Data Processing Agreement
Effective date: 14 August 2026
Version 3. Replaces the version of 11 August 2026, which replaced the text of 16 July 2026 and the erratum of 8 August 2026.
This Data Processing Agreement (“DPA”) is entered into between:
(1) Crocker Digital Ltd, a company incorporated in England and Wales with company number 17008789, registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ (“Processor”, also “CraftCert”, “we”); and
(2) the account holder of the Customer's CraftCert account — being the person or business in whose name the account is registered — acting as controller of the personal data it enters or causes to be processed through the service (“Controller”, “Customer”, “you”). The service does not collect a company name or registration number; where the Customer is a business, the account holder contracts on behalf of that business.
This DPA forms part of and is incorporated into the CraftCert Terms of Service at https://craftcert.co.uk/terms/ (the “Agreement”). In the event of conflict between this DPA and the Agreement in relation to the processing of Customer Personal Data, this DPA prevails.
This DPA is offered to any business Customer — typically a candle, wax-melt, reed-diffuser or room-spray maker, including makers whose range also includes cosmetic products — that processes personal data through the service. It takes effect automatically: this DPA is incorporated into the Agreement as a matter of contract when the Customer creates an account, and applies whenever the Customer enters or causes to be processed personal data relating to people who are not users of the service (for example, ingredient-supplier contacts, and individuals named in the formulation notes, ingredient entries or support correspondence the Customer provides). The Customer does not need to sign or tick a box separately for this DPA to apply — automatic incorporation into the Agreement is how we meet UK GDPR Article 28 for every business Customer. If a Customer's internal procurement process requires a bilateral signed copy, contact us at support@craftcert.co.uk.
1. Interpretation
1.1 In this DPA, the following expressions have the meanings set out below. Terms not defined here have the meaning given in the Agreement, and capitalised terms not defined in either have the meaning given in UK Data Protection Law.
“Affiliate” — any entity controlling, controlled by, or under common control with a party.
“Applicable Data Protection Law” or “UK Data Protection Law” — the UK General Data Protection Regulation (as retained and amended by The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any successor legislation, together with any guidance or code of practice issued by the Information Commissioner.
“Customer Personal Data” — personal data provided by or on behalf of the Customer to the Processor for processing under the Agreement. This includes data the Customer enters, and metadata generated by the service in the course of processing that data.
“Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Controller”, “Processor”, and “Special Category Data” — as defined in UK Data Protection Law.
“Restricted Transfer” — a transfer of Personal Data from the UK to a country which is not the subject of UK adequacy regulations.
“Schedule 1” — the processing description set out at the end of this DPA.
“Schedule 2” — the technical and organisational measures set out at the end of this DPA.
“Schedule 3” — the list of approved sub-processors referred to in clause 5.
“Standard Contractual Clauses” — the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018 on 2 February 2022, or the International Data Transfer Addendum to the EU Standard Contractual Clauses issued on the same date, in each case as they may be updated from time to time.
1.2 In this DPA, references to “writing” include email.
2. Subject matter, nature, purpose, duration
2.1 The Processor processes Customer Personal Data only to provide the CraftCert service in accordance with the Agreement and this DPA, and only on the Customer's documented instructions.
2.2 The full description of processing — subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data — is set out in Schedule 1.
2.3 This DPA takes effect on the day the Customer first uses the service and continues until the later of (a) termination of the Agreement, and (b) the Processor completing the deletion or return of Customer Personal Data in accordance with clauses 9.1 to 9.3. For the avoidance of doubt, the retention of audit records under clause 9.5 does not extend the term of this DPA; the Processor's obligations in respect of those records, in particular clauses 4.2, 4.3 and 7, survive termination for as long as it holds them.
3. Roles of the parties
3.1 In respect of Customer Personal Data entered or caused to be processed by the Customer, the Customer is the Controller and the Processor is the Processor. This captures, for example, ingredient-supplier contacts named in the safety-data-sheet information the Customer enters, safety assessors or other advisors the Customer names in formulation notes, and individuals named in free-text fields or in support correspondence.
3.1a Uploaded supplier documents. In relation to Personal Data contained in a safety data sheet uploaded by or on behalf of the Customer, the Customer is the Controller and CraftCert is the Processor. This includes Personal Data relating to employees and other personnel of the Customer's suppliers.
