TrustWatt
    Back to Legal Hub

    Last updated: 21 January 2025

    Data Processing Addendum

    Draft Template — For Discussion

    This is a draft Data Processing Addendum (DPA) template. It does not constitute legal advice. Partners should review with their own legal counsel before signing.

    This template outlines how TrustWatt and partners handle personal data when processing on behalf of each other.

    1. Parties

    This Data Processing Addendum ("DPA") is entered into between:

    • [COMPANY LEGAL NAME] ("TrustWatt", "we", "us")
    • [Partner Company Name] ("Partner", "you")

    2. Definitions

    • "Controller" — The party that determines the purposes and means of processing personal data
    • "Processor" — The party that processes personal data on behalf of the Controller
    • "Personal Data" — Information relating to an identifiable individual
    • "Processing" — Any operation performed on personal data
    • "Sub-processor" — A third party engaged by a Processor to process personal data

    3. Controller and Processor Roles

    When TrustWatt is the Controller

    TrustWatt is the Controller for personal data collected through the TrustWatt platform (driver accounts, reviews, etc). When partners access this data to fulfil quote requests, they act as independent Controllers for their own follow-up activities.

    When Partner is the Controller

    Partners are Controllers for data they collect directly (their customer records, installation data, etc). When partners share data with TrustWatt for platform features, TrustWatt may act as a Processor.

    4. Processing Instructions

    The Processor shall:

    • Process personal data only on documented instructions from the Controller
    • Ensure personnel are bound by confidentiality obligations
    • Implement appropriate security measures
    • Assist the Controller in responding to data subject requests
    • Delete or return personal data upon termination, unless required by law to retain

    5. Security Measures

    Both parties shall implement appropriate technical and organisational measures, including:

    • Encryption of personal data in transit and at rest
    • Access controls and authentication
    • Regular security testing and assessment
    • Incident detection and response procedures
    • Business continuity and disaster recovery

    6. Sub-processors

    The Processor shall not engage a Sub-processor without prior written authorisation from the Controller.

    When Sub-processors are authorised, the Processor shall:

    • Maintain a list of Sub-processors
    • Impose data protection obligations on Sub-processors
    • Remain liable for Sub-processor compliance
    • Notify the Controller of any changes to Sub-processors

    7. Breach Notification

    In the event of a personal data breach, the Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of the breach.

    Notification shall include:

    • Nature of the breach
    • Categories and approximate number of data subjects affected
    • Likely consequences
    • Measures taken or proposed to address the breach

    8. International Transfers

    Personal data shall not be transferred outside the UK/EEA without appropriate safeguards, such as Standard Contractual Clauses or adequacy decisions.

    9. Data Subject Rights

    The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, etc) by providing relevant information and cooperation.

    10. Return and Deletion of Data

    Upon termination of the agreement or upon request:

    • The Processor shall return or delete all personal data, at the Controller's choice
    • The Processor shall provide written confirmation of deletion
    • Retention is permitted only where required by law

    11. Audit Rights

    The Controller may audit the Processor's compliance with this DPA, with reasonable notice and during normal business hours. The Processor shall cooperate with audits and provide necessary information.

    12. Contact

    For DPA enquiries, contact us at:
    Email: [DPO OR PRIVACY CONTACT EMAIL]

    Need to execute a DPA?

    If you're a partner and need to formalise a Data Processing Addendum, please contact our team to discuss your specific requirements.

    Version note:

    If we make big changes, we'll post an update here and may notify you in-app.