Simple Smooth Safe
Data protection

Data Processing Agreement

This applies where we process personal data on a customer's behalf. It forms part of the Terms of Service and is offered on these terms to every customer, without needing to be requested.

Version 1.0 Effective 10 August 2026

This is an archived version. It is published so that customers who ordered while it was in force can read the text that applied to them. It is not the current version — see the current documents.

1. Start here: in normal operation, we are not your processor

Our products run in your tenant, on your infrastructure. Your data does not flow to us as part of using them, and there is no SSS-operated service holding a copy of it. In the ordinary course of a subscription there is therefore no processing by us to govern.

This agreement exists for the exceptions — chiefly support access — and because your procurement team needs a DPA on file regardless. It is deliberately short about our obligations, because our exposure is deliberately small.

ProductWhere the data livesDoes it reach us?
SSS DocGenYour Dataverse; rendering happens in a container in your Azure subscriptionNo. Documents are returned to the caller and, unless Attach is used, stored nowhere.
SSS DMSYour Dataverse and your SharePoint, read in placeNo. It does not migrate, copy or move anything.
PSA HubYour Dataverse, native tablesNo. The app runs on the Power Platform under your Entra ID.

2. Roles

You are the controller. You decide what personal data goes into the products, why, and for how long. You are responsible for having a lawful basis for it and for informing your own data subjects.

We are a processor only in the specific circumstances in section 3, and only to the extent of them.

For our own website visitors and business contacts we are an independent controller — that is the Privacy Policy, not this document.

3. When we process your data, and why

The complete list:

SituationWhat we may seeDuration
Support access — diagnosing a case you have raised Whatever is visible in the environment or record concerned, which may include personal data of your staff or clients For the case only. Access is granted by you and ends when it closes.
Diagnostic material you send us — a log, a screenshot, a failing record id, an exported template Only what you chose to include Deleted within 90 days of the case closing.
Implementation and migration services, where an Order includes them The data in scope of that engagement For the engagement. Working copies are deleted within 30 days of completion.

Outside these, we do not access your environments. We have no standing credentials into your tenant, and we do not want any.

3.1 Categories of data subject and data

Determined by you, not us. In practice: your employees and contractors (identity and contact details, time and expense records, utilisation), and your clients' business contacts (names, addresses, billing details) as they appear in documents and project records. We do not require special-category data and none of the products is designed for it. If your use involves special-category data, tell us before an engagement so we can agree the extra measures.

4. Our obligations as processor

Where section 3 applies, we will:

5. Security measures

The measures we apply to any of your data we hold, in the terms of Art. 32:

6. Sub-processors

You give general authorisation for the sub-processors below. They are the same processors listed in the Privacy Policy, because we do not run a separate estate for customer data.

Sub-processorPurposeLocation
Microsoft Ireland Operations LtdEmail, file storage and collaboration, where a support case involves material you sent usEU
Our hosting providerServing this website. Holds no customer data.EU

Plausible is not listed here: it never touches customer personal data, only aggregate website statistics, and it is covered by the Privacy Policy instead.

We will give you 30 days' notice before adding or replacing a sub-processor, by email to your billing contact. If you reasonably object on data-protection grounds within that period, we will work with you to find an alternative; if none is workable, you may terminate the affected Product and receive a pro-rata refund for the unexpired term.

We remain fully liable to you for a sub-processor's performance of its data-protection obligations.

7. International transfers

Our sub-processors are established in the EU and data stays in the EU. Where a sub-processor's group could access data from outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to sub-processor), with a transfer impact assessment and supplementary measures where the assessment calls for them.

Where the SCCs apply and this document conflicts with them, the SCCs prevail.

8. Audit

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and respond to a security questionnaire once in any twelve-month period. Our security and compliance review is available on request under NDA.

Where that is genuinely not enough for your regulator, you may audit — on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost.

9. Personal data breach

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours of becoming aware. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed — to the extent we know them, with updates as we learn more rather than a delay until we know everything.

Notifying your supervisory authority and your data subjects is your decision as controller. We will give you what you need to make it and to make it on time.

10. Return and deletion

At the end of an engagement, or on your written request, we delete or return any of your personal data we hold and delete existing copies — except where EU or member-state law requires retention, in which case we tell you what and why.

Your production data is unaffected by any of this, because it is in your own tenant and was never anywhere else.

11. Liability and precedence

Liability under this agreement is subject to the limits in section 10 of the Terms of Service, except where the GDPR does not permit that.

This agreement takes precedence over the Terms of Service on data protection matters, and the SCCs take precedence over this agreement, as section 7 says.

12. Getting a signed copy

These terms apply automatically to every customer without signature. If your procurement or compliance process requires a countersigned DPA, or your own paper, email info@simplesmoothsafe.com and we will sign or review it. We do not treat a DPA as a negotiation.