Data Processing Agreement
Standing Article 28 terms that apply whenever you store your own clients' personal data in Fern Dale Makers Studio.
You (the maker) are the controller of any personal data about other people that you choose to enter or upload into the app.
Kathryn Barnes, trading as Fern Dale Handcrafted, operator of Fern Dale Makers Studio (referred to here as "we" or "us"), is the processor for that data. We store and process it only to make the relevant features work for you, and only on your documented instructions.
Separately, we are the controller of your own account data (your email, sign-in identifiers, subscription status and service logs). That processing is described on the Privacy & data page and is not covered by this agreement.
Subject matter: hosted storage and retrieval of all third-party personal data you enter or upload inside your private account area — not only Customers and Invoices.
Duration: for as long as your account is active, plus the return-or-delete choice window in section 10.
Nature and purpose: storing, displaying, editing, searching, printing and exporting the records you create; keeping backups and logs needed to run the service securely.
Categories of data subject: your business clients and their contacts (wholesale stockists, retailers, trade buyers), your bespoke and private clients, your suppliers and their staff, and any other identifiable individual you choose to record.
Categories of personal data covered, wherever in the app you put them:
- customer and stockist records — business name, billing and delivery address, contact name, telephone number, email address;
- invoices and the payment-status information you record against a person or business;
- client product briefs and bespoke commission details, limited to non-sensitive product preferences and commercial requirements you note down;
- supplier and trade contacts, including named account contacts and their contact details;
- uploaded documents and images of any kind — supplier declarations, client correspondence, signed paperwork, photographs — where they contain personal data;
- free-text notes, planner entries, concept and Drawing Board content, and any other field where you mention an identifiable person.
Sales information imported from a selling platform: where you import an Etsy sales file, or in future connect your own online shop, we process only order references, order dates, items, quantities, prices, currency, discounts, refunds or cancellations, and the links you make to your own product records. We do not request or store your customers' names, addresses, email addresses or telephone numbers from those sales, and no card or payment details are processed. That information is stored and displayed solely so you can see your own sales and margins, is never shared with other customers and is never sent to an AI model.
Special category data: the app is not designed for special category or criminal-offence data, and you must not enter it — including health information, skin conditions, or allergy details linked to an identifiable person, in a client brief, note or anywhere else.
We process the data covered by this agreement only on your documented instructions. Your instructions are: this agreement, the settings and choices available in the app, the actions you take in it, and anything else you ask us in writing. We will not process the data for our own purposes.
This applies to transfers as well as to storage: any transfer of the data to a third country or international organisation happens only on those documented instructions, which include your authorisation of the sub-processors in section 8 and the hosting locations they use. The only exception is where we are required to process or transfer data by UK or EU law, in which case we will tell you before doing so unless the law prohibits it.
We will also tell you if, in our opinion, an instruction you give us infringes data protection law.
We will:
- process the data only to provide the service to you, and never sell it, market to your contacts, or use it for advertising, profiling or analytics;
- never let an AI feature independently access customer, invoice, client-brief, supplier-contact, note, planner or Drawing Board content, and never use that content to train AI models — the single exception is the supplier-document auto-fill you deliberately trigger, described in section 8;
- keep it confidential, and ensure that everyone we authorise to access it is under a duty of confidentiality and has appropriate training — in practice that is Kathryn Barnes, and no other person has administrative access to your account data;
- help you respond to your data subjects' requests — access, rectification, erasure, restriction, portability and objection — with the information and tooling available to us, at no extra charge;
- tell you promptly, and normally within 5 working days, if one of your data subjects contacts us directly with a request or complaint about their data, and pass it to you rather than answering it ourselves;
- make available the information you reasonably need to demonstrate your own compliance with Article 28, drawing on our own records and on the documentation our providers publish.
How we help with an access request. When you receive a request from one of your data subjects, the one-month period is yours to manage, and it does not start — or is paused — while you are reasonably seeking clarification or confirming the person's identity. Our part is to give you what the app holds: you can export the relevant records from within the app yourself, and where you cannot we will search on your behalf. That search will be reasonable and proportionate — we look where the data would sensibly be held, not through every historic backup copy, which is what the law now expects. If a request is complex or repeated and you extend your response period, we will keep supplying information over that longer period at no extra charge.
Complaints from your data subjects. If someone complains to us about data you control, we pass it to you rather than answering it — you are the one who must acknowledge it and look into it. If someone complains to us about our handling of data as controller, we acknowledge it within 30 days and respond as set out on our Privacy & data page.
Fern Dale Makers Studio is run by one person on managed hosting. Our commitments here are what a business of that size can genuinely deliver: prompt help, honest information, and the security the platform provides. We do not claim a 24-hour support desk, a security operations team, or our own data centre.
