Data processing terms
These data processing terms describe how TDH3 Systems Ltd processes personal data for a business customer using the paid TDH3 service. They form part of the TDH3 service terms unless the customer and TDH3 Systems agree a separate signed data processing agreement that expressly replaces them.
1. Roles and scope
For personal data a customer places in its operational workspace for its own business purposes, the customer normally acts as controller and TDH3 Systems acts as processor. TDH3 Systems separately acts as controller for its own sales enquiries, account and subscription administration, provider support administration, security and abuse records, and records it must keep for its own legal or business purposes.
2. Processing details
Subject matter: hosting and operating the TDH3 business-operations service and the customer workflows the customer chooses to use.
Duration: for the active customer relationship and the controlled export, retention, backup and deletion period after it ends.
Nature and purpose: storing, organising, retrieving, displaying, securing, backing up and otherwise processing customer data to provide authorised commercial, operational, planning, compliance, document, communication, purchasing, finance and field workflows.
Typical data: names, business contact details, account identifiers, customer and supplier contacts, job/site information, staff and subcontractor allocation details, qualification and competence evidence, operational notes, uploaded documents, communications records, delivery/evidence records and related audit data.
Typical data subjects: the customer's users, employees and subcontractors; its customers and site contacts; suppliers and their personnel; and other people whose business details are legitimately recorded by the customer.
3. Customer instructions
TDH3 Systems processes customer operational personal data only on the customer's documented instructions, including instructions expressed through authorised use of the service, unless UK law requires different processing. If TDH3 Systems considers an instruction to breach applicable data-protection law, it will inform the customer where legally permitted rather than silently expanding the processing purpose.
4. Confidentiality and security
People authorised by TDH3 Systems to process customer personal data must be subject to confidentiality obligations. TDH3 Systems uses technical and organisational measures intended to preserve confidentiality, integrity, availability and tenant isolation, including authenticated access, role and tenant boundaries, protected storage, security logging, controlled provider administration and resilience/recovery controls appropriate to the service.
5. Subprocessors
The core service currently relies on specialist infrastructure providers. TDH3 Systems remains responsible for imposing appropriate data-protection obligations on subprocessors used to process customer operational data. Material new subprocessors for customer operational data will be notified through the customer/service communication route so that a customer can raise a reasonable data-protection objection before the material change takes effect where required.
| Provider | Purpose | Customer operational data boundary |
|---|---|---|
| Supabase | Database, authentication and protected storage services | May process tenant account, operational and document data needed for the enabled service. |
| Vercel | Application hosting, delivery and runtime | May process application requests and customer data needed to execute authorised server routes. |
| Cloudflare R2 | Independent retained-document backup | May hold protected backup copies and verification metadata for documents included in the backup scope. |
Stripe is used for TDH3 Systems' own subscription billing and payment administration. It is not used as the storage system for customer operational records. Optional email, messaging, telephony, telematics, accounting or other integrations are not treated as live subprocessors merely because the product has an integration boundary; provider-specific processing starts only when an integration is actually approved, configured and enabled.
6. International transfers
Where a processing route creates a restricted transfer of personal data outside the UK, TDH3 Systems will use an applicable lawful transfer route, such as UK adequacy regulations or appropriate safeguards, and will carry out any transfer assessment required for the chosen safeguard. Provider locations and transfer arrangements are reviewed against the actual production service rather than assumed from product capability.
7. Individual rights and customer assistance
The customer remains the primary contact for rights requests concerning operational data it controls. Taking account of the nature of the processing, TDH3 Systems will provide reasonable technical and organisational assistance so the customer can respond to applicable access, correction, erasure, restriction, objection and portability requests. TDH3 Systems may require appropriate identity, authority and tenant-scope checks before carrying out an export or deletion instruction.
8. Security incidents and DPIAs
TDH3 Systems will notify the customer without undue delay after becoming aware of a personal data breach affecting personal data processed for that customer, and will provide information reasonably available to assist the customer with its obligations. TDH3 Systems will also provide reasonable assistance with security obligations, data protection impact assessments and regulator consultation where the nature of the processing requires it.
9. Return, deletion and backups
At the end of the service, customer operational data will be returned or deleted in line with the customer's documented instruction, subject to data that must be retained by law, an agreed legal hold, or controlled backup/recovery copies. Data removed from the live service may remain beyond normal use in protected backups until the applicable backup deletion cycle completes; it will not be restored into ordinary use except for legitimate recovery purposes.
10. Audit information
TDH3 Systems will make information reasonably necessary to demonstrate these processor obligations available to the customer and will support reasonable audits or inspections required by applicable data-protection law, subject to appropriate confidentiality, security, scope and non-disruption controls.
11. Customer responsibilities
The customer is responsible for the lawfulness of the personal data and instructions it provides, for minimising data placed in free-text fields and documents, for controlling authorised users, and for avoiding unnecessary special-category or criminal-offence data unless it has a defined lawful and operational need.
Contact
Raise a privacy or data-processing request →
Version 1.0 · Last updated: 27 August 2026.