01
Parties and acceptance
This agreement is between Developyn Ltd, registered in England and Wales at Cradley Enterprise Centre, Maypole Fields, Cradley, Halesowen, B63 2QB ("we", "us", the processor), and the organisation named when this agreement is accepted ("you", the controller).
It forms part of, and is subject to, our Terms of Service. Where this agreement and the Terms conflict on the handling of personal data, this agreement wins.
How it is entered into. Completing the form in section 09 and confirming that you are authorised to act for your organisation brings this agreement into force between us and that organisation from the moment you submit it. No signature, countersignature or exchange of documents is needed, and nothing is held pending review at our end. You will be emailed a copy of what you accepted, with a reference.
If your process needs paper. Some procurement processes cannot accept a click-through record. Write to support@developyn.com quoting your reference and we will return a countersigned copy of this same text on our letterhead. That copy changes nothing: it restates the agreement you already have, so you do not have to wait for it before adopting Laver.
Negotiated wording. These are our standard terms and we publish them so you can review them before you talk to us. We are a small company and we do not have the capacity to negotiate bespoke processor terms with every customer; if something here is a blocker for you, tell us and we will say plainly whether we can change it rather than leave you waiting.
This is not legal advice. We drafted this document ourselves from the text of the legislation and from how Laver actually works. Have your own adviser read it before you rely on it, as you would with anybody's.
02
Roles and scope
For the work your organisation puts into its workspaces — tickets, comments, subtasks, wiki pages and their history, file attachments, and the names and email addresses of the people you invite — you are the controller and we are the processor. You decide what goes in, who may see it and how long it stays; we process it to give you the service.
For a narrow set of data we are the controller in our own right, and this agreement does not cover it: the account records of the individuals who sign in, our billing records, our security and audit logs, our server logs, and the visit counting described in the Privacy Policy. We hold those to run and secure the service and to meet our own legal obligations. The same split is set out in section 01 of that policy and section 01 of the Trust Centre.
Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject, as Article 28(3) requires.
Special category data. Laver is a work tracker and is not designed to hold data revealing health, race, ethnicity, political opinions, religious beliefs, trade union membership, genetics, biometrics, sex life or sexual orientation, or data about criminal offences. The measures in Annex 3 are not written for that data. If your intended use involves it, tell us before you accept this agreement so that we can tell you honestly whether Laver is suitable.
03
Our obligations as processor
Article 28(3) of the UK GDPR sets out eight things this contract has to say. Each is below, in the order the legislation uses, with what it means for Laver in practice. If you are working through a checklist, this is the map:
- Article 28(3)(a) — Documented instructions. We process personal data only on your documented instructions, including on transfers.
- Article 28(3)(b) — Confidentiality. Everyone we authorise to process the data is bound to keep it confidential.
- Article 28(3)(c) — Security measures. We take the measures required by Article 32, set out in full in Annex 3.
- Article 28(3)(d) — Subprocessors. We engage another processor only under the conditions in Article 28(2) and (4).
- Article 28(3)(e) — Assisting with data subject rights. We help you answer requests from the people whose data it is.
- Article 28(3)(f) — Assisting with Articles 32 to 36. We help you with security, breach notification and impact assessments.
- Article 28(3)(g) — Deletion or return. At the end of the agreement we delete or return the data, at your choice.
- Article 28(3)(h) — Information and audits. We give you what you need to demonstrate compliance, and allow audits.
(a) We act only on your documented instructions
We process personal data in your workspaces only to provide the service, and otherwise only on your documented instructions — including any instruction about transferring it to another country. Your use of Laver, this agreement and the Terms of Service together are those instructions; anything beyond them needs a written instruction from you.
If we are required by law to process it some other way, we will tell you before we do, unless the law forbids us from telling you. We will tell you if we think an instruction of yours breaks data protection law rather than quietly carry it out.
We do not use your workspace content to train machine learning models, we do not sell it, and we do not use it for advertising. We read it only where you ask us to look at something, or where we must to keep the service running, safe or lawful.
(b) Everyone who handles it is bound to confidentiality
Access to production systems is limited to the people who need it to operate Laver, and each of them is under a duty of confidentiality that survives their engagement ending. Laver is operated by a very small team, which is worth knowing in both directions: the list of people who could reach your data is short, and it is not backed by the separation of duties a larger organisation would have.
(c) We take the security measures Article 32 requires
The measures we actually have in place are listed in Annex 3, along with the ones we do not. We have written that annex to be checked rather than admired: everything in it can be verified from the outside or is stated on the Trust Centre with its provenance.
