Legal
Data Processing Agreement
Last updated: 3 June 2026
Draft — pending legal review
This document is a structural scaffold. The wording must be reviewed and finalised by legal counsel before launch.
This DPA forms part of the agreement between the customer (controller) and Plumb (processor). [REVIEW: finalise with counsel; consider a signable version.]
1. Roles
The customer is the controller; Plumb is the processor for personal data processed to provide the service.
2. Subject matter and duration
[REVIEW: processing subject matter, nature, purpose, duration, categories of data subjects and data.]
3. Processor obligations
Plumb processes personal data only on documented instructions, ensures confidentiality, and applies appropriate technical and organisational measures.
4. Sub-processors
Plumb engages the sub-processors listed on the Sub-processors page and will give notice of changes. [REVIEW: notice period and objection rights.]
5. Security
See the Security page for technical and organisational measures (data residency, encryption, RLS access control, audit logging).
6. Data subject requests
Plumb assists the controller in responding to data subject requests.
7. Personal data breach
[REVIEW: breach notification timing and process.]
8. Return and deletion
On termination, Plumb returns or deletes personal data per the controller's instruction. GDPR erasure is audit-logged.
9. Audits
[REVIEW: audit rights and process.]
10. International transfers
[REVIEW: data residency (UK/EEA) and any transfer safeguards.]