EmberSuite Fire

Data Processing Agreement

Last updated: 15 September 2026

When you record a client's name, a building's address, or the people named in a fire risk assessment, that information is personal data about people who never signed up with us. Under the UK GDPR you are the controller of that data and we process it on your behalf. Article 28 requires a written contract between us that sets out how. This is that contract.

You don't need to sign anything. This agreement forms part of our Terms of Service and applies automatically from the moment you use the Service to store data about your own clients. If your own compliance process needs a countersigned copy, email [email protected] and we will send you a PDF signed by us for you to countersign.

1. Parties

Words defined in the Terms ("Service", "Documents", "Your Content") mean the same here. "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, as amended. "Client Data" means the personal data you enter into the Service about people other than yourself and your own team, as described in section 2.

For your own account data (your name, email and billing details) we are the controller, not your processor. That is covered by our Privacy Policy, not this agreement.

2. Details of the processing

Subject matterHosting, storing, rendering, converting to PDF and (on your instruction) emailing the records you keep about your clients and the premises you work on.
DurationFor as long as your account is active, plus the deletion window in section 10 (up to 90 days after closure).
Nature and purposeStorage and retrieval; generating certificates, risk assessments, logbook entries, quotations and invoices from the data you enter; converting Documents to PDF; sending Documents and compliance reminders that you have approved; searching and reporting within your own account. We process Client Data only to provide the Service to you, never for our own purposes.
Categories of personal data
  • Client and site contact details: names, job titles, email addresses, phone numbers, postal addresses.
  • Building and premises information linked to a responsible person, landlord or occupier.
  • Names, roles and statements of people recorded in fire risk assessments, logbook entries and findings (for example the responsible person, persons consulted, a validator).
  • Invoice and quotation data: amounts, payment status, reference numbers.
  • Assessment and logbook evidence photographs, which may incidentally show people.

Special-category data. Personal emergency evacuation plans (PEEPs) and any note about a person's health, disability or mobility are special-category data with a higher legal bar. The Service is not designed to hold them. Record only what your assessment genuinely requires, and keep it to the minimum.

Categories of data subjectYour clients and their staff; responsible persons, landlords, managing agents and occupiers of the premises you work on; anyone else you name in a Document.

3. Your obligations as controller

You are responsible for having a lawful basis for the Client Data you enter, for telling your own clients how their data is handled, and for the accuracy of what you record. You warrant that your instructions to us (which are: the ordinary use of the Service) comply with Data Protection Law. If you invite team members, you are responsible for what they enter.

4. Our obligations as processor

We will:

  1. Act only on your documented instructions. Your instructions are these Terms, this agreement and the actions you and your team take in the Service (creating, editing, generating, sending and deleting records). We will not process Client Data for any other purpose, and we will not transfer it outside the UK except as described in section 7, unless UK law requires us to, in which case we will tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law we will tell you.
  2. Keep it confidential. The only person with administrative access to Client Data is the Processor. Anyone we later authorise to access it will be bound by a written duty of confidentiality first.
  3. Keep it secure, with the measures in section 5, and keep those measures under review.
  4. Use sub-processors only as allowed by section 6.
  5. Help you respond to rights requests (section 8).
  6. Help you meet your own security, breach, and impact-assessment duties under Articles 32 to 36, taking into account the nature of the processing and the information we hold. That includes providing what you reasonably need for a data protection impact assessment of your use of the Service.
  7. Delete or return the data at the end (section 10).
  8. Show you we are complying (section 11).

5. Security measures

The measures we have in place, which we treat as the minimum:

6. Sub-processors

You give us general authorisation to use the sub-processors below. Each one processes Client Data only for the purpose shown, under a written contract that imposes data-protection obligations equivalent to this agreement. We remain fully responsible to you for their performance.

Sub-processorPurposeRegion
SupabaseDatabase, authentication and file storageEU
StripePayment processing and subscription billingEU / US
CloudflareWebsite hosting, security, and inbound email routingGlobal / EU
PDFShiftConverting a Document to PDF at the moment you generate or send itEU
AnthropicAI features (support chat and voice-fill): processes the text you enter, then does not retain it for trainingUS
n8n (Autoshworks)Automation of compliance remindersEU
ResendSending account emails and the Documents you approve in the OutboxEU

Changes. If we intend to add or replace a sub-processor we will give you at least 30 days' notice by email or in-app notice before it handles Client Data. If you object on reasonable data-protection grounds and we cannot resolve it, you may close your account before the change takes effect and we will refund any prepaid fees for the unused period.

7. International transfers

Client Data is stored in the UK. Two sub-processors can receive it outside the UK and EU: Stripe (billing metadata only, not your Documents) and Anthropic (only the text you choose to enter into voice-fill or the support chat). Those transfers rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the sub-processor's own safeguards. We will not make any other transfer outside the UK without putting an appropriate safeguard in place first.

8. Rights requests

If someone whose data you hold asks us directly to access, correct, delete or restrict it, we will not act on the request ourselves. We will pass it to you within 5 working days and help you respond, because you are the controller and the decision is yours. Most requests you can satisfy yourself: every client, Document and record can be viewed, exported or deleted from within the Service. Where you need more than that, tell us and we will assist within a reasonable time, without charge unless the request is manifestly unfounded or excessive.

9. Personal data breaches

If we become aware of a personal data breach affecting Client Data we will tell you without undue delay, and in any case in time for you to meet your own 72-hour duty to notify the ICO. We will tell you what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we have done and recommend. We will keep you updated as we learn more, and we will not tell the affected data subjects on your behalf unless you ask us to or the law requires it.

10. Deletion and return at the end

You can export your data from the Service at any time, and you should do so before closing your account. When your account is closed (by you or by us under the Terms), we delete Client Data within 90 days, including copies held by sub-processors within their own deletion cycles. The only exception is data we are legally required to keep, such as billing records for tax purposes, which we retain only for that period and only for that purpose. If you delete an individual record in the Service it is removed straight away, along with its linked records and evidence photographs.

11. Showing you we comply

On request we will give you the information you reasonably need to check that we are meeting this agreement: a description of our security measures, our sub-processor list, and the certifications and audit reports our hosting sub-processors publish. If that is genuinely not enough, you may audit us once in any 12-month period on 30 days' written notice, at your own cost, during business hours, in a way that does not compromise the security of other customers' data. We will tell you if we believe an instruction from you would breach Data Protection Law.

12. Liability

Each party is liable to the other for its own breaches of this agreement and of Data Protection Law. Our liability under this agreement is subject to the same limits and exclusions as clause 11 of the Terms, except that nothing limits liability that Data Protection Law does not allow us to limit.

13. General

14. Contact

Data protection questions, sub-processor objections, or to request a countersigned copy: [email protected]
Postal: 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England