Data Processing Agreement

Version 2026-07. Last updated July 2026.

This Data Processing Agreement (the "DPA") governs how CleanDone, operated by Makappen Ltd (registered in England and Wales, company no. 11985285), processes your customers' personal data on your behalf. It is made under Article 28 of the UK GDPR and forms part of the Terms of use. By creating an account you agree to it.

1. Parties and roles

For the personal data of your customers, you (the cleaner or cleaning business holding an account) are the controller and Makappen Ltd is your processor. For your own account data, Makappen Ltd is the controller, as set out in the Privacy notice. This DPA governs our processing of your customers' personal data on your behalf.

2. Subject matter, duration, nature and purpose

Subject matter and purpose: providing the CleanDone service - bookings, scheduling, client records, payment tracking and customer notifications - as instructed by you through your use of the product. Nature of processing: storage, organisation, retrieval, transmission (email and SMS notifications), encryption and deletion. Duration: for as long as you maintain an account, and until data is deleted under clause 9.

3. Categories of data subject and personal data

Data subjects: your customers and prospective customers, and any named team members you add. Personal data: identifiers and contact details (name, phone, email); location and access data (home address and access notes, encrypted at rest; postcode in plain text for route grouping); and service records (enquiries, quotes, scheduled and completed cleans, checklist items, payment status). The service does not request special-category data (Article 9); you must not enter special-category data into free-text fields.

4. Your instructions

We process the personal data only on your documented instructions - which include your configured use of the product and this DPA - unless the law requires otherwise (in which case we'll tell you, unless we're legally prohibited from doing so). We'll also tell you if we think an instruction breaks data-protection law.

5. Confidentiality

Anyone we authorise to process the data is bound by confidentiality.

6. Security (Article 32)

We implement appropriate technical and organisational measures (see Annex 2), including AES-256-GCM encryption at rest of home addresses, access notes and bank details; encryption in transit (HTTPS/TLS); scrypt password hashing; hashed session tokens; strict per-account data isolation; and rate-limiting of public endpoints.

7. Sub-processors

You give general authorisation for the sub-processors listed in Annex 3. We'll tell you about any intended changes (additions or replacements) and give you the chance to object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this DPA.

8. Assistance to you

Taking account of the nature of processing, and so far as the product allows, we'll help you respond to data-subject requests (the product provides self-service export, rectification and erasure - see the Privacy notice), and meet your Article 32-36 obligations (security, breach notification, data protection impact assessments and prior consultation).

9. Breach notification

We'll tell you without undue delay after we become aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification duties.

10. Return and deletion

On termination, or on your request, we'll delete your customers' personal data - you can trigger full deletion in-app at any time ("Delete my account", or "Delete permanently" on an individual client). Backups held by our sub-processors are overwritten on their normal cycle.

11. Audits and information

We'll make available the information reasonably necessary to show we comply with Article 28 - through our documentation and security summaries - and we'll contribute to audits to the extent the law requires.

12. International transfers

Your customers' personal data is stored in the UK - our database and file storage are hosted in London. Some hosting and compute run in the EU/EEA (Dublin), which the UK recognises as adequate. Where a sub-processor processes data outside the UK and EEA (for example Twilio or Stripe in the US, or Vercel's US parent company), those transfers are covered by an adequacy decision or the UK International Data Transfer Agreement (or Standard Contractual Clauses with the UK Addendum), as applicable.

Annex 1 - Processing details

As set out in clauses 2 and 3 above.

Annex 2 - Technical and organisational measures

MeasureImplementation
Encryption at rest (sensitive fields)AES-256-GCM, random IV, authentication tag
Encryption in transitHTTPS/TLS on all endpoints and sub-processor calls
Authenticationscrypt password hashing; hashed session tokens in httpOnly/secure cookies
Access controlper-account isolation on every query; ownership re-checks on every mutation
Resilience to attackserver-side input validation, parameterised queries, rate-limited public endpoints
Secrets managementkeys in platform-encrypted environment variables, never in code

Annex 3 - Authorised sub-processors

Sub-processorPurposeLocation
VercelApplication hosting / computeEU/EEA (Dublin)
SupabaseDatabase and photo storage (Postgres + Storage)UK (London)
SentryError monitoring (application diagnostics)EU/EEA (Frankfurt)
ResendTransactional emailUS (with transfer safeguards)
TwilioSMS (when enabled)US (with transfer safeguards)
StripePayment processingUS/EU (with transfer safeguards)
GoCardlessDirect Debit collection (when enabled)UK/EU
GoogleSign-in (only with "Continue with Google")US (with transfer safeguards)
postcodes.ioPostcode to map coordinates (postcode only)UK

Contact

Questions about this agreement: support@cleandone.co.uk.