Back to home

Data Processing Agreement

Last updated: 23 August 2026

This agreement governs our processing of personal data on your behalf. It applies in addition to the Terms of Service and is concluded automatically when you create a Werkea account — you do not need to sign anything for it to apply. If your own compliance process requires a signed copy on paper or as a countersigned PDF, write to hello@werkea.com and we will provide one.

Where this agreement and the Terms of Service conflict on the handling of personal data, this agreement takes precedence.

The parties, and who is who

You — the contractor or company holding the Werkea account — are the controller.

Ovanth Systems LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, company number 17412466 ("Werkea", "we") is the processor.

This agreement covers the data you enter about your own customers: their names, addresses, contact details, the job notes, quotes, projects, photos and renders you create for them. It also covers what you record about the people who work for you — the worker names and hours you enter in site diary entries. It does not cover your own account data — your name, email, company details and billing — because for that we are the controller in our own right, and the Privacy Policy explains it.

It is concluded under Art. 28(3) UK GDPR and Art. 28(3) EU GDPR, and, where your business is in Switzerland, under Art. 9 revFADP.

What we process, and for how long

Subject matter: providing the Werkea service to you.

Duration: for as long as your account exists, and afterwards only as set out under "Deletion and return" below.

Nature and purpose: storing, organising, transmitting and displaying the records you create; transcribing voice recordings you dictate; generating draft quote line items from those notes; structuring dictated site diary notes into a dated record; generating illustrative renders from photos you upload; sending quotes and notifications to the recipients you choose.

Categories of data subjects: your customers and prospective customers; the people who work for you, where you name them in a site diary entry; and any other individual you name in a job note, quote, project or diary entry.

Types of personal data: names, postal addresses, email addresses, telephone numbers, job and site descriptions, quote and pricing details, photographs of job sites, worker names and hours worked, and any other personal data you choose to enter into a free text field.

Special category data: Werkea is not designed or intended for special category data under Art. 9 GDPR, nor for criminal offence data under Art. 10. Do not enter it. If you do, you do so as controller and on your own assessment of the lawfulness of doing so.

Our instructions

We process this personal data only on your documented instructions. Using the product is itself an instruction: creating a customer, dictating a note, generating a quote or a render, saving a site diary entry, and sending a quote each instruct us to carry out that processing. The Terms of Service and this agreement are your standing documented instructions; further instructions can be given at hello@werkea.com.

We do not use the personal data you enter for our own purposes. In particular, we do not sell it, we do not use it to advertise to anyone, and we do not use it to train AI models. Our AI providers process it to return a result to you and, under our agreements with them, do not use it to train their models.

Where we are required by UK or EU law to process the data beyond your instructions, we will tell you before doing so unless that same law forbids telling you.

If we consider an instruction of yours to infringe data protection law, we will tell you promptly and may suspend that instruction until it is resolved.

Confidentiality

Everyone we allow to access this personal data is bound by a duty of confidentiality, and access is limited to the people who need it to run and support the service.

Security

We take the measures required by Art. 32 GDPR. Concretely, as the product stands today:

Data is held in the EU. The database, authentication and file storage all run in Supabase's Stockholm region; the server functions that read them run in Vercel's Stockholm region.

Data is encrypted in transit over TLS, and encrypted at rest by our hosting provider. Third-party access tokens we hold on your behalf are additionally encrypted by us with AES-GCM before being stored.

Tenant isolation is enforced in the database itself. Every table carrying customer records has row-level security switched on, and every policy is scoped to the company of the signed-in user, so one account cannot read another's rows even if the application layer is wrong.

Passwords are never stored by us in readable form — authentication is handled by Supabase, which stores a hash. Accounts can enable two-factor authentication, and sign-in attempts are rate limited.

Error reports sent to our monitoring provider are stripped of personal data before transmission: no request bodies, no cookies, no customer records.

You can export everything in your account, and permanently delete the whole account and its content, yourself from Settings at any time.

We may change these measures as the product develops, provided the level of protection is not reduced.

The measures above are also kept internally as a formal technical and organisational measures record, reviewed at least once a year, which we can provide on request to support your own due diligence.

Sub-processors

You give us general authorisation to engage sub-processors. The ones we use today, what each does and where it processes, are listed in the Privacy Policy, which forms part of this agreement.

We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain fully liable to you for their performance.

We will tell you before adding or replacing a sub-processor, with at least 30 days' notice. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative; if none is workable, you may terminate the affected part of the service and stop paying for it, without penalty.

[TO DO BEFORE LAUNCH: countersigned processing agreements in place with each sub-processor named in the Privacy Policy. Most of them publish a standard DPA that is accepted online — but accepting each one is a step that has to actually be done, and this clause promises it has been.]

International transfers

Some of our sub-processors process data outside the UK, the EEA and Switzerland — the Privacy Policy says which and where. Where they do, the transfer is covered by appropriate safeguards: the processor's certification under the EU-US Data Privacy Framework, or the EU standard contractual clauses together with the UK International Data Transfer Addendum and, for Swiss data, the FDPIC-recognised amendments to those clauses.

We do not transfer this personal data to a country without such safeguards in place.

Helping you with data subject requests

Werkea gives you direct access to the data in your account, so you can answer most requests yourself: you can view, correct, export and delete any customer record from within the app.

Where a request needs more than that, we will help you, taking into account the nature of the processing and the information available to us. If a data subject contacts us directly about data you control, we will not answer the substance of it — we will forward it to you without undue delay and tell the person to contact you.

Personal data breaches

If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay, and in any case within 48 hours of becoming aware of it. The notification will describe what we know: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.

Notifying the supervisory authority and, where required, the affected individuals is your responsibility as controller. We will give you the information you reasonably need to do it.

We will also assist you, on request, with data protection impact assessments and prior consultations under Art. 35 and Art. 36 GDPR, to the extent the information is available to us.

Deletion and return

You can export your data at any time from Settings, in a single file, in a machine-readable format. That is the return mechanism under Art. 28(3)(g), and it stays available for as long as your account exists.

Cancelling a subscription does not delete anything: your account and its content stay as they are, without paid access, until you delete them.

Deleting the account removes your company's records and files from our live systems immediately. Our hosting provider does not currently take automated backups of this data on the plan we use, so once deletion runs, that data cannot be recovered by us or by our hosting provider.

We keep no copy beyond that, except where UK or EU law requires us to — for example, billing records, which are our own controller data, not yours.

Audits and information

On reasonable written request, and not more than once a year unless a supervisory authority requires otherwise or there has been a breach affecting your data, we will give you the information you need to demonstrate that we meet our obligations under this agreement.

That will normally be answers to a written questionnaire and copies of any certifications or audit reports we or our sub-processors hold. Where that is genuinely not enough for you to satisfy your own obligations, we will agree an on-site or remote audit with you, at reasonable notice, during business hours, subject to confidentiality, and without unreasonable disruption to the service.

Liability, term and governing law

This agreement starts when you create your account and ends when your account is deleted. The clauses on deletion, confidentiality and liability survive it.

The limitation of liability in the Terms of Service applies to this agreement as well, except where data protection law does not allow it to. Nothing here limits a data subject's rights against either of us.

This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, on the same basis and subject to the same mandatory local rules as set out in the Terms of Service.

Where the EU standard contractual clauses apply to a transfer under this agreement, the governing law and jurisdiction those clauses require prevail for that transfer.

We use cookies to measure how visitors reach werkea.com and to show relevant ads. Nothing loads until you say yes. Privacy policy