(d) Subprocessors
You give us general authorisation to engage subprocessors. The current list is Annex 2 — there are three, and that is the whole list. Each is engaged under a written contract imposing data protection obligations no weaker than these, and we remain fully liable to you for what they do.
Before we add or replace one, we will update Annex 2 on this page and email the address that accepted this agreement, at least 30 days before the change takes effect. If you object on reasonable data protection grounds within those 30 days, tell us; if we cannot resolve it, you may terminate your subscription for the affected service and we will refund the unused part of anything you have already paid.
(e) We help you answer people's requests
Taking account of the nature of the processing, we will help you meet your obligation to answer requests from data subjects exercising their rights — access, rectification, erasure, restriction, portability and objection.
Be aware how that help works today. Each individual can export their own account and content from their profile, and can delete their own account, without involving either of us. Anything beyond that — a request you receive about someone else's data in your workspace, or a request to correct or erase specific content — is handled manually by us on your written request. We will acknowledge within 5 working days and complete it within 20, so that you can answer within your own one-month deadline. There is no self-service tool for it and we are not going to pretend otherwise.
(f) We help you with Articles 32 to 36
We will help you, so far as the information is ours to give, with keeping the processing secure, with notifying breaches, and with data protection impact assessments and any prior consultation with the regulator.
Breaches. If we become aware of a personal data breach affecting your data we will tell you without undue delay and in any case within 48 hours, at the address that accepted this agreement. We will tell you what we know, what we are doing and what we recommend, and we will keep telling you as we learn more. We will not wait until we have a complete picture before the first message. Notifying the ICO and, where required, the affected individuals is your decision as controller; we will give you what you need to make it.
(g) Deletion or return at the end
When your use of Laver ends, you choose whether we delete your data or return it. Every member can export their own account and content as a JSON file from their profile while the account is open, so the practical route to a copy is open to you throughout.
Tell us your choice within 30 days of the end. If you ask for deletion, or if you tell us nothing within those 30 days, we delete your workspaces and their content. Deleted accounts are closed immediately and scrubbed 30 days later, as the Privacy Policy describes.
One honest caveat: our backups are taken daily and kept for 14 days, so data you have deleted can persist in a backup for up to that long before it ages out. We do not restore individual records out of backups to delete them, and while it sits there it is not processed for any other purpose. Copies we must keep to meet a legal obligation — billing records, for instance — are kept for as long as that obligation lasts and for nothing else.
(h) Information and audits
We will give you the information you reasonably need to show that we are meeting these obligations, and allow and contribute to audits, including inspections, by you or an auditor you appoint.
In practice: the Trust Centre answers most of it in public and states its own evidence, and we will complete a reasonable security questionnaire on request. For anything further, give us 30 days' notice; audits are once a year unless a breach or a regulator's instruction makes another one necessary, and are conducted so as not to disturb other customers' data. You bear your own costs, and ours where an audit is repeated within a year without cause.
We do not hold a SOC 2 report or ISO 27001 certification and cannot offer one in place of an audit. That is stated as a gap on the Trust Centre and it is stated here too.
04
International transfers
Your workspace content is held in the United Kingdom. The application, the database and every uploaded file are on a single DigitalOcean machine in London, so the ordinary answer to "where is our data?" is: here.
Two of the three subprocessors in Annex 2 may process limited personal data outside the UK — Stripe for payments, and Mailgun for transactional email through its European infrastructure. Where that happens we rely on the appropriate safeguards: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the Standard Contractual Clauses themselves, together with any additional measures the transfer risk assessment calls for.
We will not transfer your workspace content outside the UK other than through the subprocessors named in Annex 2, and we cannot add one without the 30 days' notice and the objection right in clause (d) above.
Read that for what it is. It is a commitment about who processes your data and about your right to object before that changes. It is not a data residency guarantee — we have not committed to keeping the hosting region fixed, and section 02 of the Trust Centre says the same thing.
05
Term, liability and governing law
Term. This agreement starts when you accept it and runs for as long as we process personal data on your behalf, together with the deletion or return period in clause (g).
Changes. If we change this document we will publish the new version here with a new version number and effective date, and email the address that accepted it at least 30 days beforehand if the change is material. The version you accepted continues to apply until you accept a new one, unless the change is needed to comply with the law.
