UK GDPR & Data Protection Act 2018 Legal Schedule

Data Processing Agreement (DPA)

Effective Date: 5 August 2026 Blink Digital Services Limited ("Processor") & Customer ("Controller")

This Data Processing Agreement ("Agreement") forms part of the agreement between Blink Digital Services Limited ("Processor") and the customer using My Receipt Assistant ("Controller"). This Agreement applies where Blink Digital Services Limited processes Personal Data on behalf of the Controller in connection with the My Receipt Assistant service.

1

Parties

Data Controller

The Controller is the accounting practice, bookkeeper or other organisation subscribing to My Receipt Assistant and determining the purposes and means of processing Personal Data.

Data Processor
Blink Digital Services Limited
The Barns, Caverswall Common, Caverswall, Stoke-On-Trent, Staffordshire, ST11 9EU
Telephone: 01782 939079 | Email: hello@blinkdigital.uk
2

Definitions

For the purposes of this Agreement:

Controller: means the organisation that determines the purposes and means of processing Personal Data.
Processor: means Blink Digital Services Limited.
Personal Data: has the meaning given under the UK GDPR.
Processing: includes collecting, recording, storing, organising, transmitting, retrieving, deleting and otherwise handling Personal Data.
Data Subject: means the individual whose Personal Data is processed.
3

Purpose of Processing

The Processor shall process Personal Data solely for the purpose of providing the My Receipt Assistant service, including:

  • Creating user accounts
  • Receiving uploaded receipts and documents
  • Secure storage of documents
  • Making documents available to authorised users
  • Sending notifications
  • Providing customer support
  • Maintaining system security
  • Backups and disaster recovery
  • Improving and maintaining the service

The Processor shall not use Personal Data for its own marketing purposes or sell Personal Data to third parties.

4

Categories of Personal Data

Depending on how the Controller uses the Service, Personal Data may include:

  • Names
  • Email addresses
  • Telephone numbers
  • Business names
  • User account details
  • Receipt images
  • Invoice images
  • Expense claims
  • Financial transaction information
  • VAT information
  • Merchant names
  • Dates of transactions
  • Notes attached to uploaded documents
  • Device information
  • IP addresses
  • Login records

The Controller is responsible for determining what Personal Data is uploaded to the Service.

5

Categories of Data Subjects

Personal Data may relate to:

  • Clients of accounting firms
  • Sole traders
  • Company directors
  • Employees
  • Contractors
  • Business owners
  • Users of the My Receipt Assistant platform
6

Controller Obligations

The Controller confirms that it:

  • Has a lawful basis for processing Personal Data.
  • Has provided appropriate privacy information to Data Subjects.
  • Will comply with the UK GDPR and Data Protection Act 2018.
  • Will only upload Personal Data necessary for the purposes of the Service.
  • Is responsible for responding to Data Subject requests unless otherwise agreed.
7

Processor Obligations

Blink Digital Services Limited shall:

  • Process Personal Data only on documented instructions from the Controller unless required by law.
  • Ensure personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement appropriate technical and organisational measures to protect Personal Data.
  • Assist the Controller, where reasonably possible, in responding to Data Subject rights requests.
  • Assist the Controller in meeting obligations relating to security, breach notification, impact assessments and consultations with supervisory authorities where appropriate.
  • Make available information reasonably necessary to demonstrate compliance with this Agreement.
8

Security Measures

The Processor maintains appropriate technical and organisational security measures, including, where appropriate:

  • Encrypted communications using TLS
  • Password-protected user accounts
  • Role-based access controls
  • Secure cloud hosting
  • Firewall protection
  • System monitoring and logging
  • Regular security updates
  • Data backups
  • Access restricted to authorised personnel
  • Procedures for detecting and responding to security incidents

Security measures may be updated from time to time to reflect evolving technology and risks.

9

Sub-processors

The Controller authorises the Processor to use sub-processors where reasonably necessary to provide the Service.

Current sub-processors include:

Sub-processor Purpose
Amazon Web Services (AWS) Cloud hosting and infrastructure
DigitalOcean Cloud hosting and infrastructure
Stripe Payment processing
Google LLC (Google Analytics) Website analytics
Meta Platforms Ireland Ltd Advertising measurement and marketing analytics

The Processor will ensure that sub-processors are bound by contractual obligations that provide a level of data protection substantially equivalent to this Agreement.

The Processor may add or replace sub-processors from time to time and will maintain an up-to-date list available upon request or via its website.

10

International Transfers

Where Personal Data is transferred outside the United Kingdom, the Processor shall ensure appropriate safeguards are implemented in accordance with the UK GDPR, including:

  • UK International Data Transfer Agreement (IDTA)
  • UK Addendum to the EU Standard Contractual Clauses
  • Adequacy Regulations
  • Any other lawful transfer mechanism recognised under UK law
11

Confidentiality

The Processor shall ensure that all persons authorised to process Personal Data:

  • Are bound by confidentiality obligations.
  • Receive appropriate data protection training where necessary.
  • Only access Personal Data where required to perform their duties.
12

Personal Data Breaches

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller.

The notification will include, where reasonably available:

  • Nature of the breach
  • Categories of data affected
  • Likely consequences
  • Measures taken or proposed to mitigate the breach
13

Data Subject Requests

Where the Processor receives a request directly from a Data Subject regarding Personal Data processed on behalf of the Controller, the Processor shall, unless legally prohibited, promptly notify the Controller and will not respond directly except on the Controller's documented instructions.

14

Retention and Deletion

Upon termination of the Service, and subject to applicable legal obligations, the Processor shall, at the Controller's choice:

  • Return Personal Data in a commonly used electronic format; or
  • Securely delete Personal Data within a reasonable period.

Backup copies may remain until overwritten in accordance with the Processor's standard backup retention practices.

15

Audit Rights

The Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement.

Where reasonably required, and not more than once in any twelve-month period (unless required by law or following a confirmed security incident), the Controller may request reasonable evidence of the Processor's compliance.

Any audit shall:

  • Be conducted during normal business hours.
  • Be subject to reasonable notice.
  • Avoid disruption to the Processor's business.
  • Respect the confidentiality of other customers and the Processor's systems.

The Processor may satisfy audit requests by providing independent audit reports, certifications or security documentation where appropriate.

16

Liability

Each party's liability under this Agreement shall be subject to the limitations of liability contained within the main Terms of Service, except where liability cannot lawfully be excluded or limited under applicable law.

17

Term

This Agreement remains in force for as long as the Processor processes Personal Data on behalf of the Controller.

18

Governing Law

This Agreement shall be governed by and construed in accordance with the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction over any dispute arising from this Agreement.

Section link copied to clipboard!