Last updated 7 September 2026
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of our Terms of use and Privacy notice. It sets out how Urban Assist Services Ltd processes personal data on behalf of customers and professionals in line with UK GDPR Article 28.
Who this is for
This DPA applies where Urban Assist processes personal data on behalf of a business customer or professional acting as controller — for example, where a property manager books on behalf of tenants and we handle tenant contact details on their instructions, or where we process data for professionals under their controller directions. In those cases Urban Assist is the processor and the business customer / professional is the controller.
When you book as a consumer for your own home, you are a data subject, not a controller. We are the controller for your account, booking, and payment data — our Privacy notice describes that relationship. This DPA does not grant consumers controller or audit rights. Professionals and business customers who receive personal data through the platform are independent controllers for the data they control; contact your assigned professional directly if you need to exercise rights over data they hold separately.
Definitions
“Controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings in the UK GDPR and Data Protection Act 2018. “Standard Contractual Clauses” means the EU SCCs as given effect for UK transfers by the International Data Transfer Addendum (IDTA).
Subject matter and duration
Subject matter: provision of the Urban Assist marketplace — discovery, booking, messaging, payment handling, and support. Duration: for as long as your account is active and for the retention periods in our Privacy notice (for example, 6 years for financial records after the end of the relevant tax year).
Nature, purpose, and types of data
- Purpose: create a booking, assign a professional, take payment, exchange messages about the job, and resolve disputes.
- Data subjects: customers, professionals, and operational staff handling bookings.
- Categories of data: account details (name, email, phone), service addresses and derived coordinates, booking and payment records, messages, reviews, and device data (session token, postcode preference, and push token only if enabled).
- Special category data: not intentionally processed. Do not include it in booking notes or messages.
Our obligations as processor
- Process personal data only on documented instructions from you, unless required by law.
- Ensure staff who access data are bound by confidentiality.
- Implement appropriate technical and organisational measures — encryption in transit and at rest, granular access controls at the database level, least-privilege access, logging, and backups — see our Security policy.
- Assist you with data subject requests where we hold data on your behalf.
- Notify you without undue delay after becoming aware of a personal data breach, with the information required by Article 33(3) as it becomes available.
- On termination, delete or return personal data at your choice, except where retention is required by law (for example, tax records retained without contact details attached).
- Make available information necessary to demonstrate compliance and allow for audits.
Sub-processors
We use the following sub-processors. A sub-processor processes only what it needs:
| Provider | Role | Data shared | Location |
|---|---|---|---|
| Supabase | Database and authentication | Account, bookings, messages, reviews | UK / EEA |
| Twilio | SMS delivery for one-time codes | Phone number, delivery metadata | US / EEA (SCCs + IDTA) |
| Stripe | Payment processing (controller of card data) | Payment reference, amount — card details go directly to Stripe | US / EEA (SCCs + IDTA) |
| Google Firebase | Push delivery and chat storage | Push token, booking reference, chat message content | US (SCCs + IDTA) |
| Sentry | Error monitoring | Scrubbed error reports, device metadata | US / EU (SCCs + IDTA) |
| Vercel | Hosting | IP address, request logs | US / EU (SCCs + IDTA) |
| Postcodes.io / getAddress.io | Address lookup | Postcode only | UK |
| Google Maps | Map previews | Service address when you open a booking | US (SCCs + IDTA) |
We will inform you before adding a new sub-processor and give you an opportunity to object on reasonable grounds related to data protection.
International transfers
Data is stored in the UK or the European Economic Area. Where a sub-processor transfers data outside the UK, the transfer relies on UK adequacy regulations or the IDTA to the EU SCCs. A copy of the relevant safeguards can be made available on request.
Data subject rights and assistance
Consumers can download their data and delete their account from account settings. For any other request, email info@urbanassist.co.uk.
Where you are the controller under this DPA and need our help to respond to a data subject request, we will assist taking into account the nature of the processing.
Audit rights
Where you are the controller under this DPA, on reasonable notice we will make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections where required. Audits are to be conducted during business hours, with minimal disruption, and under confidentiality.
Liability and precedence
Liability under this DPA follows our Terms of use “Our responsibility to you”. In case of conflict between this DPA and the Privacy notice on processing roles, this DPA prevails for processor activity.
Contact and acceptance
Urban Assist Services Ltd, 128 City Road, London EC1V 2NX — info@urbanassist.co.uk. For providers, acceptance of this DPA is included in platform onboarding. A signed PDF is available on request.
This page is a public summary. The binding DPA for enterprise or public-sector customers may be executed as a separate annex.
