Data Processing Agreement

Version 2026-10-08 · last updated 2026-10-08

This agreement forms part of the Terms of Service between the Customer (the controller) and Ebrora (MWaste, the processor) and sets out the terms required by Article 28 of the UK GDPR for the personal data in the Customer's records. It is accepted at sign-up and the version accepted is recorded on the company.

1. Subject matter, duration, nature and purpose

Subject matterPersonal data contained in the records the Customer creates in MWaste.
DurationFor as long as the Customer's company exists in MWaste, plus the 30-day deletion window.
NatureHosting, storage, display, computation (drivers' hours, CO₂, pricing), document generation, email delivery, export, and submission to Defra when switched on.
PurposeProviding the MWaste service as described in the Terms.
Data subjectsThe Customer's staff and drivers; its customers' and third parties' contacts; signatories on documents; vehicle keepers where identifiable.
CategoriesNames, work contact details, roles; driver licence and qualification details; vehicle positions and three-word addresses; photos and signatures; hours and fatigue data; incident reports; commercial records. No special-category data is required by the service; incident reports may incidentally contain health information the Customer chooses to record.

2. Processor obligations

MWaste will:

  • process the personal data only on the Customer's documented instructions — which are: the Terms, this agreement, the settings the Customer's Owners and Admins choose in the app, and the actions its users take — unless UK law requires otherwise, in which case MWaste tells the Customer first where the law allows;
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement the technical and organisational measures in section 4;
  • engage sub-processors only under section 3;
  • help the Customer respond to data-subject requests, using the export and deletion tools in the app and by email where those do not suffice;
  • help the Customer with security, breach notification, data protection impact assessments and consultations with the ICO, taking account of the information available to MWaste;
  • delete or return the data at the end of the service under section 6;
  • make available the information needed to show compliance and allow audits under section 7;
  • tell the Customer immediately if an instruction, in MWaste's opinion, infringes data protection law.

3. Sub-processors

The Customer gives general authorisation for the sub-processors below, and for MWaste to add or replace sub-processors on at least 30 days' notice by email to Owners and by updating the sub-processors page. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved the Customer may terminate and export under the Terms. MWaste imposes on each sub-processor data-protection terms no less protective than this agreement and remains liable for their performance.

Sub-processorPurposeLocation
Vercel Inc.Application hosting, serverless functions, CDN, build pipelineFunctions and data in London (lhr1); global edge network; USA for build and support
Neon Inc.PostgreSQL databaseUK (London, AWS eu-west-2) — encrypted at rest and in transit
Cloudflare, Inc.Object storage (R2) for photos, signatures, documents and exportsWestern Europe storage; global network
Resend, Inc.Transactional email (invites, alerts, digests, customer packs)USA (international transfer safeguards: UK IDTA / Addendum)
Stripe Payments Europe, Ltd.Subscription billing and card paymentsEU / USA (Stripe's own safeguards)
Google LLCSign in with Google (only when a user chooses it) (only when used)Global; EU / USA
Microsoft Corporation (Entra ID)Sign in with Microsoft 365 (only when a company enables it) (only when enabled)EU / USA
Functional Software, Inc. (Sentry)Error monitoring (only when a dsn is configured)EU (Frankfurt) or USA depending on configuration
what3words LtdThree-word addresses on signatures and positionsUK
Routing provider (openrouteservice / Mapbox, as configured)Road routes and ETAs on the Live Map (only when a routing key is configured)EU (openrouteservice, Heidelberg) or USA (Mapbox)
Esri (ArcGIS)Satellite map tiles (proxied through MWaste)USA / global CDN
OpenStreetMap FoundationStreet map tiles on the Live MapUK / EU
Defra (Digital Waste Tracking service)Receipt-of-waste submissions — only when an Owner switches submission on (only when switched on)UK (government service)

4. Security measures

  • Encryption in transit (TLS 1.2+) and at rest for the database and file storage; secrets encrypted with rotated keys.
  • Every record and file scoped to the Customer's company; role-based permissions; optional depot restriction; customer-portal and API scopes limited to the customer's own records.
  • Two-factor authentication (required for Owners and Admins); session and device management; sign-in throttling and lockouts; CSRF and origin checks; security headers and a content security policy.
  • Audit logging of every change (who, when, what); legal records are superseded, never silently altered.
  • Signed, expiring links for documents; uploads scanned for type and size; photo and document keys never guessable.
  • Hosting in the UK with providers holding ISO 27001 / SOC 2 attestations; database backups with point-in-time recovery; monitoring and alerting of errors and cron failures.
  • Access by MWaste staff limited to what support requires, logged, and under confidentiality.

5. Personal data breach

MWaste notifies the Customer's Owners without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Customer's data, with the information Article 33(3) requires as it becomes available, and cooperates in the Customer's response.

6. Deletion and return

At any time the Customer can export every register and document from the app. When the company is deleted (Owner action with a 30-day cooling-off) all personal data in the Customer's records is permanently deleted after the 30 days, from live storage and, as backups expire, from backups, except where UK law requires MWaste to keep it. A tombstone without personal data is kept.

7. Audit

MWaste provides, on request and no more than once a year unless a breach or regulator requires more, the information reasonably necessary to demonstrate compliance with this agreement (including sub-processor attestations where available) and allows an audit by the Customer or an independent auditor it appoints, on 30 days' notice, during business hours, under confidentiality, at the Customer's cost unless it reveals a material breach.

8. International transfers

Data is held in the UK and the EEA except where a sub-processor listed above processes limited data elsewhere; each such transfer is covered by UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.

9. Liability and precedence

Each party's liability under this agreement is subject to the limits in the Terms, save that nothing limits liability to data subjects under the UK GDPR. If this agreement conflicts with the Terms on data protection, this agreement prevails.

Contact for data protection matters: support@mwaste.co.uk.