The relevant Data Subjects are supplier personnel, including technical, regulatory and emergency contacts. The types of Personal Data may include names, job titles or roles, employer, business postal addresses, email addresses, telephone numbers, and any other Personal Data appearing in an uploaded SDS.
CraftCert processes this Personal Data only on the Customer's documented instructions and solely to receive and store the SDS, compute and store its file-integrity hash, retrieve and transmit the SDS to the authorised Customer, and delete it in accordance with the Agreement. CraftCert does not extract, parse, index or analyse the SDS contents, contact the individuals concerned, or use their Personal Data for any purpose of its own.
3.2 In respect of the account data of the Customer's account holder (name, email address, password credential, audit-log entries, subscription and billing state held with our payment provider, and the email-notification preference), the Processor is an independent Controller. Processing of that data is described in the Processor's Privacy Policy at https://craftcert.co.uk/privacy/.
3.3 Nothing in this DPA creates a joint-controllership arrangement under Article 26 of the UK GDPR in respect of Customer Personal Data.
4. Processor obligations (UK GDPR Article 28(3))
The Processor shall:
4.1 Instructions. Process Customer Personal Data only on the documented instructions of the Customer, including with regard to Restricted Transfers, unless required to do so by the law of the United Kingdom to which the Processor is subject; in such a case, the Processor shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Customer's instructions are those contained in (a) the Agreement, (b) this DPA, (c) the configuration options the Customer sets in-product, and (d) any further written instruction notified to support@craftcert.co.uk. If the Processor considers that an instruction infringes Applicable Data Protection Law, it shall immediately inform the Customer.
4.2 Confidentiality. Ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality.
4.3 Security (Article 32). Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in force at the date of this DPA are set out in Schedule 2. The Processor may update Schedule 2 from time to time provided the level of protection is not materially diminished.
4.4 Sub-processors. Engage sub-processors only in accordance with clause 5.
4.5 Data-subject rights assistance (Articles 12–23). Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. In particular:
- The service provides Customer-operated data export and deletion at the account level, and in-product correction of profile fields.
- For Data Subject requests that cannot be fulfilled through the self-serve tooling (e.g. requests made by ingredient suppliers, or by third parties whose names appear in data the Customer has entered or sent to support), the Customer is responsible for responding to the Data Subject. The Processor will supply reasonably-necessary data or information on request to enable that response.
4.6 Article 32–36 assistance. Assist the Customer, taking into account the nature of the processing and the information available to the Processor, in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments, prior consultation).
4.7 Return or deletion (clause 9). At the end of the provision of services, return or delete Customer Personal Data in accordance with clause 9.
4.8 Audit information (clause 10). Make available to the Customer all information necessary to demonstrate compliance with this clause 4, and allow for and contribute to audits in accordance with clause 10.
4.9 Records. Maintain records of all categories of processing activities carried out on behalf of the Customer as required by Article 30(2) of the UK GDPR.
5. Sub-processors
5.1 The Customer grants the Processor a general authorisation to engage the sub-processors listed in Schedule 3 (and those currently listed at https://craftcert.co.uk/subprocessors/, which forms part of Schedule 3 by reference), for the purposes set out against each entry.
5.2 The Processor shall:
(a) impose on each sub-processor, by written contract, data-protection obligations substantially equivalent to those imposed on the Processor under this DPA;
(b) remain liable to the Customer for the performance of each sub-processor's obligations;
(c) give at least 30 days' prior notice of the addition or replacement of a sub-processor, by email to the address registered on the Customer's account and by updating the public subprocessor list. There is no exception to this notice requirement, including for a provider the Processor regards as a technical successor to an existing sub-processor.
5.3 If the Customer has a reasonable, data-protection-based objection to a new sub-processor, it shall notify the Processor within 14 days of the notice. The parties shall work in good faith to resolve the objection. If no resolution is agreed within a further 30 days, the Customer may terminate the Agreement without penalty and the Processor shall refund any pre-paid but unused portion of the subscription.
6. International transfers
6.1 The Processor shall not transfer Customer Personal Data to a country outside the UK unless one of the following applies:
- (a) the country is the subject of UK adequacy regulations;
- (b) the transfer is governed by the Standard Contractual Clauses;
- (c) another transfer mechanism permitted by Applicable Data Protection Law is in place.
