Data processing agreement
Last updated: 11 July 2026
This Data Processing Agreement (DPA) forms part of the agreement between AssessHub (the 'Processor') and the Customer (the 'Controller') and applies to all personal data the Customer submits to the service. It is written to satisfy Article 28 UK GDPR.
1. Subject matter and duration
The Processor processes personal data contained in the Customer’s fire risk assessments — including names of responsible persons and persons consulted, site addresses, photographs and uploaded documents — solely to provide the AssessHub service, for the duration of the subscription.
2. Instructions
The Processor acts only on the Controller’s documented instructions, which are: provide the service as described in the Terms, including storage, AI-assisted drafting on request, report generation and backup. The Processor will inform the Controller if an instruction appears to infringe data protection law.
3. Security measures
The Processor implements appropriate technical and organisational measures, including:
- Per-tenant segregation of all assessment data and photographs (organisation-scoped storage keys and queries).
- Encryption in transit (TLS) and at rest at the infrastructure providers.
- Multi-factor authentication on all user accounts and active-session device limits.
- Role-based access control (owner / assessor / QC) and a full audit trail of changes.
- Access to production systems restricted to authorised personnel on a need-to-know basis.
4. Sub-processors
The Controller authorises the following sub-processors: Clerk (authentication), Stripe (billing), Railway (hosting), Cloudflare (object storage), OpenRouter (AI processing). The Processor will give at least 30 days’ notice of any change, during which the Controller may object on reasonable grounds. Transfers outside the UK are protected by adequacy decisions or the IDTA / SCCs with UK Addendum.
5. Assistance and breach notification
The Processor will assist the Controller with data subject requests and with Articles 32–36 obligations, and will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Customer’s data.
6. Deletion and return
On termination of the subscription, the Controller may export its reports and data. The Processor will delete customer content within 90 days of termination, except where retention is required by law.
7. Audit
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and, no more than once per year and on reasonable notice, allow audits limited to that purpose.