Data Processing Agreement

Version 1.1 — effective 2026-10-04

COLDLOG DATA PROCESSING AGREEMENT Version 1.1, effective 4 October 2026 This Data Processing Agreement ("DPA") forms part of the ColdLog Terms of Service. It applies where a customer company ("the Customer" or "Controller") enters personal data into ColdLog and Woodins Cooling Services Ltd trading as ColdLog ("the Provider" or "Processor") processes that personal data on the Customer's behalf. "Data Protection Law" means applicable UK data protection law, including the UK GDPR and Data Protection Act 2018, as amended or replaced. 1. DETAILS OF PROCESSING Subject matter. Provision of the ColdLog software platform. Duration. For the duration of the Customer's account and any applicable post-termination retention period. Nature and purpose. Activities required to provide the ColdLog service, including receiving, storing, organising, displaying, calculating from, synchronising, backing up, retrieving, exporting, analysing where instructed, and deleting Customer Data. Categories of individuals. May include Customer employees, engineers, subcontractors, administrators, clients, site contacts, supplier contacts and other individuals whose details are entered by the Customer. Types of personal data. May include names, email addresses, telephone numbers, business addresses, site addresses, signatures, photographs, job records, service records, engineering records, timesheets, holiday records, absence records, vehicle records, expense information and other operational information entered by the Customer. Special-category personal data. ColdLog is not intended as a medical-record system. Absence records or free-text fields may contain health information if the Customer chooses to enter it. The Customer is responsible for ensuring that any special-category personal data is entered and processed lawfully. 2. CUSTOMER RESPONSIBILITIES 2.1 The Customer is responsible for determining the purposes and lawful basis for processing personal data entered into ColdLog. 2.2 The Customer is responsible for providing appropriate privacy information to staff, clients and other affected individuals. 2.3 The Customer instructs the Provider to process Customer Data as reasonably necessary to: - provide ColdLog; - perform actions initiated by authorised users; - maintain and secure the service; - provide support; and - comply with this DPA. 2.4 The Customer should avoid entering unnecessary medical information or other sensitive personal information. 2.5 Where health information or other special-category data is entered, the Customer is responsible for identifying a lawful basis and applicable special-category condition under Data Protection Law. 3. PROVIDER OBLIGATIONS The Provider will: 3.1 process personal data only on documented instructions from the Customer unless required to do otherwise by law; 3.2 where legally permitted, notify the Customer before processing required by law outside the Customer's instructions; 3.3 ensure persons authorised to access personal data are subject to appropriate confidentiality obligations; 3.4 implement appropriate technical and organisational measures designed to protect personal data; 3.5 provide reasonable assistance to the Customer in responding to individuals exercising data protection rights; 3.6 provide reasonable assistance regarding security obligations, breach investigations, data protection impact assessments and regulatory consultation, taking into account the nature of the processing and information available to the Provider; 3.7 make available information reasonably necessary to demonstrate compliance with this DPA; and 3.8 notify the Customer if, in the Provider's reasonable opinion, a documented instruction clearly infringes Data Protection Law. 4. SUB-PROCESSORS 4.1 The Customer gives general authorisation for the Provider to appoint sub-processors reasonably required to operate ColdLog. Current service providers are: Base44. Purpose: application infrastructure, hosting, database, file storage, authentication, application functionality, email-related functions, and automated or AI features. Customer Data is stored on Base44's servers in the United States and may be processed in other locations used by the provider. Postcodes.io. Purpose: postcode lookup. Receives the postcode only. Other infrastructure or specialist providers. ColdLog may use additional service providers for functions such as communications, monitoring, analytics required to operate the service, technical support or application infrastructure. 4.2 Payment providers such as Stripe may process billing information directly and may act as independent controllers for some processing activities. Stripe does not need to receive the Customer's operational job records merely to process ColdLog subscription payments. 4.3 We will give reasonable advance notice, by email or within ColdLog, of any intended addition or replacement of a sub-processor, so that the Customer has the opportunity to object. 