6.2 Where the Processor relies on the Standard Contractual Clauses for a Restricted Transfer to a sub-processor, the Processor is authorised by the Customer to enter into those clauses on the Customer's behalf as exporter. The Customer acknowledges that the current Restricted Transfers supporting the service are set out in Schedule 3.
6.3 Where the Processor relies on appropriate safeguards rather than UK adequacy regulations for a Restricted Transfer, it will complete and keep under review a proportionate transfer risk assessment for that transfer or for the series of connected transfers of which it forms part. The Processor will make available a summary of any such assessment it holds to the Customer on reasonable request.
7. Personal data breach
7.1 The Processor shall notify the Customer in writing without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 The notification shall include, to the extent known at the time:
- (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned;
- (b) the likely consequences of the Personal Data Breach;
- (c) the measures taken or proposed to be taken to address the Personal Data Breach and to mitigate its possible adverse effects;
- (d) the name and contact details of the Processor's point of contact for further information.
7.3 The Processor shall cooperate with the Customer in investigating, mitigating, and remediating the Personal Data Breach, including providing reasonable assistance with any notification to the Information Commissioner (Article 33) and to affected Data Subjects (Article 34).
7.4 For the avoidance of doubt, notification of a Personal Data Breach is not an admission of fault or liability by the Processor.
8. Data subject requests
8.1 If the Processor receives a request directly from a Data Subject to exercise any right under UK Data Protection Law in respect of Customer Personal Data, the Processor shall, without undue delay, forward the request to the Customer and shall not respond to the Data Subject directly except (a) to confirm receipt and forward, or (b) as instructed by the Customer or required by law.
8.2 Where the request is made by a Data Subject whose personal data is processed by the Processor as Controller under clause 3.2 (e.g. the Customer's own account holder exercising rights in relation to their account record), the Processor shall handle the request directly as Controller.
9. Return and deletion
9.1 On termination or expiry of the Agreement, the Processor shall, at the Customer's choice expressed in writing within 30 days of termination, delete or return to the Customer all Customer Personal Data, and delete existing copies, except to the extent that the Processor is required to retain a copy by applicable law and except as described in clause 9.5.
9.2 If the Customer does not make a choice within the 30-day window, the Processor shall default to deletion in accordance with the Data Retention and Deletion policy.
9.3 Deletion is deemed complete when the data is no longer accessible in the Processor's production environment and ordinary backup rotation has expired that copy: primary data deleted within 90 days; backup expiry within a further 7 days per Schedule 2 §7, in each case from the date of the deletion instruction (or the default date under 9.2).
9.4 The Processor may retain de-identified, aggregated, or anonymised data for product-analytics purposes where such data no longer constitutes Personal Data.
9.5 Audit records. Audit records held in the in-product audit log described in Schedule 2 §8 are not removed by the deletion process in clauses 9.1 to 9.3, and persist after that process has completed. Each audit record holds the date and time of the event, the action type, the type and identifier of the affected record, the account identifier, and event metadata. Immediately before an account is erased, the Processor removes the identifying content from that account's audit records — the account email address, the product names the Customer entered, and any ingredient names captured in the metadata — and the account identifier is then set to null by the deletion itself. Records left behind by deletions completed before 10 August 2026 have been cleaned in the same way. The record, its action type and its timestamp are retained; this removes identifiers, it does not delete records. What remains is defined by a fixed list of permitted metadata fields rather than a list of fields to remove, so a field added in future is stripped on deletion unless it has been reviewed and added deliberately. Two categories on that list are stated openly: where the Processor's own operator acted on the account, the entry keeps that operator's internal identifier, which identifies the operator and not the Data Subject; and payment entries keep references to the corresponding records at the Processor's payment sub-processor, retained as financial records and not because they are anonymous. Audit records do not hold formulation content, label content or evidence-pack bodies. They may hold ingredient names: where the classification engine refuses to produce a label, the record of that refusal captures the ingredients that caused it, together with their concentrations and hazard codes. That content is removed when the account is erased, as described above, but it is present for as long as the account exists. Audit records belonging to live accounts also continue to hold the account email address. No deletion process removes audit records at any age, and the Processor does not represent that they are deleted after any particular period. The Customer may request deletion of audit records relating to it by writing to privacy@craftcert.co.uk; the Processor will honour the request unless a legal obligation, or an actual or reasonably anticipated legal claim, requires the record to be kept.
