Governance
Data Processing Addendum
This addendum records the Article 28 UK GDPR terms on which PUEpredict processes personal data on a customer's behalf. It forms part of the Terms of Service and is designed to be attached to a procurement pack without amendment.
Version 1.0 · Last updated 1 September 2026 · PUEpredict Limited (in formation), United Kingdom
1. Roles
The customer is the controller and PUEpredict Limited (in formation) is the processor for all personal data contained in the customer's tenancy. Each party complies with the UK GDPR and the Data Protection Act 2018 in respect of its role.
2. Subject matter and duration of processing
Processing lasts for the term of the subscription plus the 30-day export window, and covers provision of the PUEpredict platform: authentication, facility and telemetry management, generation of optimisation recommendations, and production of compliance reports.
- Categories of data subject — the customer's operations, engineering and sustainability personnel who hold tenancy accounts.
- Categories of personal data — name, work email address, tenancy role, authentication metadata, and the audit record of actions taken in the platform.
- Special category data — none. The customer must not upload special category data.
3. Processor obligations
- Process personal data only on documented instructions from the customer, which these terms and the customer's use of the platform constitute.
- Ensure personnel with access are bound by confidentiality and receive data protection training.
- Implement and maintain the technical and organisational measures in clause 4.
- Assist the customer with data subject requests, data protection impact assessments and regulator engagement.
- Delete or return personal data on termination, except where retention is legally required.
- Make available the information necessary to demonstrate compliance, and permit audit no more than once a year on 30 days' notice, subject to confidentiality.
4. Technical and organisational measures
- Tenancy isolation enforced by database row-level security, so authorisation is applied by the database on every query rather than by client code.
- Role assignments held in a dedicated table separate from user profiles, evaluated by security-definer database functions; privileged operations re-verify the caller's role server-side.
- Passwords stored only as salted hashes; sessions carried as short-lived bearer tokens validated on the server for every request.
- TLS 1.2+ in transit and encryption at rest.
- Least-privilege access for engineering staff, with production access logged.
- Telemetry ingestion authenticated per integration with a revocable token scoped to a single facility.
- Automated daily backups with point-in-time recovery, and documented restore testing.
- Change control with peer review, dependency vulnerability scanning, and automated security review of database policies.
5. Sub-processors
The customer authorises the sub-processors below. We impose data protection terms on each that are no less protective than this addendum, and remain liable for their performance. We will give at least 30 days' notice before adding or replacing a sub-processor; the customer may object on reasonable data protection grounds and, if the objection cannot be resolved, terminate the affected service without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Managed cloud platform (hosting, database, authentication, storage) | Runs the application and stores tenancy data, credentials and telemetry. | United Kingdom / EEA |
| Transactional email provider | Delivers account confirmation, password reset and team invitation emails. | EEA |
| Application error monitoring | Captures diagnostic traces so faults can be corrected. | EEA |
6. International transfers
Personal data is stored in the United Kingdom or EEA. Any transfer to a third country is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment made available to the customer on request.
7. Personal data breach
We will notify the customer's Operations Leads without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting their tenancy, with the nature of the breach, categories and approximate volumes affected, likely consequences, and the measures taken or proposed. We will not notify the ICO on the customer's behalf unless instructed.
8. Return and deletion
On termination the customer may export all facility data, recommendations, implementation records and compliance reports for 30 days in PDF, DOCX or CSV. After that window, personal data is deleted from live systems within 30 days and from backups within 90 days.
9. Contact
Data protection contact: privacy@puepredict.co.uk. Security contact for vulnerability reports: security@puepredict.co.uk.