4.4 Where the Customer has reasonable data-protection grounds for objecting to a new sub-processor, the parties will attempt in good faith to resolve the concern. Where no reasonable solution can be found, the Customer may terminate the affected subscription before the relevant change takes effect. 4.5 Where required by law, the Provider will have appropriate written terms in place with its processors and sub-processors. 5. INTERNATIONAL TRANSFERS The Customer acknowledges that Customer Data is stored in the United States and that some service providers may process Customer Data elsewhere outside the United Kingdom. The Provider will take reasonable steps to ensure that restricted transfers are supported by a lawful transfer mechanism recognised under applicable UK data protection law. This may include: - an adequacy regulation; - UK-approved standard contractual arrangements; - an International Data Transfer Agreement; - an approved UK Addendum; or - another legally recognised safeguard. The Provider will make further information regarding applicable safeguards available to the Customer on reasonable request. 6. SECURITY MEASURES The Provider maintains technical and organisational controls designed to protect Customer Data. Measures may include: - individual login credentials; - customer account segregation; - role-based permissions; - restricted administrative functionality; - access controls; - encrypted transmission; - third-party platform security controls; - backup or recovery systems; - monitoring for security issues; and - data export functionality. The precise technical implementation may change as ColdLog and its underlying infrastructure develop. Any such changes will not intentionally materially reduce the overall level of protection provided to Customer Data. 7. PERSONAL DATA BREACHES 7.1 The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. 7.2 Where reasonably practicable, the Provider aims to provide an initial notification within 48 hours after becoming aware of such a breach. This 48-hour period is an operational target and does not override any stricter legal requirement to notify without undue delay. 7.3 Information provided will, where known, include: - the nature of the incident; - the categories of data affected; - categories or approximate numbers of individuals affected; - likely consequences; - measures taken or proposed; and - contact information for follow-up. 7.4 Information may be supplied in stages where complete details are not immediately available. 7.5 The Customer remains responsible for determining whether it must notify the Information Commissioner's Office, affected individuals or another regulator. 8. RIGHTS REQUESTS Where the Provider receives a request directly from an individual relating to Customer Data for which the Customer is controller, the Provider may refer that individual to the Customer. The Provider will provide reasonable assistance to enable the Customer to respond to valid requests. 9. AUDITS AND COMPLIANCE INFORMATION 9.1 The Provider will make available information reasonably required to demonstrate compliance with this DPA. 9.2 In ordinary circumstances, compliance reviews will first be addressed through written security information, compliance documentation, questionnaires, applicable third-party certifications and information supplied by relevant infrastructure providers. 9.3 A Customer may request a more detailed audit where reasonably necessary to demonstrate compliance with Data Protection Law, particularly following a material security incident or where required by a competent regulator. 9.4 Audits must: - be proportionate; - protect the confidentiality and security of other customers; - avoid unreasonable disruption; - take account of shared third-party infrastructure; and - normally be subject to reasonable prior written notice. 9.5 The Provider may satisfy audit requirements using independent audit reports, certifications or equivalent information where appropriate. 10. RETURN AND DELETION 10.1 The Customer may export Customer Data during an active subscription and during any applicable read-only export period. 10.2 Following account closure, Customer Data will normally remain available for up to 90 days. 10.3 After the applicable retention period, the Provider will delete or render inaccessible Customer Data unless continued retention is required by law. 10.4 Customer Data contained in routine backups may remain temporarily after primary deletion and will be deleted or overwritten through normal backup retention cycles. 11. END OF PROCESSING At the end of the services, the Customer may request return or deletion of Customer Data in accordance with the functionality and retention periods described in the Terms of Service and this DPA. 12. LIABILITY AND PRECEDENCE 12.1 The limitations and exclusions of liability in the ColdLog Terms of Service apply to this DPA to the fullest extent permitted by law. 12.2 Where this DPA conflicts with the Terms of Service specifically on the processing of personal data for which the Customer is controller and ColdLog is processor, this DPA takes priority.