9.6 Record of a deletion request. When an account erasure completes, the Processor writes a single minimal record that the request was made and completed: a reference number, the account email address, the date the request was made, the date it completed, and the outcome. It deliberately does not record the account identifier. Audit records under clause 9.5 retain an internal reference to the account they concerned; storing that same identifier here would re-create a means of linking those records to a named individual for the life of this record, defeating the removal described in clause 9.5. The email address alone serves this record's purpose. It holds no formulation content, product, ingredient, label, evidence or correspondence data, and no free text. Its purpose is to enable the Processor to demonstrate that the request was honoured if the question is later raised by the Data Subject or a supervisory authority — the purpose recognised by Article 17(3)(e) of the UK GDPR — and the Processor's lawful basis as Controller of that record is Article 6(1)(f), its legitimate interest in being able to evidence compliance. It is retained for 12 months from completion and is then deleted automatically by a scheduled job that runs daily; the period is enforced in code and not by administrative practice. Access is restricted to the server-side service role: no user token, administrator or otherwise, can read or write this record through the application. The Processor's sole director can reach it directly, which is how a manually-actioned erasure writes it. This record constitutes personal data and the Processor does not represent it as anonymised or pseudonymised.
10. Audit
10.1 The Processor shall make available to the Customer, on reasonable request and not more than once per 12-month period, the following information in order to demonstrate compliance with this DPA:
- (a) the Processor's current Technical and Organisational Measures (Schedule 2);
- (b) the Processor's Records of Processing Activities to the extent relevant to the Customer;
- (c) the most recent independent audit reports or security certifications held by any of the Processor's sub-processors. The Processor does not itself hold an independent audit report or security certification;
- (d) a summary of any material Personal Data Breach affecting Customer Personal Data in the preceding 12 months.
10.2 If the information provided under 10.1 does not reasonably address the Customer's concern, the Customer may, on 30 days' written notice and at the Customer's cost, conduct an on-site audit of the Processor's facilities and processing operations relevant to this DPA. The Customer shall appoint an independent auditor who is not a competitor of the Processor, and the auditor shall enter into reasonable confidentiality undertakings.
10.3 The parties shall agree the audit scope, timing, and methodology in good faith. Audits shall be conducted during business hours and shall not unreasonably interfere with the Processor's operations.
10.4 If the Processor is required to investigate or respond to an audit that does not identify a material compliance failure, the Customer shall reimburse the Processor's reasonable costs at the Processor's then-current professional-services rate.
11. Liability
11.1 The liability of each party arising from or in connection with this DPA is governed by the limitation of liability provisions of the Agreement. For the avoidance of doubt, the limitation-of-liability cap in the Agreement is a single cap that applies to the Agreement and this DPA together, and the Processor's total aggregate liability shall not exceed that cap.
11.2 Nothing in this DPA excludes or limits either party's liability for (a) death or personal injury caused by negligence, (b) fraud or fraudulent misrepresentation, or (c) any other liability that cannot be limited or excluded under applicable law.
11.3 As between the parties, the Customer shall remain responsible for ensuring that it has a lawful basis for the processing it instructs the Processor to carry out, including collecting any consents or providing any notices required of the Customer as Controller. The Customer shall indemnify the Processor against any claim, loss, or regulatory action arising from the Customer's failure to do so, except to the extent caused or materially contributed to by the Processor.
12. General
12.1 Order of precedence. This DPA prevails over any conflicting term of the Agreement in respect of processing of Customer Personal Data.
12.2 Variations. The Processor may amend this DPA on at least 30 days' notice to reflect changes in Applicable Data Protection Law or to the service. If the amendment materially reduces the Customer's protections, the Customer may terminate the Agreement for convenience on notice given within the 30-day window, and the Processor shall refund any pre-paid but unused subscription fees. Where a revision is published with immediate effect, the Customer may exercise the right in this clause in respect of that revision at any time, without a window, by writing to privacy@craftcert.co.uk. The Processor will action it, with the refund, without requiring the Customer to make out the point.
12.3 Governing law and jurisdiction. This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
12.4 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force and effect.
12.5 Notices. Notices to the Processor shall be sent to privacy@craftcert.co.uk and (for notices of a legal nature) copied to the Processor's registered office. Notices to the Customer shall be sent to the email address registered on the Customer's account.
