Data Processing Agreement
Last updated: 11 July 2026
Plain summary: When you use our free CRM to store your own customers' data, you are the "controller" and we are your "processor". This agreement is the standard UK GDPR contract that governs that relationship. It applies automatically when you sign up for a CRM account, with no separate signature required.
1. Parties
Processor: DNO Renewables Ltd, a company registered in England and Wales (No. 15929837), whose registered office details are available on request.
Controller: the installer, company or individual who registers for and uses the DNO Renewables CRM.
2. Scope
This DPA applies whenever the Controller uses the free DNO Renewables CRM to store, process or manage personal data of end customers, site occupants, or any other third parties whose data the Controller uploads into the CRM.
This DPA does not apply to data about the Controller themselves (their own account details, company info, etc.). That relationship is governed by our Privacy Policy.
3. Categories of Data & Data Subjects
The Controller may upload the following categories of personal data about the following categories of data subject:
- •Data subjects: the Controller's end customers, homeowners, business occupants, and their nominated contacts
- •Categories of data: name, contact details (email, phone), site address, MPAN, technical site details, uploaded documents (LOAs, SLDs, photos)
- •Special category data: none is expected. The Controller must not upload special category data (health, biometric, etc.) into the CRM.
4. Processor Obligations
We will:
- •Process the Controller's data only on the Controller's documented instructions (as expressed through use of the CRM's features)
- •Ensure that people authorised to access the data are bound by confidentiality
- •Implement appropriate technical and organisational security measures (see Section 7)
- •Assist the Controller in responding to data subject requests, data protection impact assessments, and communications with the ICO, where reasonably possible
- •Notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting their data
- •Delete or return all of the Controller's data within 30 days of termination of the CRM account, save where retention is required by law
- •Make available to the Controller all information necessary to demonstrate compliance with UK GDPR Article 28, and allow for reasonable audits
5. Controller Obligations
The Controller warrants that they:
- •Have a lawful basis for processing the personal data they upload
- •Have provided (or will provide) all necessary privacy notices to their data subjects
- •Have obtained any consents required to share the data with us as their processor
- •Will not upload special category data or data of children under 16 without prior written agreement
- •Are responsible for the accuracy and lawfulness of data they enter into the CRM
6. Sub-Processors
The Controller authorises us to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Base44 | Hosting, database, file storage, authentication | EU / UK |
| Email delivery provider | Sending transactional CRM notifications | EU / UK |
We will give the Controller at least 30 days' notice before engaging any new sub-processor by publishing an update to this list. If the Controller objects, they may terminate their CRM account and have their data returned.
7. Security Measures
We maintain the following technical and organisational measures:
- •Encryption in transit (TLS 1.2+)
- •Encryption at rest for database and file storage
- •Role-based access controls; least-privilege for engineering staff
- •Row-level security, so each Controller can only access their own CRM data
- •Regular backups; documented recovery procedures
- •Secure credential storage; multi-factor authentication for privileged accounts
- •Audit logging of privileged administrative actions
8. International Transfers
Where any sub-processor is located outside the UK/EEA, transfers are made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, with appropriate supplementary measures where required.
9. Term & Termination
This DPA takes effect when the Controller registers for a CRM account and continues until the CRM account is closed. On termination, we will delete or return the Controller's data within 30 days, unless retention is required by law.
10. Governing Law
This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales.
11. Contact
For any question about this DPA or to exercise rights under it, contact info@dnorenewables.co.uk.