This agreement is part of the Tipslip terms of service (legal/terms-of-service.md). It applies automatically when you accept those terms. You do not need to sign it. If you want a signed copy, ask us and we will countersign the version in Annex 4. The text is the same.
It meets Article 28(3) of the UK GDPR [B1, B19].
1. Who is who
1.1 You (the firm) are the controller of the personal data in your records: your customers and producers, your drivers, and the waste records they appear in.
1.2 We (Skrivon Ltd, trading as Tipslip) are your processor for that data. We process it only to provide Tipslip to you.
1.3 Schedule 1 describes the data, the people it is about, and what we do with it.
1.4 This agreement does not cover data we control ourselves: your account and office-user details, billing records, support emails, and our security logs. Our privacy notice covers those [URL of legal/privacy/customers.md].
1.5 Words like "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" mean what they mean in the UK GDPR.
2. Your instructions
2.1 We process your personal data only on your documented instructions. Your instructions are:
- the terms of service and this agreement;
- the choices you make in Tipslip's settings and by using it (for example, adding a driver, entering a Defra API code for a site, emailing a transfer note to a customer);
- any other written instruction you give us that we agree to.
2.2 Sending receipt records to Defra's service is processing on your instruction. Once Defra receives a record, Defra is a separate controller of it. We are not Defra's processor and Defra is not ours.
2.3 If the law requires us to process your data in a way you have not instructed, we will tell you first, unless the law forbids that.
2.4 We will tell you if we think an instruction breaks data protection law. We do not have to follow an instruction we reasonably believe is unlawful.
2.5 Your confirmation. You confirm that you are allowed to give us these instructions, and that you have a lawful basis for the processing. In particular, as the employer, you confirm you have met your own obligations for capturing your drivers' location, photos and signatures: telling your drivers in advance, a lawful basis, and a data protection impact assessment. We provide templates to help [URL of legal/templates/]. They are not legal advice.
3. What we will not do with driver data
3.1 We will not:
- use driver location, photos, signatures or signed names for any purpose of our own, including product analytics, benchmarking, machine learning or model training;
- build profiles of drivers, or combine your driver data with another firm's;
- sell, rent or share driver data with anyone other than recipients you instruct and the sub-processors in clause 6;
- add continuous or background location tracking. Tipslip takes one location fix when a driver confirms a job, and no other;
- send Defra any driver data beyond the fields the statutory record needs. Tipslip sends Defra no GPS positions, photos or signatures.
3.2 If we ever want to change what the driver app captures, we will give you at least 30 days' notice first, so you can update your own notices and assessment.
4. Our own limited use
4.1 Separately from clause 2, we act as a controller for a small number of our own purposes:
- keeping Tipslip secure, including platform logs;
- counts per firm for running our business (for example number of sites, drivers, jobs and submissions, and time to first accepted receipt);
- statistics combined across firms that cannot identify any person or firm. That means no driver- or job-level rows in any output, no location data, and no figure describing fewer than 5 firms or drivers [B20];
- a minimal record of each submission we sent to Defra for you, kept after the contract ends (clause 10.3).
4.2 We do not use your customers' or drivers' details for our own marketing.
5. Confidentiality and security
5.1 Everyone we allow to access your personal data is bound by a duty of confidentiality, in their contract or by law. We allow access only to people who need it to run, support or secure Tipslip.
5.2 We take the security measures in Annex 2, which we believe are appropriate to the risk [B7]. We may change them, but not in a way that makes them less protective overall.
6. Sub-processors
6.1 You give us general permission to use sub-processors. Our current list, with what each does and where, is at legal/sub-processors.md [published URL TBC].
6.2 Each sub-processor is bound by a written contract with data protection terms that give at least the same protection as this agreement. We remain responsible to you for their work.
6.3 New sub-processors. We will email your account owner at least 30 days before a new sub-processor starts processing your personal data. If we are replacing one with a directly equivalent service purely for security or availability, we will give 14 days' notice and say why.
6.4 Objecting. You can object by emailing support@tipslip.co.uk within the notice period, with your reasons. We will try to resolve it. If we cannot, you can end the affected service and we will refund any fees you have paid for the time after it ends.
7. Helping you with data subject rights
7.1 Tipslip lets you find, view and correct most records yourself. Your owners and admins can download all of your firm's data, or one driver's jobs, locations, photos and signatures, from the office app.
7.2 If a data subject (for example one of your drivers or customers) contacts us directly about your data, we will not answer the request ourselves. We will pass it to you within [2 working days] and tell them we have done so.
7.3 We will help you answer requests within the legal time limit, as far as we reasonably can given what the service holds [B5].
8. Other help we give you
8.1 We will give you reasonable help with:
- security of processing;
- data protection impact assessments, including our own assessment of driver location, photo and signature capture, and the product facts you need for yours;
- any prior consultation with the ICO.
