Data Processing Agreement
Last updated: July 6, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Maintral and the business using it (the “Operator”) and applies where Maintral processes personal data on the Operator’s behalf.
1. Roles
The Operator is the controller of its customers’ and staff personal data and determines the purposes and means of processing. Maintral acts as a processor on the Operator’s documented instructions (the Terms, this DPA, and use of the service). Where local law uses a different term (e.g. “data intermediary”), the equivalent role applies.
2. Scope
Subject matter: provision of the Maintral service. Duration: the account term plus the retention period. Data subjects: the Operator’s customers and staff. Data types: contact details, booking and transaction records, and staff/work records — and special-category data (e.g. health notes) only where the Operator chooses to enter it, processed strictly on the Operator’s instruction and lawful basis.
3. Our obligations
- Process only on documented instructions; flag instructions that appear unlawful.
- Keep personnel under confidentiality; apply appropriate technical and organisational security.
- Assist with data-subject requests, DPIAs, and regulator engagement.
- Notify the Operator without undue delay of a personal-data breach with the detail needed to meet their deadlines.
- Delete or return personal data on termination, subject to legal retention.
4. Sub-processors
The Operator authorises the sub-processors listed at /subprocessors. We impose data-protection terms on each no less protective than this DPA and remain responsible for them, and give notice of new sub-processors.
5. International transfers
Where processing involves a cross-border transfer we rely on an appropriate mechanism (EU/UK Standard Contractual Clauses / UK IDTA, adequacy where applicable, and the transfer requirements of the Thailand, Singapore, and Malaysia PDPAs).
6. Security
Encryption in transit and at rest, AES-256-GCM encryption of sensitive tokens, role-based access control, audit logging, backups, and an incident-response process.