Data Processing Terms

The Article 28 agreement between you as controller and us as processor.

These Data Processing Terms form part of, and are incorporated into, the Posttime Terms & EULA. They are the written contract required by Article 28(3) of the UK GDPR (and of the EU GDPR where it applies) between you as controller and us as processor. Where these terms conflict with the Terms & EULA on the subject of personal data, these terms take precedence.

1. The parties and their roles

You (the customer firm) are the controller. You decide whose personal data goes into Posttime and why, and you are responsible for having a lawful basis for it.

We are the processor: Yeti Trading and Holding Company Limited, trading as Posttime, a company registered in England & Wales (no. 16962101), registered office Garden Flat, 48 Lower Oldfield Park, Bath, BA2 3HP. ICO registration number ZC157856.

We act as a controller only for our own business records — your account and billing details, and our support correspondence with you. That is covered by our Privacy Policy, not by these terms.

2. What we process for you

ItemDetail
Subject matterProviding the Posttime time recording, matter, document, billing and accounting service.
DurationFor as long as your subscription lasts, plus the return-or-deletion period in section 9.
Nature and purposeHosting, storing, organising, retrieving, displaying, transmitting, backing up and deleting the data you put into the service, and generating the documents and reports you ask for.
Types of personal dataDetermined by you. Typically: names, contact details and addresses of your clients and the parties to your matters; your staff's names, contact details and time records; correspondence and documents you file; and financial and billing details.
Categories of data subjectYour staff, your clients, and third parties connected to your matters — for example directors, guarantors, executors, beneficiaries and opposing parties.
Special category dataNot required by the service, but the service accepts free text and uploaded documents, so you may put such data in. You remain responsible for the Article 9 condition that permits it.

3. Our obligations

We will:

  • Process only on your documented instructions, including on international transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it. Your use of the service, and these terms, are your instructions. We will tell you if we think an instruction breaches data protection law.
  • Keep it confidential. Everyone we authorise to process your data is bound by a duty of confidence and is told what they may and may not do with it.
  • Secure it with appropriate technical and organisational measures under Article 32 — see section 5.
  • Not use your data for our own purposes. We do not sell it, we do not profile your clients, and we do not use it to train third-party AI models.

4. Sub-processors

You give us general authorisation to appoint sub-processors. We impose the same data protection obligations on each of them by contract, and we remain fully liable to you for their performance.

The current list of sub-processors — covering hosting, payment processing, email delivery, and the optional integrations you choose to switch on — is available at any time from privacy@posttime.uk. We will give you at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds within that period, you may terminate the affected part of the service without penalty for the unused remainder of your term.

5. Security

Our measures include: encryption in transit (HTTPS/TLS everywhere, enforced by HSTS); each firm's data held in a separate database rather than a shared table; role-based access levels set by you; an audit log of significant actions; a strict Content Security Policy; encrypted, access-controlled backups; and access to production systems limited to named personnel using key-based authentication. See Security for more. We review these measures as the service changes.

6. Helping you meet your own obligations

Taking into account the nature of the processing and what we know, we will give you reasonable assistance with:

  • Data subject rights. The service is built so you can find, correct, export and delete records yourself. If a request reaches us instead of you, we will not respond to it directly — we will pass it to you promptly.
  • Security, breach notification and impact assessments under Articles 32 to 36.

7. Personal data breaches

We will notify you without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting your data. We will tell you what we know — what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it — and will keep you updated as we learn more, so that you can meet your own 72-hour deadline to the ICO.

8. International transfers

Your data is stored and processed on servers in Germany, within the EEA. We do not transfer it outside the UK or EEA except where you switch on an optional integration that involves one, or where a sub-processor requires it — in which case we rely on UK adequacy regulations, the UK International Data Transfer Addendum, or Standard Contractual Clauses with appropriate supplementary measures.

9. Return and deletion

You can export your data at any time while your subscription is live. On termination, at your choice, we will return or delete your personal data and delete existing copies within 90 days, except to the extent we are required by law to keep it. Backups age out on their normal cycle and remain protected until they do.

10. Audit and information

We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will allow and contribute to audits, including inspections, by you or an auditor you appoint. In practice we ask that you first accept the documentation we can provide; where that is not enough, audits are on reasonable notice, during business hours, no more than once a year unless a breach or a regulator says otherwise, and subject to confidentiality.

11. Contact

Data protection questions, sub-processor lists, breach notifications and audit requests: privacy@posttime.uk.

You may also complain to the Information Commissioner's Office at ico.org.uk.