All policies

UK Data Protection Addendum

Last reviewed

The terms under which we process personal data on behalf of our customers under UK GDPR.

This Data Protection Addendum ("Addendum") forms part of the agreement between Sentinel Vero Ltd ("Sentinel Vero", "we") and the customer named in that agreement ("Customer", "you") for the use of Vero (the "Agreement"). It applies whenever we process personal data on your behalf in providing Vero.

If this Addendum and the Agreement conflict on data protection, this Addendum takes priority.

1. Definitions #

In this Addendum:

  • Data Protection Law means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, as amended or replaced from time to time.
  • Customer Personal Data means personal data that we process on your behalf in providing Vero.
  • Controller, processor, data subject, personal data, personal data breach and processing have the meanings given in the UK GDPR.
  • Subprocessor means a third party we engage to process Customer Personal Data.

2. Roles #

You are the controller of Customer Personal Data. We are your processor. Each of us will comply with the obligations that Data Protection Law places on us in that role.

You are responsible for having a lawful basis for the processing, for giving data subjects the information the law requires, and for the lawfulness of the instructions you give us. This includes, where you use Vero to track vehicles or engineers, informing your workers and carrying out any data protection impact assessment the law requires.

3. Instructions #

We will process Customer Personal Data only on your documented instructions. The Agreement, this Addendum and your use of Vero's features and settings are your documented instructions.

If the law requires us to process Customer Personal Data other than on your instructions, we will tell you before doing so, unless the law prohibits it.

We will tell you promptly if we believe an instruction breaks Data Protection Law.

4. Confidentiality #

We will make sure everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, and has access only to what they need for their role.

5. Security #

We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the UK GDPR. Our current measures are described in Data security at Vero. We may update those measures, but we will not reduce the overall level of protection.

6. Subprocessors #

You give us general authorisation to engage subprocessors. Our current subprocessors are listed on our subprocessors page.

Before we add or replace a subprocessor, we will give you at least 30 days notice by email to your account administrator. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may end the affected part of the service and we will refund any prepaid fees for the period after termination.

We will put a written contract in place with each subprocessor that gives Customer Personal Data the same level of protection as this Addendum. We remain responsible to you for our subprocessors' performance.

7. International transfers #

We will only transfer Customer Personal Data outside the UK, or allow a subprocessor to do so, where the transfer complies with Data Protection Law. This means the destination benefits from UK adequacy regulations, or the transfer is covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with any supplementary measures needed.

8. Helping you respond to data subjects #

Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights, mainly through Vero's features for finding, exporting, correcting and deleting data. If we receive a request directly, we will pass it to you without undue delay and will not respond ourselves unless you ask us to.

9. Helping you meet your other obligations #

We will give you reasonable help with data protection impact assessments, prior consultations with the Information Commissioner, and your security obligations, taking into account the nature of the processing and the information available to us. We may charge for help that goes beyond what Vero's standard features and documentation provide, at the rates in the Agreement.

10. Personal data breaches #

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Our notice will include, as far as we then know:

  • What happened, and when
  • The categories and approximate number of data subjects and records affected
  • The likely consequences
  • The steps we have taken or propose to take

We will provide further information as it becomes available, and cooperate with you in dealing with the breach. Notifying you is not an admission of fault.

11. End of the service #

When the Agreement ends, you may export your Customer Personal Data using Vero's export features for 30 days. After that, we will delete Customer Personal Data within 90 days, including from backups on their normal rotation, unless the law requires us to keep it. If the law requires us to keep it, we will protect it and process it only for that purpose.

12. Audits #

We will make available the information reasonably needed to show that we comply with this Addendum. This will normally be our written answers to your security questionnaire and our current security documentation.

If that information is not enough, or a regulator requires it, you may carry out an audit, or appoint an independent auditor bound by confidentiality, once in any 12 month period, with at least 30 days notice, during normal business hours, and in a way that does not disrupt our business or compromise other customers' data. You will bear the costs of any audit unless it reveals a material breach of this Addendum.

13. Liability #

Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Agreement.

14. Governing law #

This Addendum is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex: details of the processing #

Subject matter Providing the Vero platform and related support and professional services
Duration The term of the Agreement, plus the export and deletion periods in section 11
Nature and purpose Storing, organising, displaying, analysing and transmitting data to manage quotes, scheduling, field service, compliance records, assets, payroll verification and customer communication. Using AI services to transcribe and structure engineer notes, read supplier price lists and draft quote wording
Categories of data subject Your employees and contractors, including engineers; your customers and their staff; site contacts and keyholders; your suppliers' contacts
Categories of personal data Names, job titles, work contact details; site addresses and access arrangements; engineer qualifications and training records; vehicle location, journey and timing data; timesheet and mileage data; photos and voice recordings captured on site; signatures on certificates and handover documents; account sign in and activity data
Special category data None intended. You should not enter special category data into Vero
Subprocessors As listed on our subprocessors page

Questions about this policy? Email hello@sentinelvero.com