Data Processing Agreement
Last updated: 2026-09-13
This Data Processing Agreement ("DPA") forms part of the Terms of Service between BusyBee Hub Ltd (company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]) ("we", "us") and the customer who uses BusyBee Hub ("you"). You accept it when you accept the Terms. If this DPA and the Terms conflict on the processing of personal data, this DPA applies.
1. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018 and any other UK law about personal data that applies.
- Customer Personal Data means personal data you or your team put into BusyBee Hub, or that reaches BusyBee Hub from services you connect, which we process for you. It includes data about your customers, suppliers, tenants, contractors, property co-owners and the people you invite.
- Sub-processor means a company we engage to process Customer Personal Data.
- Personal Data Breach, controller, processor, data subject and processing have the meanings given in Data Protection Law.
2. Roles
You're the controller of Customer Personal Data and we're your processor. Schedule 1 describes the processing.
We're a separate controller of the personal data we use to run our own business, such as your account, subscription, support conversations and security logs. Our Privacy Policy covers that data, not this DPA.
3. Your responsibilities
You confirm that:
- you have a lawful basis for the Customer Personal Data you put into BusyBee Hub and for asking us to process it
- you've given the people concerned any privacy information Data Protection Law requires
- you won't put special category data (such as health information) or criminal offence data into BusyBee Hub unless it's necessary and lawful
- your instructions to us comply with Data Protection Law
4. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are the Terms, this DPA and the way you and your team use and configure BusyBee Hub, unless the law requires otherwise (in which case we'll tell you first, unless the law prevents it)
- tell you if we believe an instruction breaks Data Protection Law
- make sure anyone at BusyBee Hub who can access Customer Personal Data is bound by confidentiality
- keep the technical and organisational security measures in Schedule 2 in place
- help you respond to data subjects exercising their rights, taking into account the nature of the processing; much of this you can do directly in BusyBee Hub by editing or deleting records
- help you with security, breach notifications, data protection impact assessments and consultations with the ICO, where they relate to our processing
- make available the information you reasonably need to show that we comply with this DPA
5. Personal Data Breaches
If we become aware of a Personal Data Breach affecting Customer Personal Data, we'll tell you without undue delay and in any event within 48 hours. We'll give you the information we have about what happened, the data and people affected, the likely consequences and what we're doing about it, and update you as we learn more. Telling you about a breach isn't an admission of fault.
6. Sub-processors
You give us general authorisation to use Sub-processors. The Sub-processors we use today are listed in Schedule 3.
We'll tell you by email at least 30 days before we add or replace a Sub-processor. If you have reasonable data protection grounds to object, tell us within that period. We'll try to address your concern; if we can't, you can cancel your subscription before the change takes effect and we'll refund any amount you've paid for the period after cancellation.
We'll have a written contract with each Sub-processor that gives Customer Personal Data protections equivalent to this DPA, and we remain responsible to you for their work.
7. International transfers
Customer Personal Data is hosted in the UK. Where a Sub-processor processes it outside the UK, we'll make sure the transfer is covered by UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
8. Audits
If the information we provide under section 4 isn't enough to show that we comply with this DPA, you can ask to audit our compliance. You'll need to give us at least 30 days' written notice, carry out the audit during business hours without disrupting our service, keep what you learn confidential, and pay your own costs. Audits are limited to once a year unless there's been a Personal Data Breach or the ICO requires one.
9. Deleting and returning data
While you use BusyBee Hub, you can edit or delete records, and download your reports as CSV or PDF and an accountant pack for each tax year. You can ask us for a copy of other Customer Personal Data.
When your use of BusyBee Hub ends, Customer Personal Data is deleted:
- within 30 days of you asking us to delete your account or organisation, or
- automatically, when an organisation has been read-only for 12 months, after we've warned the owner by email at least 30 days in advance, as described in the Terms
Deleted data may remain in encrypted backups for a short period until they're overwritten. We'll keep Customer Personal Data longer only if the law requires it.
10. Services you connect
Some services you choose to use through BusyBee Hub aren't our Sub-processors:
- HMRC receives your submissions as a separate controller.
- TrueLayer provides the connection to your bank under its own authorisation from the Financial Conduct Authority, and is responsible as a controller for the data it collects from your bank to provide that service. We process the account and transaction data it passes to us as your processor.
- Your own Stripe account, if you connect one to take payments from your customers, is covered by your own agreement with Stripe.
11. Liability and duration
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law doesn't allow those limits. This DPA lasts for as long as we process Customer Personal Data for you.
Schedule 1: Details of the processing
Subject matter and purpose: providing BusyBee Hub as described in the Terms: keeping books and records, sending invoices, estimates and reminders, bank feeds and imports, property and tenancy management, CIS records, tax estimates and submissions to HMRC, reports, and Finble.
Duration: for as long as you use BusyBee Hub, and until the data is deleted under section 9.
Nature of processing: storing, organising, displaying, calculating, sending by email, reading uploaded documents with AI, transmitting to the services you connect, and deleting.
Data subjects:
- your customers and their contacts, including people who pay your invoices online
- your suppliers
- your tenants and property co-owners
- contractors you work for under CIS
- the team members and accountant you invite
- anyone else whose details appear in the records, documents or bank transactions you put into BusyBee Hub
Types of personal data:
- names, company names, email addresses, phone numbers and postal addresses
- VAT numbers and employer references
- invoice, payment, rent, deposit and transaction details
- bank account names, masked account numbers, balances and transactions
- the contents of receipts, statements and other documents you upload
- notes you add
Special category data: none intended.
Schedule 2: Security measures
- encryption in transit (TLS) and at rest
- HMRC and bank access tokens stored encrypted in a secrets vault
- row-level security in the database, so each organisation's data is only available to its members according to their role
- two-factor authentication available to all users and required for our staff
- a minimum password length of 12 characters, sign-in rate limits and bot protection on sign-in and registration forms
- bank sort codes and account numbers stored masked
- card details handled only by Stripe, and online banking credentials only by your bank and TrueLayer
- staff access limited by role, with staff actions such as suspending or deleting accounts recorded in an activity log
- error monitoring configured not to collect IP addresses or cookies, and, in our background functions, to remove access tokens, tax identifiers and HMRC fraud prevention data before reports are sent
Schedule 3: Sub-processors
- Supabase, Inc.: database, authentication, file storage and background functions. Location: London, UK.
- Vercel, Inc.: application hosting. Location: London, UK, with delivery through Vercel's global network.
- Vercel, Inc. (AI Gateway) and Google: AI processing for Finble and for reading uploaded receipts and statements. Location: may include the United States.
- Resend: delivery of the invoices, estimates, reminders and notifications sent from BusyBee Hub. Location: may include the United States.
- Functional Software, Inc. (Sentry): error monitoring. Location: may include the United States.
Version 2026-09-13

