Last updated 29 August 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between SAUNDY LTD (company number 17363175, registered office 128 City Road, London, England, EC1V 2NX) ("Saundy", the "Processor") and the customer ("Customer", the "Controller"). It applies whenever the Customer's use of Saundy Inspect involves personal data of people other than the Customer's own portal users, and reflects the requirements of Article 28 UK GDPR.

1. Roles and scope

For personal data contained in the Customer's inspection content (sites and property records, inspections, reports, photos, notes, defect records, report signatures, and content the Customer submits to the Service's optional AI-assisted features, together the "Customer Personal Data"), the Customer is the controller and Saundy is the processor. For portal account data (names and emails of the Customer's team members), Saundy is an independent controller as described in the Privacy Policy.

2. Details of processing (Art. 28(3))

Subject matter Field inspection capture, defect tracking, and inspection report generation for the Customer's properties
Duration The term of the Customer's agreement (subscription, prepaid credits, or Programme term), plus the deletion periods in section 10
Nature and purpose Storing inspection content captured by the Customer's inspectors; generating and storing PDF reports from it; tracking defects through to sign-off; where the Customer uses them, optional AI-assisted features that draft, review, or summarise the Customer's content, including template drafting and the conversion of uploaded documents (via the sub-processor listed at Sub-processors, which records what each feature sends)
Categories of data Names, roles, and drawn signatures of report signatories; names of people recorded in inspection notes or answers; people appearing incidentally in inspection photos; property addresses and identifiers, which may relate to identifiable occupants
Categories of data subjects The Customer's personnel and contractors who sign reports; occupants, visitors, and other third parties who appear in inspection content
Special category data Not permitted; see the Terms of Service, section 5

3. Customer instructions

Saundy processes Customer Personal Data only on the Customer's documented instructions, including as configured through the Service's templates, permission groups, and APIs, unless required otherwise by law (in which case Saundy informs the Customer unless legally prohibited). Saundy will inform the Customer if, in its opinion, an instruction infringes the UK GDPR.

4. Confidentiality

Persons authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations.

5. Security (Art. 32)

Saundy implements appropriate technical and organisational measures, including:

  • TLS encryption for all data in transit;
  • sign-in tokens and password-reset tokens stored only as cryptographic hashes; passwords stored as salted hashes;
  • tenant-level isolation of each Customer's data enforced at the data-access layer;
  • role-based access control with per-area permission groups governing who in the Customer's organisation can manage templates, sites, inspections, and defects;
  • append-only event history on defect records (raise, severity change, sign-off, reopen) preserving who did what.

6. Sub-processors

The Customer gives general written authorisation for the sub-processors listed at Sub-processors, which is the authoritative record. Saundy will update that page at least 30 days before a new or replacement sub-processor begins processing Customer Personal Data, and organisation administrators may subscribe to be notified of changes by emailing hello@saundy.com. The Customer is responsible for reviewing the page; the Customer may object on reasonable data-protection grounds within 30 days of a change being posted, and if the objection cannot be resolved may terminate the affected services. Saundy imposes data-protection obligations on sub-processors equivalent to this DPA and remains liable for their performance.

7. Assistance with data subject requests

Taking into account the nature of the processing, Saundy assists the Customer in responding to data subject requests:

  • Erasure and rectification: inspection content is editable and deletable by the Customer directly in the Service: photos can be removed from records, notes and answers amended (issuing a corrected report version), and defect records, inspections, and property records deleted.
  • Access: the Customer can export inspection reports as PDF and review the underlying records in the Service.
  • Requests received by Saundy directly from the Customer's data subjects are forwarded to the Customer without undue delay.

8. Assistance with compliance

Saundy assists the Customer, insofar as reasonably possible, with the Customer's obligations under Articles 32–36 UK GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to Saundy.

9. Personal data breaches

Saundy notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing the information reasonably required for the Customer's own notification obligations.

10. Deletion and return

  • Inspection content has no automatic expiry; it is the Customer's business record, retained until the Customer deletes it.
  • On termination of the agreement, remaining Customer Personal Data is deleted in line with the Privacy Policy retention table, except where retention is required by law.
  • The Customer can export report PDFs and review records before termination through the Service.

11. International transfers

Customer Personal Data is transferred outside the UK only to the sub-processors listed, protected by UK adequacy regulations, the UK IDTA, or the UK Addendum to the EU SCCs, as incorporated in each sub-processor's data processing terms.

12. Audit

Saundy makes available the information reasonably necessary to demonstrate compliance with this DPA and, where that information is insufficient, allows audits by the Customer or an independent auditor mandated by the Customer, at the Customer's cost, no more than once per year, on reasonable notice, and without access to other customers' data.