Last updated: April 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Core M8 Ltd(“Corem8”, “we”, “our”, the Processor) and the customer identified in the underlying subscription or order form (“Customer”, “you”, the Controller) governing the use of the Corem8field service management platform (the “Service”).
It reflects the parties' obligations under Article 28 of the UK General Data Protection Regulation, the EU General Data Protection Regulation, and the UK Data Protection Act 2018.
This page reproduces the operative terms of the DPA in readable form. A version ready for counter-signature is available on request from privacy@corem8.com.
Terms used in this DPA have the meanings given to them in the UK GDPR and EU GDPR unless otherwise defined. In particular:
The processing of Personal Data by the Processor in order to provide the Service to the Controller.
The processing lasts for the term of the underlying subscription and any post-termination period required to return or delete Personal Data in accordance with section 10.
Hosting, transmission, retrieval, organisation, storage, analysis, and display of Personal Data in order to operate the field service management features of the Service, including customer relationship management, job scheduling, invoicing, messaging, payments, and the AI-assisted features the Controller enables.
Identifiers (names, emails, phone numbers, addresses), job and service records, scheduled appointment data, photographs uploaded by the Controller or its users, message content (SMS, WhatsApp, email), invoice and payment records, and any further data the Controller chooses to submit through the Service.
The Controller's own staff and contractors (users of the Service), the Controller's customers, and any third parties whose personal data the Controller chooses to enter into the Service.
The Controller is the data controller of the Personal Data. The Processor acts as a data processor on behalf of the Controller, except for Personal Data processed for its own legitimate business purposes (billing of the Controller, platform security, fraud prevention, aggregate analytics of Service usage), in respect of which the Processor acts as an independent controller as described in our Privacy Policy.
The Processor will process Personal Data only on documented instructions from the Controller. The Controller's instructions are set out in this DPA, in the underlying subscription agreement, and in the Controller's configuration and use of the Service. Additional instructions outside the ordinary use of the Service are subject to mutual agreement and may be chargeable.
The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes the UK GDPR or the EU GDPR.
The Processor ensures that personnel authorised to process Personal Data are bound by appropriate obligations of confidentiality.
The Controller grants the Processor a general authorisation to engage the sub-processors listed at corem8.com/sub-processors, as updated from time to time.
The Processor will:
The Controller may object to a new sub-processor on reasonable data protection grounds as described in that page.
The Processor implements and maintains appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Current measures include, at a minimum:
These measures are reviewed periodically and updated to reflect changes in threat landscape, technology, and regulatory expectations.
Personal Data may be transferred to jurisdictions outside the United Kingdom or the European Economic Area for the purpose of operating the Service. The Processor relies on appropriate transfer mechanisms as set out at corem8.com/sub-processors, including the Standard Contractual Clauses, the UK IDTA Addendum, and the UK–US and EU–US Data Privacy Frameworks where applicable.
Where the Controller requires the SCCs to apply directly between the parties, the parties agree that the SCCs (module two, controller to processor) are incorporated into this DPA by reference and apply in the following configuration: the Controller is the data exporter, the Processor is the data importer, Clause 7 (docking) applies, Clause 9(a) option 2 (general authorisation) applies with the notification period published at corem8.com/sub-processors, Clause 11 is not used, Clause 17 selects the law of England and Wales, and Clause 18 selects the courts of England and Wales.
The Service provides the Controller with tools to respond to data subject requests for access, rectification, erasure, restriction, and portability in respect of Personal Data within the Service.
Where a Data Subject submits a request directly to the Processor, the Processor will, without undue delay, forward it to the Controller and will not respond substantively unless instructed to do so.
The Processor will assist the Controller, taking into account the nature of the processing and the information available to the Processor, to fulfil the Controller's obligation to respond to Data Subject requests.
The Processor will notify the Controller without undue delay and in any event within 72 hours after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.
The notification will include, to the extent known at the time:
The Processor will provide reasonable assistance to the Controller in meeting its notification obligations to supervisory authorities and affected Data Subjects.
On termination or expiry of the underlying subscription, the Processor will, at the Controller's option, either return or delete all Personal Data in its possession, subject to the following:
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and this DPA. This will ordinarily be satisfied by providing current certifications or independent audit reports of the Processor's sub-processors and of the Processor itself where available.
Where the Controller has a reasonable basis to believe the certifications and reports do not provide sufficient assurance, the Controller may request an audit subject to reasonable scope, advance notice, confidentiality, and frequency (not more than once in any 12 month period unless required by a supervisory authority).
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the underlying subscription agreement, except where such exclusion or limitation would be unlawful under the UK GDPR or the EU GDPR.
A Controller that wishes to put a counter-signed copy of this DPA in place should email privacy@corem8.com from the billing contact on the account, stating the registered business name, registered office address, and billing contact. We will return a counter-signed PDF within five business days.
Where a Controller begins use of the Service without executing a separate DPA, this page forms part of the Controller's agreement with Corem8 and will govern the processing of Personal Data.
Email: privacy@corem8.com
Entity: Core M8 Ltd, registered in England & Wales
Sub-processor list: corem8.com/sub-processors