12.6 Entire agreement. This DPA, together with the Agreement, constitutes the entire agreement between the parties in respect of processing of Customer Personal Data.
Change note — version 3, 14 August 2026
What changed. CraftCert has added a feature that lets a Customer upload and store supplier documents — safety data sheets, allergen declarations, certificates and specifications — against the materials it buys. Previously the Customer could only type information out of those documents into the service; now the document itself can be stored. This revision discloses that processing. Specifically: new clause 3.1a records that the Customer is Controller and CraftCert is Processor in respect of Personal Data contained in an uploaded safety data sheet, and states what CraftCert does and does not do with it; and Schedule 1 is amended to add the categories of Data Subject, types of Personal Data, nature of processing, purpose and retention position for uploaded documents.
Effective date. This revision takes effect on 14 August 2026.
If you would prefer more time to consider this change, or you consider it reduces your protections, you may terminate under clause 12.2 and receive a refund of any pre-paid, unused subscription — at any time. Write to privacy@craftcert.co.uk.
Previous versions. Version 2 (11 August 2026) is superseded by this revision and is retained; it replaced the text of 16 July 2026 and the erratum of 8 August 2026. The full text of each earlier version is retained in CraftCert's source-control history and is available on request from privacy@craftcert.co.uk.
Schedule 1 — Processing description (UK GDPR Art 28(3))
| Element | Detail |
|---|---|
| Subject matter | Provision of the CraftCert compliance service to the Customer: GB CLP classification, formulation records, draft label generation and evidence-pack export for chemical products — candles, wax melts, reed diffusers, solid diffusers and room sprays — under the GB CLP regime. CraftCert does not provide cosmetics-regulation services: it does not produce Cosmetic Product Safety Reports, SCPN notifications, Product Information Files or INCI ingredient lists, and does not classify or label finished cosmetic products. Where the Customer is a cosmetic maker, or records a cosmetic product in the service, the Processor stores the product and formulation data the Customer enters; no cosmetics-regulation output is produced. |
| Duration | From the date this DPA takes effect until the return or deletion of Customer Personal Data under clause 9, subject to the position on audit records stated in clause 9.5. Uploaded supplier documents are retained for the lifetime of the set of documents they belong to and are not subject to time-based deletion, because a Customer's issued labels may depend on them; they are deleted on deletion of the account, on deletion of the material or document by the Customer in-product, or on the Customer's instruction under clause 9. |
| Nature of processing | Storing, organising, retrieving, adapting, structuring, analysing (deterministic CLP classification rule engine, allergen cross-reference, label-layout calculation), transmitting, erasing personal data. In respect of uploaded supplier documents the operations are limited to: receiving and storing the document as supplied; computing and storing a file-integrity hash of it; retrieving and transmitting it to the authorised Customer; and deleting it. The document's contents are not extracted, parsed, indexed or analysed. |
| Purpose | (a) generating GB CLP classifications, product records and draft labels for chemical products including candles, wax melts, reed diffusers and room sprays; (b) storing formulation data and supporting evidence entered by the Customer; (c) enabling the Customer to export and present this information to local Trading Standards officers, to the Office for Product Safety and Standards, and to its own advisors; (d) retaining, at the Customer's instruction, the supplier documents the Customer uploads, so that the evidence underlying a classification remains available to the Customer. |
| Categories of Data Subjects | (a) ingredient-supplier contacts (sales representatives, technical contacts, regulatory affairs, and emergency contacts) named in the safety-data-sheet information the Customer enters or appearing in a safety data sheet or other supplier document the Customer uploads; (b) safety assessors, formulators or other advisors the Customer names in formulation notes or in support correspondence; (c) individuals named in free-text fields the Customer completes (product names, formulation notes, ingredient entries, feedback comments). |
| Types of Personal Data | Names and contact details (postal, email, telephone) appearing in the supplier information the Customer enters for its labels; ingredient-supplier contact details transcribed from safety data sheets; Personal Data contained in safety data sheets and other supplier documents the Customer uploads and CraftCert stores as supplied — which may include names, job titles or roles, employer, business postal addresses, email addresses and telephone numbers; free-text content entered by the Customer (product names, formulation notes, ingredient names, feedback comments) where it names an individual; and the content of support correspondence the Customer sends to the Processor. |
| Special Category Data | Not actively solicited. Customers are instructed in the Acceptable Use Policy not to provide special-category data beyond what is strictly necessary as compliance evidence. Where special-category data appears incidentally in correspondence, the Customer must identify its lawful basis under Article 9 of the UK GDPR. |
| Children's data | Not expected. CraftCert is a B2B compliance service; no consumer / child-facing flows. |
| Frequency of processing | Continuous for the duration of the subscription. |
Schedule 2 — Technical and organisational measures
The Processor implements, at minimum, the following measures as at the date of this DPA:
- Encryption in transit. HTTPS enforced on all public endpoints. HSTS preload. TLS 1.2 minimum.
