← Back

Data Processing Agreement

The Back Kitchen · Last updated July 2026

iBrain LTD · Private Limited Company (Ltd), registered in England & Wales · Company No. 13129970 · London, United Kingdom

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between iBrain LTD (the “Processor”) and the Customer (the “Controller”) and applies whenever the Processor processes personal data on the Controller's behalf as part of The Back Kitchen. It reflects the requirements of Article 28 of the UK GDPR.

1. Subject-matter, nature & purpose

The Processor processes personal data solely to provide the The Back Kitchen platform to the Controller: hosting, storing, displaying, backing up, transmitting, exporting and deleting personal data uploaded by the Controller's users.

2. Duration

This DPA applies for the term of the Controller's subscription, plus a run-off period during which data is exported or deleted (see §10).

3. Types of personal data & data subjects

The Controller decides what to upload. Typical categories include: names, work emails, phone numbers, roles and messages of the Controller's own employees, clients, consultants, suppliers and subcontractors — collected in projects, packages, supplier directories and communications.

4. Roles

The Controller determines the purposes and means of processing (Article 4(7) UK GDPR). The Processor processes only on documented instructions from the Controller.

5. Processor obligations

The Processor will:
  • Process personal data only on the Controller's documented instructions (including these Terms and the Service configuration).
  • Ensure that anyone authorised to process the data is under a duty of confidentiality.
  • Implement appropriate technical and organisational measures (see §6).
  • Assist the Controller in responding to data-subject rights requests, and in security, breach-notification and impact-assessment obligations (Articles 32–36).
  • Notify the Controller without undue delay after becoming aware of a personal data breach.
  • Make available all information necessary to demonstrate compliance and allow the Controller to audit, subject to reasonable notice and confidentiality.
  • Delete or return all personal data at the end of the Service, unless UK law requires storage (see §10).

6. Security measures

The Processor maintains reasonable, industry-standard security including:
  • TLS encryption in transit for all traffic.
  • Encryption at rest for the database and file storage (via Supabase / Vercel).
  • Row-level security so each workspace's data is isolated from every other workspace.
  • Least-privilege access for staff; audit logs of platform activity.
  • Regular backups; recovery procedures tested by the underlying providers.
  • Vulnerability patching by the underlying platforms (Supabase, Vercel, Next.js).

7. Sub-processors

The Controller authorises the Processor to engage the sub-processors listed below to provide the Service. Current sub-processors:
  • Supabase Inc. — database, authentication, file storage (EU region).
  • Vercel Inc. — application hosting (global edge).
  • Payment processor — Paddle / Stripe (billing).
  • OpenAI — only where the Controller opts in to AI features.
  • Google / Meta (WhatsApp) — only where the Controller enables the relevant integration.
The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor. If the Controller reasonably objects, either party may terminate the affected part of the Service.

8. International transfers

Where personal data is transferred outside the United Kingdom, the Processor relies on the UK International Data Transfer Agreement (UK IDTA) or an equivalent lawful mechanism, and applies supplementary safeguards as needed.

9. Data-subject requests & breach notification

The Processor will forward any data-subject request received directly to the Controller and will not respond independently, unless legally required. In the event of a personal data breach, the Processor will notify the Controller without undue delay, and provide information reasonably needed for the Controller's own notification obligations.

10. Return & deletion

On termination, the Controller may export its data using the Service's export functions for up to 30 days. After that, the Processor will delete personal data from its production systems within a further 30 days, and from backups on the ordinary rotation cycle (typically 60–90 days). Anonymised aggregates may be retained.

11. Liability

Liability under this DPA is governed by the limits in the Terms of Service.

12. Governing law

This DPA is governed by the laws of England & Wales.

13. Contact

Notices and questions about data processing: info@ecomsocity.com.

© 2026 The Back Kitchen — a product of iBrain LTD (England & Wales)