Data Processing Agreement
Version 1.1, 19 September 2026. Forms part of the Terms of Service.
In plain terms: when you store information about your own customers and suppliers in Cargohold, that remains your data and you decide what happens to it. We only handle it to run the service for you. This document is the contract that says so, which UK GDPR Article 28 requires us to have.
1. Roles
You are the controller of the personal data you put into Cargohold about other people — typically your customers and your supplier contacts. SteadyKeel is the processor of that data.
Separately, SteadyKeel is the controller of your own account information (your email address, company name, billing records). That is covered by the privacy page, not this agreement.
2. Subject matter and duration
We process your data for as long as you have an account, and to provide the service described at cargohold.steadykeel.co.uk/product. Processing ends when you delete the data, delete the company, delete your account, or the agreement ends.
3. Nature and purpose of processing
Storage, retrieval, organisation, and display back to you; import from marketplaces you connect; export at your request; backup; and deletion. We do not use your data to train any model, we do not profile your customers, and we do not sell or share it.
4. Types of personal data and categories of data subject
| Category of data subject | Personal data |
|---|---|
| Your customers | Name; contact details you choose to enter; free-text notes; and (where you use the shipping fields) delivery address, shipping method and tracking reference |
| Your supplier contacts | Name of contact; contact details you choose to enter; free-text notes |
| Colleagues you invite | Email address |
Cargohold is not designed for special category data (health, biometrics, race, religion, political opinions, sexual orientation, trade union membership) or for criminal offence data. Please do not enter it — including in free-text notes.
5. Your obligations and rights
You confirm that you have a lawful basis for the personal data you put into Cargohold, that you have given the required privacy information to the people it concerns, and that your instructions to us comply with data protection law. You may give us instructions, and terminate this agreement, at any time.
6. Our obligations
5.1 Instructions
We process your data only on your documented instructions, which are: the actions you take in the app, and this agreement. If we are ever required by law to process it otherwise, we will tell you first unless the law forbids it. If we consider an instruction from you to infringe UK GDPR or other data protection law, we will tell you immediately.
5.2 Confidentiality
Access is limited to the people who need it to run the service. At the time of writing, that is one person: the sole trader operating SteadyKeel, who is bound by a duty of confidentiality.
5.3 Security (Article 32)
- Encryption in transit (TLS) and at rest.
- No passwords are stored — sign-in is by one-time emailed link, so there is no password database to compromise.
- Each company's data is isolated at the database query level. That isolation was verified on 2026-09-18 by attempting cross-company reads, writes, renames and deletes — all refused — and is re-verified after significant changes.
- Administrative access to the service does not expose your customers, suppliers, products or orders.
- Marketplace credentials you connect are never returned to a browser and are excluded from exports and backups.
- Daily backups with a tested restore procedure. Backup contents are encrypted.
5.4 Sub-processors
You give general authorisation for the sub-processors below. We will give at least 30 days' notice by email before adding or replacing one, and you may object; if we cannot resolve your objection you may terminate and export your data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, storage | EU/UK edge |
| Resend (and Amazon SES) | Sending sign-in links and notifications | EU (eu-west-1) |
| Stripe Payments Europe | Subscription billing (account data only — not your customer records) | EU/UK |
| Anthropic PBC | AI features: converting what you type into actions | US |
| Microsoft (OneDrive) | Encrypted off-site copy of backups | EU/UK |
We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
Anthropic receives only what you type into the AI boxes, plus the names and units of your materials and products. It does not receive your customers, suppliers, prices, orders or addresses. It does not train on data submitted through its API, and retains API inputs and outputs only for a limited period for trust-and-safety purposes.
5.5 Assisting you
We will help you meet your own obligations:
- Data subject requests — most you can action yourself, immediately, and whether or not you are subscribed: export everything (CSV or JSON), correct any record, delete a customer, supplier, product or sales order, clear the delivery details from an order while keeping the order itself, or delete a company. To close an account entirely, email us — we action it within 5 working days. For anything else, email us and we will respond within 5 working days.
- Breach notification — we will tell you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, with what we know and what we are doing.
- Impact assessments and consultations — we will provide the information you reasonably need for a data protection impact assessment, for any prior consultation with the ICO, and for communicating a breach to affected individuals.
5.6 Retention and deletion
Your records are kept until you say otherwise. You are the controller of the data you put into Cargohold, so you set its retention — not us. By default nothing of yours is ever deleted on a schedule of ours.
Where your own policy requires deletion, set it in the app under Your data → How long we keep it. We then act on that as your documented instruction. You can currently set a period for supplier price history, completed sales orders, unmatched storefront listings, and your AI query history; the default for each is keep indefinitely.
| Data | Retention | Whose decision |
|---|---|---|
| Your business records — customers, suppliers, stock, orders, price history | Kept until you delete them or your account closes, unless you set a period | Yours |
| Your AI query history | At most 180 days. You may set a shorter period. | Shared — 180 days is our ceiling, you can ask for less |
| Support messages you send us | 24 months | Ours (we are the controller of these) |
| Page-view counts (no personal data) | 25 months | Ours |
| Price-check history (our operational copy) | 400 days | Ours |
| Payment event records | 400 days | Ours |
| Encrypted backups | 14 dated encrypted copies, normally covering the last 14 days | Ours |
The only ceiling we impose is on the AI query log: we keep at most 180 days of it to detect misuse of the AI features, which is our own obligation rather than an instruction from you. Everything else about your records is your call.
Deleting a record, a company or your account removes it from the live service immediately; encrypted backup copies age out within approximately 14 days, after which it is gone permanently.
On termination, at your choice we will either return your data to you (as the standard CSV or JSON export) or delete it. Unless you tell us otherwise within 30 days of termination we will delete it, including from backups as those age out, except where we are required by law to retain it.
5.7 Audit
We will make available the information needed to demonstrate compliance with this agreement. Given the size of the service we do not maintain a formal audit programme, but on reasonable written notice — no more than once in any 12 months, except following a personal data breach — we will answer your security questionnaire and will permit an inspection by you or an auditor you mandate, at your cost, subject to confidentiality and to it not compromising other customers' data.
7. International transfers
Data is currently served from the EU/UK. The one transfer outside that is to Anthropic (US) for the AI features, covered by the EU standard contractual clauses as extended by the UK International Data Transfer Addendum, supported by a transfer risk assessment we have carried out and will share on request. It applies to AI-box text only. If you would rather no data left the UK/EU, do not use the chat box, Assistant or bulk import — every other feature works without them.
8. Liability and law
The liability provisions of the Terms of Service apply to this agreement. It is governed by the law of England and Wales.
Need this signed? Email [email protected] and we will provide a countersigned copy for your records.