Data Processing Agreement — Ireland
The Article 28 terms under which Cerrax processes your customers' personal data on your instructions.
This agreement forms part of the Terms of Service and applies whenever Cerrax processes personal data on your behalf. It uses the meanings given in the GDPR (Regulation (EU) 2016/679) and the Data Protection Act 2018. Where this agreement and the Terms conflict on data protection, this agreement governs.
1. Which of us is which
You are the controller of your customers’ personal data. We are your processor of it: we act on your instructions and for no purpose of our own. For your own account data — your name, your login, your firm’s settings and billing — we are a controller in our own right, and our Privacy Policy covers that.
2. What we process, and for how long
- Subject matter and purpose: producing removals quotations and supporting the jobs that follow from them, on your instructions.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Type of personal data: names, addresses, contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home.
- Categories of data subject: your customers, the people at the properties you move between, and the people you authorise to use Cerrax on your behalf.
We do not ask for and do not want special-category data. Please do not enter health, biometric or similar information into free-text fields.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and it is never used to identify anyone — so we do not treat it as biometric data. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
3. We act on your instructions
We process your customers’ personal data only on your documented instructions — which include your use of the product and this agreement — unless Union or Member State law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaches data protection law, we will say so.
4. Confidentiality
Everyone we allow to access your customers’ personal data is bound by confidentiality and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We take the technical and organisational measures Article 32 requires, described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.
6. Sub-processors
You give us general written authorisation to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We impose data protection obligations on each of them no less protective than these, and we remain fully responsible to you for their performance. We will give you reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve your objection, you may terminate.
7. Helping you meet your own obligations
Taking into account the nature of the processing, we will help you with requests from data subjects — access, correction, erasure, portability, objection — and with your duties under Articles 32 to 36 on security, breach notification and impact assessments. If a data subject contacts us directly about data we hold for you, we will refer them to you rather than answer for you. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and with the information you need to notify the Data Protection Commission within your 72 hours.
8. Deletion and return
At the end of the agreement you may ask us to delete or return your customers’ personal data, and we will do so within a reasonable period, except where Union or Member State law requires us to keep it. Committed pricing records are never silently altered — but personal identifiers within them can be redacted, which is how erasure is honoured without falsifying a record of what was quoted.
9. De-identified job data
Cerrax gets more accurate as it sees real outcomes. After personal data is deleted or redacted, we keep the de-identified shape of the job and what it cost — volume, distance, access, crew, hours, price — and we may continue to use it. This survives deletion and the end of this agreement, because by then it is no longer personal data.
We only treat data as de-identified once it can no longer be linked to a person, and we hold it to that standard before it is used this way.
10. Learning across firms
We use de-identified outcome data from across all firms using Cerrax, in every country, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations, and will allow and contribute to audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise.
13. International transfers
We hold your customers’ personal data in the United Kingdom, in London. That is a transfer out of the European Union, and it is lawful because the European Commission has decided that the United Kingdom provides an adequate level of protection (Decision (EU) 2021/1772, extended in 2025). You authorise it on that basis. Where a sub-processor processes data outside the EU and the UK, we rely on the EU standard contractual clauses (Decision (EU) 2021/914) with any supplementary measures the transfer needs. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
14. Contact
Data protection questions, data subject requests and breach notifications: hello@cerrax.io.