Security assistance (Article 32). We will assist you in ensuring your own compliance with the security obligations — for example by describing the technical and organisational measures we apply, answering reasonable security questions, and telling you about material changes to those measures.
Breach notification (Articles 33–34). We will notify you without undue delay after becoming aware of a confirmed personal data breach affecting the data covered by this agreement, and normally within 24 hours of confirming it. Much of what we would learn comes from our hosting and database providers' own alerts and incident reports, so available information may be supplied in phases as further details become known. We will give you the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point — so that you can meet your own 72-hour reporting deadline to the ICO. We will give you the information you need for any communication to affected individuals under Article 34, and you remain responsible as controller for the wording and issuing of that communication; we will not notify your data subjects ourselves unless you ask us to or the law requires it of us.
Loss or corruption of data. If data covered by this agreement is lost, destroyed, corrupted or made unusable while in our care, we will tell you without undue delay and restore it from the backups available to us so far as recovery is possible — at no charge to you. We cannot recreate data that no backup holds, and we cannot recover anything you delete yourself: deleting a record or an account takes effect immediately and cannot be undone. We will take reasonable steps to limit the effect of any breach or unlawful processing, and share what we and our providers establish about the cause.
Who tells whom. Notifying your data subjects, the ICO or any other regulator, and offering any remedy to affected individuals, is your decision as controller. We will not do either in your place unless you ask us to or the law requires it of us directly. We will not disclose the data to anyone else without your written request, except where the law compels us — and where it does, we will tell you first so you can object, unless we are prohibited from telling you.
DPIAs (Article 35). On request, we will provide the information you reasonably need to carry out a data protection impact assessment covering your use of the app, including how the processing works, where data is stored, and which sub-processors are involved. Writing and signing off the assessment is yours to do.
Prior consultation with the ICO (Article 36). Where a DPIA indicates you need to consult the ICO, we will provide the information the ICO asks for about our processing and answer reasonable follow-up questions about it. We do not represent you in that consultation. References to the ICO in this agreement mean the UK data protection regulator, and should be read as referring to its successor if it is renamed or restructured.
You are responsible for having a lawful basis for holding other people's details, for the accuracy of what you enter, for telling those people how you use their data, and for keeping your own account credentials secure.
You instruct us to process the data as described in sections 2 and 3. If you need us to process it differently, contact us first.
The measures we apply are the ones described on our Privacy & data page: HTTPS/TLS in transit, row-level security on the database so records are only reachable by the account that owns them, private storage for uploaded files, hashed credentials, and least-privilege administrative access.
Encryption at rest, network protection, backups, resilience and the regular testing of those controls are provided and tested by our hosting and database providers as part of their managed platform, and we rely on their published documentation for evidence of them. We do not operate our own servers or hold our own security certifications.
We review our own settings — access, policies and storage privacy — when we change the app and at least once a year. We may change specific measures over time, but not in a way that materially reduces the level of protection.
You give us general written authorisation to engage sub-processors to run the service. The current list — hosting and the managed backend, the database/authentication/storage platform behind it, transactional email infrastructure, and the payment processors — is published and kept up to date in the Sub-processors section of our Privacy & data page.
Before a new or replacement sub-processor begins processing the data covered by this agreement, we will notify you in advance by email to your account address, and we will update the sub-processor list on the Privacy & data page at the same time. We aim to give as much notice as the provider change allows, and will not make the change without giving you a meaningful opportunity to object first. During that period you may object on reasonable data-protection grounds. If you object, we will work with you to find a solution; if none is available, you may terminate your subscription without penalty for the unexpired period, as set out in our refunds & cancellations policy. Where a change is forced on us at short notice by a provider, we will tell you as soon as we can and your right to object and terminate without penalty still applies.
Each sub-processor is engaged under written terms no less protective than those in this agreement, and we remain fully liable to you for their performance.
AI providers. No AI feature independently accesses the data covered by this agreement: customer records, invoices, client briefs, supplier-contact records, notes, planner content and Drawing Board content are not read by any AI model, and none of that content is used to train AI models. There is one exception, which happens only when you deliberately trigger it: when you choose supplier-document auto-fill in the Ingredient Library, the file you selected is sent in full to the AI service on your documented instruction, and that file may incidentally contain third-party personal data such as a named supplier contact, email address, telephone number or signature. For that limited processing action the Lovable AI Gateway and the model provider used for the request act as sub-processors of the data covered by this agreement, and you authorise them on that basis. Please remove or redact personal data you do not need read before submitting a document for auto-fill.
