★ Data processing
Data processing agreement
Where a partner's customers' personal data is processed by Joulely, the partner is
the controller and Joulely is the processor. Article 28 of the UK GDPR requires a written
contract for that, and we have one. It is sent on request, in full, before you commit to
anything.
business@joulely.co.uk, marked for the
data-protection contact. We will send the agreement, the security statement and the
sub-processor annex together.
Why it is sent rather than published
- It has not been through a solicitor yet. It was drafted in-house so that
professional review is a review rather than an origination: the Article 28 checklist is worked
through in full and the factual annexes describe what the system actually does. Publishing it
as a finished document would misrepresent that status.
- The liability clause is not drafted. It is the clause most likely to be got
wrong by a non-lawyer and the most expensive to get wrong, and it is being drafted with the
insurance position alongside it. It is settled with you, in the negotiation, not decided in
advance on a web page.
- It is executed with your details in it. Named parties, a completed contacts
schedule on both sides, and an annex recording your documented instructions. A published copy
would be missing all three.
What it covers
- Roles, and they differ by product. The agreement sets out where the partner is
controller and Joulely processor, and where Joulely is a controller in its own right for its
own users. Getting that boundary wrong is the commonest defect in a vendor DPA.
- Processing only on documented instructions, with purpose limitation stated as
a list of what Joulely may and may not do with the data. Nothing is used to train a model,
nothing is sold, and nothing is shared for anyone's marketing.
- Data minimisation, and the limits of pseudonymisation stated precisely. Data
the partner can re-identify remains personal data. The agreement does not claim
otherwise.
- Security measures as a factual annex, not a page of adjectives. It is the same
substance as the security statement, including the section listing
what we do not have, so what you audit is what you signed.
- Sub-processors: a named list, at least 30 days' notice of a change, and a
14-day right to object on reasonable documented data-protection grounds. The one limitation we
will not paper over is on the sub-processor page: our upstream
agreement with the meter-data provider has no sub-processor clause, so we cannot compel
disclosure of their chain and we will not warrant it.
- Assistance with data-subject rights and with DPIAs, on the deadlines published
on the service levels page. Those are already firm.
- Breach notification with an actual deadline: 24 hours from becoming aware,
updates at least every 48 hours while it is open, and a written root-cause report within 20
working days of closure.
- An audit and inspection right for the partner over Joulely. We hold no ISO
27001 or SOC 2 certificate to hand you instead, so we answer questionnaires directly and
accept the audit right in the contract.
- International transfers and processing location, stated as they are: the
application, the database and both backup copies are in Germany, and the meter-data provider
is in the UK. Any change of location gets 30 days' notice and an objection right.
- Retention, deletion, return and exit. What happens to the data when the
agreement ends, on a 30-day clock with written certification, and what a partner gets back
before it does.
- Mutual termination on equal notice. The same notice each way. A processor
agreement that only one side can leave is not a partnership.
Related
The security statement and
sub-processor list are the annexes to this agreement in published
form. The service levels page carries the deadlines. The
trust pack names the contracting entity. Consumer use is governed by our
terms of service and privacy notice, and use of the
bill-engine API by the API terms.
Version 2026-08-13.
Trust pack · Security · Sub-processors · Service levels