Data Processing Addendum
Summary of our processor terms for customers using Plutoo Garage.
1. Purpose of this page
This page summarises how Plutoo Garage (“we”, “us”) processes personal data on behalf of our customers when they use the Plutoo Garage product. It is a public summary for transparency. Where you have a signed agreement or full Data Processing Addendum (DPA) with us, that signed document prevails.
For how we process data as a controller on this marketing website, see our Privacy Policy.
2. Roles
- Customer — the garage / business using Plutoo Garage is the controller (or independent controller) of personal data they upload or collect in the product (for example customer, vehicle and job records).
- Plutoo Garage — acts as a processor (or sub-processor where the customer is itself a processor) when we process that data to provide the service.
3. What we process
Subject to the customer’s configuration and use of the product, we may process contact details, vehicle and job information, invoices, messages, account user details and related operational records needed to run workshop, stock, sales and invoicing features.
4. Instructions and purpose
We process customer personal data only to provide, secure, support and improve the Plutoo Garage service, and as otherwise documented in the customer agreement or written instructions (including product settings and support requests). We do not sell customer personal data.
5. Confidentiality and security
Personnel with access are bound by confidentiality obligations. We apply appropriate technical and organisational measures (access control, encryption in transit where applicable, backups, monitoring). See our Security page.
6. Sub-processors
We use vetted sub-processors for hosting, email, infrastructure and related services needed to run the product. We remain responsible for their performance under our contracts. A current list can be requested from [email protected]. We will give customers reasonable notice of material sub-processor changes where required by the DPA.
7. International transfers
Where personal data is transferred outside the UK, we use appropriate safeguards such as the UK IDTA / Addendum or Standard Contractual Clauses with our providers, unless another lawful transfer mechanism applies.
8. Assistance with rights and compliance
Taking into account the nature of processing, we will assist customers (via product features and support) with data subject requests, security, DPIAs and consultations with supervisory authorities, where reasonably required.
9. Breach notification
If we become aware of a personal data breach affecting customer data we process, we will notify the customer without undue delay and provide information reasonably available to help them meet their own notification duties.
10. Retention and deletion
During the subscription we retain data as needed to provide the service. After termination or on written request (subject to legal retention needs and backups), we will delete or return customer personal data in line with the agreement, and delete remaining copies within a reasonable period.
11. Audits
Customers may request information reasonably necessary to demonstrate compliance with processor obligations. On-site or intrusive audits are subject to notice, confidentiality, scope limits and (where appropriate) reimbursement of costs, as set out in the full DPA.
12. Contact and full DPA
To request our full Data Processing Addendum for contracting, or questions about processing: [email protected].