Roles
This agreement applies where App-Artery processes personal data on a workshop's behalf. It forms part of our terms of service.
The workshop is the controller. App-Artery is the processor. The workshop decides what personal data is recorded and why; we process it only on the workshop's documented instructions, which include the instructions given by using the features of the service.
We will tell the workshop if we believe an instruction breaches data protection law.
Subject matter and duration
Subject matter: providing workshop management software.
Duration: for as long as the workshop holds an account, and for any period afterwards during which we are required to retain records.
Nature and purpose: storing, organising and displaying records of customers, vehicles and work carried out on them, and sending emails the service generates.
Categories of data subject: the workshop's customers, and the workshop's own staff who hold accounts.
Categories of personal data: names, telephone numbers, email addresses, postal addresses, vehicle registrations and vehicle details, service and repair history, and prices charged. No special category data is required by the service, and it should not be entered into it.
Sub-processors
The workshop authorises the following sub-processors:
- Amazon Web Services (AWS): hosting, database and storage, in the London region, eu-west-2.
- Amazon Simple Email Service (AWS SES): transactional email, being invitations and password resets.
We will give notice before adding or replacing a sub-processor, and the workshop may object on reasonable data protection grounds.
Security measures
The measures below are the ones actually in place. We have deliberately not listed anything we do not do.
- Data encrypted at rest, and in transit over TLS.
- The database is not reachable from the internet; it sits in private subnets and accepts connections only from the application.
- Role-based access control within the application, with four roles, so that staff see only what their role allows. A workshop's records are separated from every other workshop's at the point of every query.
- Passwords stored using a one-way hash, never in a recoverable form.
- Access to production systems restricted to App-Artery personnel who need it.
- Daily backups, retained for seven days.
We do not currently hold ISO 27001, SOC 2 or an equivalent certification, we do not carry out formal penetration testing, and we do not operate 24-hour monitoring. We would rather say so than imply otherwise.
Confidentiality
Anyone we authorise to process the workshop's personal data is bound by a duty of confidence.
Assisting the controller
We will help the workshop respond to requests from data subjects, and to meet its obligations on security, breach notification and data protection impact assessments, taking into account what we know and what the service can do.
If we become aware of a personal data breach affecting the workshop's data, we will tell the workshop without undue delay and give them what we know, so that they can meet their own 72-hour obligation.
International transfers
The workshop's data is processed in the United Kingdom, in the AWS London region. We do not transfer it outside the United Kingdom, and there is therefore no transfer mechanism to describe.
If that changes, we will give notice first and put an appropriate safeguard in place before any transfer.
Deletion and return
On request, and at the end of the agreement, we will delete or return the workshop's personal data. Deleting a customer in the application removes their record and everything attached to it immediately.
We keep only what law requires us to keep, and for no longer than it requires.
Audit
We will make available the information reasonably needed to show that we are meeting this agreement, and will contribute to an audit conducted by the workshop or an auditor it appoints, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.