Legal
Data Processing Agreement
Last updated 28 July 2026
This Data Processing Agreement (DPA) forms part of the agreement between Simtec Consult Ltd (Processor) and the customer organisation using SIMTRACA (Controller).
It applies where the Processor handles personal data on the Controller's behalf through the service.
1. Definitions
In this DPA:
- Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, PECR where applicable, and other binding UK data protection law;
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach, and Processing have the meanings given by Applicable Data Protection Law;
- Customer Data means data submitted to or generated through the service for the Controller;
- Sub-processor means another processor engaged by the Processor to process Personal Data under this DPA; and
- Services Agreement means the Terms of Service, order, subscription, or other agreement governing the Controller's use of SIMTRACA.
If this DPA conflicts with the Services Agreement on the processing of Personal Data, this DPA takes priority.
2. Roles and scope
The Controller determines the purposes and means of Processing Customer Data. The Processor processes Personal Data only to provide, secure, maintain, and support SIMTRACA and as otherwise documented in the Services Agreement.
The Controller is responsible for:
- complying with Applicable Data Protection Law;
- ensuring its Processing instructions are lawful;
- providing required privacy information to Data Subjects;
- identifying an appropriate lawful basis;
- configuring user access and permissions; and
- ensuring Customer Data is accurate, relevant, and limited to what is necessary.
The Processor acts as an independent Controller for account administration, security, billing, legal compliance, and operation of its own business, as described in the Privacy Policy.
3. Documented instructions
The Processor will process Personal Data only:
- on the Controller's documented instructions, including instructions given through authorised use of the service;
- as described in this DPA and the Services Agreement; or
- where required by UK law.
If UK law requires other Processing, the Processor will inform the Controller before Processing unless the law prohibits that notice.
The Processor will promptly inform the Controller if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. The Processor may suspend the affected Processing while the parties resolve the issue.
4. Confidentiality
The Processor will ensure that people authorised to process Personal Data:
- are bound by confidentiality obligations;
- receive appropriate data protection and security guidance; and
- access Personal Data only as needed for their role.
5. Security
Taking account of the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing, the Processor will maintain appropriate technical and organisational measures proportionate to the risks.
Current measures include, where applicable:
- encryption in transit;
- secure password hashing and support for passkeys and two-factor authentication;
- tenant and role-based access controls;
- server-side processing of platform credentials and regulatory API requests;
- access controls for production systems and service providers;
- logging and audit trails for material application events;
- backup and recovery procedures;
- vulnerability and dependency management;
- incident response procedures; and
- staff and supplier confidentiality controls.
The Controller acknowledges that security measures may evolve to reflect technical development and changed risks, provided overall protection is not materially reduced.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage Sub-processors needed to provide the service.
The Processor will:
- maintain a current list of material Sub-processors;
- impose data protection obligations that provide substantially equivalent protection to this DPA;
- remain responsible for each Sub-processor's performance of those obligations; and
- provide reasonable notice before adding or replacing a material Sub-processor.
If the Controller reasonably objects to a new Sub-processor on data protection grounds, the parties will work in good faith to find a practical solution. If no solution is reasonably available, the Controller may stop using the affected feature or terminate the affected service in accordance with the Services Agreement.
7. International transfers
The Processor will not transfer Personal Data outside the United Kingdom unless the transfer complies with Applicable Data Protection Law.
Where a destination is not covered by UK adequacy regulations, the Processor will use an appropriate safeguard, which may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- binding corporate rules; or
- another mechanism recognised by UK law.
The Processor will carry out transfer risk assessment and supplementary measures where required.
8. Assistance with Data Subject rights
Taking account of the nature of Processing, the Processor will provide reasonable assistance for the Controller to respond to requests from Data Subjects exercising their rights.
If the Processor receives a request relating to Customer Data:
- it will not respond on the Controller's behalf unless authorised or legally required;
- it will direct the requester to the Controller where practicable; and
- it will notify the Controller without undue delay, unless prohibited by law.
The Controller is responsible for deciding how to respond and for meeting statutory deadlines.
