Legal
Data processing agreement.
What we may do with the personal data in your book, who else touches it, and how it is kept safe. This is the contract UK GDPR Article 28 requires between you and us, and it forms part of our terms of service.
Last updated: 19 September 2026
1. What this is
This is the data processing agreement between Michael Doherty (a sole trader trading as Skip Deck) of 42 Knoll Drive, Coventry CV3 5BU, ICO registration ZC244421 — "we", "us" — and the skip hire firm subscribing to SkipDeck — "you".
It forms part of our terms of service and is the written contract UK GDPR Article 28(3) requires between a controller and its processor. Where this agreement and the terms disagree about personal data, this agreement wins.
You are the controller. We are your processor. The personal data in your book is yours: your customers and their contacts, the people who sign for a delivery, your drivers, your office staff. You decided to collect it and why. We hold and process it for you, on your instructions, and for no purpose of our own.
Schedule 1 says exactly what is processed and about whom. Schedule 2 says how it is kept safe.
2. What we may do with it
Only what you tell us to. Your instructions are these terms, this agreement, and the things you and your people do inside the product. We will not process your book for anything else — not to improve the software by reading it, not to train anything, not to build a picture of the market, and never to sell.
If we think an instruction of yours would break data protection law, we will tell you and we may pause that instruction until it is resolved.
What support can see. Our admin tooling shows us your trading name and office contact, your user accounts, when each was last in, and counts of jobs, customers, lorries, invoices and receipts. It returns nothing from inside your book — no customer, site, address, job, invoice, note or photograph — and a test in our build fails if it ever does. Every time we look is written into your own sign-in log, and your Data protection screen shows you how many times and when.
3. Our people
Everybody with access to your book is bound to keep it confidential, and that duty does not end when they stop working with us. Access is limited to those who need it to run or support the service.
4. Security
We take the technical and organisational measures set out in Schedule 2, which is a description of what the software and the deployment actually do rather than a statement of intent. We may change individual measures, but not so as to weaken the overall level of protection.
The single most important one: each firm's book is a separate database in a separate container, routed by hostname. There is no shared database and no query path from one firm's deployment into another's.
5. Sub-processors
You give us general authorisation to use the sub-processors below. This list is the authoritative one — where any other page, document or email of ours disagrees with it, this is the one to rely on.
- Hetzner Online GmbH — hosting, storage and backups. Servers in Helsinki, Finland. Receives everything, because the service runs there.
- Amazon Web Services (Simple Email Service) — sends the email your book sends. Servers in the London region. Receives the email address of anybody you write to and the content of the message: booking confirmations, invoices, receipts and ticket links.
- OpenStreetMap Foundation (Nominatim) — receives a site address once, the first time it is turned into map coordinates. United Kingdom.
- Overpass API — receives map areas to look up road and site data. No personal data reaches it.
- Xero — only if you connect your own Xero account, and only the invoice data you choose to send.
Route planning is not on this list, because it is not sent anywhere. Journey times, distances and road restrictions are calculated on our own server from a public map extract. No address or coordinate from your book reaches a commercial routing provider.
If an email to one of your customers bounces or is reported as spam, the report — which contains that person's email address — reaches our own mailbox, which is provided by Google. It is a small flow and we would rather state it than leave it out.
Adding one. We will tell you at least 30 days before we add or change a sub-processor. If you object on reasonable data protection grounds within those 30 days and we cannot resolve it, you may end your subscription for that reason and we will refund the unused part of anything you have paid.
Every sub-processor is under written terms no less protective than these, and we stay responsible to you for what they do.
6. Where your data is
Your book is stored in the EU (Finland) and your email is sent from the UK (London). Both are covered for UK purposes — the EU by the UK's adequacy regulations, the UK by being the UK.
Where a provider's own support staff may access data from outside the UK or EU, that access is governed by that provider's data processing terms, including the international transfer safeguards UK law requires. We will give you the details of those terms on request.
We do not transfer your book outside the UK or EU for any purpose of our own.
7. When somebody in your book asks about their information
If a person contacts us directly about data we hold for you, we will not answer them on your behalf. We will tell them to come to you, and tell you it happened.
We will help you answer them. The product has the common requests built in: find a person across customers, contacts, sites and jobs that were never linked to a customer record; export everything held about them; erase them, with a preview first and the records the law requires you to keep held back. That is on your Settings → Data protection screen.
8. If something goes wrong
If personal data in your book is lost, exposed or altered without authority, we will tell you without undue delay and in any case within 24 hours of becoming aware. We will tell you what we know, what we are doing, and who to contact — enough for you to meet your own 72-hour duty to the ICO.
We keep a record of what happened and what was done about it, and you may have it.
