Data Processing Agreement
Effective 23 September 2026 · Iskal Limited
This Agreement applies when Iskal processes personal data for a business customer (the Controller) while providing Iskal services.
Instructions and purpose
Iskal processes personal data only on documented Controller instructions, unless law requires otherwise, to provide, secure, support and maintain selected Iskal functions. Processing may include collection, storage, organisation, access, transmission to the Controller, export and deletion of job-request information.
Data and security
Data may include homeowner contact details, addresses, work descriptions, answers, photos, measurements, budgets, notes and related files. Iskal restricts production-data access to authorised people with a business need and applies controls appropriate to risk. It will assist with data-subject requests, incidents and impact assessments where required.
Subprocessors and transfers
Iskal may use subprocessors needed to provide the service, subject to appropriate safeguards. The public register is at /subprocessors/. Where required, Iskal uses an approved transfer mechanism and safeguards.
Deletion and return
On valid Controller instruction or service termination, Iskal will return, delete or genuinely anonymise active Controller personal data within 30 days, subject to law and reasonable technical time. Protected backups may remain only until their cycle expires, with a maximum 90-day target; they are isolated from ordinary use and are not deliberately restored into active processing. A separate Iskal-controlled homeowner identity may be retained only with its own lawful basis and never to reveal the Controller's prior job data to another tradesperson.
Audit and precedence
Iskal will make reasonable compliance information available. A Controller may request a reasonable audit annually, or more often for a regulator, serious incident or credible concern. This DPA prevails on personal-data processing where it conflicts with the main agreement.