Legal and compliance
Data Processing Agreement
Our obligations as a processor under UK GDPR Article 28, written to be signed as it stands.
This agreement is written to be accepted as it stands. It is drafted to satisfy Article 28(3) of the UK GDPR in full, so that an information governance officer can read it once and sign rather than negotiate a variation. If your authority needs it as a countersigned document on your own paper, ask and we will provide one.
1. Parties and roles
This agreement is between the local highway authority using Highways Transparency Reporter (the Controller) and Infin8 Digital Limited (the Processor).
It applies to personal data the Processor processes on the Controller's behalf in providing the service. It does not apply to the account data of the Processor's own users, for which the Processor is itself a controller — see the Privacy Policy.
"UK GDPR", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018.
2. Subject matter, duration, nature and purpose
| Subject matter | Preparing, checking, exporting and publishing the Controller's highways maintenance transparency report. |
|---|---|
| Duration | For as long as the Controller uses the service, and for 30 days after it stops, to allow export. |
| Nature | Storage, structured retrieval, validation, document generation and transmission by email of service messages. |
| Purpose | Solely to provide the service to the Controller. No other purpose, and specifically not the Processor's own product analytics, profiling or model training. |
| Categories of data subject | The Controller's officers who use the service; the officers named in the report's sign-off block (head of service and section 151 officer); any individual incidentally named in a document the Controller uploads. |
| Categories of personal data | Name, work email address, job title, organisational role; sign-in times and truncated IP addresses; content of uploaded documents in so far as it contains personal data. |
| Special category data | None is required, requested or expected. The Controller undertakes not to upload special category data. |
3. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions, including as to transfers, unless required otherwise by law — in which case the Processor will tell the Controller before processing, unless the law forbids that on important grounds of public interest.
The Controller's use of the service, and this agreement, together constitute the documented instructions. The Processor will tell the Controller immediately if, in its opinion, an instruction infringes data protection law.
4. Confidentiality
The Processor ensures that everyone authorised to process the personal data is under a binding obligation of confidentiality, that access is limited to those who need it to provide or support the service, and that the obligation survives the end of their engagement.
5. Security — Article 32
The Processor implements appropriate technical and organisational measures. These are set out in full in the Security & Hosting Statement, which forms part of this agreement. In summary:
- TLS 1.3 in transit; modern ciphers only, with HTTP Strict Transport Security.
- Credentials and API keys sealed with AES-256-GCM in the database.
- Passwordless authentication, so there is no password store to breach.
- Strict per-organisation access control on every read of report data.
- An append-only audit log of security-relevant actions.
- A content security policy forbidding any third-party resource.
- Automated backups: Daily, retained for 14 days.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors below. The Processor will give at least 30 days' notice before adding or replacing one, and the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate without penalty and receive a pro-rata refund of any prepaid fees.
| Sub-processor | Purpose | Location |
|---|---|---|
| Akamai Technologies (Linode) | Hosting and storage | United Kingdom |
| Google Workspace | Transactional email — sign-in codes, invitations, licence confirmations. Receives an email address and message text only. | As configured by the Controller's administrator |
| The Controller's chosen AI provider | Only if the Controller's administrator enables the assistant. Receives the text of documents the Controller has chosen to include. Off by default; when off, nothing is sent. | As selected by the Controller's administrator |
Each sub-processor is engaged under a written contract imposing the same obligations as this agreement. The Processor remains fully liable to the Controller for their performance.
7. International transfers
Personal data is processed in United Kingdom and is not transferred outside the UK or the EEA. If a transfer ever became necessary, the Processor would first put in place a lawful transfer mechanism — adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — and tell the Controller before any data moved.
The one qualification is the AI provider in the table above: if the Controller's administrator selects an endpoint outside the UK or EEA, that is the Controller's own instruction and the Controller is responsible for the transfer mechanism. The service does not select one.
8. Assisting with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in responding to requests to exercise data subject rights. In practice the service gives the Controller direct access to export, correct and delete everything it holds, so most requests need no involvement from us at all. Where they do, we respond within 5 working days and charge nothing.
If a data subject contacts the Processor directly about the Controller's data, the Processor will not respond substantively but will pass the request to the Controller promptly.
9. Personal data breach
The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent known at the time, supplemented as more becomes known rather than delayed until complete.
The Processor assists the Controller in meeting its own obligations under Articles 33 to 36, including any data protection impact assessment and any prior consultation with the supervisory authority.
10. Deletion or return
At the Controller's choice, the Processor deletes or returns all personal data at the end of the provision of services, and deletes existing copies, unless law requires storage. In practice: the Controller may export everything at any time; on termination the data remains available for export for 30 days and is then deleted, including from backups as those backups age out on the retention schedule.
Deleting a report deletes its answers, its uploaded documents and its document trace records with it.
11. Audit
The Processor makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
In the ordinary case this is satisfied by the Security & Hosting Statement, the vendor pack available from the Publish step, and written answers to a security questionnaire — which we will complete on request at no charge. An on-site inspection may be requested once in any twelve months on 30 days' notice, and more often following a personal data breach.
12. General
- This agreement takes effect when the Controller first uses the service and continues for as long as processing continues.
- Where this agreement and the Website Terms of Service conflict on the subject of personal data, this agreement prevails.
- Governed by the law of England and Wales.
- Neither party excludes or limits liability for breach of this agreement beyond what data protection law permits.
Contact
Questions about this document go to contact@infin8.digital.
A registered address has not been published on this installation.