8.2 Help beyond what Tipslip's standard documents and tools provide may be charged at a reasonable rate, agreed in advance. Help with a breach that we caused is always free.
9. Personal data breaches
9.1 If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any event within 48 hours of becoming aware of it, even if we are still finding out what happened. We aim to tell you within 24 hours of confirming it.
9.2 We will tell you what we know: what happened, what data and roughly how many people are affected, the likely consequences, and what we are doing about it. If we do not know everything yet, we will tell you what we have and update you as we learn more.
9.3 We will help you decide whether to report to the ICO within its 72-hour deadline and whether to tell the people affected [B3]. The decision and the report are yours. We will not contact the ICO or your data subjects about your data without your agreement, unless the law requires us to.
10. When the contract ends
10.1 Return. You can export all your personal data at any time, and after the contract ends as follows:
- days 1 to 30: your account is read-only and you can export it yourself;
- days 31 to 90: we will provide a full export on request, within [10 working days].
The export includes every record, all photos, signatures and PDFs, and submission history, in common formats.
10.2 Deletion. After day 90, we delete your personal data from Tipslip, including files in storage, and ask our sub-processors to do the same. Copies in backups are deleted when those backups expire, within [35 days — to confirm, P-011]. If you ask us in writing to delete sooner, we will, once you confirm you have kept any records the law requires you to keep.
10.3 What we keep. The law requiring you to keep waste records applies to you, not to us [B19]. We keep only:
- a minimal submission ledger: for each record we sent to Defra, the IDs, times, status and a fingerprint (hash) of the content, but not the content itself. We keep it for 6 years as a controller, to show what we sent if there is a dispute [B25];
- anything else the law requires us to keep, which we will tell you about.
11. Showing we comply, and audits
11.1 We will make available the information you reasonably need to check we comply with this agreement. We start with written answers and our security overview [URL TBC].
11.2 If that is not enough, you can carry out a remote audit (document review and questions to our staff) once a year, at your cost, on 30 days' written notice. You or your auditor must keep what you learn confidential and must not see other firms' data.
11.3 We allow on-site audits only where a regulator requires one.
11.4 You can audit more often after a personal data breach affecting your data, or if a regulator requires it.
12. International transfers
12.1 Tipslip's database is in the UK (Supabase, London). File storage is in the same Supabase project; we are confirming its region with Supabase. The office app and its background processing run in the UK (Vercel, London).
12.2 Some sub-processors may process personal data outside the UK. Annex 3 lists each one we know of, and the safeguard we rely on. We will not transfer your personal data outside the UK without one of these safeguards in place [B6]:
- a UK adequacy decision (for example for the EEA);
- the UK-US Data Bridge, where the US recipient is certified;
- the UK International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses.
13. Liability
Each party's liability under this agreement is subject to the limits in clause 12 of the terms of service. Those limits do not affect a data subject's own rights against either of us under the law.
14. Changes and conflicts
14.1 We may update this agreement in the same way as the terms of service (clause 17 there). We will not reduce the protection it gives your data without 30 days' notice and the right to cancel.
14.2 If this agreement and the terms of service disagree about personal data, this agreement wins.
Schedule 1. Details of the processing
Subject matter. Providing Tipslip: recording waste movements, producing transfer notes and receipts, sending receipt records to Defra's service, and storing and exporting the records.
Duration. The length of the contract, then until deletion under clause 10.
Nature. Collection through the driver and office apps, storage, organisation, retrieval, display, producing PDFs, emailing documents to recipients you choose, sending records to Defra, export, and deletion.
Purpose. To let you record and evidence waste movements and meet your duty of care and digital waste tracking obligations.
People the data is about.
- your drivers;
- your customers and waste producers, including householders and sole traders;
- contacts at receiving sites, brokers, dealers and other carriers named on your records.
Categories of personal data (from legal/data-map.md):
| Category | What it includes |
|---|---|
| Driver identity and login | Full name; a hashed PIN (never the PIN itself); last login time; an offline login credential held on the phone. No driver email or phone number. |
| Driver location fix | One latitude and longitude with accuracy, and the time, taken once when a driver confirms a job. |
| Device identifier | A random identifier for the phone, used for support and to spot duplicates. |
| Photos | Photos of the load and skip. They may incidentally show people, number plates or property. |
| Signatures | Drawn signature images and printed names of drivers and, optionally, customers. |
| Customers and producers | Name, email, phone, address, and registration number where they are a broker or dealer. |
| Waste records | Job type, addresses and postcodes, vehicle registration, waste codes, descriptions, weights, containers, hazardous and POPs details, treatment codes, dates and times. Mostly not personal data, but linked to named people. |
| Transfer notes and receipt PDFs | The generated documents and the email addresses they were sent to. |
| Defra submissions | Copies of what was sent to and received from Defra, including carrier and broker contact details. Your Defra API code is removed from stored copies. |
| Sync log | Copies of the data each phone sent. |
Special category data. None intended. A photo that happens to show a person is not, by that alone, special category data [B24].
