Data Processing Agreement

The terms on which we process the personal data you enter about your own customers, where you are the controller and we are your processor.

Effective 5 September 2026

1. Purpose and parties

1.1 This Data Processing Agreement (“DPA”) is entered into between Stella Apps, trading as ProvenBatch (“Processor”, “we”, “us”) and the customer identified on the ProvenBatch Account (“Controller”, “you”), and applies wherever you use the ProvenBatch Service (the “Service”) to process personal data about your own customers, contacts, or orders (the “Customer Personal Data”).

1.2 This DPA is incorporated by reference into, and forms part of, our Terms of Service for every Account that uses order, customer, or contact features of the Service. It applies automatically from the point you first enter Customer Personal Data into the Service — you do not need to separately sign it for it to take effect, though we will provide a signed copy on request.

1.3 This DPA reflects the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018. Where this DPA and the Privacy Policy both address the same subject matter (for example, sub-processors or retention), this DPA governs as between Controller and Processor for Customer Personal Data specifically; the Privacy Policy governs our own processing of your Account data as controller.

2. Definitions

Terms defined in the UK GDPR (“personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”) have the same meaning in this DPA. “Sub-processor” means a third party engaged by us to process Customer Personal Data in providing the Service. “UK Data Protection Legislation” means the UK GDPR and the Data Protection Act 2018, as amended or replaced from time to time.

3. Subject matter, duration, nature and purpose of processing

Subject matterCustomer Personal Data you choose to enter into the Service (see clause 4)
DurationFor as long as your Account is active, plus the retention and grace periods described in clause 10
Nature of processingStorage, retrieval, display, and, where relevant, AI-assisted reading of images you upload (see clause 5)
Purpose of processingTo provide the Service to you — recording orders, generating and archiving Labels, and the other features you use

4. Categories of data subjects and personal data

4.1 Categories of data subjects: your own customers, and any individual contact you record against an order or a supplier (for example, a named contact at a supplier business).

4.2 Categories of personal data: names, email addresses, phone numbers, delivery or contact addresses, and order details (what was ordered, when, and any note you attach to it).

4.3 ⚠️ Special category data — worth flagging explicitly. Where you record a customer’s allergy or dietary requirement against an order (for example, “customer asked for nut-free”), that is special category data (health data) under Article 9 UK GDPR, and you, as Controller, are responsible for having a lawful basis and an Article 9 condition for recording it — most commonly, your own explicit consent from that customer, given for the purpose of fulfilling their order safely. We process it only as your instructions direct (that is, by storing and displaying it back to you), and we do not use it for any purpose of our own.

5. How Customer Personal Data reaches AI processing (if at all)

5.1 Customer Personal Data of the kind described in clause 4 (order and contact details) is not ordinarily sent to our AI providers (Anthropic and Groq). The AI features described in the Privacy Policy clause 5 are directed at receipts, packaging, and recipe pages (photo reading), at notes you dictate (voice transcription), and at questions you ask (the assistant) — not at order or customer records.

5.2 The situations in which this could overlap are:

  • photographing a document (for example, a handwritten order note) that happens to contain a customer’s name or details and using a photo-reading feature on it — that image, and any personal data visible in it, is sent to Anthropic in the same way described in the Privacy Policy;
  • dictating a voice note that mentions a customer (for example, a corrective-action note that names the customer whose order was affected) — that recording reaches Groq for transcription in the same way, and is not retained by us once the text is returned;
  • asking the assistant about an order or customer record — the excerpt the assistant looks up in order to answer you reaches Anthropic as part of the conversation, which is not stored after the panel is closed.

In each case the data is processed as the Privacy Policy clause 5 describes. You should bear this in mind before putting a customer’s personal data through a feature not designed for that purpose.

5.3 One route out that is not an AI feature, stated here so that clause 5.2 is not read as the whole list. If you send us feedback from inside the Service and attach a screenshot, that image is stored in the UK, but the item we raise in our issue tracker — hosted by GitHub in the United States — embeds it as an image through a link that remains valid for about five years. A screenshot of an order screen can therefore carry Customer Personal Data outside the UK. It happens only when you choose to attach one, the transfer is covered by clause 9, and you can ask us to delete the image at any time. See clause 7.2 of the Privacy Policy.

6. Our obligations as Processor

We will:

6.1 process Customer Personal Data only on your documented instructions, which for the purposes of this DPA are given by your use of the Service and its documented features, unless we are required to do otherwise by UK or EU law (in which case we will tell you before processing, unless the law prohibits this);

6.2 ensure that anyone we authorise to process Customer Personal Data — including Dave Biley and any future employee or contractor of Stella Apps — is subject to a duty of confidentiality;

6.3 implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing, and against accidental loss, destruction, or damage, having regard to the state of the art, the cost of implementation, and the nature of the data concerned (Article 32 UK GDPR) — see the Annex for a summary of current measures;

6.4 not engage a new sub-processor to process Customer Personal Data without giving you prior notice, as described in clause 7;

6.5 taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as reasonably possible, to respond to a data subject’s request to exercise their rights under UK Data Protection Legislation;

6.6 assist you, taking into account the nature of processing and the information available to us, in meeting your obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments, and prior consultation with the ICO);

6.7 notify you without undue delay after becoming aware of a Customer Personal Data breach, so that you can meet your own 72-hour notification obligation to the ICO where required — see clause 8;

6.8 at your written request, and at the end of the provision of the relevant Service, delete or return Customer Personal Data, save to the extent we are required by law to retain it, and subject to the retention periods in clause 10;

6.9 make available to you all information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to reasonable audits or inspections by you or an auditor you appoint, on reasonable notice, no more than once a year (or more often if required following a personal data breach affecting Customer Personal Data), subject to reasonable confidentiality protections and cost arrangements to be agreed given the scale of a sole-trader business.