9. Assistance with compliance
Taking account of the nature of Processing and information available to it, the Processor will provide reasonable assistance with:
- security obligations under UK GDPR Article 32;
- Personal Data Breach notifications under Articles 33 and 34;
- data protection impact assessments under Article 35; and
- prior consultation with the ICO under Article 36.
Assistance beyond the standard service may be charged at reasonable rates where the work is substantial and not caused by the Processor's breach.
10. Personal Data Breaches
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
The notice will provide available information about:
- the nature of the breach;
- affected categories and approximate numbers of Data Subjects and records;
- likely consequences;
- measures taken or proposed to address and mitigate the breach; and
- a contact for further information.
Information may be provided in phases if it is not all available at once. The Processor will take reasonable steps to contain, investigate, mitigate, and remediate the breach.
The Processor's notice does not admit fault or liability. The Controller remains responsible for deciding whether notification to the ICO within 72 hours, or communication to Data Subjects, is required.
11. Deletion and return
During the subscription, the Controller may access and download data through available service features.
On termination, the Processor will, at the Controller's choice and subject to technical availability:
- allow a reasonable period for retrieval of Customer Data; and
- delete or return Personal Data after that period.
The Processor may retain data where UK law requires it and may retain Personal Data in backups until those backups expire through ordinary rotation. Any retained data remains protected by this DPA and will not be used for another purpose.
12. Information and audits
The Processor will make information reasonably necessary to demonstrate compliance with UK GDPR Article 28 available to the Controller.
The Controller may conduct an audit no more than once in any 12-month period, unless:
- required by a competent supervisory authority;
- following a material Personal Data Breach; or
- there are reasonable grounds to suspect material non-compliance.
Audits must:
- be arranged with reasonable prior written notice;
- take place during normal business hours;
- avoid unnecessary disruption;
- protect other customers' information and the Processor's security and confidentiality; and
- use existing independent reports and documentation before requesting an on-site inspection.
The Controller bears its audit costs. The Processor may charge reasonable costs for assistance beyond standard documentation unless an audit identifies a material breach by the Processor.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Services Agreement, except to the extent Applicable Data Protection Law prevents that limitation.
14. Duration and changes
This DPA starts when the Processor first processes Personal Data for the Controller and continues until that Processing ends.
We may update this DPA where necessary to reflect changes in law, regulatory guidance, or the service. We will give reasonable notice of a material change.
15. Governing law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to the rights and powers of the ICO and other competent authorities.
Schedule 1: Processing details
Subject matter and duration
Provision of SIMTRACA for the term of the Services Agreement, including any agreed post-termination retrieval and deletion period.
Nature and purpose
- hosting and organising waste operations records;
- user and organisation administration;
- preparing, validating, submitting, and updating DEFRA digital receipts;
- retrieving Environment Agency public carrier information;
- storing signatures, delivery photographs, audit records, and submission outcomes;
- providing support, security, backup, and service maintenance; and
- carrying out the Controller's authorised instructions.
Categories of Data Subjects
- the Controller's members, Org Admins, staff, and contractors;
- staff and representatives of customers, producers, brokers, carriers, and receiving organisations;
- drivers and other people involved in waste movements;
- signatories and operational contacts; and
- people whose details appear in support requests or audit history.
Categories of Personal Data
- names, business contact details, job or organisation roles;
- account, authentication, membership, device, and session information;
- addresses, signatures, photographs, vehicle details, and carrier details;
- Waste Transfer Note and digital receipt information linked to identifiable people;
- permit, licence, exemption, registration, and Waste Tracking identifiers;
- audit, support, submission, warning, and error information; and
- other Personal Data the Controller chooses to enter into free-text or uploaded content.
Special category and criminal offence data
The service is not designed for special category or criminal offence data. The Controller must not submit such data unless it has confirmed a lawful basis, appropriate safeguards, and that the Processing is necessary.
Frequency
Continuous and on demand as authorised users use the service.
Schedule 2: Processor contact
Simtec Consult Ltd
Company number 13710785
Illtud House, Station Road, Llantwit Major, Vale of Glamorgan, Wales, CF61 1ST
[email protected]