Annex 2. Security measures
This lists only what Tipslip does today, and marks what is planned. We do not claim any certification.
In place
- Encryption in transit. All three apps are served over HTTPS only, with HSTS. Tipslip refuses to connect to Defra over an unencrypted connection.
- Encryption at rest. Data is stored with Supabase, which encrypts stored data at rest as a platform feature. [To confirm against Supabase's own security documentation before publication; not configured or verified in our code.]
- Keeping firms apart. Every record carries its firm's ID. Two separate layers stop one firm seeing another's data: every query is filtered by firm in our code, and the database itself enforces the same rule (row-level security). Tested against a real database in our integration suite.
- Private file storage. Photos, signatures and PDFs are in a private storage bucket, in a folder per firm. Nothing is public. Files are opened with signed links that expire after 15 minutes, including the transfer-note link emailed to a customer.
- Access by role. Office users have owner, admin or office roles. Only owners and admins can change firm settings or retry or correct Defra submissions.
- Driver credentials. PINs are stored only as strong one-way hashes. Too many wrong PINs lock driver sign-in for the firm. Deactivating a driver stops their phone syncing at its next connection.
- Secrets. Your Defra API code is never logged, never printed on a PDF or export, and is removed from stored copies of requests and responses.
- Minimal capture. One location fix per job, only while the app is open, never in the background. No analytics, tracking, advertising or AI services in the product.
- Hosting in the UK. Database in London; file storage in the same project, region being confirmed; office app and background processing in London.
- Monitoring. Independent checks run on a separate provider and feed a public status page.
Built, going live with the next release (not yet in place)
- A log of who in your firm viewed a job, downloaded an export or deleted a photo, which your owners and admins can read. Our own admin page views are logged separately (P-005).
- Removing hidden location data (EXIF) from photos on the phone before upload (P-001). Not yet checked on every phone.
- Automatic deletion when retention periods end, never earlier than 3 years for waste records (P-003).
Planned, not yet in place
- Multi-factor sign-in for owners, admins and our own staff (P-010).
- A written permission matrix, and restricting our internal admin screens to a read-only database role that cannot read driver or customer tables (P-009). Today our admin area can technically read all firms' data, though its screens show only firm-level summaries.
- Documented and tested backups (P-011).
Annex 3. Transfers outside the UK
Only sub-processors that handle your personal data (clause 1.1) are listed. Stripe, Cloudflare and Plausible handle only data we control ourselves (billing, status-page subscribers, website visits), so they are covered by our privacy notice, not this agreement.
| Sub-processor | Data | Where | Transfer outside UK? | Safeguard |
|---|---|---|---|---|
| Supabase | All of it | Database London (eu-west-2); storage believed co-located | To confirm: remote support or admin access from outside the UK | To confirm (P-006) |
| Vercel | All data passing through the apps; request logs | Office app London (lhr1); driver app region not set | To confirm: driver app region, platform logs, support access | To confirm (P-006) |
| Inngest | Background job data, mostly IDs | Not known; US company | Likely | To confirm: Data Bridge or IDTA/Addendum (P-006) |
| Resend | Customer email addresses and the PDFs sent to them | Not known; US company | Likely | To confirm: Data Bridge or IDTA/Addendum (P-006) |
| Google (Gmail, support inbox) | Whatever you send support, which may include screenshots or job details | Not known | Likely | To confirm (P-006) |
Transfer risk assessment: one per transfer (placeholder)
Complete one for each "likely" or confirmed transfer above before publication. The UK now calls this the "data protection test" [B6].
| Heading | Content |
|---|---|
| Sub-processor and entity | [legal entity, country] |
| Data and people | [categories from Schedule 1] |
| How often and how much | [continuous / on demand; volume] |
| Safeguard | [Data Bridge certification checked on (date) / IDTA / Addendum] |
| Local law risk | [government access laws in the destination; is this data likely to interest authorities?] |
| Extra measures | [encryption, minimisation, IDs only] |
| Conclusion | [protection not materially lower than in the UK: yes / no] |
| Checked by, date |
Annex 4. Signature block (optional)
Signed for and on behalf of [firm name] (controller)
Name: ______________________ Position: ______________________
Signature: ______________________ Date: ______________________
Signed for and on behalf of Skrivon Ltd (processor)
Name: ______________________ Position: ______________________
Signature: ______________________ Date: ______________________
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 2026-09-25 | First draft. Not published. |