AAquino Command

Data Processing Agreement

Customer control, documented instructions.

1. Processing details

Subject matter: operation, security, support and authorised integration of the Customer’s Aquino workspace. Duration: the subscription plus the agreed return, deletion and backup-retention period. Purpose: managing roofing enquiries, customers, follow-ups, calls, quotes, calendar items, documents, users and service administration.

Data subjects: the Customer’s prospects, customers, staff, subcontractors and other business contacts. Personal data: identity and contact details, enquiry content, property or job information, communications, scheduling data, call metadata, quotes, account activity, uploaded business documents and technical audit data. The service is not intended for special-category data unless specifically agreed in writing.

2. Instructions

Aquino processes customer data only on documented instructions from the Customer, including the configuration and ordinary use of the service, unless UK law requires otherwise. Aquino will inform the Customer before legally required processing unless the law prohibits that notice, and will notify the Customer if an instruction appears to infringe applicable data-protection law.

3. Confidentiality and security

Anyone authorised to process customer data must be bound by confidentiality. Aquino will maintain measures appropriate to the risk, including authenticated access, server-enforced company membership and roles, workspace-scoped queries, encrypted integration secrets, signed inbound webhooks, restricted file handling, audit records and incident procedures.

4. Sub-processors

The Customer gives general written authorisation for sub-processors needed for hosting, authentication, email delivery, connected Google services, billing and support. Aquino will impose materially equivalent data-protection obligations and remain responsible for its sub-processors’ performance. The active provider list must be supplied in the order form or service schedule, and the Customer may raise a reasonable data-protection objection to a material new sub-processor.

5. Individual rights

Taking account of the nature of processing, Aquino will provide reasonable assistance with access, correction, deletion, restriction, objection and portability requests. Workspace owners can export data and correct or delete operational records, subject to permissions, retention commitments and human review for irreversible actions.

6. Compliance assistance

Aquino will provide reasonable information and assistance for security obligations, personal-data-breach assessment, data-protection impact assessments and regulator consultation, considering the processing and information available to Aquino. Each party remains responsible for its own legal duties.

7. Incidents

Aquino will notify the Customer without undue delay after becoming aware of a personal-data breach affecting customer data, provide available information about its nature and likely impact, take reasonable containment and remediation steps, and provide updates as the investigation develops.

8. Return and deletion

At the end of the service, and at the Customer’s choice, Aquino will return or delete customer data unless UK law requires retention. The Customer should take a workspace export before closure. Residual copies in controlled backups are isolated from ordinary use and removed according to the documented backup-retention cycle.

9. Audits

Aquino will make information reasonably necessary to demonstrate compliance with these processor obligations available to the Customer. On reasonable notice, the Customer may conduct or appoint an auditor to conduct a proportionate audit, subject to confidentiality, security and avoidance of disruption or access to other customers’ data.

10. International transfers

Aquino will not make a restricted transfer of customer data without a lawful transfer mechanism and required safeguards. The applicable hosting location, transfer mechanism and activated sub-processors must be recorded in the customer service schedule.

11. Priority and changes

If this DPA conflicts with the main service terms on processing customer personal data, this DPA takes priority. Any customer-specific processing instructions, approved special-category data or transfer arrangements must be written into the signed order form or schedule.