Possessions · LIGHT AND DARK ENERGY LTD
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Possessions Terms where a customer uses the service in a business or professional capacity and LIGHT AND DARK ENERGY LTD processes personal data on that customer’s behalf.
1. Parties and roles
The customer is the controller and LIGHT AND DARK ENERGY LTD, company 15095270, is the processor for Customer Personal Data. Each party remains independently responsible for processing for which it acts as controller. Terms including personal data, processing, controller, processor and data subject have the meanings in applicable UK data-protection law.
2. Instructions and duration
We process Customer Personal Data only on the customer’s documented instructions: the Terms, this DPA, configuration and use of the service, and lawful support requests. Processing continues while the account is active and during the documented deletion and backup-expiry periods. We will inform the customer if an instruction appears to infringe applicable data-protection law, unless prohibited from doing so.
3. Processing details
The subject matter is hosting and operating a private asset-management service. Processing may include collection, storage, organisation, retrieval, encryption, transmission, export, deletion, backup and restoration. Its purpose is to provide authentication, asset records, locations, obligations, cash flow, occupancy, calendar import, encrypted notes and attachments, support and security. Data subjects may include the customer’s household members, beneficial owners, tenants, guests, staff, advisers, contractors, suppliers and other contacts. Data may include identity or contact references, asset relationships, locations, occupancy, payments or obligations, calendar entries, operational notes and encrypted attachments. The service is not designed for special-category data, criminal-offence data, children’s data or authentication secrets belonging to third parties, and customers must not enter such data unless lawfully authorised and appropriate safeguards are in place.
4. Confidentiality and security
Personnel authorised to process Customer Personal Data are bound by confidentiality. We maintain measures appropriate to the risk, including access controls, encryption in transit, browser-side encryption for designated protected fields and attachments, pseudonymous access, restricted production access, logging, backups, retention controls and incident procedures. Security measures may evolve provided protection is not materially reduced.
5. Subprocessors
The customer gives general authorisation for the subprocessors identified in the Privacy Policy, currently including DigitalOcean and its disclosed infrastructure subprocessors. Stripe/Link, OpenStreetMap/Nominatim and a customer-selected calendar host generally process relevant data under their own roles and notices rather than as Possessions subprocessors. We will update the published recipient information before adding a subprocessor that materially affects Customer Personal Data. A customer may object on reasonable data-protection grounds by contacting us before the change takes effect; if no reasonable alternative is available, either party may end the affected service.
6. Assistance
Taking account of the nature of processing and information available to us, we will reasonably assist the customer with data-subject requests, security obligations, breach assessment, data-protection impact assessments and regulator consultations. We will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide available information needed for the customer’s assessment. The customer is responsible for responding to data subjects and regulators where it is controller.
7. Deletion, return and audit information
Self-service export and deletion tools allow the customer to retrieve and delete active vault data. On account deletion or termination, active Customer Personal Data is deleted subject to documented legal retention and encrypted backup expiry, currently no more than 35 days. On reasonable request we will provide information necessary to demonstrate compliance and permit a proportionate audit no more than once annually, unless a regulator or substantiated incident requires more. Audits must protect other customers, security and confidentiality and should use existing reports and remote review before on-site access.
8. International transfers
Primary production hosting is in the United Kingdom. Where a restricted transfer occurs, the parties incorporate the applicable UK International Data Transfer Addendum or other lawful safeguard used by the relevant supplier. The customer authorises transfers described in the Privacy Policy, subject to those safeguards.
9. Customer responsibilities and precedence
The customer must provide lawful instructions, an appropriate legal basis and required notices; minimise data; configure access securely; and ensure it has authority to process and upload Customer Personal Data. If this DPA conflicts with the Terms on processor obligations, this DPA prevails. The liability provisions of the Terms apply to this DPA to the extent permitted by law.