Legal

Data Processing Agreement

Last updated: 24 July 2026

When you put data into RepBud about other people — your contacts, customers, suppliers or employees — you are the data controller and Charnette Ltd is your processor. These Article 28 terms govern that, and apply automatically when you use RepBud. Our Privacy Policy covers the data we hold about you as our customer.

1. Roles

You (the customer) are the controller. Charnette Ltd, trading as RepBud, is the processor. Where you are yourself a processor for someone else, we act as sub-processor and these terms apply as if you were the controller.

One exception, stated plainly because it is genuinely different: where you take card payment on an invoice through Charnette Payments, the charge is created on our own Stripe account and we deduct a platform fee before passing the balance to you. For that flow we act as a controller of the payer’s payment data for our own commercial purpose, not as your processor. Payers are given their own privacy information at the point of payment.

This agreement forms part of our Terms of Service and is incorporated into them by reference. Where it conflicts with those terms on data protection, this agreement prevails.

2. Subject matter, duration, nature and purpose

We process personal data only to provide the RepBud service to you. That covers customer relationship management — logging interactions, generating client reports and meeting briefs, syncing calendars and contacts where you connect an account, sending email and WhatsApp on your instruction through Reach and Relay, and finding work email addresses through Smart Email Finder — and, where you use RepBud Revenue, bookkeeping, invoicing, payroll and tax filing.

Processing lasts for as long as your account is active, and then for the wind-down period in section 8.

3. Types of personal data

  • Contact data — names, emails, phone numbers, job roles and company details of your professional contacts
  • Interaction data — notes, emails, meeting records and messages you log, including voice notes you record and any images or files you upload
  • Calendar data — event titles, times, locations and attendee names and email addresses, where you connect a Google or Microsoft account
  • Financial and transaction data — bank and card transactions, invoices, bills, expenses, receipts and ledger entries
  • Payroll data — employee names, salary, National Insurance numbers, tax codes and bank details, where you run payroll
  • Tax data — VAT, Corporation Tax and Self Assessment figures and the documents generated from them
  • Usage data — email opens and link clicks on messages you send, and device identifiers used to deliver push notifications

Special category data. RepBud Revenue’s payroll module records statutory sick pay and statutory maternity, paternity, shared parental and adoption pay against a named employee. Those entries reveal information about health and family circumstances, so they are special category data under Article 9(1) and we should not pretend otherwise. We process them only on your instruction, to produce the payroll you have asked for. The Article 9(2) condition — normally Article 9(2)(b), obligations in the field of employment and social security law — and the appropriate policy document required by Schedule 1 to the Data Protection Act 2018 are yours to hold, as the employer. We apply the safeguards in section 6 to that data.

Beyond payroll we do not require special category data and ask that you do not enter it. If you do, identifying an Article 9 condition for it remains yours.

4. Categories of data subject

  • Your contacts and prospects
  • Your customers and their staff
  • Your suppliers and their staff
  • Your employees and directors (where payroll is used)
  • Your own team members with access to your account

5. Our obligations

We will:

  • Process personal data only on your documented instructions — using the service is your instruction — including as regards any transfer of personal data to a country outside the UK, unless we are required to process by law, in which case we will tell you first unless the law forbids it
  • Tell you immediately if, in our opinion, an instruction you give us infringes the UK GDPR, the Data Protection Act 2018 or other applicable data protection law — we may pause the processing concerned until you confirm or withdraw the instruction
  • Ensure everyone authorised to process the data is under a duty of confidentiality
  • Implement appropriate technical and organisational measures (Article 32) — see section 6
  • Not engage a sub-processor without the general authorisation in section 7, and only under a written contract on the terms described there, remaining fully liable to you for what our sub-processors do
  • Assist you, by appropriate technical and organisational measures and so far as is possible, in responding to requests from individuals exercising their rights
  • Assist you in meeting your own obligations on security, breach notification to the ICO and to affected individuals, data protection impact assessments and prior consultation (Articles 32 to 36), taking into account the nature of the processing and the information available to us
  • Notify you of a personal data breach on the timescale and with the content set out in section 10
  • Delete or return the data at the end of the service, at your choice, per section 8
  • Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in section 9

6. Security

  • All data encrypted in transit (TLS) and at rest
  • Row Level Security so one customer's data cannot be reached by another
  • Passwords hashed; access to production strictly controlled
  • Per-company access grants, so an accountant you authorise sees only the entity you granted
  • Backups managed by our hosting provider

7. Sub-processors

You give general authorisation for the sub-processors below. Before we add or replace one we will give you at least 30 days’ written notice, by email to your account address and by updating this page. You may object within those 30 days on reasonable data protection grounds; if we cannot resolve your objection you may terminate the affected service and we will refund any prepaid fees for the unused period.

