Data processing agreement
These are our standard processor terms for RAMSReady. They apply where you use the service to process personal data for which you are the controller, which is the normal position for an organisation account.
Version 1, 9 October 2026. If your organisation has its own data processing agreement, send it to us and we will review and sign it instead.
1. The parties and their roles
- Controller: you, the customer organisation.
- Processor: Bloor Engineering Ltd, registered in England and Wales, company number 14230472, registered office 11 Pennine Way, Swadlincote, Derbyshire DE11 9EX.
- Contact for data protection: george@bloorengineering.com.
Where you are a sole trader using the service for yourself, you are the data subject rather than a controller, and our privacy notice governs instead.
2. What is processed
- Subject matter and purpose: providing RAMSReady to you, namely the health and safety documents you generate, and your account details.
- Nature of the processing: storage, retrieval, generation of documents from the information you supply, and transmission to the AI providers listed in our privacy notice.
- Categories of data subject: your employees and any other people named in the documents you create.
- Types of personal data: names, contact details, job roles, and whatever else you choose to enter into your records. We do not require special category data and ask that you do not enter it.
- Duration: for as long as your account is active, plus the retention periods in our privacy notice.
3. Our obligations as processor
Under Article 28(3) of the UK GDPR we will:
- (a) process personal data only on your documented instructions, including on transfers, unless we are required to do otherwise by law, in which case we will tell you first unless the law forbids it.
- (b) ensure that everyone authorised to process the data is under a duty of confidence.
- (c) take the security measures required by Article 32, which are set out in section 4.
- (d) not engage another processor without your prior authorisation. The sub-processors we currently use are named in our privacy notice, which we update before any change takes effect. Each is bound by terms no less protective than these.
- (e) help you respond to requests from individuals exercising their rights.
- (f) help you meet your obligations on security, breach notification, impact assessments and consultation with the ICO.
- (g) delete or return the personal data when the service ends, unless we are required by law to keep it, and tell you which applies.
- (h) give you the information you need to show compliance, and allow and contribute to audits and inspections.
If we think an instruction from you would breach data protection law, we will tell you rather than simply carry it out.
4. Security measures
- All traffic between the user and the service is encrypted in transit with TLS over HTTPS.
- The connection between the application and the database is encrypted with TLS 1.3, and the application verifies the database server's certificate, so the link cannot be silently intercepted.
- Passwords are stored only as hashes.
- Card details go directly to Stripe. We never receive or store full card numbers.
- The application reaches the database through an account limited to the specific tables it needs, rather than an administrative account.
- Records are separated by account, and a request can only read records belonging to the signed in account.
- A full database backup is taken nightly, copied to separate off-site storage, verified after the copy, and retained for 14 days. Failures raise an alert.
- Access to production systems is limited to the people who need it for operating or repairing the service, under confidentiality obligations.
We will not materially reduce these measures during the term.
5. Personal data breaches
We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data, so that you have time to meet your own 72 hour duty to the ICO. The notification will describe what happened, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we cannot give you everything at once we will give you what we have and follow up.
6. International transfers
Your records are stored in Helsinki, Finland, which is in the European Economic Area and covered by the United Kingdom's adequacy findings, so no additional safeguard is needed for storage. Some of our sub-processors are in the United States. Those transfers rely on the UK Extension to the EU to US Data Privacy Framework, or on the standard contractual clauses in the relevant provider's terms. The current list, with the basis for each, is in our privacy notice.
7. AI processing
The service generates documents by sending the information you enter to the AI providers named in our privacy notice. They are used under paid API terms that do not permit them to train their models on your content. If you would rather your data were not processed this way, the service cannot function, so please do not upload it.
8. Audit, term and signature
You may audit our compliance with these terms once a year on reasonable notice, or more often following a breach, and we will answer a security questionnaire instead where that satisfies you. These terms take effect when you start using the service and end when your account closes and the retention periods in our privacy notice expire.
We are a small company and these are our standard terms rather than a negotiated contract, so they are not solicitor drafted. We would rather sign your own data processing agreement than have you accept wording you are not comfortable with. Email us and we will turn it round quickly. For a countersigned copy of this document on letterhead, ask and we will send one.