Vasker

Data processing addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between your organisation (“Customer”) and Tweed Tyne Technologies Ltd (“Processor”) for use of Vasker, under UK GDPR Article 28.

Last updated: 31 August 2026

1. Roles

Customer is the controller of personal data entered into Vasker about members, donors, Gift Aid declarants and related individuals (“Customer Personal Data”). Tweed Tyne Technologies Ltd processes that data as processor to provide Vasker.

Tweed Tyne Technologies Ltd remains controller of its own account, billing, security and support data, as described in the Privacy policy.

2. Details of processing

  • Subject matter: hosting and processing Customer Personal Data in Vasker (cash book, members, Gift Aid/GASDS, uploads, reports and exports).
  • Duration: for the term of Customer’s account, plus any grace, archive and backup retention period, or earlier deletion on written request.
  • Nature and purpose: storage, retrieval, transmission, backup, display and deletion as needed to operate the features Customer enables, including optional HMRC claim submission when live submission is available.
  • Types of data: names, addresses, contact details, donation and subscription amounts, Gift Aid declaration fields, transaction narratives, receipt images/files, organisation identifiers, and technical logs linked to user actions.
  • Data subjects: members, donors, officers, independent examiners and other individuals whose data Customer chooses to store.

3. Processor obligations

Tweed Tyne Technologies Ltd shall:

  • process Customer Personal Data only on documented instructions from Customer (including configuration and use of Vasker), unless UK law requires otherwise;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational measures as summarised in Security and compliance;
  • not engage a sub-processor without the safeguards in section 4;
  • assist Customer, taking into account the nature of processing, with data subject requests, security incidents, and data protection impact assessments where reasonably required;
  • delete or return Customer Personal Data after the end of providing services, subject to backup expiry and legal retention, when Customer so instructs;
  • make available information necessary to demonstrate compliance with this DPA and allow reasonable audits (remote questionnaire or equivalent) on fair notice, no more than once per year unless a suspected breach requires earlier review.

4. Sub-processors

Customer authorises the Processor to use the following sub-processors for Customer Personal Data. We will post material changes on this page and, where practicable, give prior notice so Customer may object on reasonable data-protection grounds.

Sub-processor Role Location notes
Railway Corp (“Railway”) Application hosting, managed PostgreSQL, Redis, media object storage US-incorporated provider; Customer workloads hosted in Railway’s EU region
Cloudflare, Inc. Bot protection (Turnstile) on authentication and public forms; Email Routing/Workers for inbound support mail where configured US-incorporated; processes limited technical data (and routed message content for inbound mail) to complete those functions
IDrive Inc. (IDrive e2) Encrypted offsite backup object storage US-incorporated; backup storage in London region (eu-west-3)
Transactional email (SMTP provider) Delivery of service emails where Customer Personal Data appears (e.g. officer invites) As configured for Vasker; used only to send those messages

Google Analytics 4 and the Meta Pixel are used to measure visits to the Vasker website (and, for Meta, the effectiveness of our own advertising). They are described in the Privacy policy and are not sub-processors for Customer Personal Data: we do not send member, donor or Gift Aid records to Google or Meta.

The Processor remains responsible for sub-processor performance. International transfers rely on appropriate transfer tools (such as UK/EU Standard Contractual Clauses or a valid Data Privacy Framework certification) as offered by each provider.

5. Security

Measures include HTTPS for connections, TLS for production database connections, hashed passwords, role-based multi-tenant isolation, audit logging of sensitive actions, restricted production access, encryption in transit and at rest for backups with provider controls, and bot protection on public entry points. Further detail: Security and compliance.

6. Personal data breaches

After becoming aware of a personal data breach affecting Customer Personal Data, the Processor will notify Customer without undue delay and provide information reasonably available to help Customer meet UK GDPR notification duties. Customer remains responsible for notifying the ICO or data subjects where required.

7. Customer obligations

Customer warrants it has a lawful basis and any required notices/consents for Customer Personal Data, will not instruct unlawful processing, and will use roles and exports responsibly. Customer is responsible for HMRC and charity retention periods for records it must keep outside Vasker.

8. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms of service, except where UK data protection law prohibits limitation. If there is a conflict between this DPA and the Terms on data-protection subject matter, this DPA prevails.

9. Governing law

This DPA is governed by the law of Scotland. Operator details: company number SC874131; ICO registration ZC184042.

10. Related policies

Privacy policy · Terms of service · Security and compliance · Who we are