Legal

Data Processing Agreement

Last updated: 3 June 2026

Draft — pending legal review

This document is a structural scaffold. The wording must be reviewed and finalised by legal counsel before launch.

This DPA forms part of the agreement between the customer (controller) and Plumb (processor). [REVIEW: finalise with counsel; consider a signable version.]

1. Roles

The customer is the controller; Plumb is the processor for personal data processed to provide the service.

2. Subject matter and duration

[REVIEW: processing subject matter, nature, purpose, duration, categories of data subjects and data.]

3. Processor obligations

Plumb processes personal data only on documented instructions, ensures confidentiality, and applies appropriate technical and organisational measures.

4. Sub-processors

Plumb engages the sub-processors listed on the Sub-processors page and will give notice of changes. [REVIEW: notice period and objection rights.]

5. Security

See the Security page for technical and organisational measures (data residency, encryption, RLS access control, audit logging).

6. Data subject requests

Plumb assists the controller in responding to data subject requests.

7. Personal data breach

[REVIEW: breach notification timing and process.]

8. Return and deletion

On termination, Plumb returns or deletes personal data per the controller's instruction. GDPR erasure is audit-logged.

9. Audits

[REVIEW: audit rights and process.]

10. International transfers

[REVIEW: data residency (UK/EEA) and any transfer safeguards.]