Data Processing Agreement

Version 1.0 — effective 29 July 2026. This DPA forms part of the Platform Terms between the customer organisation (the controller) and PRODRO GROUP LIMITED (the processor) and sets out the terms required by Article 28 UK GDPR. For the processing where PRODRO GROUP LIMITED is itself the controller (accounts, security, billing, support), see the privacy notice.

1. What is processed, and why

  • Subject matter and duration:hosting and processing of the customer's grant-management records for as long as the customer uses the service, plus the retention period applying to each grant record.
  • Nature and purpose:storage, display, integrity-protection (hashing, append-only audit) and sharing on the customer's instructions of grant records, evidence documents, reports and related material.
  • Categories of data subjects:the customer's staff and volunteers; staff of counterpart organisations on shared grant records; and any individuals appearing in uploaded documents (which the platform asks uploaders to minimise and redact).
  • Categories of personal data:names, work contact details and roles; the content of uploaded documents and records. The service is designed NOT to hold beneficiaries' personal data; special-category data is not sought and should not be uploaded unless strictly necessary for the grant record.

2. Processor obligations

  • We process customer data only on the customer's documented instructions — which are: these terms, the platform's documented behaviour (including its append-only audit trail and write-once evidence), and the actions the customer's authorised users take in the product. We will tell the customer if we believe an instruction infringes data protection law.
  • Everyone processing customer data for us is bound by confidentiality obligations.
  • We assist the customer, so far as reasonably possible, with data subject rights requests, security, breach notification, and data protection impact assessments relating to the service.
  • We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information a controller needs for its own 72-hour obligations.
  • At the end of the service we return or delete customer data as described in the Platform Terms (export always available; deletion subject to grant-record retention and the shared, append-only audit trail, which the customer instructs us to maintain as part of the service).
  • We make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits (on reasonable notice, no more than annually unless a breach has occurred, at the customer's cost).

3. Security measures

Measures in place today — each of these is implemented in the product, not aspirational:

  • Mandatory multi-factor authentication (authenticator app) for every account; passwords stored only as salted scrypt hashes; repeated failures lock the account; sessions are revocable, expire after inactivity, and are revoked on credential resets.
  • All traffic encrypted in transit (TLS); data encrypted at rest by our hosting providers.
  • Org-scoped access control: every grant-record read and write passes a single authorisation choke point; permissions are explicit per member and enforced server-side.
  • Evidence files are write-once and SHA-256 hashed at upload; every change to any record is written to a hash-chained, append-only audit log enforced by database triggers.
  • Backups are managed by our database provider; restore is tested.

4. Subprocessors and transfers

  • The customer gives general authorisation to the subprocessors listed at /subprocessors. We will give at least 30 days' notice (in the app or by email) before adding or replacing a subprocessor, and the customer may object on reasonable data-protection grounds — if we cannot resolve the objection, the customer may terminate and export.
  • Each subprocessor is bound by a written contract imposing data-protection obligations equivalent to this DPA; we remain responsible for their performance.
  • Where processing involves a transfer outside the UK, it is protected by the provider's UK GDPR-compliant transfer mechanism (the UK International Data Transfer Agreement or Addendum to EU Standard Contractual Clauses). Current transfer positions are stated honestly on the subprocessor page.

5. Liability and contact

Liability under this DPA is subject to the limits in the Platform Terms. Data-protection contact: Kieran McCloud, kieran@prodro.co.uk. PRODRO GROUP LIMITED, company no. 17268651, 71-75, Shelton Street, London, England, WC2H 9JQ.