
- Personal data: account details (name, email, role, job title, optional photo), bookings, access/sign-in events (time and method — no biometrics, no location), visitor details, notifications, hours adjustments, billing & financial records (company rent/fees, invoices, payment status, billing contact) and audit records.
- Data subjects: the Building's members, staff, company tenants and their visitors.
3. ECET's obligations as processor
ECET shall:
- process personal data only on the controller's documented instructions (including for international transfers), unless required by law — and tell the controller if an instruction appears to breach data-protection law;
- ensure people authorised to process the data are bound by confidentiality;
- take appropriate technical and organisational security measures (Art 32 — see §6);
- not engage a sub-processor without prior authorisation, and impose equivalent data-protection terms on each one (see §4);
- assist the controller, taking account of the nature of processing, to respond to data-subject rights requests;
- assist the controller with its Art 32–36 duties — security, breach notification, data-protection impact assessments, and prior consultation;
- at the controller's choice, delete or return all personal data at the end of the service, and delete existing copies unless retention is legally required;
- make available the information needed to demonstrate compliance with Art 28, and allow and contribute to audits and inspections (see §10).
4. Sub-processors
The controller authorises ECET to use the sub-processors below. ECET gives advance notice (at least 30 days where the vendor allows) of any intended change, and the controller may object on reasonable data-protection grounds.
Database & authentication (your data stored in the EU — Ireland)
Location: EU storage; contracting entity in Singapore · Transfer: EU SCCs + UK Addendum
Application hosting & delivery
Location: United States · Transfer: EU SCCs + UK IDTA; EU–US Data Privacy Framework (where certified)
Transactional email (invites, confirmations) — name & email only
Location: United States · Transfer: EU SCCs + UK Addendum; EU–US Data Privacy Framework (UK Extension)
Each vendor maintains its own sub-processor list and DPA at the link shown. Live Data Privacy Framework certification should be checked on the official register before relying on it.
5. International transfers
Primary storage is in the EU (Ireland), which has UK adequacy. Transfers to US sub-processors rely on an appropriate Article 46 safeguard — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — supported by a transfer risk assessment, and the UK Extension to the EU–US Data Privacy Framework where the recipient is certified.
6. Security (Art 32)
Encryption in transit and at rest; database row-level security isolating each tenant's data; least-privilege, audited access to production; passwords stored only as bcrypt hashes; and regular review. Measures are kept appropriate to the risk.
7. Personal data breaches
ECET will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information the controller needs to meet its own Art 33/34 obligations.
8. Assistance
ECET provides tooling and information to help the controller meet data-subject requests (including the one-click export), and to support DPIAs, breach handling and (from 19 June 2026) the new duty to facilitate data-protection complaints.
9. Return or deletion
On termination, at the controller's choice ECET will return or delete the personal data and delete remaining copies, unless UK law requires continued storage.
10. Audit
ECET makes available the information needed to demonstrate Art 28 compliance and allows for, and contributes to, audits — including inspections — conducted by the controller or an auditor it mandates, on reasonable notice.
11. Records of processing
ECET maintains a processor record under Art 30(2) covering the categories of processing carried out for each controller, transfers and safeguards, and a description of its security measures.
See also the Privacy Policy, Cookies and Terms.