Deletion you carry out yourself takes effect immediately. You can delete individual records at any time, and export or print them first if you want a copy. When you delete a record, or delete your whole account, the active copies are removed from your account and from the live systems we control at that point — not after a holding period — and the deletion cannot be undone. Deleting your account also cancels any live subscription and removes your uploaded files, notification tokens and our record of emails sent to your address.
When your subscription or this agreement ends, you choose whether we return the data covered by this agreement to you in a commonly used machine-readable format, or delete it. The 30 days after the end date is the window for you to tell us which you want — it is not a holding period before deletion. If we hear nothing in that time, we delete it.
Where you choose deletion, we delete the active copies of that data from the live systems we control without undue delay on your instruction. At the same time, backup copies are put beyond ordinary use — they are not restored, searched or used for any other purpose — and are deleted as they age out of the relevant provider's documented, verified backup-retention cycle. We do not state a fixed period for that cycle, because it is set and evidenced by the provider rather than by us. Where you choose return, we delete our copies on the same basis once you have confirmed receipt of the export. Anything we are required by law to retain is kept only for as long as that legal duty lasts.
If you ask us to, we will confirm in writing that the deletion has been carried out, normally within 5 working days of completing it. That confirmation covers the copies we control; we cannot certify the timing of a provider's backup cycle beyond what the provider documents. Where the law, a regulator or a court requires us to keep something, we will tell you what it is, why we have to keep it, and when it will be deleted.
We do not retain your records for tax purposes. Any financial records we keep to meet our own legal retention duties are records of Fern Dale Makers Studio's own subscription income — who paid us, for what plan, when and how much. They are not your customer records, your client briefs or the invoices you raise on your own customers, and none of those are retained on that basis.
We will allow for and contribute to audits and inspections of the processing covered by this agreement, carried out by you or by an independent auditor you mandate, as required by Article 28(3)(h).
Reasonable and proportionate conditions apply:
- at least 30 days' written notice, during normal business hours, and no more than once in any 12-month period — unless you have reasonable grounds to suspect non-compliance or a breach, or a regulator or the law requires otherwise, in which case no notice limit applies;
- the auditor signs a reasonable confidentiality agreement, and the audit must not compromise the security or confidentiality of other customers' data;
- we have no data centre or business premises to inspect, so an audit is carried out remotely and on documents — our written answers, our own records, and the certifications and audit reports our providers publish. Where you reasonably need something only a provider can give, we will ask them for it, but we cannot grant access to their systems or premises;
- you bear your own and the auditor's costs, and we may charge our reasonable costs for time spent beyond the first audit in a 12-month period, unless the audit reveals a material breach of this agreement.
We are a one-person business, so please tell us in advance what you need to see; we will work with you to complete the audit efficiently.
Administrative access to your account data sits with one person, Kathryn Barnes. If that ever changes — a contractor helping with support or development, for example — that person will be bound by confidentiality, given appropriate data protection training for what they do, and limited to the access the work needs.
We know of nothing in data protection law that stops us providing the service described in our Terms of use.
We are responsible to you for our own failure to meet this agreement or data protection law, and for the acts and omissions of our sub-processors as if they were our own.
You are responsible for the matters set out in section 6 — having a lawful basis, the accuracy of what you enter, informing your own data subjects, keeping your credentials secure, and not entering special category data.
Our overall financial liability under this agreement is subject to the same limits and exclusions as our Terms of use, which form part of the same contract. Nothing here limits liability that cannot lawfully be limited, and nothing here limits either party's own direct liability to a data subject or to a regulator under data protection law.
This agreement takes effect when you first store another person's details in the app and continues for as long as we hold any of the data it covers — including through the return or deletion windows in section 10, which survive the end of your subscription.
A material breach of this agreement is a material breach of our Terms of use. If we breach it, you may end your subscription immediately by telling us in writing, and section 10 then applies. Your right to end your subscription because you object to a new sub-processor is set out in section 8.
Formal notices under this agreement — data-subject requests, breach questions, audit requests, objections to a sub-processor, deletion or return instructions, a DPIA pack, or a countersigned copy for your own records — should be sent in writing to Kathryn Barnes, trading as Fern Dale Handcrafted, 288 Ferndale Road, Swindon, SN2 1HL, at contact@ferndale-handcrafted.co.uk. You can also reach us through the Support page. Email counts as writing. We will send notices to you at the email address on your account. This does not apply to the service of legal proceedings.
If we update these terms we will change the version and date at the top of this page. Material changes affecting the data covered by this agreement will be notified to account holders by email and in-app. We review the descriptions in sections 2, 7 and 8 at least once a year, and update them when our practices change.