Last updated: July 2026
Capitalised terms used in this Addendum shall have the meaning given to them in: (1) the master Terms of Service and Website Terms of Use (together, the “Agreement”); and (2) for any terms not defined in the Agreement, the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
You acknowledge and agree that:
1.1 You are the Data Controller and TouchRight Software Ltd (“TouchRight”) is the Data Processor for any Personal Data you enter into the TouchRight Web and Mobile Application ecosystem (including all current or future desktop dashboard portals, websites, or mobile applications), or that you instruct us to process on your behalf.
1.2 You retain absolute control of the Personal Data and remain solely responsible for your compliance obligations under any applicable UK legislation relating to the Personal Data. You warrant that you have obtained all necessary rights, lawful bases, and consents, and have provided all required privacy notices necessary for TouchRight to process the Personal Data in accordance with the Agreement.
1.3 Where TouchRight processes Personal Data relating to the relationship between different joint customers (such as multi-branch networks or corporate partnerships), it is accepted that each customer may act as a joint Controller in relation to aspects of that Personal Data, and TouchRight will remain obligated to retain and process such Personal Data in accordance with the instructions of the continuing active customer.
1.4 TouchRight may permanently anonymise the Personal Data so that it is no longer capable of identifying a living individual and therefore no longer constitutes Personal Data under UK law. TouchRight reserves the right to utilise such anonymised, aggregated data for its own legitimate business purposes, including system optimization and platform performance profiling.
In respect of all Personal Data we process as a Data Processor on your behalf under the Agreement, TouchRight shall:
2.1 Only process that Personal Data on your documented instructions (which explicitly include the terms, subscription settings, and configurations detailed within the Agreement) unless otherwise required to do so under applicable UK or sovereign law; in such cases, we shall, where lawfully permitted to do so, provide prior written notice to you before processing.
2.2 Ensure that all persons, employees, and internal agents authorised to process the personal data are bound by strict, legally enforceable requirements of confidentiality.
2.3 Inform you immediately if, in our professional opinion, an operational instruction received from you would result in a direct breach of the UK GDPR or applicable UK data protection laws.
2.4 Provide reasonable operational assistance to you to conduct Data Protection Impact Assessments (DPIAs) where explicitly required under applicable law.
2.5 Provide reasonable assistance to you in relation to regulatory communications with, and notifications to, supervisory authorities (such as the ICO) and data subjects.
2.6 Implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, or accidental loss, alteration, unauthorised disclosure or access.
2.7 Notify you promptly, and without undue delay, in the event of a verified security breach leading to the accidental, unauthorised, or unlawful loss, alteration, disclosure of, or access to, the Personal Data.
2.8 Only transfer Personal Data outside of the United Kingdom by executing approved statutory safeguards required for the international transfer to comply with UK data protection laws. This includes utilising the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses alongside verified cloud security parameters.
3.1 You grant TouchRight a general written authorisation to appoint third-party Sub-processors (including cloud hosting providers, secure automated billing engines, digital adopt systems, and enterprise generative AI processing models) to assist in executing our service delivery.
3.2 We shall maintain an up-to-date schedule of active Sub-processors and will provide prior written notice of any intended addition or replacement of a Sub-processor at least 14 days before the change takes effect. If you reasonably object to the addition on legitimate data protection grounds, you must notify us in writing within that 14-day window, and both parties shall work together in good faith to reach a compliant operational resolution.
3.3 TouchRight confirms that it enters into formal written contracts with all appointed Sub-processors, imposing data protection obligations that are equivalent to, and no less restrictive than, those set out in this Addendum.
4.1 At your reasonable written request, and subject to appropriate confidentiality agreements, TouchRight will provide summary evidence of our operational compliance with this Addendum, including relevant executive summaries of third-party system security certifications (such as AWS SOC 2 or ISO 27001 audit reports).
5.1 Upon the official termination of the Agreement, and subject to any rights of any other joint Controllers in relation to the platform files, TouchRight shall systematically decommission active user access.
5.2 In alignment with the Agreement's data lifecycle, TouchRight will maintain account data within the live environment for 90 days from the official termination date to facilitate client extraction. Following this 90-day window, TouchRight will delete or permanently anonymise the Personal Data, and will only retain archived copies if strictly required to do so under applicable UK corporate tax, financial accounting, or statutory legal obligations.
5.3 The provisions of Section 5.2 shall be entirely superseded where a client actively executes a transition to our Hibernate Plan, under which personal data is maintained securely in an active, read-only state for the duration of the hibernate subscription.
6.1 Duration: For the active term of the primary subscription Agreement plus the 90-day post-termination live database extraction window (unless extended via the Hibernate Plan).
6.2 Nature and Purpose: To provide property inspection software-as-a-service utilities, mobile field report capturing, automated generative text layout assistance (ReportAssist), technical desktop support, secure billing handling, and data synchronization with integrated third-party estate agency CRMs.
6.3 The Types of Personal Data Processed:
(a) Identity and Contact Data: Full names, company positions, corporate roles, business email profiles, and telephone contact channels.
(b) Technical Device Telemetry: System access logs, network identifiers, IP addresses, system crash diagnostic keys, and onboarding platform interface interactions.
(c) Geographic Location Data: Device-specific GPS tracking data captured exclusively during active utilisation of the native application's Lone Worker feature.
(d) Property Portfolio Content Data: Landlord names, landlord addresses, landlord emails, landlord phone records, tenant names, occupant names, tenant emails, tenant phone numbers, and descriptive property inspection photographs.
6.4 The Categories of Data Subjects Processed:
(a) Landlords and property owners.
(b) Your corporate personnel (including employees, field clerks, branch consultants, and independent contractors).
(c) Active tenants, property applicants, and previous occupants.
(d) Contractors, maintenance operators, and third-party property visitors.
6.5 Special Category Data: It is explicitly stated and agreed that no special category personal data (as defined under Article 9 of the UK GDPR) is anticipated, requested, or intended to be processed within the TouchRight Software platform architecture.
Copyright © 2026 TouchRight Software Ltd. All rights reserved.