Data Processing Agreement (DPA)
ArbHub LTD
Version 1.0 — 1 September 2026
This Data Processing Agreement (Agreement) forms part of the contract between ArbHub LTD and the customer for the use of ArbHub.
By creating an ArbHub account, inviting users, or otherwise using the service to store personal data, the customer agrees to this Agreement. For organisation or committee purchases, the parties may also sign the signature block at the end.
This is a standard processor contract. It is not a substitute for legal advice. ArbHub LTD recommends that customers have their own adviser or DPO review it.
1. Parties
Processor
Name: ArbHub LTD
Registered office: 9 Elmcroft Crescent, Bristol, England, BS7 9NF
Company number: 14726285
ICO registration: ZB673550
Contact: info@arbhub.app
Controller
The organisation that holds the ArbHub subscription and uses the service (the Customer), including the legal entity named in any signed copy of this Agreement.
2. Background and roles
2.1 ArbHub is cloud software for arboriculture and tree-work businesses. Customers use it to manage administration such as quotes, invoices, jobs, clients, sites, risk assessments, method statements, incidents, toolbox talks, equipment records, and related files.
2.2 For personal data that the Customer or its users enter into ArbHub (for example staff, clients, site contacts, and records created in the course of work), the Customer is the controller and ArbHub LTD is the processor.
2.3 ArbHub LTD is the controller of its own account, billing, support, and product-improvement data (for example the name and email of the person who buys licences). That processing is described in the ArbHub Privacy Policy and is outside the scope of this Agreement.
2.4 This Agreement applies whenever ArbHub LTD processes personal data on the Customer’s behalf in connection with the service. It is intended to meet Article 28 of the UK GDPR and the Data Protection Act 2018.
3. Definitions
In this Agreement:
UK GDPR means the United Kingdom General Data Protection Regulation, as tailored by the Data Protection Act 2018.
personal data, process, controller, processor, data subject, personal data breach, and special category data have the meanings in the UK GDPR.
service means the ArbHub application and related hosting, support, and billing.
Customer data means personal data processed by ArbHub LTD on the Customer’s behalf, as described in Schedule 1.
subprocessor means another processor engaged by ArbHub LTD to process Customer data.
4. Details of processing
4.1 The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are set out in Schedule 1.
4.2 ArbHub LTD shall process Customer data only:
to provide, maintain, secure, and support the service;
on the Customer’s documented instructions (including those given by using the service, for example creating a client, inviting a user, or uploading a file); and
as required by UK law, in which case ArbHub LTD shall tell the Customer before processing unless the law prohibits that notice.
4.3 ArbHub LTD shall not sell Customer data or use it for its own marketing of third-party products.
4.4 The Customer is responsible for:
the lawfulness of its instructions and of the personal data it puts into ArbHub;
providing any privacy notices its staff, clients, or others need;
having a lawful basis for processing, including an Article 9 condition if it records health or other special category data, and telling staff that emergency medical and next-of-kin details are visible to the rest of the account; and
deciding who in its organisation may access the account.
5. Security
5.1 ArbHub LTD shall implement appropriate technical and organisational measures to protect Customer data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, taking account of the nature of the data and the risks involved.
5.2 Those measures include, as a minimum, the measures in Schedule 2. ArbHub LTD may update them provided the overall level of protection is not reduced.
5.3 ArbHub LTD shall ensure that people authorised to process Customer data are bound by confidentiality.
6. Subprocessors
6.1 The Customer gives a general written authorisation for ArbHub LTD to use the subprocessors in Schedule 3, and to appoint replacement or additional subprocessors in the same categories (hosting, email, payments, analytics, maps/location, and optional integrations the Customer enables).
6.2 ArbHub LTD shall impose data-protection terms on each subprocessor that are no less protective than this Agreement, so far as they apply to that subprocessor’s services.
6.3 ArbHub LTD shall remain responsible to the Customer for the subprocessor’s processing of Customer data.
6.4 ArbHub LTD shall keep Schedule 3 reasonably up to date on this page. If a change is material, ArbHub LTD shall give the Customer notice (for example by email or an in-app notice). The Customer may object on reasonable data-protection grounds. If the parties cannot agree a reasonable alternative, the Customer may stop using the affected feature or end the subscription.
