← Back to VoltMate

Information & trust

Data Processing Addendum

The UK GDPR processor terms that apply when VoltMate processes a business customer’s personal data on that customer’s instructions.

Last updated: 10 September 2026

Service operator

VoltMate is a trading name of Shalva Aptsiauri, operating as a sole trader in the United Kingdom.

Business address: 30 Spence Terrace, North Shields, NE29 0JD, United Kingdom

Email: support@voltmate.co.uk

How this becomes part of your contract

For applicable business use, this DPA is incorporated into the VoltMate Terms of Service. No separate signature is required unless the parties agree otherwise in writing.

1. Status and scope of this Addendum

This Data Processing Addendum (DPA) forms part of the VoltMate Terms of Service and applies where a customer, workspace owner or organisation using VoltMate (Customer) is a controller and VoltMate processes personal data on the Customer’s behalf as a processor. It is intended to satisfy the processor-contract requirements of Article 28 of the UK GDPR.

The DPA does not change the separate situations described in the Privacy Policy where VoltMate acts as controller for its own account administration, billing, support, security, service operations or other purposes determined by VoltMate. If VoltMate determines the purposes and means of a particular processing activity, that activity is outside the processor scope of this DPA.

2. Parties and data-protection laws

The Customer is the controller for Customer Personal Data unless applicable law assigns a different role. The processor is the UK sole-trader operator of VoltMate identified on this page and in the Terms of Service.

Data Protection Laws means the UK GDPR, the Data Protection Act 2018 and other applicable United Kingdom data-protection or privacy legislation, in each case as amended or replaced. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given by applicable Data Protection Laws.

3. Processing details required by Article 28

Subject matter: providing the VoltMate software service and the workspace functions the Customer chooses to use, including storage, organisation, retrieval, display, transmission, backup, sharing, certificate and inspection workflows, operational communications and support relating to Customer-controlled records.

Duration: for the period in which VoltMate provides the relevant service to the Customer, plus the limited retention, recovery, backup and deletion periods described in the Terms, Privacy Policy and documented service procedures, unless applicable law requires longer storage.

Nature and purpose: collecting from the Customer or authorised users, recording, structuring, storing, retrieving, consulting, using, transmitting, making available to authorised recipients, securing, backing up, restoring and deleting Customer Personal Data as necessary to provide the requested service and follow documented instructions.

Types of personal data can include names, contact details, property or service addresses, client and job records, calendar information, quotes and invoices, inspection and test records, certificate data, uploaded files, sharing or portal details and other information the Customer deliberately places in the workspace. VoltMate is not designed to require special-category or criminal-offence data; if the Customer chooses to submit such data, the Customer remains responsible for ensuring that the processing is necessary, lawful and appropriately instructed.

Categories of data subject can include the Customer’s clients and prospective clients, employees, workers, contractors, electricians, suppliers, property owners, landlords, tenants, occupiers, authorised portal recipients and other people whose details the Customer lawfully records in VoltMate.

The Customer retains the rights and obligations of a controller, including deciding why Customer Personal Data is processed, ensuring a lawful basis and transparency, setting retention requirements and giving lawful documented instructions.

4. Documented instructions

VoltMate will process Customer Personal Data only on the Customer’s documented instructions, including instructions expressed through the Terms, this DPA, the Customer’s configuration and feature choices, authorised API or application actions, and written support directions. VoltMate may process otherwise where required by applicable UK law; where legally permitted, VoltMate will inform the Customer of that requirement before the processing.

If VoltMate considers an instruction to infringe Data Protection Laws, VoltMate will inform the Customer without undue delay and may suspend the affected processing while the instruction is reviewed. The Customer must not instruct VoltMate to process personal data unlawfully.

5. Confidentiality

VoltMate will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, whether contractual or statutory, and receive access only where reasonably necessary for their role.

6. Security of processing

VoltMate will implement and maintain technical and organisational measures appropriate to the risk, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals. Measures can include access controls, authenticated access, encryption or secure transmission where appropriate, environment and secrets controls, operational logging, measures supporting confidentiality, integrity, availability and resilience, backup and recovery controls, vulnerability and dependency maintenance, incident-response procedures, and periodic testing or review of relevant safeguards.

Security measures may evolve as the service changes. VoltMate will not materially reduce the overall level of protection for Customer Personal Data during a paid service term without a legitimate operational or legal reason. No internet service can guarantee absolute security.

7. Assistance to the Customer

Taking account of the nature of the processing, VoltMate will use appropriate technical and organisational measures, insofar as reasonably possible, to help the Customer respond to requests by data subjects exercising their rights under Chapter III of the UK GDPR.

Taking account of the nature of processing and the information available to VoltMate, VoltMate will also provide reasonable assistance with the Customer’s obligations concerning security of processing, personal data breach notification, communications to affected data subjects, data protection impact assessments and prior consultation with the ICO where those obligations relate to processing carried out by VoltMate on the Customer’s behalf.