- Encryption at rest. Postgres volumes encrypted at rest (AES-256) by the Supabase-managed infrastructure.
- Access control. Row-level security policies on every table that stores Customer Personal Data. Client calls pass through the authenticated session; service-role calls are confined to the server runtime and never exposed to the browser.
- Authentication. Supabase Auth with email + password. Password reset requires a signed link. Session cookies are first-party. Automated abuse checks (Cloudflare Turnstile) protect the sign-up, log-in and password-reset forms.
- Personnel. Production access is held only by the sole director of Crocker Digital Ltd, who is subject to the statutory and fiduciary duties of confidentiality owed in that capacity. Access is granted on the principle of least privilege. The Processor does not presently employ or contract any other person with production access; if it does, that person will be placed under a written confidentiality commitment before access is granted.
- Sub-processor management. Sub-processors are selected and engaged in accordance with clause 5. Material infrastructure providers (Stripe, Supabase) publish SOC 2 Type II reports or equivalent independent assurance obtained directly from those providers. Each sub-processor's data-processing terms are linked from /subprocessors/.
- Backups. Supabase automated daily backups. Backup media is encrypted. Point-in-time recovery is not enabled on the Processor's database.
- Logging. An in-product audit log records product, label, account-lifecycle and subscription events — for example product created, product archived, label generated, label refused, account deletion requested, account soft-deleted, account restored, subscription created, trial expired, and refund processed. Sign-in and data-export events are not recorded. Each entry holds the date and time, the action type, the affected record type and identifier, the account identifier, the account email address, and event metadata; for product events that metadata includes the product name the Customer entered. Entries do not hold formulation content, label content or evidence-pack bodies; entries recording a refused label do hold the ingredient names, concentrations and hazard codes that caused the refusal. Reads are restricted by row-level security to the Processor's administrator role; writes are made only from the server runtime. The audit log is not immutable — the Processor makes no representation that entries cannot be altered or removed, and there is no database-level control preventing it. Retention of audit records is described in clause 9.5. On account deletion the identifying content is removed from that account's entries — the account email address, the product name and any ingredient names in the metadata — and the account identifier is set to null. The Processor does not represent that the remaining entries are anonymous: entries recording a payment retain references to the corresponding records at the Processor's payment sub-processor, from which the individual could be looked up, and are retained on that basis as financial records. For all other entries what remains is an action, a timestamp, an internal record reference and a fixed list of non-identifying fields. The internal record reference on account-level entries is the account's own identifier, and the Processor stores that identifier against the corresponding customer record at its payment sub-processor, which also holds the Data Subject's email address. The Processor can therefore trace such an entry back to a named individual for as long as that payment record persists (approximately seven years), in respect of any Data Subject who has completed a checkout. The Processor states this rather than representing the entries as unlinkable, and is separately working to remove that identifier from the payment sub-processor. The record under clause 9.6 is deliberately written without an account identifier so as not to add a further route of the same kind. Entries belonging to live accounts continue to hold the account email address. The record of a deletion request written at that point is described in clause 9.6.
- Vulnerability management. Dependencies are tracked, and the Processor's continuous-integration pipeline runs an
npm auditadvisory scan against production dependencies on every build, so no release ships without the current advisory position being recorded. A separate automated report re-checks production dependencies daily across the Processor's services. The scan is reporting-only: it does not fail the build, and an outstanding advisory does not by itself prevent a deployment. That is a deliberate engineering decision — a hard gate on upstream advisory feeds stops unrelated work on code nobody has changed — and the Processor states it rather than representing a gate it does not operate. Advisories are assessed by the Processor on severity and on whether the affected code path is reachable in this service; the Processor does not commit to a fixed remediation period and no automated control enforces one. Error monitoring via Sentry with request-body stripping. - Incident response. The Processor operates a documented breach-response process, published at /security/breach-process/, and notifies affected Customers under clause 7.