7. International transfers
7.1 The primary database is hosted in Google’s Europe multi-region (eur3, Belgium and the Netherlands). Application processing runs in London (Google Cloud europe-west2).
7.2 Some subprocessors may process data in the UK, the EEA, or other countries. Where Customer data is transferred outside the UK, ArbHub LTD shall ensure a lawful transfer mechanism is in place, such as:
a UK adequacy regulation (including the UK’s adequacy arrangements for the EEA); or
the UK International Data Transfer Agreement, UK Addendum to the EU Standard Contractual Clauses, or an equivalent safeguard.
7.3 Transfers between the UK and the EEA are made in reliance on the UK’s adequacy regulations for the EEA, where applicable.
8. Assistance, rights, and incidents
8.1 Taking into account the nature of the processing, ArbHub LTD shall help the Customer, by appropriate technical and organisational measures, to respond to requests from data subjects to exercise their rights under the UK GDPR (access, rectification, erasure, restriction, portability, and objection).
8.2 To exercise those rights in respect of Customer data, the Customer should use the tools in the service where available, or email info@arbhub.app. ArbHub LTD shall respond to Customer requests of this kind without undue delay.
8.3 ArbHub LTD shall help the Customer with its obligations relating to security, data protection impact assessments, and consulting the ICO, where this is relevant to ArbHub’s processing and the Customer asks for that help.
8.4 If ArbHub LTD becomes aware of a personal data breach affecting Customer data, it shall notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware, with enough information for the Customer to meet its own notification duties. ArbHub LTD shall reasonably cooperate in investigating and mitigating the breach.
8.5 The Customer is responsible for deciding whether to notify the ICO or affected individuals, unless the law requires ArbHub LTD to notify them directly.
9. Records, information, and audit
9.1 ArbHub LTD shall keep the records of processing required of a processor and shall make available to the Customer the information reasonably needed to demonstrate compliance with this Agreement.
9.2 The Customer may audit ArbHub LTD’s compliance with this Agreement on reasonable written notice, no more than once in any 12-month period unless a personal data breach or genuine suspicion of material non-compliance justifies a further audit. Audits shall be during normal business hours, limited to what is necessary, and shall not unreasonably disrupt the service or compromise other customers’ security or confidentiality.
9.3 ArbHub LTD may satisfy an audit request by providing up-to-date security information, third-party certifications of its subprocessors (for example Google Cloud ISO 27001 or SOC 2 reports), and written answers to reasonable questionnaires.
10. Return and deletion
10.1 During the subscription, the Customer can access, export, and delete much of its data through the service.
10.2 When the Customer’s account ends, ArbHub LTD shall, at the Customer’s written choice, delete Customer data or return a copy of it, unless UK law requires ArbHub LTD to keep it.
10.3 If the Customer does not ask for return within 30 days of the account ending, ArbHub LTD may delete Customer data from live systems. Residual copies in encrypted backups will drop out of the backup cycle in the ordinary course, and in any event will not be kept longer than 90 days after deletion from live systems unless the law requires a longer period.
10.4 An account that is only archived or marked inactive is not deleted until the Customer asks for deletion or the account is fully closed.
11. Term and changes
11.1 This Agreement starts when the Customer first uses the service (or on the date of signature, if earlier) and continues for as long as ArbHub LTD processes Customer data.
11.2 ArbHub LTD may update this Agreement from time to time, for example if the law or the service changes. The current version will be published at this URL. Material changes will be notified by posting the updated Agreement and, where appropriate, by email or an in-app notice. Continued use after the effective date of a change constitutes acceptance, except where a signed copy applies and the Customer’s written agreement is required.
11.3 If there is a conflict between this Agreement and ArbHub’s general terms or privacy policy about the processing of Customer data, this Agreement prevails.
12. Liability and law
12.1 Each party is responsible for its own compliance with the UK GDPR. Nothing in this Agreement limits liability that cannot be limited by law, including for fraud.
