Data Protection

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between HiveSuite Limited and our customers for the processing of personal data under UK GDPR.

Version: 1.0 Effective: 14 September 2026 Processor: HiveSuite Limited Company No.: 16791803 Contact: privacy@hivesuite.co.uk
How this DPA works: This DPA automatically applies to all HiveSuite customers. By using HiveSuite and accepting our Terms of Use, you incorporate this DPA into your agreement with us. You do not need to sign a separate document. If you require a countersigned copy for your records, contact privacy@hivesuite.co.uk.

1 Definitions

In this DPA:

  • "Controller" means you, the HiveSuite customer, who determines the purposes and means of processing personal data using the HiveSuite service.
  • "Processor" means HiveSuite Limited, which processes personal data on behalf of the Controller to provide the service.
  • "Data Protection Laws" means the UK GDPR (the retained EU law version of Regulation (EU) 2016/679), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended from time to time.
  • "Personal Data", "Data Subject", "Processing", "Personal Data Breach", and "Subprocessor" have the meanings given in UK GDPR.
  • "Service" means the HiveSuite platform and related services provided under the Terms of Use.
  • "Agreement" means the Terms of Use and this DPA together.

2 Scope, Duration and Purpose

Subject matter. This DPA governs the processing of personal data by HiveSuite on behalf of the Controller in connection with the provision of the Service.

Duration. This DPA applies for the duration of the Controller's subscription and continues until all personal data processed under this DPA has been deleted or returned.

Nature and purpose. HiveSuite processes personal data to provide the Controller with business management software services, including CRM, job management, quoting, invoicing, scheduling, team management, compliance documentation, SMS messaging, email communications, customer portal functionality, public forms, AI-powered features, financial tools, and integrations with third-party services, as described in the Terms of Use.

3 Categories of Data and Data Subjects

Categories of data subjects:

  • The Controller's customers, clients, and contacts
  • The Controller's employees, workers, contractors, and team members
  • Individuals who submit information through public enquiry forms
  • Individuals who receive SMS messages or emails sent through the Service
  • Individuals who interact with the Customer Portal

Categories of personal data:

  • Contact information (names, email addresses, phone numbers, postal addresses)
  • Business information (company names, VAT numbers, trade details)
  • Job and service records (work descriptions, locations, dates, status)
  • Financial data (quotes, invoices, expenses, payment references)
  • Communications content (SMS messages, emails, portal messages)
  • SMS consent and opt-out records
  • Workforce data (time tracking, GPS location, photographs, job notes)
  • Documents, images, videos, and file attachments
  • Compliance and certification records
  • Public form submission data (as configured by the Controller)
  • AI feature inputs and outputs

4 Controller Obligations

The Controller warrants and undertakes that:

  • It has a lawful basis for each processing activity carried out using the Service
  • It has provided all required privacy notices to data subjects whose personal data is processed through the Service
  • It has obtained any consents required for the processing, including for SMS messaging and direct marketing
  • Its instructions to the Processor comply with all applicable Data Protection Laws
  • It is responsible for the accuracy and completeness of personal data provided to the Service

5 Processor Obligations

HiveSuite shall:

  • Process personal data only on the documented instructions of the Controller, unless required to do so by applicable law (in which case we will inform the Controller before processing, unless prohibited by law)
  • Ensure that all persons authorised to process personal data are subject to appropriate confidentiality obligations
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs, and the nature of the processing
  • Not engage another processor (subprocessor) without the Controller's prior authorisation, subject to section 6 below
  • Assist the Controller, taking into account the nature of the processing, with appropriate technical and organisational measures for the fulfilment of the Controller's obligations to respond to data subject requests
  • Assist the Controller with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor
  • At the Controller's choice, delete or return all personal data after the end of the provision of services, and delete existing copies unless applicable law requires continued storage
  • Make available to the Controller all information necessary to demonstrate compliance with UK GDPR Article 28 obligations and allow for and contribute to audits, as described in section 9

6 Subprocessors

General authorisation. The Controller provides general written authorisation for the Processor to engage subprocessors as necessary to provide the Service. The current list of subprocessors is available at hivesuite.co.uk/subprocessors.

Notification of changes. The Processor will update the Subprocessors page before engaging a new subprocessor and will use reasonable efforts to notify the Controller of material changes (for example, by email or through the HiveSuite portal). The Controller should monitor the Subprocessors page periodically.

Objections. If the Controller has a reasonable objection to a new subprocessor on data protection grounds, the Controller should notify HiveSuite in writing within 14 days of the change being published. We will work in good faith to address the objection, which may include offering an alternative configuration. If no resolution can be reached, the Controller may terminate the affected part of the Service.

Subprocessor obligations. The Processor will impose data protection obligations on each subprocessor that are no less protective than those in this DPA. The Processor remains liable for the acts and omissions of its subprocessors.

7 International Data Transfers

Where personal data is transferred outside the United Kingdom, the Processor will ensure that appropriate safeguards are in place in accordance with UK GDPR, which may include: reliance on UK adequacy regulations; the UK International Data Transfer Agreement or Addendum; or the ICO-approved standard contractual clauses. Details of the processing locations of subprocessors are available on the Subprocessors page.

8 Personal Data Breach

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's data. The notification will include, to the extent available:

  • A description of the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned
  • The name and contact details of a point of contact at HiveSuite
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach and mitigate its effects

The Processor will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

9 Audit and Information Rights

The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with UK GDPR Article 28. The Processor will contribute to audits and inspections conducted by the Controller or an independent auditor appointed by the Controller, subject to the following:

  • The Controller must provide at least 30 days' written notice of any audit request
  • Audits will be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations
  • The scope of audits is limited to the processing activities relevant to the Controller's data
  • Any third-party auditor must be bound by appropriate confidentiality obligations and must not be a competitor of HiveSuite
  • Reasonable costs associated with audit requests beyond routine information provision may be charged to the Controller

10 Deletion and Return of Data

Upon termination or expiry of the Agreement, the Processor will, at the Controller's election:

  • Make the Controller's data available for export using the export tools provided within the Service; or
  • Delete the Controller's personal data

Following the post-termination period described in our Terms of Use, the Processor will delete all remaining personal data unless applicable law requires continued retention (for example, billing records retained for HMRC purposes). Deletion will be carried out within a reasonable timeframe, and the Processor will confirm deletion upon request.

11 Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Use. This DPA does not increase or decrease the total aggregate liability of either party under the Agreement.

12 General

Conflict. In the event of any conflict between this DPA and the Terms of Use, this DPA shall prevail with respect to matters relating to data protection.

Governing law. This DPA is governed by the laws of England and Wales.

Contact. For questions about this DPA, contact privacy@hivesuite.co.uk.

Get in Touch

Have a question? We'd love to hear from you.