Data processing agreement.
Your clients' information is yours, and the law wants your instructions to us written down. This is them.
Last updated 2 September 2026
Why this page exists
When you put a client's name and address into Pascal, you are the data controller and we are your data processor. UK data protection law says that relationship has to be governed by a written contract that covers a specific list of things. This page is that contract. It is between you, the customer named on the subscription, and Pascal Software Ltd, and it takes effect when you accept the terms of service, which it forms part of.
You do not need to sign anything separately or ask us for a copy. If your own client or an auditor wants to see the arrangement, send them here.
Words like controller, processor, personal data, data subject and personal data breach mean what they mean in the UK GDPR and the Data Protection Act 2018.
What we do with it, and for how long
Subject matter and purpose. We host and process the personal data you put into Pascal so that we can provide the service you subscribe to: recording enquiries, clients and properties, scheduling and running jobs, producing quotes, certificates and invoices, storing photographs and documents, sending those documents to the people they are for, and the reporting built on top of all of it.
Duration. For as long as your subscription lasts, and then through the retention period set out below.
Types of personal data. Names, contact details, postal addresses, property addresses, job and appointment records, quotes, invoices and payment records, certificate contents including test results and observations, photographs taken on site, correspondence, and anything else you choose to type into a notes field. The terms ask you not to put special category data or criminal offence data into Pascal, and this agreement assumes you have not.
Categories of people. Your clients and their contacts, occupants of properties you work at, people at your suppliers, and your own staff.
What you are promising us
A processor agreement only works if the controller's side holds up, so here is your half of it. You confirm that you have a lawful basis for everything you put into Pascal, that the people concerned have been told what they need to be told, and that your instructions to us do not require us to break the law.
You are responsible for the accuracy of what you enter, and for keeping your own privacy notice honest about the fact that a software provider holds this information for you. Pointing your clients at this page is a perfectly good way of doing that.
We act on your instructions
We process personal data only on your documented instructions, including where a transfer outside the UK is involved, unless the law requires otherwise. If it does, we will tell you before we do it unless the law forbids that too.
Your instructions are: this agreement, the terms of service, the settings and choices you make inside the product, and anything else you ask us to do in writing that we agree to. Using a feature is an instruction to run it. Connecting Xero is an instruction to send the invoices and contacts you send there. Photographing a board for reading is an instruction to send that photograph to be read.
If we think an instruction breaks data protection law, we will say so rather than quietly carry it out.
Two things we do for ourselves, and not for you
Data protection law says that a processor deciding the purpose of some processing is a controller for that processing, whatever the contract calls it. There are two things Pascal does that meet that description, and naming them here is the honest way to handle it. For these two, and nothing else, we are the controller, we rely on our own legitimate interests, and the privacy notice is the notice that covers them.
- A small set of board photographs. When somebody photographs a distribution board for reading, we may keep the photograph and the corrections your engineer made to what came back, so we can measure how accurate the feature is. It is capped at sixty examples across every customer put together, and every one of them is deleted when that work finishes, and by 31 December 2027 at the latest. Tell us you would rather not take part and we will delete yours inside a month and exclude you from then on. Note what this is and is not: a photograph sent for reading is working material that never joins your records. Photographs uploaded to an observation, a job or a quote are your data, held under this agreement, and none of this applies to them.
- The list of addresses that bounce. When an email hard bounces or somebody reports it as spam, we record the address and stop sending to it. That list is one list for the whole service rather than one per customer, because an address that rejects mail rejects everybody's, and a sending reputation is shared by every customer using it.
Both are exceptions to the paragraph above, and to the deletion clause below. If either is a problem for you, say so before you subscribe and we will tell you honestly whether we can work round it.
Confidentiality
Everybody who can reach personal data on our side is bound to keep it confidential, and access is limited to the people who need it to do their job or to support you. That obligation does not end when someone leaves.
Security
We take appropriate technical and organisational measures to protect personal data, taking account of what is available, what it costs, and the risk to the people concerned. In practice that means encryption in transit, encrypted backups held on separate credentials from the live system, hashed passwords, a company filter applied automatically by the framework to every query the application makes, private file storage served only through authorisation checks, restricted and key-based access to production systems, two factor authentication and passkeys available on every account, and rate limiting on the routes that would otherwise be worth attacking. The privacy notice describes this in more ordinary language.
We keep those measures under review, and we may change them, so long as we do not reduce the level of protection.