If VoltMate receives a rights request that clearly concerns Customer Personal Data controlled by the Customer, VoltMate may direct the requester to the Customer and will not independently decide the substance of the request unless required by law.

8. Sub-processors and general authorisation

The Customer gives VoltMate general written authorisation to use sub-processors where they are reasonably required to provide the service. VoltMate will ensure that each sub-processor processing Customer Personal Data is bound by written terms providing an equivalent level of protection for the relevant Article 28 obligations, and VoltMate remains responsible to the Customer for the sub-processor’s performance of those obligations as required by law.

Sub-processors can include Vercel for application hosting and delivery, Neon for PostgreSQL infrastructure, AWS services used for backup and recovery infrastructure, OpenAI where an authorised user deliberately uses an AI feature with Customer Personal Data, and Resend where an authorised workflow sends email containing Customer Personal Data. The precise providers involved depend on the features the Customer uses.

Before a new or replacement sub-processor begins materially processing Customer Personal Data under this DPA, VoltMate will provide advance notice of the intended change, normally at least 14 days in advance, through an account notice, email or published sub-processor notice. The Customer may object before the change takes effect on reasonable data-protection grounds. VoltMate will work in good faith to address the objection, which can include providing information about safeguards, avoiding the affected feature where feasible, or allowing termination of the affected service where no reasonable alternative is available.

9. International transfers

VoltMate will not make a restricted transfer of Customer Personal Data contrary to applicable UK Data Protection Laws. Where a restricted transfer requires a safeguard, VoltMate will use an available lawful mechanism such as UK adequacy regulations or an appropriate Article 46 safeguard, together with supplementary measures where required for the circumstances.

Where a Customer instruction itself requires disclosure to a recipient outside the United Kingdom, the Customer remains responsible for the lawfulness of that instruction and VoltMate will follow it only to the extent permitted by this DPA and applicable law.

10. Personal data breaches

VoltMate will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data processed under this DPA. VoltMate will provide information reasonably available to help the Customer meet applicable notification and communication duties, including the nature of the incident, affected data where known, likely consequences and mitigation steps, and may provide information in phases as the investigation develops.

Notification under this section is not an admission of fault or liability. The Customer is responsible for deciding whether it must notify the ICO, affected individuals or another authority, except where law places a separate notification duty directly on VoltMate.

11. Return, deletion and end of processing

At the end of the relevant processor services, VoltMate will, at the Customer’s choice, return or delete Customer Personal Data and delete existing copies, unless applicable UK law requires continued storage. Where return is chosen, VoltMate will provide the data using a reasonably available export method or format. The Customer should request or complete any required export before account closure where the service provides a self-service export route.

Deletion from active systems does not necessarily rewrite every historical backup immediately. Backup expiry and restoration safeguards operate under the retention and erasure-replay approach described in the Privacy Policy. Any retained backup copy remains protected by this DPA, is put beyond ordinary use, and may not be restored for ordinary use after a valid deletion except as required for disaster recovery, legal compliance or another lawful reason. It will be deleted through the applicable backup deletion cycle unless law requires continued storage.

12. Information, audits and inspections

VoltMate will make available information reasonably necessary to demonstrate compliance with Article 28 obligations that apply to the processing under this DPA. This may include relevant policies, security descriptions, sub-processor information, incident information and other compliance evidence appropriate to the risk.

VoltMate will allow for and contribute to audits and inspections by the Customer or an independent auditor appointed by the Customer. Audits should, where possible, use existing documentation and remote evidence first, be conducted on reasonable prior notice, avoid unnecessary disruption, protect other customers’ confidentiality and security, and be limited to information relevant to the Customer’s processing. These practical safeguards do not restrict a mandatory audit, regulator request or investigation that cannot lawfully be limited.

13. Customer responsibilities

The Customer is responsible for ensuring that its collection and use of Customer Personal Data is lawful, fair and transparent; that it has authority to give instructions and disclose data to VoltMate; that users are appropriately authorised; and that the service is configured consistently with the Customer’s own retention, confidentiality and security obligations.

The Customer should provide only personal data reasonably necessary for the intended workflow and should not use VoltMate as the sole archive for records that law, professional rules or business-continuity requirements require the Customer to retain independently.

14. Order of precedence, liability and changes

If this DPA conflicts with the Terms of Service on a matter concerning VoltMate’s processing of Customer Personal Data as processor, this DPA prevails for that matter. The Terms continue to govern the rest of the service relationship. Nothing in this DPA reduces rights or obligations that cannot lawfully be limited.

Liability arising from this DPA is subject to the liability provisions of the Terms of Service to the extent permitted by law. A material change to this DPA will be dated and notified where required. If applicable law requires a new contractual commitment rather than notice, VoltMate will obtain it before relying on the change.

15. Contact

Questions about this DPA, sub-processors, security information, audit requests or processor assistance can be sent through the Contact page using Privacy & data request or to support@voltmate.co.uk. Please do not send passwords, payment-card details or unnecessary personal data with the request.