The short version
This is the data processing agreement, version 1, dated 27 September 2026. It forms part of our Terms of Service and applies to every customer workspace, from the day the workspace is opened. You do not need to sign anything for it to apply.
When you keep records about other people in DockLedger, such as your drivers, the contacts at your carriers and suppliers, and your own staff, you decide what happens to them. The law calls you the controller and us the processor. We act only on your instructions, and this agreement sets out what we promise in that role, as Article 28 of the UK GDPR requires.
If your procurement team needs a signed copy, email hello@dockledger.co.uk and we will sign this same text.
1. Who this is between, and who does what
This agreement is between you, the business that holds a DockLedger workspace, and Angelo Guedes, a sole trader established in England and Wales trading as DockLedger ("DockLedger", "we", "us"). They are the same parties as the Terms of Service.
For the records you and your users keep in your workspace, you are the controller and we are your processor. This agreement covers that data.
For the data about your own account with us (who signed up, billing, support conversations and our security logs), we are the controller. Our privacy policy covers that, not this agreement.
Words such as controller, processor, personal data, processing and personal data breach mean what they mean in the UK GDPR and the Data Protection Act 2018.
2. What it covers and for how long
What it covers: the personal data in the records you and your users keep in your workspace, and what we do with it to run DockLedger for you.
How long: from the day you open a workspace for as long as we hold any of those records, which is until they are deleted under clause 11.
3. What we do with your records, and why
We process your records only to provide DockLedger to you. In practice that means:
- Storing them in our database and file storage in London, and showing them to the people you give logins to, including the hauliers and suppliers you send portal links to.
- Printing and emailing them when your users ask, for example a delivery note, a label or an evidence pack.
- Receiving a carrier's vehicle position for a booked load from that carrier's telematics account, while the load is booked, and showing it on your yard board.
- Working out routes and drawing maps, which sends a delivery address to our mapping provider when your user asks for it.
- Answering a question your user asks the console assistant (clause 13 says exactly what is sent).
- Reading a photograph of a delivery note into proposed lines, when your user asks for it. The photograph goes to Anthropic as it is, and nothing it returns is saved until your user confirms it.
- Syncing contacts, invoices and product codes to Xero or Sage, only if you connect them.
- Keeping backups and error reports, so the service can be restored and fixed.
We do not sell your records, use them for advertising, use them to train AI models, or use them for any purpose of our own.
4. The data and the people it is about
The people your records are about:
- Drivers who deliver to or collect from your sites.
- Contacts at your carriers, suppliers and customers.
- Your own staff, including console users and people using the floor apps.
- Hauliers and suppliers who use the portal links you send them.
- People who sign for a delivery on a phone.
The kinds of personal data:
- Names, phone numbers and email addresses.
- Vehicle registrations.
- Arrival, departure and waiting times, and which bay a vehicle used.
- Positions: a vehicle's position from a carrier's telematics account while a load is booked (kept 30 days, then deleted); the latest position a driver chooses to share from their phone on the way in, which stays on the booking; and the phone's position, with its accuracy, when a delivery is signed for.
- Delivery signatures, and photographs of delivery paperwork, which can show names and signatures.
- Your staff's logins: name, email address, role, and a record of what they did in DockLedger.
- Anything your users type into notes and other free-text fields.
DockLedger is not built for special category data, such as health information, or for criminal records. Please do not put either into it.
5. Your instructions
We process your records only on your documented instructions, including about sending them outside the UK (clause 13). Your instructions are:
- the Terms of Service and this agreement;
- the settings you choose and the modules you switch on; and
- what your users do in DockLedger, and anything else you ask us in writing at hello@dockledger.co.uk.
If an instruction would need work outside the normal service, we will tell you and agree it with you first.
If we think an instruction breaks data protection law, we will tell you straight away, and we do not have to follow it until that is resolved.
If the law makes us process your records in some other way, for example under a court order, we will tell you before we do it, unless the law forbids us from telling you.
6. Confidentiality
Everyone we allow to process your records is bound to keep them confidential, either by a written agreement or by a legal duty. Only people who need access to run, support or fix DockLedger have it.
In the normal course, nobody at DockLedger reads your records. Our support desk reads the support conversations you start. Our customers page shows us, for each workspace, the plan, when someone last signed in, activity counts, the state of any integrations and open support tickets. It does not show your records.
Direct access to the database is limited to DockLedger’s owner and the automated jobs that run the service. The owner opens a customer’s records only to fix a problem, to act on that customer’s instructions, to investigate a security incident, or when the law requires it. The access controls are described on our security page.
7. Security
We keep in place at least the technical and organisational measures listed under "How the wall is built", "What DockLedger staff can see" and "If something goes wrong" on our security page, as they stood on the date of this version.
We may change those measures as the product changes, but not in a way that lowers the overall protection of your records.
8. Sub-processors
You give us general permission to use the suppliers listed in the table in our privacy policy that handle the records you keep in DockLedger. The table says what each one does, what data it receives and where it processes it.
Stripe and Better Stack do not handle those records. Xero and Sage are not our sub-processors. When you connect them, your records go to your own account there on your instruction, and your agreement with Xero or Sage covers what happens next.
