Legal

Data Processing Addendum

Last updated: 19 August 2026. This DPA is binding where VariationDesk processes personal data on behalf of a business customer.

This DPA forms part of the VariationDesk Terms of Service. The current service-provider list is on the Sub-processors page.

1. Status and parties

This Data Processing Addendum (DPA) forms part of the VariationDesk Terms of Service and any order, pilot or subscription agreement that incorporates those terms. It is binding whenever VariationDesk Ltd processes personal data on behalf of a customer.

For customer workspace personal data, the customer is the controller and VariationDesk Ltd is the processor unless the parties expressly agree otherwise in writing. VariationDesk remains an independent controller for its own account administration, billing, security, support and business records.

2. Subject matter, duration, nature and purpose

The subject matter is the processing of customer workspace data needed to provide the VariationDesk service. Processing continues for the duration of the service and any lawful retention period that applies after termination.

Processing may include collection, recording, organisation, storage, retrieval, consultation, transmission, generation of evidence documents, controlled disclosure, restriction, deletion and other operations necessary to provide authenticated access, project and variation workflows, evidence capture, customer approval, support, security and customer-enabled integrations.

3. Data subjects and personal data

Data subjects may include customer employees, workers, subcontractors, directors, site representatives, client or main-contractor contacts, approvers, signatories, support contacts and other people whose information the customer lawfully places in the service.

Personal data may include names, business contact details, account and role information, project references, photographs, foreground location captured with evidence, voice recordings and transcripts, signatures, IP/device or browser records, approval records, audit history and other information contained in customer-submitted evidence. Customers should not intentionally upload special-category or criminal-offence data unless they have a lawful basis and it is genuinely required.

4. Customer instructions

VariationDesk processes customer personal data only on the customer's documented instructions, including the configuration and actions the customer performs through the service, except where applicable law requires otherwise.

If VariationDesk is required by law to process personal data outside the customer's instructions, VariationDesk will inform the customer before processing unless the law prohibits that notice. If VariationDesk believes a customer instruction infringes applicable data-protection law, VariationDesk will inform the customer without undue delay and may suspend the affected processing while the parties resolve the issue.

5. Confidentiality and access

VariationDesk ensures that people authorised to process customer personal data are subject to appropriate confidentiality obligations and receive access only to the extent needed for their role.

Customers are responsible for maintaining appropriate user access, removing leavers, keeping credentials secure and ensuring their users have authority to submit the information they place in VariationDesk.

6. Security

VariationDesk maintains technical and organisational measures appropriate to the risk, including authenticated access controls, tenant isolation, role-based permissions, encrypted transport, private evidence-storage controls, audit logging, abuse controls, provider security controls and operational security testing.

VariationDesk may update security measures as technology, threats and the service develop, provided the overall protection of customer personal data is not materially reduced.

7. Sub-processors

The customer gives VariationDesk general written authorisation to use the sub-processors listed on the published Sub-processors page and replacements needed to operate the service. VariationDesk will make material sub-processor changes available through that page or another reasonable notice mechanism.

VariationDesk will impose data-protection obligations on sub-processors that provide protection equivalent in substance to the obligations applicable to VariationDesk under this DPA, and VariationDesk remains responsible to the customer for the performance of those obligations to the extent required by applicable law.

A customer with a reasonable data-protection objection to a new sub-processor should contact VariationDesk promptly after notice. The parties will work in good faith on a reasonable alternative where available; if no reasonable alternative exists, either party may terminate the materially affected service in accordance with the governing agreement.

8. International transfers

Where customer personal data is transferred outside the United Kingdom, VariationDesk will use a lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another legally recognised safeguard.

9. Data-subject rights and regulatory assistance

Taking account of the nature of the processing, VariationDesk will provide reasonable assistance to enable the customer to respond to requests to exercise data-subject rights where the relevant personal data is processed through VariationDesk.

VariationDesk will also provide reasonable assistance with the customer's obligations concerning security, personal-data breaches, data-protection impact assessments and prior consultation with a regulator, taking account of the nature of processing and the information available to VariationDesk.

10. Personal-data breaches

VariationDesk will notify the customer without undue delay after becoming aware of a personal-data breach affecting personal data processed on the customer's behalf and will provide information reasonably available to VariationDesk to help the customer assess and meet its notification obligations.

Notification of an incident is not an admission of fault or liability.

11. Return and deletion

At the end of the service, and subject to the customer's choice where required by applicable law, VariationDesk will delete or make available for return customer personal data within the capabilities of the service, unless applicable law requires continued retention.

Some commercial evidence, audit, security, billing, tax or dispute records may be retained where VariationDesk has an independent lawful obligation or legitimate need to keep them. Where retained data remains customer-controlled personal data, the protections in this DPA continue to apply for the retention period.

12. Compliance information and audits

VariationDesk will make available information reasonably necessary to demonstrate compliance with the processor obligations that apply under UK data-protection law.

On reasonable written notice, the customer may request a proportionate audit or inspection relating to the processing covered by this DPA. The parties should first use available security documentation, certifications, test summaries and written responses where these can reasonably satisfy the request. Any further audit must protect other customers, security-sensitive information and confidentiality, avoid unreasonable disruption, and be carried out no more than once in any 12-month period unless required by a regulator or a material security incident.

13. Liability, precedence and governing terms

The liability provisions, governing law, dispute provisions and other commercial terms in the applicable VariationDesk agreement apply to this DPA unless data-protection law requires otherwise.

If this DPA conflicts with the general Terms of Service on the processing of customer personal data, this DPA prevails for that processing. A separately signed enterprise or data-processing agreement prevails to the extent it expressly conflicts with this DPA.

14. Contact

Data-protection requests relating to this DPA can be sent to info@variationdesk.co.uk. Security incidents requiring urgent coordination can also be raised through the published VariationDesk support route.