Version 2.0.0Status: PublishedAudience: BUSINESS_OWNER

Data Processing Addendum (DPA)

Effective: 8 October 2026·Last Updated: 8 October 2026

Managed Policy Notice

This document reflects the platform operational specifications and UK GDPR data architecture. Business subscriber schedules and tenant-specific policies supersede standard operational schedules where agreed in writing.

This Data Processing Addendum ("DPA") supplements the Pro TeamX Terms of Service between Pro SolutionX LTD ("Processor") and the Customer ("Controller"). It reflects the mandatory contractual terms required under Article 28 of the UK GDPR and EU GDPR for the processing of personal data.

1. Processing Scope & Instructions

The Controller appoints the Processor to process personal data solely on the documented instructions of the Controller for the purpose of providing field service management SaaS functionality.

The subject matter, duration, nature, and purpose of processing are defined in Schedule 1 to this Addendum.

2. Technical & Organizational Security Measures

The Processor implements robust security measures including AES-256 encryption at rest, TLS 1.3 encryption in transit, strict multi-tenant logical partitioning, role-based access control, and automated audit logging.

All personnel authorized to process personal data have committed to strict confidentiality obligations.

3. Authorized Subprocessors

The Controller provides general written authorization for the Processor to engage the cloud subprocessors listed in our Privacy Policy and subprocessor registry.

The Processor shall notify the Controller of any intended changes concerning the addition or replacement of subprocessors, giving the Controller the opportunity to object on reasonable data protection grounds.

4. Security Incidents, Assistance & Audits

The Processor shall notify the Controller without undue delay upon confirming a personal data breach affecting Customer Data, and shall provide reasonable assistance to fulfill statutory notification duties.

Upon termination of the SaaS agreement, the Processor shall, at the choice of the Controller, delete or return all Customer Data, unless statutory record-keeping regulations require continued preservation.

Questions or Data Subject Rights?

To exercise statutory privacy rights under UK GDPR or ask compliance questions, visit our Privacy Center or contact our Data Protection Officer at privacy@prosolutionx.com.