Version 1.0, 4 August 2026. Article 28, UK General Data Protection Regulation. A schedule to the Terms of Service for Professional accounts.
This applies when you use Level Best for client work. Your clients' data stays yours: you are the controller, we are your processor, and this sets out what that means in practice. If you are using Level Best for your own house or garden, this page is not about you, and the privacy policy covers everything that is.
(1) RICHARD COWTAN, trading as LEVEL BEST, of [postal address], United Kingdom (the "Processor"); and
(2) The customer identified in the Order (the "Controller"), being the person or firm that has subscribed to the Level Best Professional plan.
each a "Party" and together the "Parties".
(A) The Processor provides Level Best, a web application for planning, budgeting and running house and garden projects (the "Service"), under its Terms of Service (the "Principal Agreement").
(B) In using the Service the Controller instructs the Processor to process personal data relating to the Controller's own clients and personnel.
(C) This agreement (the "DPA") records the terms required by Article 28(3) UK GDPR and forms part of the Principal Agreement.
1.1 In this DPA: "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, and "DPA 2018" means the Data Protection Act 2018. "Data Protection Legislation" means the UK GDPR, the DPA 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended.
1.2 "controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR.
1.3 "Controller Personal Data" means personal data processed by the Processor on behalf of the Controller under the Principal Agreement, as described in Annex 1.
1.4 "Sub-processor" means any processor engaged by the Processor to process Controller Personal Data.
1.5 Where this DPA conflicts with the Principal Agreement in relation to the processing of Controller Personal Data, this DPA prevails.
2.1 The Parties acknowledge that, in respect of Controller Personal Data, the Controller is the controller and the Processor is a processor.
2.2 The Processor is a separate and independent controller in respect of personal data it processes for its own purposes, including the Controller's own account and contact details, billing records, service and security logs, and correspondence with the Processor. That processing is governed by the Processor's privacy policy and not by this DPA.
2.3 Each Party shall comply with its own obligations under Data Protection Legislation. The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided any privacy information its data subjects are entitled to, and that it is entitled to disclose Controller Personal Data to the Processor for that processing.
3.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex 1.
3.2 The Processor shall process Controller Personal Data only on the Controller's documented instructions, including as to transfers to a third country, unless required to do otherwise by law to which the Processor is subject. Where the Processor is required by law to process otherwise, it shall inform the Controller of that legal requirement before processing, unless that law prohibits it from doing so on important grounds of public interest.
3.3 The Principal Agreement, this DPA, and the Controller's use of the features of the Service constitute the Controller's documented instructions. Additional instructions must be agreed in writing and may be subject to a reasonable charge where they require work outside the ordinary operation of the Service.
3.4 The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Legislation. The Processor may suspend the relevant processing until the instruction is confirmed, amended or withdrawn.
4.1 The Processor shall ensure that any person authorised to process Controller Personal Data is subject to an appropriate duty of confidentiality, whether contractual or statutory, and that access is limited to those who need it to perform the Processor's obligations.
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate the measures described in Annex 3.
5.2 The Processor may update the measures in Annex 3 provided that the level of protection is not materially reduced.
6.1 The Controller gives the Processor general written authorisation to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Annex 2.
6.2 The Processor shall inform the Controller of any intended addition or replacement of a Sub-processor by email to the address the Controller has given for account notices, and by updating the list published at levelbest.build/privacy. The Processor shall give at least thirty (30) days’ notice where it is able to do so. Where the change arises from a change made by an existing Sub-processor and the notice the Processor receives is shorter than thirty (30) days, the Processor shall inform the Controller promptly, and in any event within three (3) business days of becoming aware, passing on as much of the notice period as it has received.
6.3 The Controller may object to an intended change on reasonable data protection grounds by written notice within fourteen (14) days of being informed, or within such shorter period as remains of the notice the Processor received where the second sentence of clause 6.2 applies. The Parties shall work together in good faith to resolve the objection, which may include making the affected feature unavailable to the Controller. If no resolution is reached within thirty (30) days, the Controller may terminate the Principal Agreement in respect of the affected part of the Service without penalty, and shall be refunded any sums paid in advance for the period after termination.
6.4 The Processor shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor's obligations.
7.1 Certain Sub-processors process Controller Personal Data outside the United Kingdom, as identified in Annex 2.
7.2 Where the Processor transfers Controller Personal Data to a country that is not the subject of UK adequacy regulations, it shall ensure that the transfer is subject to appropriate safeguards under Article 46 UK GDPR, which shall ordinarily be the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner, together with any transfer risk assessment required.
8.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III UK GDPR.
8.2 The Processor shall, taking into account the nature of processing and the information available to it, assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessment and prior consultation).
8.3 If the Processor receives a request from a data subject in relation to Controller Personal Data, it shall not respond to it substantively but shall promptly inform the Controller and, where it can identify the relevant Controller, direct the data subject to it.
8.4 The Service provides features enabling the Controller to access, correct, export and delete Controller Personal Data itself. Where the Controller can meet a request using those features, the Processor's assistance under clause 8.1 is limited to reasonable support in doing so.
9.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Controller Personal Data.
9.2 The notification shall describe, to the extent known: the nature of the breach including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and the name and contact details of a point of contact. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.
9.3 The Processor shall not notify a supervisory authority or any data subject of a breach affecting Controller Personal Data on the Controller's behalf, or name the Controller in any public statement, without the Controller's prior written consent, unless required by law.
