Ribbonmark
Home Privacy Terms DPA
Legal

Data processing addendum

Last updated 22 July 2026 · Ribbonmark is a product of Hili Limited

On this page 1. Definitions 2. Processing of personal data 3. Confidentiality & personnel 4. Security 5. Sub-processors 6. Assistance to you 7. International transfers 8. Personal data breach 9. Return & deletion 10. Audits 11. General Schedule A — Processing details Schedule B — Sub-processors

This Data Processing Addendum (the "DPA") forms part of the agreement between Hili Limited ("Ribbonmark", "we", "us") and the customer organisation named in the applicable order or account ("Customer", "you") governing use of the Ribbonmark website and application (the "Service"), including our Terms of Service (together, the "Agreement"). It applies wherever we process personal data on your behalf as your processor. If this DPA conflicts with the rest of the Agreement, this DPA prevails to the extent of the conflict in relation to the processing of personal data.

1. Definitions

  • "Data Protection Law" means all law applicable to the processing of personal data under the Agreement, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR").
  • "personal data", "controller", "processor", "data subject", "processing" and "personal data breach" have the meanings given in Data Protection Law.
  • "Customer Personal Data" means personal data that you (or your users) submit to the Service and that we process on your behalf, as described in Schedule A.
  • "Sub-processor" means a third party engaged by us to process Customer Personal Data in order to provide the Service.
  • "Restricted Transfer" means a transfer of Customer Personal Data out of the United Kingdom (or the European Economic Area, where EU GDPR applies) that would be prohibited by Data Protection Law without an appropriate safeguard.

2. Processing of personal data

For Customer Personal Data, you are the controller and we are your processor. We will process Customer Personal Data only:

  • to provide, maintain, secure and support the Service in accordance with the Agreement;
  • in accordance with your documented instructions, which the Agreement and your (and your users') use of the Service constitute; and
  • as required by law — in which case we will inform you of that legal requirement before processing, unless the law prohibits us from doing so.

We will not sell Customer Personal Data or use it for our own purposes. We will notify you promptly if, in our opinion, an instruction infringes Data Protection Law, or if we become unable to comply with this DPA, and in that case you may suspend the affected processing. The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Schedule A.

3. Confidentiality & personnel

We ensure that everyone we authorise to process Customer Personal Data is bound by contractual or statutory obligations of confidentiality, and that personnel with access to Customer Personal Data receive appropriate training on privacy, confidentiality and data security.

4. Security

We implement and maintain appropriate technical and organisational measures to protect the security, confidentiality and integrity of Customer Personal Data, designed to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include the measures described in section 7 of our Privacy policy: UK-region hosting, encryption in transit and at rest, database-level isolation of each organisation's data, access controls and logging. We keep these measures under review and will not materially reduce the overall security of the Service during your subscription.

5. Sub-processors

You give us general written authorisation to engage the Sub-processors listed in Schedule B, and other Sub-processors provided that we:

  • impose on each Sub-processor, by written contract, data protection obligations in substance no less protective than those in this DPA;
  • remain responsible to you for the performance of each Sub-processor's obligations; and
  • give you reasonable prior notice of any intended addition or replacement of a Sub-processor (by updating Schedule B and, where the change materially affects Customer Personal Data, notifying you directly).

You may object to a new Sub-processor on reasonable data-protection grounds within 30 days of notice. If we cannot offer a reasonable alternative, you may terminate the affected part of the Service and we will refund any prepaid fees for the unused period — this is your sole remedy for such an objection.

6. Assistance to you

Taking into account the nature of the processing, we will:

  • assist you, by appropriate technical and organisational measures and in a reasonable and timely manner, in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, objection, portability). If a data subject contacts us directly about Customer Personal Data, we will refer them to you and will not respond substantively except on your instruction or where required by law;
  • assist you in meeting your obligations regarding security, breach notification, data protection impact assessments and prior consultation with supervisory authorities, taking into account the information available to us; and
  • provide the information reasonably necessary to demonstrate our compliance with this DPA.

