This Data Processing Addendum ("DPA") forms part of the agreement between Xegen Ltd ("Processor", "we") and the customer identified in the Order Form ("Controller", "you") for the provision of RepairSphere.
It applies wherever we process personal data on your behalf. Terms defined in the Terms of Service have the same meaning here.
1. The parties
Processor: Xegen Ltd, registered in Scotland (SC745778), Summit House, 4-5 Mitchell Street, Edinburgh, EH6 7BD, United Kingdom. Contact: privacy@repairsphere.com.
Controller: the customer named in the Order Form.
2. Roles
For Customer Data — everything you and your staff record in RepairSphere about your customers, their vehicles and your work — you are the controller and we are the processor. You decide why and how that data is used; we act on your instructions.
Separately, we are an independent controller for your account records, the user accounts of your staff, and our billing records. That processing is governed by our Privacy Policy, not by this DPA.
3. Details of the processing
Set out explicitly, as Article 28(3) requires.
| Subject matter | Providing, supporting and maintaining the RepairSphere service. |
|---|---|
| Duration | For the term of your subscription, plus the 30-day export window that follows it. |
| Nature and purpose | Hosting, storage, retrieval, organisation, display, backup, transmission of notifications you instruct us to send, and deletion. All to enable you to manage vehicle repairs. |
| Categories of personal data | Names; email addresses; telephone and WhatsApp numbers; postal addresses; messaging preferences recorded per channel; vehicle and registration details; photographs of vehicles and damage; job, estimate and repair status history; insurer and assessor contact details; staff names, work records and time entries. |
| Categories of data subject | Your customers; your staff; contacts at insurers, assessors and suppliers you deal with. |
| Special category data | None is required by the service, and you should not enter any. If you do, you remain the controller of it and are responsible for having a lawful basis under Article 9. |
4. Our obligations
We will:
- process Customer Data only on your documented instructions, including the instructions implicit in your use of the service, unless the law requires otherwise — in which case we will tell you before processing, unless the law forbids that;
- ensure that people authorised to process Customer Data are bound by confidentiality;
- implement appropriate technical and organisational measures under Article 32 — see section 5;
- assist you, so far as is reasonable, in responding to requests from data subjects;
- assist you with your obligations under Articles 32 to 36, including security, breach notification and data protection impact assessments;
- on termination, delete or return Customer Data as set out in the Terms;
- make available the information reasonably needed to demonstrate compliance with Article 28, and allow for audits as set out in section 9;
- tell you if, in our opinion, an instruction from you infringes data protection law.
5. Security
Our measures include: separation of each customer's data from every other customer's; a role and permission model restricting access to what a user's job requires; an audit trail of changes; encryption of data in transit; access controls and authentication for our own staff; and regular backups.
We review these measures as the service develops. We may change them, but not in a way that materially reduces the protection of Customer Data.
6. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will give you the information reasonably available to us so that you can meet your own notification obligations.
We do not commit to a fixed number of hours. A deadline we could not reliably meet would be worth less to you than a commitment we keep.
7. Sub-processors
You give us general written authorisation to engage sub-processors. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.
Our current sub-processors:
| Sub-processor | Service | Data processed | Location |
|---|---|---|---|
| OVH SAS (France) | Hosting and infrastructure | All Customer Data | London, United Kingdom (see section 8) |
| Amazon Web Services | Transactional email (Amazon SES) | Recipient name, email address, message content | Ireland (eu-west-1) |
| WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland | WhatsApp Business Cloud API — only where you use a sender we provide | Recipient phone number, message content, delivery status | Meta infrastructure, which may be outside the UK and EEA |
7.1 WhatsApp — which case applies to you
This distinction matters, and a published page cannot know which applies to you, so both are stated:
- If you send from a WhatsApp number we provide, the WhatsApp Business Account is ours, and Meta is our sub-processor as listed above.
- If you connect your own WhatsApp Business Account — for your whole business or for an individual site — your relationship with Meta is your own. Meta is not our sub-processor in that configuration: it is your processor or counterparty, and the arrangement between you and Meta governs it. We relay your messages.
7.2 Changes
We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account contact. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and we will refund fees covering the period after termination.
7.3 Support tickets
Support tickets you raise through the in-app Support Tickets feature are handled by SupportLayer.app, our own support desk product — also run by us, not a separate company, so it is not listed in the table above as a sub-processor. This is not Customer Data processing: a support ticket carries the name and email address of the staff member raising it, their tenant and site, and the ticket's subject and description, which is your account data governed by our Privacy Policy, not this DPA (see section 2).
You should not include Customer Data in a ticket description. If you do, it is handled under the same technical and organisational measures as the rest of this DPA, since it never leaves our own processing.
8. Location of processing and international transfers
Customer Data is hosted in the region specified in your Order Form, from: United Kingdom, Germany. Every available region is within the UK or the EEA.
Production currently runs in London, United Kingdom. Transactional email is processed in Ireland.
Transfers are made on the following bases:
- United Kingdom. No transfer arises: we are established in the UK and production runs in London.
- Ireland (transactional email) and the Germany region. Both are within the EEA, to which personal data may be transferred from the UK under the UK's adequacy regulations without additional safeguards.
- WhatsApp Ireland Limited (WhatsApp Business Cloud API), where you use a sender we provide. Our sub-processor is established in Ireland, so the transfer to it is within the EEA and rests on the adequacy regulations above. Its onward transfers to Meta infrastructure outside the UK and EEA are covered by the standard contractual clauses in that contract, with the UK Addendum where the transfer originates in the UK. Where you connect your own WhatsApp Business Account, Meta is not our sub-processor and this basis does not apply — see section 7.1.
9. Audit
On reasonable written request, and no more than once a year unless a regulator requires otherwise or a breach has occurred, we will provide the information reasonably necessary to demonstrate our compliance with this DPA.
Where that is genuinely insufficient, you may audit us on 30 days' notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost.
10. Data subject requests
If we receive a request from a data subject relating to Customer Data, we will not respond to it ourselves except to acknowledge it and direct them to you. We will pass it on promptly and help you respond, because the decision is yours to make, not ours.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
12. Governing law
This DPA is governed by the law of Scotland, and the Scottish courts have non-exclusive jurisdiction, matching the Terms of Service.
13. Language
This DPA is published in more than one language. If a translation differs from the English version, the English version prevails.