Before we add or replace a sub-processor that will handle your records, we will email the account owner at least 30 days beforehand and update the table.
If you object on reasonable data protection grounds, tell us within those 30 days. We will talk it through and, where we can, offer a way to keep your records away from that supplier. If we cannot resolve it, you may cancel, and we will refund any period you have paid for beyond the date of the change.
Each sub-processor is bound by a written contract that places on it the same data protection obligations as this agreement. We remain responsible to you for what they do with your records.
9. Helping you with people's rights
People your records are about can ask to see, correct, erase or take a copy of their data, or object to its use. Most of this you can do yourself: your users can look up, correct and export records, and clear a contact's details, from the console.
Erasing one person across every booking, for example a driver's name and phone number, is not yet something the console does. Ask us and we will do it by hand within 30 days of your instruction. Where a legal duty to keep a delivery record applies, we keep the record and remove what we can.
If someone contacts us directly about records you control, we will pass the request to you within 5 working days and act on your instructions. We will not answer it ourselves, other than to tell the person we have passed it on.
10. Breaches, and help with your other duties
If we become aware of a personal data breach affecting your records, we will tell you without undue delay, and within 72 hours of becoming aware of it. We will tell the account owner by email:
- what happened;
- what data, and roughly how many people, are affected;
- what is likely to happen to the people affected;
- what we have done about it;
- what you should do; and
- who to contact at DockLedger for more information.
If we do not know everything at first, we will tell you what we know and follow up as we find out more. We record every breach in our incident register, whether or not it has to be reported.
Because you are the controller of these records, deciding whether to report the breach to the ICO and whether to tell the people affected is yours. We will give you the information you need to do it.
We will also help you, as far as the information we hold allows, with your own security duties, data protection impact assessments, and consulting the ICO before high-risk processing (Articles 32 to 36 of the UK GDPR). Where that help would take more than a few hours, we may agree a fee with you before we start.
11. At the end: return and deletion
While your subscription is active you can export your records from the console. After you cancel, the console closes, so ask us and we will send you your records in a machine-readable format.
You can ask for your workspace to be deleted at any time from the console (the account menu, then Your workspaces). The deletion date is then shown to everyone in the workspace, and any owner can call it off for 7 days.
We delete the workspace within 30 days of the request, and in any case no later than 90 days after your subscription ends. The only exceptions are our own billing records for your account, which UK tax law requires us to keep for six years, and any records you have asked us in writing to keep.
When the 7 days are up, the workspace and its records are deleted automatically overnight. Stored files, such as photographs, are removed within 30 days of the request. If nobody asks, we delete the workspace by hand no later than 90 days after your subscription ends.
Our database provider takes a backup every day and keeps each one for 7 days, so deleted records drop out of those backups within 7 days. We do not restore a backup except to recover the service.
12. Audits and information
We will give you the information you reasonably need to show that this agreement is being kept, including answers to your security questionnaires.
You, or an independent auditor you appoint who is bound to confidentiality, may audit our compliance with this agreement. Give us 30 days' written notice. Audits are limited to one in any 12 months, unless there has been a breach affecting your records or a regulator asks for one. We may first offer written answers and evidence; if they do not settle your question, the audit goes ahead. Each of us pays our own costs.
13. Sending data outside the UK
Your records are stored in London, on Supabase (eu-west-2), and the site's server functions run in London, on Vercel.
The console assistant uses Anthropic, in the USA. When one of your users asks the assistant a question, the question goes to Anthropic with the counts, references, times, carriers and bays for the screen in view. Personal fields (driver names, phone numbers, vehicle registrations, signatures, positions and email addresses) are removed before anything is sent. Two other features also use Anthropic, and both send personal data. The delivery-note reader sends the photograph as it is: it can show names and signatures, and nothing is removed from it. Support chat sends the text your user types. Anthropic does not use any of this to train models. These transfers are covered by the standard contractual clauses in Anthropic's data processing terms, with the UK International Data Transfer Addendum.
Error reports go to Sentry, in the EU. Before a report leaves, DockLedger removes link tokens, email addresses, phone numbers and database key details from it.
Resend, in the USA, sends the emails your users ask for, such as delivery notes.
Any other sub-processor that handles your records outside the UK is shown with its location in the sub-processor table. Each such transfer is covered by UK adequacy regulations, by the UK-US data bridge where the supplier is certified under it, or by the standard contractual clauses with the UK International Data Transfer Addendum. We will not start a new transfer of your records outside the UK without the notice in clause 8.
14. Liability, and how this fits with the Terms
This agreement forms part of the Terms of Service. Our liability under it is subject to the limits in clause 11 of the Terms, except where the law does not allow liability to be limited.
If this agreement and the Terms disagree about personal data you control, this agreement wins.
We may update this agreement in the same way as the Terms (clause 14): if a change materially affects you, we will email the account owner at least 30 days beforehand, and you may cancel before it takes effect. Each version is numbered and dated at the top of this page.
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
15. Getting hold of us
For a rights request or a privacy concern, email security@dockledger.co.uk. For a signed copy, an audit or anything else about this agreement, email hello@dockledger.co.uk. A real person reads both.