10.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 UK GDPR and this DPA.
10.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Controller shall give at least thirty (30) days' written notice, audits shall take place during normal business hours and no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach, and the Controller shall not unreasonably disrupt the Processor's business.
10.3 The Controller shall bear its own costs of an audit and shall reimburse the Processor's reasonable costs of assisting beyond the provision of information under clause 10.1.
10.4 The Processor may satisfy clauses 10.1 and 10.2 by providing its then-current record of processing activities, a description of its technical and organisational measures, and the equivalent information published by its Sub-processors.
11.1 The Controller may export Controller Personal Data in a structured, commonly used and machine-readable format at any time using the features of the Service, and that ability continues for the term of the Principal Agreement.
11.2 On termination or expiry of the Principal Agreement the Processor shall, at the Controller's option, delete or return all Controller Personal Data and delete existing copies, unless required by law to retain it. Where no option is exercised, the Processor shall delete the data.
11.3 The Processor shall give the Controller not less than thirty (30) days after termination in which to export Controller Personal Data before deletion, during which time the Controller's account will remain accessible for export.
11.4 Deletion of live data takes effect within thirty (30) days. Residual copies held in routine encrypted backups are overwritten in the ordinary backup cycle, which does not exceed thirty (30) days, and remain subject to this DPA until they are.
12.1 The liability of each Party under or in connection with this DPA is subject to the exclusions and limitations of liability in the Principal Agreement.
13.1 This DPA takes effect on the date the Controller accepts the Principal Agreement and continues for as long as the Processor processes Controller Personal Data.
13.2 The Processor may vary this DPA on thirty (30) days' written notice where necessary to comply with Data Protection Legislation or to reflect a change in the Service, provided the change does not materially reduce the protection given to Controller Personal Data. Any other variation requires the written agreement of both Parties.
13.3 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Required by Article 28(3). This annex describes what is actually processed; it should be corrected rather than copied if the Service changes.
Subject matter and duration
Subject matter: provision of the Level Best Service to the Controller. Duration: the term of the Principal Agreement, plus the deletion period in clause 11.
Nature and purpose of the processing
Storing and displaying project records the Controller creates for its clients: budgets, schedules, quotes, materials, decision logs and attachments.
Hosting, backup, and the security and service logging necessary to run the Service.
Sending email on the Controller's instruction: invitations to view a project, and notifications of comments.
Submitting text to an artificial intelligence provider to generate estimates, drafts and document readings, when a user of the Controller's account requests it.
Making the project visible to persons the Controller invites, and to colleagues holding a seat on the Controller's account.
Types of personal data
| Category | Examples |
|---|---|
| The Controller's clients | Name; property address and postcode; email address and telephone number where the Controller records them; the content of project notes and decision logs referring to them; photographs and documents uploaded to the project |
| The Controller's personnel | Name; email address; role on the account (viewer or editor); comments written; sign-in timestamps |
| Third parties recorded in a project | Tradespeople's and suppliers' business names, contact details and quoted prices, as entered by the Controller or returned by a business listing search |
Categories of data subject
Clients of the Controller whose projects the Controller manages using the Service.
Employees, partners and contractors of the Controller who hold a seat on the account.
Individuals invited by the Controller to view a project.
Tradespeople, suppliers and other third parties whose details the Controller records in a project.
As at the date of this DPA. The current list is maintained in the Processor's privacy policy at levelbest.build/privacy.
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, authentication and file storage | European Union |
| Vercel Inc. | Application and website hosting | United States |
| Anthropic PBC | Artificial intelligence features, on user request | United States |
| Resend | Sending and receiving email | United States |
Required by Article 32. Described at a level suitable for disclosure to a customer.
Access control
Authentication by single-use link sent to the user's email address. No passwords are stored, and none can therefore be disclosed in a breach.
Multi-factor authentication is enabled on every administrative account used to operate the Service.
Row-level access rules are enforced in the database and deny by default. Tables that no browser should reach have those rules enabled with no permissions granted at all.
Column-level permissions restrict which fields a signed-in user may write, so entitlements such as plan or seat cannot be altered from a browser.
A project shared with a client is delivered as a projection built on the server, containing only the parts the Controller has granted. Data not granted is absent from the response rather than hidden in the browser.
Encryption
All data in transit is encrypted using TLS.
Data at rest is encrypted at the database and object storage layers.
Integrity and resilience
Payment and inbound-mail webhooks are verified by cryptographic signature using constant-time comparison, with a replay window.
Concurrent edits are controlled by version checks, so a change cannot silently overwrite another.
Third-party browser scripts are pinned to a specific version and verified by subresource integrity.
Automated backups are taken by the database provider and retained for no more than thirty days.
Organisational measures
Administrative access is limited to named addresses held in configuration and verified on the server for every request.
Changes of plan, grants of access and deletions of accounts are recorded in an activity log.
A record of processing activities is maintained and reviewed at least annually.
An automated test suite covering the access-control boundaries is run before every deployment.
A documented breach procedure with a 72-hour regulatory reporting path is maintained.
Where this DPA is accepted electronically as part of the Principal Agreement, no signature block is required and acceptance of the Principal Agreement constitutes acceptance of this DPA. Where a customer requires a signed counterpart:
| For the Processor | For the Controller |
|---|---|
| Signature: Name: Position: Date: | Signature: Name: Position: Date: |
Anything here that does not fit how you work, email hello@levelbest.build and we will talk about it. A term nobody can live with is not much of a term.