Data Processing Agreement
This agreement applies where Show Works Ltd processes personal data on behalf of a customer of Rental Rodeo. It forms part of the Terms of Service and takes effect automatically when you subscribe — there is nothing to sign, though we will sign a copy on request. It is the agreement required by Article 28 of the UK GDPR.
1. Parties and roles
You are the controller. Show Works Ltd is the processor. You decide what personal data goes into your instance and why; we process it only for you.
Where we act as controller in our own right — your account and billing contacts, visitors to our website — that is covered by the Privacy Notice, not by this agreement.
2. Subject matter and scope
| Subject matter | Providing the Rental Rodeo hire-management service |
|---|---|
| Duration | For as long as your subscription lasts, plus the deletion period in section 10 |
| Nature and purpose | Hosting, storage, retrieval, display, transmission of documents and notifications, backup, and deletion — all as directed by your use of the software |
| Categories of data subject | Your customers and their contacts; your own staff and crew; your suppliers' contacts; people who use your hire shop or customer portal |
| Types of personal data | Names, business and personal contact details, postal and delivery addresses, order and hire history, correspondence and notes you record, documents you generate, portal and shop account details, signatures captured on delivery or compliance paperwork, photographs you attach to records, and staff activity in the audit log |
| Special category data | None is required by the service and none should be entered. If you choose to record it — for example a health note about a crew member — you remain the controller for it and must have your own lawful basis |
3. Our instructions
We process personal data only on your documented instructions. Your use of the software, and the settings you choose in it, are those instructions; anything else we will ask for in writing. We will tell you if in our opinion an instruction breaches data protection law.
The only exception is where UK or EU law requires us to process it otherwise, in which case we will tell you before we do, unless the law forbids that.
We do not use your data to train machine-learning models, we do not send it to anyone who does, and no part of your instance sends anything to a language model.
4. Confidentiality
Everyone we authorise to process your data is bound by a duty of confidence, and we limit access to those who need it to run the service or to fix a fault you have reported.
5. Security measures
We take the measures required by Article 32. In practice:
- your data is held on hardware we own and operate in the United Kingdom, in a database separate from every other customer's;
- all traffic is encrypted in transit over HTTPS; session cookies are secure and HTTP-only;
- passwords are hashed and never recoverable; access tokens expire;
- access to the software is role-based, and access to the servers is by SSH key only, limited to named staff;
- backups are taken hourly and again nightly, automatically verified, and monitored for failure;
- an audit log records security-relevant actions, including who changed what;
- updates, including security updates, are deployed automatically.
We keep these measures under review and may change them, provided the level of protection is not reduced.
6. Sub-processors
You give us general authorisation to use the sub-processors below. We remain responsible to you for what they do. Each is bound by written terms no less protective than these.
Some are optional — they do nothing unless you enable the feature, and several need you to supply your own account credentials. If you do not enable a feature, no data reaches that provider.
| Provider | What it does | What it receives | Where | Status |
|---|---|---|---|---|
| IONOS | Sending email — quotes, invoices, reminders, portal links | Recipient name and address, and the message itself | Germany (EEA) | Always on |
| Backblaze | Off-site backup of the virtualisation cluster, hourly | A copy of everything in your instance, as part of a whole-system backup | Amsterdam, Netherlands (EEA) | Always on |
| Stripe Payments Europe Ltd | Card payments | Payer name, email, amount. Card details are entered directly with Stripe and never reach us | Ireland (EEA) | Only with your own Stripe account |
| Google LLC | Calendar sync for transport and crew jobs | Job title, times, addresses and the crew named on it | USA / EEA | Only with your own Google credentials |
| OpenFreeMap / OpenStreetMap | Map tiles on the hire map | The viewer's IP address. The pins are drawn by us and are not sent out | EEA | Only if you show the hire map |
That is the complete list for your subscription. Show Works runs an instance of its own with further integrations, built around how Show Works works rather than as part of the product; they are not available to subscribers and no data of yours reaches them. If we ever add a provider to the list above, the notice below applies before any of your data goes near it.
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period and we will either not make the change for you, offer a workaround, or let you end your subscription without penalty for the unused period.
The off-site copy, plainly. It is held in a private bucket in Amsterdam, in the European Economic Area, reachable only with a credential we hold and never listed publicly. It is not encrypted at rest today. Our storage provider is in the process of making encryption at rest its default for all storage, and we will say so here once that applies to ours. We would rather write that down than describe a control we do not yet have.
7. International transfers
Your data is stored in the United Kingdom. Where an optional feature sends data to a provider outside the UK, that transfer is made under the UK adequacy regulations where they apply, and otherwise under the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, with a transfer risk assessment on file.
8. Helping you meet your obligations
Taking into account the nature of the processing, we will help you with:
- Requests from individuals. The software already lets you find, export, correct and delete a person's records yourself. If you need more than it can do, tell us and we will help. If a request comes to us directly we will not act on it — we will forward it to you promptly and tell the person we have done so.
- Impact assessments and prior consultation under Articles 35 and 36, with the information about our processing that only we hold.
- Security under Article 32, as set out in section 5.
9. Personal data breaches
We will tell you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. We will tell you what happened, which categories and roughly how many people and records are involved, the likely consequences, and what we are doing about it — and we will keep you updated as we learn more. Reporting to the ICO and to affected individuals is your decision as controller; we will give you what you need to make it.
10. Return and deletion
You can export your data yourself at any time while your subscription is live.
When it ends, we keep your instance for 30 days so you can ask for a complete export, which we provide free of charge in a machine-readable format. After that we delete the instance and its database.
Backups are a rolling set: on our own infrastructure the most recent 48 hourly database dumps and the most recent 14 nightly ones — about two days of hour-by-hour history and a fortnight of daily — plus the hourly off-site copy of the cluster described in section 6. Deleted data therefore persists in backups until it rotates out of both. We do not restore a backup to recover deleted data, and anything restored for disaster recovery has the deletion re-applied to it. We will certify deletion in writing on request.
We keep data beyond these periods only where UK law requires it — invoices and accounting records for six years — and we keep it only for that purpose.
11. Audit
On reasonable written notice, and no more than once a year unless a breach or a regulator requires otherwise, we will make available the information needed to demonstrate we are meeting this agreement, and allow an audit by you or an independent auditor you appoint who is not a competitor of ours. Audits are conducted during business hours, in a way that does not disrupt the service or risk other customers' confidentiality, and you bear your own costs.
12. Liability and changes
The liability provisions in the Terms of Service apply to this agreement. Where this agreement conflicts with the Terms of Service on the handling of personal data, this agreement prevails.
We may update this agreement to reflect a change in the law or in how the service works. If a change materially affects you we will give you at least 30 days' notice by email.