Data Processing Agreement
Last updated: 15 September 2026
When you record a client's name, a building's address, or the people named in a fire risk assessment, that information is personal data about people who never signed up with us. Under the UK GDPR you are the controller of that data and we process it on your behalf. Article 28 requires a written contract between us that sets out how. This is that contract.
1. Parties
- The "Controller" is you: the person or business that holds the EmberSuite Fire account (including every user you invite to your team).
- The "Processor" is Shayaan Ahmed, trading as EmberSuite Fire (a sole trader, not a registered company), of 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England ("we", "us").
Words defined in the Terms ("Service", "Documents", "Your Content") mean the same here. "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, as amended. "Client Data" means the personal data you enter into the Service about people other than yourself and your own team, as described in section 2.
For your own account data (your name, email and billing details) we are the controller, not your processor. That is covered by our Privacy Policy, not this agreement.
2. Details of the processing
| Subject matter | Hosting, storing, rendering, converting to PDF and (on your instruction) emailing the records you keep about your clients and the premises you work on. |
|---|---|
| Duration | For as long as your account is active, plus the deletion window in section 10 (up to 90 days after closure). |
| Nature and purpose | Storage and retrieval; generating certificates, risk assessments, logbook entries, quotations and invoices from the data you enter; converting Documents to PDF; sending Documents and compliance reminders that you have approved; searching and reporting within your own account. We process Client Data only to provide the Service to you, never for our own purposes. |
| Categories of personal data |
Special-category data. Personal emergency evacuation plans (PEEPs) and any note about a person's health, disability or mobility are special-category data with a higher legal bar. The Service is not designed to hold them. Record only what your assessment genuinely requires, and keep it to the minimum. |
| Categories of data subject | Your clients and their staff; responsible persons, landlords, managing agents and occupiers of the premises you work on; anyone else you name in a Document. |
3. Your obligations as controller
You are responsible for having a lawful basis for the Client Data you enter, for telling your own clients how their data is handled, and for the accuracy of what you record. You warrant that your instructions to us (which are: the ordinary use of the Service) comply with Data Protection Law. If you invite team members, you are responsible for what they enter.
4. Our obligations as processor
We will:
- Act only on your documented instructions. Your instructions are these Terms, this agreement and the actions you and your team take in the Service (creating, editing, generating, sending and deleting records). We will not process Client Data for any other purpose, and we will not transfer it outside the UK except as described in section 7, unless UK law requires us to, in which case we will tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law we will tell you.
- Keep it confidential. The only person with administrative access to Client Data is the Processor. Anyone we later authorise to access it will be bound by a written duty of confidentiality first.
- Keep it secure, with the measures in section 5, and keep those measures under review.
- Use sub-processors only as allowed by section 6.
- Help you respond to rights requests (section 8).
- Help you meet your own security, breach, and impact-assessment duties under Articles 32 to 36, taking into account the nature of the processing and the information we hold. That includes providing what you reasonably need for a data protection impact assessment of your use of the Service.
- Delete or return the data at the end (section 10).
- Show you we are complying (section 11).
5. Security measures
The measures we have in place, which we treat as the minimum:
- Tenant isolation at the database level. Every record carries an organisation identifier and row-level security policies mean the database itself refuses to return another organisation's rows, regardless of what the application asks for.
- UK hosting. The primary database runs in the London (
eu-west-2) region. - Encryption in transit. All connections use TLS. Encryption at rest is provided by our hosting sub-processor.
- Authentication. Passwords are stored only as salted hashes; sign-in is protected against automated attacks with a bot challenge (Cloudflare Turnstile). Team members have per-member write permissions set by the account owner.
- Least exposure. The browser only ever holds a per-user token; privileged keys live only in server-side functions. We run no analytics or advertising trackers.
- Evidence photographs are held in private storage and served only through short-lived signed links to the account or team they belong to.
- Human-in-the-loop sending. No Document leaves the Service to a client until a person on your account presses Send.
6. Sub-processors
You give us general authorisation to use the sub-processors below. Each one processes Client Data only for the purpose shown, under a written contract that imposes data-protection obligations equivalent to this agreement. We remain fully responsible to you for their performance.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and file storage | EU |
| Stripe | Payment processing and subscription billing | EU / US |
| Cloudflare | Website hosting, security, and inbound email routing | Global / EU |
| PDFShift | Converting a Document to PDF at the moment you generate or send it | EU |
| Anthropic | AI features (support chat and voice-fill): processes the text you enter, then does not retain it for training | US |
| n8n (Autoshworks) | Automation of compliance reminders | EU |
| Resend | Sending account emails and the Documents you approve in the Outbox | EU |
Changes. If we intend to add or replace a sub-processor we will give you at least 30 days' notice by email or in-app notice before it handles Client Data. If you object on reasonable data-protection grounds and we cannot resolve it, you may close your account before the change takes effect and we will refund any prepaid fees for the unused period.
7. International transfers
Client Data is stored in the UK. Two sub-processors can receive it outside the UK and EU: Stripe (billing metadata only, not your Documents) and Anthropic (only the text you choose to enter into voice-fill or the support chat). Those transfers rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the sub-processor's own safeguards. We will not make any other transfer outside the UK without putting an appropriate safeguard in place first.
8. Rights requests
If someone whose data you hold asks us directly to access, correct, delete or restrict it, we will not act on the request ourselves. We will pass it to you within 5 working days and help you respond, because you are the controller and the decision is yours. Most requests you can satisfy yourself: every client, Document and record can be viewed, exported or deleted from within the Service. Where you need more than that, tell us and we will assist within a reasonable time, without charge unless the request is manifestly unfounded or excessive.
9. Personal data breaches
If we become aware of a personal data breach affecting Client Data we will tell you without undue delay, and in any case in time for you to meet your own 72-hour duty to notify the ICO. We will tell you what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we have done and recommend. We will keep you updated as we learn more, and we will not tell the affected data subjects on your behalf unless you ask us to or the law requires it.
10. Deletion and return at the end
You can export your data from the Service at any time, and you should do so before closing your account. When your account is closed (by you or by us under the Terms), we delete Client Data within 90 days, including copies held by sub-processors within their own deletion cycles. The only exception is data we are legally required to keep, such as billing records for tax purposes, which we retain only for that period and only for that purpose. If you delete an individual record in the Service it is removed straight away, along with its linked records and evidence photographs.
11. Showing you we comply
On request we will give you the information you reasonably need to check that we are meeting this agreement: a description of our security measures, our sub-processor list, and the certifications and audit reports our hosting sub-processors publish. If that is genuinely not enough, you may audit us once in any 12-month period on 30 days' written notice, at your own cost, during business hours, in a way that does not compromise the security of other customers' data. We will tell you if we believe an instruction from you would breach Data Protection Law.
12. Liability
Each party is liable to the other for its own breaches of this agreement and of Data Protection Law. Our liability under this agreement is subject to the same limits and exclusions as clause 11 of the Terms, except that nothing limits liability that Data Protection Law does not allow us to limit.
13. General
- This agreement lasts for as long as we process Client Data for you and ends when section 10 has been carried out.
- If this agreement conflicts with the Terms on a data-protection matter, this agreement wins.
- We may update it to reflect changes in the law, our sub-processors or the Service; material changes are notified as described in the Terms, and the "last updated" date above will change.
- It is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
14. Contact
Data protection questions, sub-processor objections, or to request a countersigned copy: [email protected]
Postal: 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England