7. International transfers

We host Customer Personal Data — including evidence photographs — in the United Kingdom, and we will not make a Restricted Transfer unless it is covered by an appropriate safeguard under Data Protection Law: UK adequacy regulations, the UK International Data Transfer Agreement ("IDTA"), or the UK Addendum to the EU Standard Contractual Clauses (and, where EU GDPR applies, the EU Standard Contractual Clauses). Where a Sub-processor listed in Schedule B processes Customer Personal Data outside the UK, the relevant safeguard is noted there, and if EU GDPR applies to you, you consent to transfers from the EEA to the United Kingdom under the European Commission's adequacy decision for the UK.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for you to meet your own notification obligations, including (as it becomes available) the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will make reasonable efforts to identify the cause of the breach and to remediate it to the extent that doing so is within our control.

9. Return & deletion of data

On termination or expiry of the Agreement, we will make Customer Personal Data available for export for a reasonable period as described in the Agreement, and then, at your choice, return or delete it within 90 days — except where and for as long as applicable law requires us to retain it, in which case we will continue to protect it under this DPA and process it for no other purpose. Fire-safety records are intended to endure for the life of a building: it is your responsibility to export and retain the records you need before deletion.

10. Audits

We will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security documentation. Where required by Data Protection Law or a supervisory authority, we will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate (bound by appropriate confidentiality obligations), provided that: audits take place no more than once in any 12-month period except following a personal data breach or where required by a supervisory authority; the scope, timing and security controls are agreed in advance; audits are conducted during business hours with minimal disruption; and you bear the costs unless the audit reveals a material breach of this DPA.

11. General

This DPA is the parties' entire agreement on the processing of Customer Personal Data and supersedes any earlier arrangements on that subject. It takes effect when you accept the Agreement (or when the parties otherwise agree to it) and remains in force for as long as we process Customer Personal Data. Liability under this DPA is subject to the limitations and exclusions in the Agreement. This DPA is governed by the laws of England and Wales. Questions can be sent to info@ribbonmark.co.uk.

Schedule A — Details of processing

Subject matter: provision of the Service under the Agreement — capture, storage and synchronisation of fire-door installation and inspection records and evidence, generation of certificates and handover packs, and related hosting and support.
Duration: the term of the Agreement, plus the export and deletion period in section 9.
Nature and purpose: hosting, storage, retrieval, organisation, display, transmission, backup and deletion of data submitted to the Service, on your instructions, to deliver the Service.
Categories of data subjects: your users (operatives, office staff and other personnel you authorise); individuals appearing in or identifiable from records and evidence you capture, such as signatories named on certificates and people incidentally appearing in site photographs.
Types of personal data: names, work contact details, employer and job role, authentication identifiers, device and log data (including IP addresses), photographs and their embedded metadata (including time and approximate location), and names appearing in generated documents.
Special category data: none intended. Where an evidence photograph incidentally captures an identifiable person, you are responsible for the lawfulness of that capture.

Schedule B — Sub-processors

The Sub-processors we use to provide the Service, current and planned, are:

Sub-processorPurposeRegion & safeguard
Google Cloud PlatformApplication hosting and evidence storageUnited Kingdom (London)
NeonManaged databaseUnited Kingdom (London)
Auth0 (Okta)Identity and loginUnited Kingdom
PostHogProduct-usage analytics (pseudonymous usage events; no field records or evidence)European Union (Frankfurt) (UK adequacy regulations)
PowerSync (planned — not yet in use)Offline data synchronisationEuropean Union (UK adequacy regulations)
Stripe (planned — only once billing is enabled)Payment processingUnited States (IDTA / UK Addendum to the EU SCCs)

We will update this Schedule when Sub-processors change, in accordance with section 5.

Ribbonmark

Ribbonmark is a product of Hili Limited, registered in England & Wales, company number 17323707. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

ProductHow it worksA day on siteSecurityFAQ
Companyinfo@ribbonmark.co.ukPrivacy policyTerms of serviceData processing addendum

© 2026 Hili Limited. All rights reserved.Ribbonmark™ is a trademark of Hili Limited.