Data Processing Addendum

Effective 2 July 2026

This Addendum forms part of the Terms of Service between D4 Digital ("the Processor") and each customer organisation ("the Controller"). It applies to personal data the Controller enters into D4 Digital OS about its own customers, staff and contacts ("Customer Personal Data"), and is written to satisfy Article 28 UK GDPR.

1. Subject matter and duration

The Processor processes Customer Personal Data to provide the D4 Digital OS platform (quoting, CRM, contracts, job management, invoicing, communications and related features), for as long as the Controller holds an account plus the 90-day export window described in the Privacy Policy.

2. Nature of the data

  • Data subjects: the Controller’s customers, prospects, staff and subcontractors.
  • Data categories: contact details, property addresses, quotes and contract records, e-signature evidence (signature image, name, timestamp, IP address), property photographs, scheduling and workforce records (including GPS clock-in coordinates where the Controller enables that feature), payment status, and communications sent through the platform.
  • Special-category data is not required by the platform and should not be entered.

3. Processor obligations

  • Process Customer Personal Data only on the Controller’s documented instructions (given through the platform’s features and settings), unless required by law to do otherwise — in which case the Processor informs the Controller unless the law forbids it.
  • Ensure everyone authorised to process the data is bound by confidentiality.
  • Implement appropriate technical and organisational measures (Section 5).
  • Assist the Controller, taking into account the nature of the processing, with data-subject requests and with the Controller’s obligations on security, breach notification and impact assessments.
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
  • At the end of the services, delete Customer Personal Data (after the export window) unless the law requires continued storage.
  • Make available information reasonably necessary to demonstrate compliance with this Addendum, and allow for audits by written request to support.

4. Sub-processors

The Controller gives general authorisation for the sub-processors listed in the Privacy Policy (hosting, database, payments, email, AI processing, and integrations the Controller chooses to connect). The Processor will update that list before adding or replacing a sub-processor; if the Controller reasonably objects, it may terminate the affected services. Each sub-processor is bound by data-protection obligations no less protective than this Addendum. International transfers are safeguarded by UK adequacy decisions or the UK International Data Transfer Agreement / Addendum.

5. Security measures

  • Per-organisation isolation enforced with database row-level security.
  • Encryption in transit (TLS) and at rest; additional AES-256-GCM field-level encryption for the most sensitive records.
  • Private file storage with short-lived signed URLs.
  • Role-based access controls inside each organisation (owner / admin / office / crew).
  • Least-privilege operational access, audit logging of signature events, and daily automated reconciliation of billing state.

6. Contact

Questions about this Addendum, sub-processors, or a signed copy for your records: support@d4digitalos.com, marked "DPA".