Effective 23 July 2026. This Data Processing Agreement (DPA) forms part of the Service Terms between the customer as controller, or processor acting with its controller's authority, and Fair Deductions Ltd as processor. It applies only where Fair Deductions processes personal data on the customer's behalf.
Processing details
The subject matter is the secure receipt, extraction, comparison, review, pricing support, document generation and deletion of tenancy reports and optional supporting evidence. Processing lasts for the customer contract and the shorter product retention period where applicable. Its purpose is to provide and support the requested Fair Deductions review.
People and data covered
Data subjects may include tenants, landlords, occupiers, visitors, guarantors, inventory professionals, agents, contractors and customer staff. Data may include identity and contact details, property addresses, report references, signatures, room and item descriptions, photographs, condition observations, correspondence, user decisions, technical identifiers and any incidental personal data in the supplied material. Customers must avoid uploading unnecessary special-category or criminal-offence data.
Documented instructions
The customer instructs Fair Deductions to process the data only to provide, secure, maintain and support the service in accordance with the contract and the customer's use of product controls. Additional instructions must be lawful, documented and agreed in writing. We will tell the customer if, in our reasonable view, an instruction infringes applicable data protection law, unless law prevents us doing so.
Customer responsibilities
The customer controls the purpose and lawfulness of the review, provides required privacy information, handles data-subject requests as controller, limits uploads to relevant information, and ensures it has authority to appoint Fair Deductions and the listed subprocessors. A customer acting as a processor confirms that its controller has authorised these instructions and appointments.
Confidentiality and security
People authorised to process customer data are subject to confidentiality obligations. Fair Deductions applies measures appropriate to the risk, including authenticated private workspaces, organisation-level access checks, private object storage, encryption in transit, restricted administrative access, secrets management, event logging, supplier controls, deletion routines and incident handling. Sentry is configured not to send default personal data and server request bodies are removed from error events.
Subprocessors
The customer gives general written authorisation for the following subprocessors:
Vercel: Application hosting and delivery.
Supabase: Authentication, database and private file storage.
OpenAI: Report extraction, comparison, image review and pricing guidance.
Trigger.dev: Background processing and job orchestration.
Resend: Transactional email.
Namecheap: Domain and support-mailbox services.
Google: Support-email access where a Gmail service is used.
Sentry: Limited error and performance monitoring.
Stripe: Checkout, billing and subscription administration.
We will ensure an appointed processor is bound by data-protection obligations appropriate to its service and remain responsible for our own Article 28 duties. We will publish material list changes and, where reasonably practicable, give at least 14 days' notice. A customer may object on reasonable data-protection grounds during that period. We will discuss a reasonable alternative; if none is available, either party may end the affected service.
International transfers
The customer authorises transfers needed to provide the service. Restricted transfers from the UK will use applicable adequacy regulations or appropriate safeguards, which may include the ICO's International Data Transfer Agreement, the UK Addendum to approved EU standard clauses, or another lawful mechanism. Fair Deductions will carry out and document proportionate transfer-risk checks where required.
Data-subject rights
Taking account of the nature of processing, Fair Deductions will provide reasonable technical and organisational assistance so the customer can respond to requests for access, correction, erasure, restriction, objection or portability. If a person contacts us about customer-controlled report data, we will normally refer the request to the customer and will not respond substantively without instructions unless law requires it.
Security, breaches and DPIAs
Taking account of available information, we will assist the customer with security obligations, personal-data breach assessment and notification, data protection impact assessments and prior consultation with the ICO. We will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting its report data and provide available information needed for the customer's response.
Deletion and return
Product report files, supporting photographs and derived case data are scheduled for deletion 30 days after upload and can be deleted sooner through product controls. At the end of processing, we will delete or, where product functionality allows, return customer-controlled personal data, unless UK law requires retention. Data awaiting deletion in protected backups will be put beyond ordinary use and removed on the applicable provider cycle.
Audit information
On reasonable request, Fair Deductions will provide information needed to demonstrate compliance with this DPA. A customer may request an audit no more than once in a 12-month period, unless a breach or regulator reasonably requires more, on at least 30 days' notice, during normal business hours, under confidentiality and without exposing another customer's data. Independent reports and supplier assurance may be used where they provide equivalent evidence. Contact support@fairdeductions.co.uk.
Order of terms
This DPA applies alongside the Service Terms. If they conflict on processing customer-controlled personal data, this DPA takes priority. Nothing in it relieves either party of its direct obligations under the UK GDPR or Data Protection Act 2018.