Due Badger

Sheet 1, data processing agreement

Data Processing Agreement.

This Data Processing Agreement ("DPA") applies where Due Badger ("Processor", "I") process personal data on behalf of you ("Controller") to provide the service. It supplements my Terms of Service and, for data protection matters, prevails if they conflict. Want a copy countersigned in your company's name, or need changes? Email dalemooney50@gmail.com.

1. Subject matter and duration

I process personal data only to provide the service to you, for as long as your account is active, plus the retention period in section 8.

2. Nature and purpose

Storing and processing the obligations, due dates, owners and notes you enter, and sending reminder emails about them.

3. Types of personal data

The names of people you record as an obligation's owner, and any personal detail you choose to put in a note, a reason or an evidence link. Your own account email address.

4. Categories of data subjects

Your staff or contacts named as obligation owners, and any individual whose details you enter into a note.

5. My obligations

  1. Process on instruction: only on your documented instructions, since using the service is your instruction, unless the law requires otherwise.
  2. Confidentiality: anyone I authorise to process the data is bound by confidentiality.
  3. Security: appropriate technical and organisational measures, set out in section 6.
  4. Sub-processors: only those in section 7, on terms no less protective than this DPA, and I stay responsible for them.
  5. Assistance: help you respond to data-subject requests and meet your security, breach and impact-assessment duties.
  6. Breach notice: tell you without undue delay after becoming aware of a personal data breach affecting your data.
  7. Deletion or return: on termination, as set out in section 8.

6. Security measures

Data encrypted in transit with TLS and HSTS; passwords hashed with PBKDF2-HMAC-SHA256; strict per-account data isolation enforced at the database layer; signed, HttpOnly, Secure sessions; hosting on Cloudflare with automated backups; rate limiting and bot protection; strict security headers. Full detail at /security.

7. Authorised sub-processors

You authorise these sub-processors. I give reasonable notice through my Sub-processors page before adding or replacing one, so you can object.

  • Cloudflare, Inc.: hosting, database, sessions, scheduling and bot protection once switched on.
  • Resend, Inc.: transactional email delivery (United States).

8. Retention, return and deletion

While your account is active I keep the data to run the service. On deletion of your account I remove personal data from live systems immediately; residual copies in automated backups age out within 30 days. I will confirm deletion in writing on request.

9. Audit

I will respond to reasonable written requests for the information needed to demonstrate compliance, no more than once a year unless a supervisory authority or a breach requires otherwise, subject to reasonable confidentiality.

10. International transfers

Where a sub-processor processes data outside the UK or EEA, I ensure an appropriate transfer mechanism is in place, such as the UK IDTA or an adequacy decision.

11. Liability and governing law

Liability under this DPA is subject to the limits in my Terms of Service. This DPA is governed by the laws of England and Wales.