MAINTRAL.

Data Processing Agreement

Last updated: July 6, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Maintral and the business using it (the “Operator”) and applies where Maintral processes personal data on the Operator’s behalf.

1. Roles

The Operator is the controller of its customers’ and staff personal data and determines the purposes and means of processing. Maintral acts as a processor on the Operator’s documented instructions (the Terms, this DPA, and use of the service). Where local law uses a different term (e.g. “data intermediary”), the equivalent role applies.

2. Scope

Subject matter: provision of the Maintral service. Duration: the account term plus the retention period. Data subjects: the Operator’s customers and staff. Data types: contact details, booking and transaction records, and staff/work records — and special-category data (e.g. health notes) only where the Operator chooses to enter it, processed strictly on the Operator’s instruction and lawful basis.

3. Our obligations

4. Sub-processors

The Operator authorises the sub-processors listed at /subprocessors. We impose data-protection terms on each no less protective than this DPA and remain responsible for them, and give notice of new sub-processors.

5. International transfers

Where processing involves a cross-border transfer we rely on an appropriate mechanism (EU/UK Standard Contractual Clauses / UK IDTA, adequacy where applicable, and the transfer requirements of the Thailand, Singapore, and Malaysia PDPAs).

6. Security

Encryption in transit and at rest, AES-256-GCM encryption of sensitive tokens, role-based access control, audit logging, backups, and an incident-response process.

To request our signed DPA or current sub-processor list, contact privacy@maintral.com.