9. Helping you with your own duties
We will give you reasonable help with data protection impact assessments and with consulting the ICO, so far as they concern the processing we do for you and using the information we have.
10. Showing you we are doing this
We will make available to you the information needed to show we are meeting the obligations in this agreement, and we will allow and contribute to audits and inspections carried out by you or an auditor you appoint.
In practice, for a firm of your size and ours, that will usually be a written answer and a copy of our procedures. Where you need more than that, we ask for reasonable notice, that it happens in working hours, that it does not disturb other firms on the same box, and that anyone attending is under confidentiality. We will not charge you for the first audit in any twelve-month period.
11. When it ends
When your subscription ends you can export your whole book — every job, customer, site, invoice and waste record, in open formats — for 90 days. Your deployment is switched off but retained during that period so nothing is lost while you decide.
After 90 days we delete it: the database, the uploaded files and the backups, on the timetable in our closure procedure. We will confirm in writing when it is done. If you would rather we deleted it sooner, say so and we will.
Where the law requires us to keep something — our own invoices to you, for instance — we keep only that, and only for as long as we must.
12. What stays yours
You remain responsible for having a lawful basis for what is in your book, for telling the people in it what you do with their information, and for the accuracy of what you put in.
You will almost certainly need to pay the ICO's annual data protection fee and be on their register. That is yours, not ours, and no subscription can do it for you.
Schedule 1 — what is processed
Subject matter. Providing the SkipDeck skip hire management service to you.
Duration. For as long as you subscribe, plus the closure period in clause 11.
Nature and purpose. Storing, organising, displaying, planning against, printing, emailing and exporting the records a skip hire firm keeps, so that you can run your business and meet your waste duty of care.
Whose data:
- Your customers, and the named contacts at them.
- People at a site who sign for a delivery or collection.
- Your drivers.
- Your office staff who hold an account.
- Members of the public who book through your booking page, or write to you through it.
What data:
- Contact details — name, business name, billing address, telephone numbers, email addresses.
- Site information — the address a skip goes to, its coordinates, access notes, where on the property it was placed, and whether a permit was needed.
- Job records — what was delivered and collected, when, by which driver, what was in it, what it weighed, and any note written about it.
- Photographs taken at a site, which may show a person's property and occasionally a person.
- Signatures and the name of whoever signed, on delivery and collection dockets and waste transfer notes.
- Money records — quotes, prices, invoices, payments and what is outstanding.
- Waste records — the transfer and consignment details the law requires, including where waste came from and where it went.
- Messages — the text of emails your book sent to a customer, and when.
- Account records for your staff — name, work email, role, sign-in history including the internet address it came from, when each was last using the system, and what they changed in the book.
No special category data is asked for anywhere in the product, and none is needed to use it. If your people type something of that kind into a free-text note, it is processed as part of that note and you remain the controller of it.
Schedule 2 — how it is kept safe
These are the measures in place, described as they are rather than as a list of intentions.
- Separation. One database and one container per firm, routed by hostname. No shared database, no cross-firm query path.
- In transit. TLS on everything, with HSTS.
- Passwords. Hashed with scrypt at interactive parameters, a salt per user, never recoverable. A minimum of twelve characters, with a person's own name, email and the obvious guesses refused.
- Sessions. Signed, HttpOnly, SameSite=Lax, Secure, and valid for fourteen days. Changing a password ends that person's sessions and nobody else's. There is a sign-out-everywhere for a lost phone or tablet that does not require a password change.
- Brute force. Five failed attempts against one email address, or forty from one internet address, inside fifteen minutes, and further attempts are refused.
- Access control. Four roles enforced centrally against a policy covering every endpoint, with anything unclassified refused rather than allowed, and a test that fails our build if an endpoint is added without a decision.
- Drivers hold a revocable per-person link rather than an account, and it can be withdrawn without affecting anyone else.
- Logging. Every sign-in, refusal, account change and support access is recorded in your own book, where you can read it.
- Backups. Taken six-hourly, integrity-checked when written, and a restore has been rehearsed against a real book.
- Retention. Periods you set yourself, with an automatic sweep that previews before it deletes and will not remove anything under a legal hold.
Two things we would rather tell you than have you find out. Our backups are not encrypted at rest — they sit in a volume on the same server as the database, and host disk encryption is the usual answer to that and is not currently configured. And the internet address recorded in your sign-in log is taken from a header the client supplies, so it is reliable enough to read a pattern from and not reliable enough to rely on as proof of where somebody was.
If either of those matters to you, ask — they are on our list, and knowing a customer is waiting on one moves it up.
Questions about any of this, or a copy signed for your records: hello@skipdeck.co.uk. What we do with information from this website, rather than from your book, is on our privacy page.