Legal

Data Processing Agreement

Effective 24 August 2026 · Cerrax Ltd, company no. 17360016, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ

This agreement forms part of the Terms of Service and applies whenever Cerrax processes personal data on your behalf. It uses the meanings given in the UK GDPR and the Data Protection Act 2018. Where this agreement and the Terms conflict on data protection, this agreement governs.

1. Which of us is which

You are the controller of your customers’ personal data. We are your processor of it: we act on your instructions and for no purpose of our own. For your own account data — your name, your login, your firm’s settings and billing — we are a controller in our own right, and our Privacy Policy covers that.

2. What we process, and for how long

  • Subject matter and purpose: producing removals quotations and supporting the jobs that follow from them, on your instructions.
  • Duration: for as long as your account is open, and afterwards only as section 8 allows.
  • Type of personal data: names, addresses, contact details, move dates, and details of the property and its contents that you or your customer enter.
  • Categories of data subject: your customers, and the people you authorise to use Cerrax on your behalf.

We do not ask for and do not want special-category data. Please do not enter health, biometric or similar information into free-text fields.

3. We act on your instructions

We process your customers’ personal data only on your documented instructions — which include your use of the product and this agreement — unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaches data protection law, we will say so.

4. Confidentiality

Everyone we allow to access your customers’ personal data is bound by confidentiality and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.

5. Security

We take appropriate technical and organisational measures, described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.

6. Sub-processors

You give us general authorisation to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We impose data protection obligations on each of them no less protective than these, and we remain responsible to you for their performance. We will give you reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve your objection, you may terminate.

7. Helping you meet your own obligations

Taking into account the nature of the processing, we will help you with requests from data subjects — access, correction, erasure, portability, objection — and with your duties on security, breach notification and impact assessments. If a data subject contacts us directly about data we hold for you, we will refer them to you rather than answer for you. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and with the information you need to notify the ICO.

8. Deletion and return

At the end of the agreement you may ask us to delete or return your customers’ personal data, and we will do so within a reasonable period, except where the law requires us to keep it. Committed pricing records are never silently altered — but personal identifiers within them can be redacted, which is how erasure is honoured without falsifying a record of what was quoted.

9. De-identified job data

Cerrax gets more accurate as it sees real outcomes. After personal data is deleted or redacted, we keep the de-identified shape of the job and what it cost — volume, distance, access, crew, hours, price — and we may continue to use it. This survives deletion and the end of this agreement, because by then it is no longer personal data.

We only treat data as de-identified once it can no longer be linked to a person, and we hold it to that standard before it is used this way.

10. Learning across firms

We use de-identified outcome data from across all firms using Cerrax to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.

11. Your numbers stay yours

Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.

12. Audit

We will make available the information you reasonably need to show we are meeting these obligations, and will allow and contribute to audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise.

13. International transfers

Where a sub-processor processes data outside the UK, we rely on an appropriate transfer mechanism such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Where your data is stored today is a question you can ask us at any time, and we will answer it for the day you ask.

14. Contact

Data protection questions, data subject requests and breach notifications: hello@cerrax.io.