Data processing terms
These terms apply between DTDT and any business using DTDT to record work for its own customers. They form part of the Terms of Service and are intended to satisfy Article 28 of the UK GDPR.
Version 1.0 · In effect from 16 August 2026
1. Roles
For the customer records, job records, messages and proof photos and videos a business creates in its workspace, the business is the controller and DTDT is the processor. DTDT is an independent controller only for provider account data, billing and the operation and security of the platform itself.
2. Subject matter, duration and scope
- Subject matter: hosting a proof-of-work record between a business and its customers.
- Duration: for as long as the business holds an active workspace, plus any deletion window described below.
- Categories of data subject: the business's customers and its own staff users.
- Types of personal data: names, email addresses, phone numbers, job identifiers and tags, appointment details, messages, and photos or videos of work — which may incidentally capture people, vehicles or property, together with capture time and, where the device provides it, location.
- No special category data is requested by the platform. Businesses must not deliberately record health, biometric or other special category data in free-text or proof captures.
3. DTDT's obligations
- Process personal data only on the business's documented instructions, which include use of the platform's normal features, unless required otherwise by law.
- Ensure people authorised to access the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (section 4).
- Assist the business, so far as reasonably possible, with data subject requests, data protection impact assessments and regulator engagement.
- Not engage a new sub-processor without updating the published sub-processor list and giving the business a reasonable chance to object.
- Make available the information needed to demonstrate compliance with Article 28 and allow reasonable audits, on notice and no more than once a year unless a regulator requires otherwise.
4. Security measures
- Data is held in the United Kingdom (London region) on managed, access-controlled infrastructure.
- Encryption in transit (TLS) and encryption at rest on the managed database and file storage.
- Row-level access rules in the database so a workspace can only read its own records, enforced on every request rather than in the interface alone.
- Proof photos and videos are served through time-limited signed links, not public URLs.
- Job tracker links are unguessable tokens; sensitive details are masked until the recipient is verified.
- Append-only audit records of changes to jobs and customer records.
- Least-privilege administrative access, with privileged operations restricted to the platform operator.
5. International transfers
Customer and job data is stored in the United Kingdom. Where a sub-processor listed on the sub-processors page processes data outside the UK, that transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent lawful transfer mechanism.
6. Personal data breaches
DTDT will notify the business without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting its workspace, with the information available at the time and updates as the picture becomes clearer. The business remains responsible for notifying the ICO and affected individuals where the law requires it.
7. Return and deletion
A business can delete its own workspace data at any time from Settings. On termination, DTDT will delete the workspace's personal data within 30 days, except where retention is required by law. Routine backups are overwritten on a rolling cycle of no more than 30 days.
8. Data subject requests
Requests from a business's customers are recorded in the workspace so the business, as controller, can respond within the statutory month. DTDT will not respond to those requests on the business's behalf unless asked to, and will forward any request it receives directly.
9. Liability and precedence
These terms sit alongside the Terms of Service. Where there is a conflict about the processing of personal data, these terms take precedence. They are governed by the laws of England and Wales.
These are the operator's own terms and are provided for transparency. They are not legal advice and have not been certified or independently assessed by any third party.
Who we are
This service is operated by Ian Baird T/A Blue Meets White, trading as Blue Meets White, of Office 1, Izabella House, 24-26 Regent Place, City Centre, Birmingham, B1 3NJ, United Kingdom.
Contact for anything in this document, including data protection requests: ian@bluemeetswhite.com.