Sub-processorLocationPurpose
SupabaseIreland (EU)Database, authentication and file storage — the primary store for your data
VercelEU / USApplication and website hosting
CloudflareGlobalDNS, inbound email routing, and R2 object storage for files uploaded through RepBud Relay
AnthropicUSAI features you choose to use — interaction summaries, client reports, Team Pulse commentary, and in RepBud Revenue the “Ask” feature and receipt capture
OpenAIUSTranscription of voice notes you record in the mobile app
GoogleUS / globalCalendar and contact sync where you connect a Google account; web font delivery
MicrosoftUS / globalOutlook calendar sync and Teams meeting creation where you connect a Microsoft account
StripeEU / USPayment processing — subscriptions and, where enabled, invoice card payments
PostmarkUSTransactional email, including invoices and statements you send
ResendUSNewsletters and connection invitations
TwilioGlobalWhatsApp message processing
Meta (WhatsApp Business API)GlobalWhatsApp integration
MapboxUSGeocoding company addresses and rendering trade-event venue maps
Hunter.ioEU (France)Smart Email Finder — we send a contact’s name and their employer’s domain to find a likely work email address
ExpoUSPush notification delivery to the mobile app
SentryEU / USError monitoring in RepBud Revenue

We engage each sub-processor under a written contract that imposes on it the same data protection obligations as are set out in this agreement, so far as they apply to the service that sub-processor actually provides, and in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. In practice this is the provider’s own data processing agreement, which we enter into on your behalf. Where a sub-processor fails to meet its data protection obligations, we remain fully liable to you for its performance.

AI processing is limited to the features you choose to use. Your data is not used to train any AI model — both Anthropic and OpenAI exclude commercial API inputs and outputs from model training. Retention is a separate question, and we would rather state it accurately than reassuringly: under Anthropic’s standard commercial terms, inputs and outputs are held for up to 30 days for operational and abuse-detection purposes, and longer where a request is flagged under their usage policy. OpenAI applies a comparable 30-day abuse-monitoring retention. We do not currently hold a zero-retention agreement with either provider. If that changes we will update this page.

8. Return and deletion

The choice between deletion and return is yours, not ours. At any time, and at the end of the service, you may tell us which you want and we will act on it — including deleting existing copies.

You can export your data yourself at any time while your account is live. On termination, we will delete your data within 30 days of you asking us to. If you have told us nothing within 90 days of termination we will delete it anyway, so it does not sit here indefinitely by default.

We will not refuse deletion on the basis of accounting or payroll retention rules. Those duties — six years for company records, three years for payroll — fall on you as the company and employer whose records they are, not on us as your software provider. Whether to keep them, and where, is your decision. Separately, we keep our own business records about you as our customer (our invoices to you, our correspondence) as a controller in our own right; that is covered by our Privacy Policy, not by this agreement.

Backups are cycled on a rolling basis and deleted data persists in them until the cycle completes, after which it is overwritten. We do not restore deleted data from backup except to recover from an incident.

9. Audit

We will make available all information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits and inspections conducted by you or by an auditor you mandate.

In practice most requests are answered by our written responses, this sub-processor list and our security documentation, and we would ask you to start there — it is faster for both of us. Where that is not enough, you may audit or inspect on 30 days’ written notice, during business hours, without unreasonable disruption, and no more than once in any 12 months. That annual limit does not apply following a personal data breach affecting your data, or where a regulator requires it — then you may audit as often as is necessary. Each party bears its own costs.

10. Personal data breach

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting personal data we process for you. That leaves you the balance of your own 72-hour window to notify the ICO.

The notification will describe, so far as we know it at the time: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take, including to mitigate harm; and a contact point for more information. Where we cannot provide all of it at once we will provide it in phases as it becomes available, without further undue delay.

We will assist you in meeting your own obligations to notify the ICO and, where required, affected individuals. We will not notify a regulator or an individual about a breach of your data on your behalf unless you ask us to.

11. International transfers

Your data is primarily stored in the EU (Ireland), on Supabase. Two qualifications we would rather state than gloss: files uploaded through RepBud Relay are stored in Cloudflare R2, which we have not restricted to an EU region; and several sub-processors listed above are US-based and receive data in the course of the features they power.

Where a sub-processor processes data outside the UK or EEA, that transfer is made under an appropriate safeguard — the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it.

You can obtain a copy of the safeguard relied on for any particular transfer by emailing privacy@repbud.app, and we will provide it or tell you where it is published.

12. Liability and governing law

Our liability under this agreement is subject to the limitations and exclusions in our Terms of Service. Nothing in this agreement limits or excludes either party’s liability to a data subject under Article 82 UK GDPR, or any liability that cannot lawfully be limited.

This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.

If we change this agreement we will publish the change on this page and update the date at the top. Where a change materially reduces your rights, we will give at least 30 days’ notice by email first.

13. The processor

For the avoidance of doubt, the processor under this agreement is:

Charnette Ltd
Registered in England and Wales, company number 17167712
Registered office: 20 Wenlock Road, London, England, N1 7GU
Data protection queries: privacy@repbud.app

Notices under this agreement may be sent to that email address or to the registered office.

This agreement is provided in good faith and reflects how RepBud actually operates, but it is not legal advice. If you process significant volumes of personal data, or payroll data for others, have your own adviser review it against your obligations.