Skip to content

Data processing agreement

Last updated 26 Sept 2026

Every customer has a data processing agreement with Stedwise. This page summarises what it commits us to. The full agreement forms part of the terms of service: email hello@stedwise.co.uk for a signed copy.

Roles

The customer is the controller for the records it keeps in Stedwise about residents, staff, key people, referrals and incidents. Stedwise is its processor. Roles are assessed activity by activity: for account and billing data, Stedwise is the controller (see the privacy notice).

What we process

  • People: residents, staff and volunteers, directors and service managers, referrers and other contacts the customer records.
  • Data: contact and role details; support records, referrals and incidents, which are special category data; and fit-and-proper check outcomes and dates, which are criminal offence data. We never store the contents of a criminal record certificate.
  • Purpose: only to provide Stedwise to the customer, on its documented instructions.

Our commitments

  • Process personal data only on the customer’s instructions, and tell it if we think an instruction breaks data protection law.
  • Make sure everyone with access is bound by confidentiality, and that support access is audited.
  • Keep appropriate security: UK hosting for the database, files and backups, TLS in transit, encryption at rest, field-level encryption for special category fields, roles scoped to schemes, two-step verification for owners and managers and for anyone who can open resident, referral, safeguarding or criminal record check records, and an audit log of every view and change to resident, staff and incident records.
  • Never send resident personal data to an AI model.
  • Use sub-processors only under written terms that give the same protection, and publish them on the sub-processor list. We tell customers before adding or replacing one, so they can object.
  • Help the customer respond to people exercising their rights, with a subject access export and an erasure workflow for each person.
  • Tell the customer without undue delay after becoming aware of a personal data breach, with the information it needs to meet its own duties.
  • Help with data protection impact assessments and consultations with the regulator where our processing is involved.
  • At the end of the contract, let the customer export its data, then delete it, unless the law requires us to keep it.
  • Make available the information needed to show we meet these commitments, and allow for reasonable audits.

Several organisations, one record

A managing agent, a housing association and a support provider are usually separate controllers. Stedwise shares nothing between them without a recorded consent and a data sharing agreement. A housing association sees counts and statuses, never resident records.

International transfers

Customer data is stored in the United Kingdom. Where a sub-processor processes data outside the UK, it is named on the sub-processor list with its region, and the transfer is covered by UK transfer safeguards.

Getting the full agreement

Email hello@stedwise.co.uk for a signed copy.

Questions about this page: hello@stedwise.co.uk.