12.2 Subject to clause 12.1, ArbHub LTD’s liability under this Agreement is subject to the limitations in the Customer’s subscription terms with ArbHub LTD. If those terms are silent, liability is limited to the fees paid by the Customer for the service in the 12 months before the claim.
12.3 This Agreement is governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.
Schedule 1 — Details of processing
Subject matter. Hosting and providing the ArbHub cloud service.
Duration. For the life of the Customer’s account, then deletion or return as in clause 10.
Nature. Storage, retrieval, display, backup, transmission, and deletion of data the Customer enters; sending transactional email; generating documents and files the Customer requests.
Purpose. To provide the service the Customer has subscribed for, including support.
Data subjects. The Customer’s staff and invited users; clients, property contacts, and other people whose details the Customer records; any other individuals appearing in files or records the Customer uploads.
Personal data. Identity and contact data (name, email, phone, address); account and role information; client, property, and job records; quotes, invoices, and related commercial records; risk assessments, method statements, incidents, toolbox talks, and similar operational records (which may include names and signatures); photos, documents, and other files; optional location data (for example device location or what3words) where the Customer uses those features.
Special category data. Only if the Customer chooses to record it. ArbHub allows optional next-of-kin and emergency medical fields (for example allergies or conditions that would matter if someone is injured). These fields are for emergency use and are visible to everyone on the Customer’s ArbHub account, including on the SOS screen, crew lists, and risk assessments. They are not a private medical record. The Customer must not record special category data unless it has a lawful basis (including an Article 9 condition for health data), and should tell its staff that these details are shared with the team for first aid.
Customer instructions. Use of the service, configuration of the account, and written instructions sent to info@arbhub.app.
ArbHub LTD does not store card numbers. Payments are handled by Stripe as described in Schedule 3.
Schedule 2 — Security measures
ArbHub LTD’s measures include:
Hosting. Customer data is hosted on Google Cloud / Firebase. Google encrypts data in transit (TLS) and at rest, and publishes ISO 27001, SOC 2, and related compliance documentation.
Location. The Firestore database is in Europe (eur3). Cloud Functions run in London (europe-west2).
Access control. Users sign in with their own credentials. Organisation data is separated by account. Users can access only the organisation(s) they belong to, subject to the permissions the Customer sets.
Administration. A small number of ArbHub personnel may access an account for support, security, or legal reasons, and only as needed.
Backups. The database is backed up daily to Google Cloud Storage.
Payments. Card data is processed by Stripe and is not stored by ArbHub LTD.
Development and operations. Access to production systems is limited to authorised personnel. Application access is authenticated.
The Customer is responsible for choosing strong passwords, managing who it invites, and what it uploads.
Schedule 3 — Subprocessors
ArbHub LTD uses the following subprocessors. Optional providers process Customer data only if the Customer uses that feature.
Always used to operate the service
Google Ireland Limited / Google Cloud / Firebase. Hosting, database, file storage, authentication, application processing, and backups. Typical location: EEA and UK (see clause 7).
Stripe Payments Europe / Stripe. Subscription payments. Typical location: EEA, UK, and other Stripe locations under Stripe’s terms.
Twilio SendGrid. Transactional email (invites, notices, billing-related mail). Location: as described in SendGrid’s DPA.
Used for product operation or improvement
Google Analytics / Google Ireland Limited. Product usage analytics. Used for web/app use.
Meta Platforms Ireland Limited. Conversion and advertising measurement (hashed identifiers where used). Used for marketing measurement.
Google Maps / Geocoding. Addresses and map features. Used when location or address features are used.
what3words Limited. Location references on sites/trees. Used when that feature is used.
OpenWeatherMap. Weather for site work. Used when weather features are used.
Kindwise / plant.id / mushroom.id. Species identification from photos. Used when identification is used.
Optional, only if the Customer connects them
Intuit (QuickBooks). Accounting sync, if enabled.
Jobber. Job/client sync, if enabled.
ArbHub LTD’s current privacy policy is published at: https://www.arbhub.app/privacy-policy