Data Processing Agreement
Version: 2026-09
This DPA forms part of the agreement between the subscribing business (“Controller”) and LBM Developments Ltd (“Processor”) where the Processor handles personal data on behalf of the Controller through the BrakerBase Service.
1. Processing details
Subject matter: operation of the BrakerBase software, including stock, order, invoice, user, dispatch, audit and integration functions.
Duration: for the subscription term plus agreed/legally required retention and backup periods.
Nature and purpose: storing, organising, retrieving, transmitting and otherwise processing personal data as required to provide the Service on the Controller’s documented instructions.
Data subjects: the Controller’s customers, prospective customers, users/staff, suppliers and other contacts whose information the Controller enters into the Service.
Types of personal data: names, contact details, delivery addresses, order/invoice references, account/user details, support information and other ordinary personal data entered by the Controller. The Service is not intended for unnecessary special-category data.
2. Documented instructions
The Processor will process personal data only on documented instructions from the Controller, including configured integrations and user actions, unless UK law requires otherwise.
3. Confidentiality
The Processor will ensure people authorised to process Controller personal data are subject to appropriate confidentiality obligations.
4. Security
The Processor will maintain appropriate technical and organisational measures proportionate to risk. Current platform measures include tenant/business separation, authentication, role controls, encrypted integration credentials, secure session controls, CSRF protection, audit logging and operational backup/export capabilities.
5. Sub-processors
The Controller authorises the use of sub-processors required to host, secure, bill or operate the Service, subject to equivalent data-protection obligations. The Provider must maintain a current sub-processor record and provide notice of material changes where required. Connected marketplaces and shipping services selected directly by the Controller may have separate controller/processor roles under their own terms.
6. Data-subject rights
Taking account of the nature of processing, the Processor will reasonably assist the Controller to respond to requests concerning data-subject rights where the relevant data is held in the Service.
7. Assistance and incidents
The Processor will reasonably assist the Controller with security, breach, impact-assessment and regulatory obligations applicable to the processing, and will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data.
8. International transfers
The Processor will not knowingly make a restricted transfer of Controller personal data without an applicable lawful transfer mechanism where one is required.
9. Return and deletion
At the end of the Services, the Controller may export business data. At the Controller’s choice and subject to applicable legal requirements, the Processor will delete or return personal data and delete remaining copies through the normal production/backup deletion cycle. Data retained by law will be protected and not used for unrelated purposes.
10. Audit and information
The Processor will make available information reasonably necessary to demonstrate compliance with applicable processor obligations and will allow reasonable audits/inspections subject to appropriate confidentiality, security and operational safeguards.
11. Controller obligations
The Controller is responsible for the lawfulness, accuracy and transparency of personal data it enters, for giving required privacy information to its own customers/data subjects, for selecting an appropriate lawful basis, and for issuing lawful documented instructions.
12. Contact
Processor: LBM Developments Ltd. Privacy contact: sy@lbmdevelopments.com.