Data Processing Agreement
Effective 8 July 2026
This Data Processing Agreement ("DPA") forms part of the Patch14 Terms of Servicebetween you ("Customer") and Granite & Fleur Digital Ltd ("Patch14", company no. 17289418). It applies wherever Patch14 processes personal data on Customer's behalf as part of the service. Terms not defined here have the meaning given to them in UK GDPR.
1. Roles
Customer is the controller of the personal data it submits to Patch14, or is itself processing that data on behalf of its own clients (for example, an MSP acting on behalf of an SME client). Patch14 is a processor, acting only on Customer's documented instructions as set out in this DPA and the underlying agreement. Where Customer is itself a processor for a third-party controller, Customer warrants it is authorised to instruct Patch14 to process that data accordingly.
2. Subject matter and duration
Patch14 processes personal data for the duration of Customer's subscription, for the purpose of providing the service described in the Terms of Service (asset monitoring, vulnerability matching, alerting, and evidence pack generation).
3. Nature and categories of data
- Data subjects — Customer's account users, and individuals identifiable from client/asset records Customer uploads or syncs (for example, a device name tied to a named employee)
- Data types — name and email address (account users); device, software, and network inventory data; PSA ticket references; no special category data is intentionally collected or required by the service
- Processing operations — storage, matching against vulnerability data, status computation, alerting, and evidence pack generation
4. Patch14's obligations
Patch14 will:
- process personal data only on Customer's documented instructions, including as set out in this DPA
- ensure personnel with access to personal data are bound by confidentiality obligations
- implement appropriate technical and organisational security measures, including encryption of stored secrets, row-level access controls, and encryption of data in transit
- assist Customer, at Customer's reasonable request, in responding to data subject requests and in meeting Customer's obligations relating to data protection impact assessments and prior consultation with supervisory authorities, to the extent these relate to Patch14's processing
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data
- at Customer's choice, delete or return all personal data at the end of the service, and delete existing copies unless retention is required by law
- make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by Customer or an auditor Customer appoints, on reasonable notice and no more than once per year absent a security incident
5. Sub-processors
Customer authorises Patch14 to engage the following sub-processors, each engaged directly by Patch14 to provide part of the service:
- Supabase — database, authentication, file storage, and secrets storage
- Vercel — application hosting and scheduled jobs
- Stripe — payment processing
- Resend — transactional email delivery
- Microsoft (Graph API) — only where Customer connects Microsoft Intune
Patch14 will give Customer at least 30 days' notice before adding a new sub-processor (by email or in-product notice), during which Customer may object on reasonable data protection grounds. Patch14 remains responsible for each sub-processor's performance of its obligations.
6. Customer-configured integrations
Where Customer connects a PSA or RMM integration it controls (Halo PSA, ConnectWise Manage, Autotask, or Lansweeper) using its own credentials with that provider, that provider is not a Patch14 sub-processor under this DPA — Customer is responsible for its own contractual and data protection relationship with that provider. Patch14's role is limited to transmitting data to and from that integration at Customer's direction.
7. International transfers
Customer's core account, client, and asset data is stored in the UK. Where a sub-processor processes personal data outside the UK, Patch14 ensures an appropriate safeguard is in place, such as an applicable UK adequacy regulation or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
8. Liability
Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.
9. Term
This DPA takes effect when Customer creates a Patch14 account and continues for as long as Patch14 processes personal data on Customer's behalf under the Terms of Service.