Data processing agreement
Where a customer's stock file contains personal data, these terms govern how we process it. They form part of the terms of service.
Last updated
Roles
The customer organisation is the controller of personal data in the files it uploads, and VapeRecord is its processor. This agreement meets Article 28(3) of the UK GDPR and applies for as long as we process that data.
Subject matter and purpose
| Subject matter | Stock and catalogue files uploaded for a check, and the results we derive from them. |
| Nature and purpose | Storing the file, matching each line to public records, calculating duty and stamp readiness, and producing the report and files the customer asks for. |
| Personal data | Usually none. Where present: names or user identifiers in a file, and the account users who upload and review it. |
| Data subjects | The customer's staff and any individuals named in its files. |
| Duration | Free checks: 90 days. Paid plans: until the customer deletes the file or the account. |
Our commitments
- We process the data only on the customer's documented instructions, which are the terms of service and the checks the customer runs.
- Everyone with access is bound by confidentiality.
- We keep appropriate technical and organisational measures: encryption in transit, a database reachable only on a private network, row-level separation between organisations, private storage with short-lived download links, and access limited to named administrators.
- We use only the subprocessors on the subprocessors page, give 30 days' notice of a new one, and flow these obligations down to them.
- We help the customer answer data subject requests and meet its security, breach and impact-assessment obligations.
- We notify the customer of a personal data breach without undue delay, and within 48 hours of becoming aware of it.
- At the end of processing we delete the data, unless the law requires us to keep it.
- We make available the information needed to show we meet these terms, and allow reasonable audits on 30 days' notice.
Files are never shared
A customer's files are never published, sold, or combined into statements about which retailer stocks which product. The only reuse is de-identified barcode confirmations (a barcode and the notification it was confirmed to match, with no account, quantity or price), described in the terms of service, which a customer can turn off at any time.
Transfers
Data is hosted in the EU. Where a subprocessor processes data elsewhere, transfers rely on the UK adequacy regulations, the Data Privacy Framework UK extension, or standard contractual clauses with the UK addendum.
Questions about this agreement: [email protected].