7. Sub-processors

7.1 You give general written authorisation for us to engage the sub-processors listed at sub-processors.md, for the purposes described there, as a condition of entering into this DPA.

7.2 We will keep that list current and will notify active subscribers by email, or by a notice within the Service, before engaging a new sub-processor that will process Customer Personal Data, giving you a reasonable opportunity to object on legitimate data-protection grounds. If you object and we cannot resolve the concern, either party may terminate the affected part of the Service without penalty.

7.3 We remain liable to you for the acts and omissions of our sub-processors to the same extent we would be liable if we performed their processing ourselves, and we impose data protection obligations on each sub-processor that are no less protective than those in this DPA.

8. Personal data breach notification

8.1 If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and in any event as soon as reasonably practicable, providing (to the extent then known):

  • the nature of the breach, including the categories and approximate number of data subjects and records affected;
  • the likely consequences of the breach;
  • the measures we have taken or propose to take to address it, including to mitigate its possible adverse effects.

8.2 We will cooperate with you and take reasonable steps as directed by you to assist in the investigation, mitigation, and remediation of the breach.

9. International transfers of Customer Personal Data

9.1 Customer Personal Data is stored in the UK (Supabase, eu-west-2), consistent with the Privacy Policy.

9.2 As described in clause 5, Customer Personal Data is not ordinarily sent to our AI providers, but could be incidentally — in a photographed document, a dictated voice note, or an assistant conversation. Where that happens, the transfer relies on the mechanism recorded in the Privacy Policy for the provider concerned: for Anthropic (photos and the assistant), the UK Addendum to the EU Standard Contractual Clauses, as set out in Schedule 3, Part B of Anthropic’s own Data Processing Addendum (Privacy Policy §9.2); and for Groq (voice notes), the UK Addendum as applied by section 8.3 of Groq’s Data Processing Addendum for GroqCloud Services, deemed signed with the Groq Services Agreement (Privacy Policy §9.3). GitHub processes Customer Personal Data only if you include it in a feedback message you choose to send, or in a screenshot you attach to one as clause 5.3 describes; that transfer is documented under GitHub’s own Data Protection Agreement — its Data Privacy Framework self-certification and the EU SCCs, with the UK Addendum applying to data protected by the UK GDPR (Privacy Policy §9.4).

9.3 We will not transfer Customer Personal Data outside the UK other than as described in this clause 9 without your prior consent, and without putting in place an appropriate transfer mechanism recognised under UK Data Protection Legislation.

10. Retention and deletion

10.1 We retain Customer Personal Data for as long as your Account is active, plus:

  • receipt images, where they form part of an order record: 6 years by default, matching HMRC record-keeping expectations. Nothing is deleted automatically — images past the retention age are queued for a manual review-and-purge by you, and an individual receipt can be pinned “keep forever” to exempt it, as described in the app;
  • Account and order data generally: a 30-day grace period after Account deletion or cancellation, after which it is permanently deleted, save for what we are legally required to keep (for example, payment and invoicing records, retained per the Privacy Policy clause 10.4);
  • feedback screenshots (clause 5.3): deleted with the rest of your data on the same 30-day basis, and on request at any time before that.

10.2 On request at any time during an active Account, or during the 30-day grace period, we will export Customer Personal Data to you in a portable format, or delete it, whichever you instruct.

11. Liability

Each party’s liability under this DPA is subject to the limitation of liability set out in clause 15 of our Terms of Service, except that nothing in this DPA limits either party’s liability for a breach of UK Data Protection Legislation to the extent such liability cannot lawfully be limited.

12. Term and termination

This DPA takes effect from the point you first enter Customer Personal Data into the Service and continues for as long as we process Customer Personal Data on your behalf, including during any Archive state under clause 10.2 of the Terms of Service, and terminates automatically when all Customer Personal Data has been deleted or returned under clause 10 above.

13. Governing law

This DPA is governed by the laws of England and Wales, on the same basis as our Terms of Service.

14. Contact

Stella Apps, trading as ProvenBatch support@provenbatch.co.uk


Annex A — Technical and organisational security measures (summary)

This annex summarises, at a level appropriate to a sole-trader software business, the security measures in place. It is a plain description of how the Service is built, not a certified security statement and not an audit result — we do not hold ISO 27001, SOC 2 or any equivalent certification, and we would rather say so than imply otherwise.

  • Access control. Customer Personal Data is only accessible to authenticated users of your own Account, enforced by row-level security at the database layer, so one customer’s tenant cannot read another’s data.
  • Encryption in transit. All access to the Service is over HTTPS/TLS.
  • Encryption at rest. Provided by our infrastructure provider, Supabase, as part of its standard hosting.
  • Function-level authentication. Every server-side function that touches customer data independently verifies the identity of the caller before processing a request (rather than relying solely on network-level protections).
  • Least-privilege sub-processor access. Deploy credentials used to operate the Service are scoped narrowly (for example, our hosting deploy credential can publish code but cannot read customer data, storage, or DNS/zone settings).
  • Backups. Provided by our infrastructure provider, Supabase, as part of its standard hosting plan.
  • Staged changes. Database and application changes are tested in a separate staging environment, using synthetic or non-production data, before being applied to the production environment holding live Customer Personal Data.
  • Sole operator. As a sole-trader business, access to production systems is currently held by one individual (Dave Biley); this is a control in itself (a minimal attack surface) but also a single point of failure worth the Controller being aware of.

(Whoever finalises this DPA should confirm this Annex against the live state of the system at the time of publication, rather than at the time of this draft.)