Other companies we use
You give us general authorisation to engage sub-processors. The current ones are listed on the who touches your data page, which is part of this agreement, and each of them is under written terms that impose data protection obligations no weaker than these. If one of them fails to meet those obligations, we remain liable to you for it.
Before we add or replace one we will update that page and email the admins on your account at least 30 days beforehand. If you object on reasonable data protection grounds, tell us within those 30 days and we will try to find a way round it. If we cannot, you can cancel your subscription and we will refund the unused part of what you have paid. That is the honest position: we are not going to run a different stack for one customer, and you should not be trapped on one you object to.
Sending data outside the UK
Your records are held in Europe, and the database and application are in London. Where a sub-processor takes personal data outside the UK, we put a lawful transfer mechanism in place first: the UK adequacy regulations where they apply, and otherwise the ICO's international data transfer agreement or the UK addendum to the standard contractual clauses, supported by an assessment of the transfer. The sub-processor page says which applies to whom.
Helping you answer your clients
If one of your clients asks to see, correct, delete or move the information you hold about them, that request is yours to answer and most of it you can do yourself in the product. Where you need us, we will help, taking account of what we can see and what the request needs.
If such a request comes to us instead, we will not act on it. We will tell the person to go to you, and tell you it arrived.
The same goes for a complaint. Since June 2026 a controller has had a statutory duty to accept data protection complaints, to acknowledge one within 30 days and to investigate it properly. For complaints about your clients' information, you are the controller and that duty is yours. Ours is on the privacy notice, and it covers complaints about what we do with information about you.
If something goes wrong
If there is a personal data breach affecting your data we will tell you without undue delay once we know, and in any event quickly enough for you to meet your own 72 hour deadline. We will tell you what happened, who and what it affected as far as we can establish, what we are doing about it, and what we suggest you do. We will keep you updated as we learn more rather than waiting until we have the full picture.
If the breach is serious enough that you have to tell the individuals affected, we will help you do that too, with whatever detail and whatever list of who was affected we can produce.
We will also help you with data protection impact assessments and with consulting the ICO, if either becomes necessary because of how you use Pascal.
Getting your data back, and deleting it
When the agreement ends, what happens to your data is your choice: we return it to you, or we delete it. Tell us which and we will do it within 30 days of being asked. That choice is yours to make at any point after the subscription ends, and it is free.
If you tell us nothing, the default is that we hold it for twelve months from the day the subscription ends, so that you can come back to it, and then delete it, having emailed the admins on the account at least 30 days beforehand.
While a subscription is still running we can usually export your data as well, and we are glad to. It is put together by hand rather than by pressing a button, so give us reasonable notice, and for a large or repeatedly requested job we may ask you to cover the time. That is a convenience rather than part of this agreement; the obligation above, at the end, is the one that matters and it costs nothing.
Four exceptions, and it is better to have them written down than discovered. Billing records are kept for six years because tax law requires it. Backups are on their own cycle, so deleted data can persist in a backup for up to 30 days before it ages out, and for seven of those days the daily backups cannot be altered by anybody, including us. Nothing is ever restored from a backup into the live system without the deletion being applied again. The two things described above under "Two things we do for ourselves" run on their own timescales, which are set out there.
Showing you we are doing this
Ask and we will give you the information you reasonably need to show you are meeting your own obligations, which for most customers is this page, the sub-processor list and a straight answer to a question.
If you need to audit us, or have somebody do it for you, we will cooperate. Give us reasonable notice, keep it to once a year unless there has been a breach or the ICO has asked, do it in working hours, do not disturb the service, and treat what you learn as confidential. If an audit needs real work from us, we may charge for the time at a reasonable rate, and we will tell you what it will cost before we start.
How this fits with everything else
This agreement forms part of the terms of service, and the liability provisions there apply to it. Where this page and the terms disagree on a data protection question, this page wins. It is governed by the law of England and Wales.
If the law changes, or the ICO issues a new standard form of clauses that we ought to be using, we will update this page and tell you, on the same 30 days' notice as anything else that matters.
Who you are dealing with
Pascal Software Ltd, registered in England and Wales, company number 17393387.
Hardicott Stables, Sandbeds Lane, Westwoodside, Doncaster, South Yorkshire, DN9 2DW
Questions about any of this go to admin@pascalsoftware.co.uk and a person answers them. For help with the product itself, or anything wrong with your account, use support@pascalsoftware.co.uk and you will get there quicker.