Liability. Each party's liability under this agreement is subject to the limitations and exclusions in the Terms of Service, which are not raised or lowered by this document. Nothing here limits any liability that cannot lawfully be limited, or affects a data subject's rights against either of us under data protection law.
Governing law. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. "UK GDPR", "personal data", "controller", "processor", "processing", "data subject" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018.
06
Annex 1 — the processing
What Article 28(3) requires this contract to set out about the processing itself.
| Subject matter | Providing the Laver work tracker — boards, tickets, comments, subtasks, sprints, a wiki and file attachments — to your organisation. |
|---|---|
| Duration | For as long as your organisation uses Laver, plus the deletion or return period in clause (g), plus up to 14 days for a backup to age out. |
| Nature and purpose | Storing, organising, displaying, indexing for search, backing up and deleting the content your members create, and sending them transactional email about it — so that your organisation can plan and track its work. |
| Types of personal data | Names, email addresses and optional phone numbers and profile pictures of the members you invite; their role and access level in your workspaces; and any personal data your members choose to put into ticket titles and descriptions, comments, wiki pages, custom fields or uploaded files. |
| Categories of data subject | Your employees, contractors and other people you invite into your workspaces; and any individual a member of yours writes about in a ticket, comment, wiki page or attachment — which may include your own customers or suppliers. |
| Special categories | None intended. See section 02. |
07
Annex 2 — authorised subprocessors
Three, and this is the whole list. It is the same list, with the same evidence behind it, as section 03 of the Trust Centre.
| Subprocessor | What it processes | Where |
|---|---|---|
| DigitalOcean | Hosts the application, the database and every uploaded file — so all workspace content | London, UK |
| Stripe | Payments and subscription billing. Card details go to Stripe and never to our servers | Global |
| Mailgun | Transactional email — the recipient's address and the content of the message | EU infrastructure |
Two absences are worth stating because products of this kind usually have them: Laver runs no third-party analytics, advertising or session replay script, and no third-party error-tracking service is enabled in production. Neither is a subprocessor because neither exists.
08
Annex 3 — technical and organisational measures
The measures in place under Article 32. Every one of these is stated on the Trust Centre with the evidence it was read from, so this annex can be checked rather than taken on trust.
- Encryption in transit. Everything is served over
HTTPS. Both the site and the API send HTTP Strict Transport Security
set to one year, including subdomains and with preload, and responses
carry a content security policy,
nosniffand astrict-origin-when-cross-originreferrer policy. - Credentials. Passwords are hashed with Argon2 and are never stored or recoverable. Two-factor authentication is available using an authenticator app with single-use backup codes, and both the secret and the codes are held hashed.
- Access control. Every request is checked against the workspace it claims to belong to, and against the member's role and access level in it. Changing a password revokes every existing session, and sessions have an absolute maximum age they cannot be renewed past.
- Abuse limits. Authentication and other sensitive endpoints are rate limited per client.
- Upload handling. Uploads are restricted by file type and size, and anything that cannot be displayed safely is returned as a download rather than rendered in the browser.
- Backups. A daily job takes a full database dump and an archive of every uploaded file. Both are kept for 14 days and then deleted automatically.
- Availability monitoring. Availability is measured every thirty seconds and every interruption is published on the status page.
- Vulnerability reports. A published route for reporting security problems, with a commitment not to pursue good-faith reporters, is set out in section 06 of the Trust Centre.
And the limits of them. An annex that lists only what exists is half a document. As of the effective date above, all of the following are true and you should factor them into your own risk assessment:
- Backups are written to the same machine they are taken from. There is no off-site or geographically separate copy, so they protect against corruption, a bad migration or a mistaken deletion — not against the loss of the host.
- Laver adds no application-level encryption of your content at rest on top of what the hosting platform provides. Individual secrets are hashed, as above, but your work content is not separately encrypted and you should not assume it is.
- There is no SOC 2 report, no ISO 27001 certification, and no third-party penetration test whose results we can share.
- There is no committed uptime figure, no service credit, and no contractual support or incident response time. The status page publishes measured availability, which is a record rather than a promise.
- Assistance with data subject requests beyond each person's own export and deletion is a manual process, on the timescales in clause (e).
We keep this annex accurate as the product changes. If we withdraw a measure, that is a material change and clause 05 applies to it.
09
Accept this agreement
Filling this in brings version 1.0 of the agreement above into force between Developyn Ltd and the organisation you name, from the moment you submit it. We will email you a copy with a reference to keep. Nobody has to approve it at our end.