Data Processing Addendum

Effective date: 31 August 2026

Processor: Alvey Group Ltd (trading as Pest Intel), company no. 14009500

A practical part of the service agreement

This Addendum applies automatically when a customer uses Pest Intel to process personal data in its site records. It forms part of the Terms of Service, so a separate signature is not required.

The customer is the controller of that site-record data and Alvey Group Ltd is the processor. Alvey Group Ltd remains an independent controller for its own account, billing, security, legal, and permitted marketing records, as described in the Privacy Policy.

1) Scope and priority

This Addendum governs the processing of Customer Personal Data by Alvey Group Ltd on the customer's behalf under the Pest Intel service agreement. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and other applicable UK data-protection law. If this Addendum conflicts with the Terms on processor obligations, this Addendum takes priority.

2) Customer instructions

  • Alvey Group Ltd will process Customer Personal Data only on the customer's documented instructions, including the Terms, configuration and use of the service, and support requests.
  • We may also process data where UK law requires it. Where legally permitted, we will tell the customer before doing so.
  • We will tell the customer if, in our reasonable opinion, an instruction infringes Data Protection Law. We may pause the affected processing while the parties resolve it.
  • The customer is responsible for its lawful basis, privacy information, user access decisions, data accuracy, and instructions to Pest Intel.

3) Confidentiality and security

People authorised to process Customer Personal Data are bound by confidentiality duties. We maintain proportionate technical and organisational measures appropriate to the risk, including access controls, encrypted connections, role-based permissions, secret management, logging, private storage, backups, and procedures for responding to security incidents.

4) Sub-processors

The customer gives general written authorisation for us to use sub-processors needed to operate Pest Intel. Current sub-processors used for Customer Personal Data include Supabase for authentication, database and storage; Vercel for hosting; and Brevo for transactional email. Stripe and delivery carriers receive limited billing or delivery data under their applicable contractual roles and do not receive routine inspection records.

We require each sub-processor to protect personal data on terms substantially equivalent to the relevant duties in this Addendum. We remain responsible for their processing to the extent required by Data Protection Law. We will give reasonable notice of a material new sub-processor where practicable. A customer may object within 10 working days on reasonable data-protection grounds, and the parties will work in good faith on a practical solution.

5) International transfers

We will not transfer Customer Personal Data outside the UK unless a lawful transfer mechanism and any required supplementary safeguards are in place. This may include UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved EU standard contractual clauses.

6) Assistance

  • Taking account of the nature of the processing, we will provide reasonable assistance with data-subject requests. The customer remains responsible for responding to the individual.
  • We will provide reasonable assistance with security, breach assessment, data-protection impact assessments, and regulator consultation where relevant to Pest Intel processing.
  • If assistance requires substantial work outside normal service operation, the parties will agree a reasonable fee in advance unless the work is required because of our breach.

7) Personal-data breaches

We will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. We will provide information reasonably available to us about the nature and likely impact, affected data and people, measures taken or proposed, and a contact for follow-up. We will take reasonable steps to contain, investigate, and remedy the incident. Notification is not an admission of fault.

8) Return and deletion

During the subscription, the customer can use Pest Intel's export tools. When the service ends, we will, at the customer's written choice, delete or return Customer Personal Data after a reasonable export period, unless applicable law requires continued storage. Secure backup copies are removed through the ordinary backup cycle and remain protected until deletion. Account, billing, contract, fraud-prevention, and security records that we hold as an independent controller follow the Privacy Policy.

9) Information and audit

We will make information reasonably necessary to demonstrate compliance with this Addendum available to the customer. A customer may conduct one proportionate audit in any 12-month period, or an additional audit following a relevant breach or regulator request. Documentary evidence and remote review will be used first. Any on-site review requires reasonable notice, must protect other customers and confidential information, and must not unreasonably disrupt the service. The customer bears its audit costs unless the audit identifies our material breach.

10) Processing details

Subject matterHosting and operating the Pest Intel site-monitoring, workflow, evidence, scheduling, reporting, support, and export service.
DurationFor the subscription term and the limited return, deletion, backup, and lawful-retention period described above.
Nature and purposeCollection, recording, organisation, storage, retrieval, consultation, transmission, support, security, backup, export, and deletion as needed to provide Pest Intel.
Data subjectsCustomer personnel, authorised users, contractors, business contacts, and people whose personal data may be incidentally included in site notes, photographs, or evidence.
Personal dataNames, work contact details, roles, authentication and audit events, site assignments, inspection actions, notes, photographs, evidence, signatures or acknowledgements, and support communications.
Special-category dataNot required for ordinary use and should not be entered. If incidentally supplied, it is processed only to provide and secure the service under the customer's instructions.
Customer rightsThe customer retains all controller rights and responsibilities, including the right to give lawful instructions, manage users, export records, and request return or deletion.

11) Contact

Data-protection questions and processor instructions: info@pestintel.co.uk.

Back to homepage

© 2026 Alvey Group Ltd
Registered in England and Wales. Company no. 14009500.
Registered office: The Old Docks House, 90 Watery Lane, Preston, Lancashire, England, PR2 1AU.
Home · Privacy · Data processing · Terms · Cookies