- Deletion. Account deletion follows the published Data Retention and Deletion policy — soft-delete window, then hard-delete by a scheduled sweep. Audit records are excepted as described in clause 9.5.
- Physical security. Delegated to the hosting sub-processors (Supabase, Netlify). The Processor does not operate its own data-centre.
Schedule 3 — Approved sub-processors
The current sub-processor list is maintained at https://craftcert.co.uk/subprocessors/ — single source of truth. The Processor's commitment to 30-day change notice is set out in clause 5.2(c).
Where the Processor initiates a restricted transfer of Customer Personal Data to an approved sub-processor, the Processor will use an applicable UK transfer mechanism and, where required, complete and review a proportionate transfer risk assessment. Applicable mechanisms may include UK adequacy regulations, the UK IDTA, or EU Standard Contractual Clauses with the ICO Addendum. Where a sub-processor instead processes the Processor's own account, billing or service-administration data, a different mechanism and a different set of clauses may apply to that processing. The table below records the mechanism relied on in each provider's data-processing terms; the Processor does not state a specific set of module clauses for a given provider unless that provider's current contract supports it.
As at the date of this DPA the sub-processors are:
| Sub-processor | Legal entity | Purpose | Region | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Supabase Inc. (US) / Supabase Ltd (UK) | Database and authentication (formulation, label and evidence records) | UK — AWS eu-west-2 (London). Management-plane access by Supabase Inc. (US). | UK/EU adequacy applies to data at rest. Management-plane access is governed by the Supabase DPA, which incorporates the EU Standard Contractual Clauses and the UK Addendum. |
| Stripe | Stripe Payments Europe, Limited (Dublin — EU contracting entity) | Payments, subscription billing | EU (Ireland) primary; US for group support operations | Adequacy (EU/UK) for the EU contracting entity; the UK Addendum to the EU Standard Contractual Clauses in the Stripe DPA as a fallback for US-importer transfers. |
| Resend | Plus Five Five, Inc. (US — 2261 Market Street #5039, San Francisco, CA 94114) | Transactional email | EU (eu-west-1) | Resend DPA, incorporating the EU Standard Contractual Clauses and the UK Addendum. |
| Netlify | Netlify, Inc. (US) | Hosting, edge functions, CDN | US with EU edge | UK IDTA / UK Addendum. |
| Cloudflare | Cloudflare, Inc. (US) | Turnstile anti-abuse checks on sign-up, log-in and password reset. Receives IP address, user agent and browser signals to issue and verify a challenge token; no account, product or formulation data. | Global edge network | Cloudflare Data Processing Addendum, incorporating the EU Standard Contractual Clauses and the UK Addendum. |
| Sentry | Functional Software, Inc. (US) | Error monitoring. Request bodies stripped before reporting; no formulation or ingredient data. | EU (de.sentry.io) | Sentry DPA, incorporating the EU Standard Contractual Clauses and the UK Addendum. |
| Upstash | Upstash, Inc. (US) | Rate-limiting cache (Redis) — holds IP addresses and user identifiers for the duration of a rate-limit window, for abuse prevention. No formulation, label or evidence data passes through Upstash. | EU | UK IDTA / UK Addendum in the Upstash DPA. |
| GoatCounter | Martin Tournoij (sole trader) | Cookieless analytics — does not ordinarily process Customer Personal Data (aggregated only) | EU | Not a Restricted Transfer. |
| Microsoft 365 | Microsoft Ireland Operations Limited | Support mailbox + DSR-instruction inbox processing (support@craftcert.co.uk) | United Kingdom | Adequacy (EU/UK); Microsoft's Online Services DPA. |
Acceptance by the Customer. This DPA is incorporated into the Agreement automatically and applies to every business Customer without a separate acceptance step. For the avoidance of doubt, the Customer is deemed to have accepted this DPA by (a) creating a CraftCert account (the Agreement at https://craftcert.co.uk/terms/ incorporates this DPA by reference), or (b) continuing to use the CraftCert service after the effective date shown above. No separate countersignature is required for the DPA to be enforceable. If your procurement process requires a bilateral signed copy, contact us at support@craftcert.co.uk.