Data Processing Agreement
Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between CLRD Technologies Ltd, a company registered in England and Wales (company number 16970508) ("CLRD", "Processor"), and the customer ("Controller") who creates an account on clrd.app and uses the Service to process personal data. By creating an account or continuing to use the Service, the Controller accepts this DPA. It governs the processing of personal data carried out by CLRD on behalf of the Controller in accordance with the United Kingdom General Data Protection Regulation (UK GDPR).

1. Scope and Definitions

This DPA applies to all activities in which CLRD or its Subprocessors process personal data on behalf of the Controller in connection with the Controller's use of the Service. Terms used in this Agreement shall be understood as defined in the UK GDPR. The Controller is the "controller" and CLRD is the "processor".

2. Subject Matter and Duration

CLRD processes personal data so the Controller can produce, store, and submit regulator-ready DNO documentation (G98, G99, G100 and related ENA connection forms, including the EVCP & HP Connections Form) and related compliance records. Processing begins when the Controller's account is created and continues for the term of the Controller's subscription, ending when the account is closed and any retention obligations under section 11 are fulfilled.

3. Nature, Purpose and Categories

3.1 Nature of the processing

Collection, recording, organisation, structuring, storage, retrieval, adaptation, use, disclosure by transmission (to Distribution Network Operators), restriction, erasure and destruction of personal data.

3.2 Purpose

To enable the Controller (a UK renewable installer) to gather installation data, generate compliance documentation, transmit it to relevant DNOs, and maintain an immutable audit trail of the resulting compliance pack.

3.3 Categories of data subjects

3.4 Categories of personal data

4. Duties of the Processor

  1. CLRD shall process personal data only on the documented instructions of the Controller (which include the Controller's use of the Service and the Service's published functionality), unless required by law to process otherwise. Where law requires other processing, CLRD shall inform the Controller of that requirement before processing, unless prohibited from doing so.
  2. CLRD shall not use personal data provided to it for any purpose other than the agreed processing, and in particular shall not use it for its own purposes.
  3. CLRD shall ensure that persons authorised to process personal data are bound by an obligation of confidentiality and have received appropriate data-protection training.
  4. CLRD shall assist the Controller, by appropriate technical and organisational measures and to the extent reasonably possible, in fulfilling its obligations to respond to data-subject requests under Articles 15–22 UK GDPR.
  5. CLRD shall assist the Controller in ensuring compliance with Articles 32–36 UK GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to CLRD.
  6. CLRD shall make available to the Controller all information necessary to demonstrate compliance with this DPA.
  7. Personal data is processed in the United Kingdom and the European Economic Area. Any transfer to a third country requires appropriate safeguards under Chapter V UK GDPR (e.g. an International Data Transfer Agreement or addendum).

5. Security of Processing

CLRD implements and maintains the technical and organisational measures set out in Annex 1 to ensure a level of security appropriate to the risk. Measures may evolve in line with the state of the art and operational best practice provided that the level of protection is not reduced. Material changes will be reflected in this DPA.

6. Rectification, Deletion and Restriction

CLRD shall rectify, delete, restrict or block personal data processed under this DPA only on the Controller's documented instructions or where required by law. Standard self-service controls are provided in the Service.

7. Subprocessors

The Controller hereby grants CLRD general written authorisation to engage the Subprocessors listed in Annex 2. CLRD shall:

8. Rights and Obligations of the Controller

  1. The Controller is responsible for the lawfulness of the processing it instructs and for safeguarding the rights of data subjects.
  2. The Controller shall ensure it has a valid legal basis under UK GDPR for the personal data it uploads to or generates within the Service.
  3. Where the Controller uses the Service on behalf of installation companies it represents (agency accounts), the Controller warrants that it is authorised — as controller, or on behalf of the relevant controller — to instruct the processing carried out through its account.
  4. The Controller may verify CLRD's compliance with this DPA by reviewing the most recent security documentation provided by CLRD on request, and where reasonably necessary by a written audit no more than once every 12 months, on at least 30 days' written notice and without unduly disrupting CLRD's operations. Audits by third parties that compete with CLRD may be refused.

9. Personal Data Breach Notification

CLRD shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Controller's data. The notification will include, to the extent then known:

CLRD will support the Controller in fulfilling its obligations under Articles 33 and 34 UK GDPR.

10. Instructions

The Controller's documented instructions are issued through the Service's user interface and configuration, the CLRD API (including webhook endpoints the Controller configures), the Service's published documentation, and explicit written communications sent through our contact form. CLRD shall promptly inform the Controller if, in CLRD's opinion, an instruction infringes UK data-protection law, and may suspend execution of the instruction until it is confirmed or amended.

11. Termination

On termination of the Service contract or on the Controller's earlier written request, CLRD shall, at the Controller's choice, return or delete all personal data processed on the Controller's behalf, and delete existing copies, unless retention is required by law. Where the Controller does not communicate a choice within 30 days of termination, CLRD will delete the data. Backup copies are overwritten in the ordinary course of operation within 90 days.

12. Liability

Each party's liability arising out of or in connection with this DPA is governed by the limitations and exclusions set out in the Terms of Service, subject to any liability that cannot be limited or excluded by applicable law. Nothing in this DPA limits a data subject's rights against either party under UK GDPR.

13. Miscellaneous

  1. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force.
  2. This DPA forms part of, and is governed by the same law as, the Terms of Service. In the event of conflict between this DPA and the Terms of Service in respect of personal data processed by CLRD on the Controller's behalf, this DPA prevails.
  3. CLRD may update this DPA from time to time to reflect changes in operations, applicable law, or Subprocessors. Material changes will be notified to the Controller by email or in-Service notice. Continued use of the Service after such notice constitutes acceptance of the updated DPA.

Annex 1 — Technical and Organisational Measures

CLRD applies measures appropriate to the risk to ensure the confidentiality, integrity, availability and resilience of personal data, including:

Annex 2 — Approved Subprocessors

CLRD currently uses the following Subprocessors:

Updates to this list will be published on this page with reasonable advance notice before any new Subprocessor begins processing.

Contact

For questions about this DPA or to exercise your rights, please use our contact form.