Data Processing Agreement

Last updated: 16 August 2026

This Data Processing Agreement ("DPA") forms part of the Dashtrack Terms of Service and applies where Dashtrack processes personal data on behalf of a customer (the "Controller") in connection with the provision of the platform. This DPA is governed by the UK GDPR and, where applicable, the EU GDPR.

1. Roles and Responsibilities

The customer is the Controller of personal data uploaded to Dashtrack (including team member and client data). Dashtrack is a Processor. Each party shall comply with its obligations under the UK GDPR and EU GDPR.

2. Data We Process on Your Behalf

The personal data processed under this DPA includes:

  • Team member account data (name, email, role, avatar)
  • Client and prospect data entered into the CRM (names, emails, phone numbers, notes)
  • Work-related data (tasks, time entries, holiday requests, meeting notes, roadmaps)

3. Purposes of Processing

We process personal data solely to provide, maintain and secure the Dashtrack service, as instructed by the Controller, and in accordance with the Terms of Service. We do not sell personal data and do not use it for advertising.

4. Data Subject Rights

Where the Controller is required to respond to data subject requests (access, rectification, erasure, restriction, portability, objection), Dashtrack will assist by providing the relevant account tools and reasonable technical support. Requests should be directed to [email protected].

5. Sub-Processors

The following sub-processors have access to customer data in connection with the service:

  • Supabase Inc. — database hosting (EU, eu-west-2)
  • Stripe Inc. — payment processing (billing data only)
  • Vercel Inc. — application hosting
  • Resend — transactional email delivery
  • Google — authentication (OAuth) and AI assistant support

The current list is maintained at this page. We will notify customers of any new sub-processor at least 14 days before use.

6. Security

Dashtrack maintains appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, access controls, and regular backups, to protect personal data against unauthorised or unlawful processing and accidental loss or damage.

7. International Transfers

Customer data is hosted in the European Union (Supabase eu-west-2, London region). Where data is transferred outside the UK or EEA, we rely on appropriate safeguards (including standard contractual clauses or an adequacy decision) in accordance with Article 46 of the UK GDPR.

8. Data Breach Notification

In the event of a personal data breach affecting customer data, Dashtrack will notify the Controller without undue delay after becoming aware of it, and will provide reasonable information to assist the Controller in meeting its own notification obligations.

9. Retention and Deletion

Data is retained for the duration of the customer's subscription and deleted (or returned at the Controller's request) within 90 days of account termination, unless legal obligations require otherwise.

10. Contact

Questions about this DPA: [email protected]. Dashtrack is operated by Victory Digital Ltd, United Kingdom.