corality

Legal

Data processing agreement

Last updated 2 October 2026

Draft, published for information. These terms are subject to change and are not an offer. A Corality subscription is governed by the order form and agreement signed with each customer. Items in square brackets are settled for each customer. Questions: hello@corality.io.

1. Parties and interpretation

This Data Processing Agreement ("DPA") is entered into between:

(1) Corality Ltd, a company registered in England and Wales under company number 15956745, whose registered office is at 128 City Road, London EC1V 2NX ("Corality", "we", "us", "our", the "Processor"); and

(2) the customer identified in the applicable Order Form (the "Customer", "you", "your", the "Controller"),

(each a "party" and together the "parties").

This DPA forms part of, and is incorporated by reference into, the SaaS Subscription Agreement between Corality and the Customer (the "Agreement"). If there is any conflict between this DPA and the rest of the Agreement in relation to the processing of personal data, this DPA prevails.

1.1 Definitions

Terms used in this DPA have the meanings given in UK Data Protection Legislation unless otherwise defined below or in the Agreement.

"UK Data Protection Legislation" means the UK GDPR (the General Data Protection Regulation as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018), the Data Protection Act 2018, and any successor or related UK legislation or regulatory guidance, each as amended or updated from time to time.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing" (and "process", "processes" and "processed"), "Personal Data Breach" and "Special Category Data" have the meanings given in the UK GDPR.

"Customer Personal Data" means the Personal Data processed by Corality on behalf of the Customer under or in connection with the Agreement, as more particularly described in Annex 1.

"Sub-processor" means any third party appointed by or on behalf of Corality to process Customer Personal Data on Corality's instructions in connection with the Agreement, as listed in Annex 3.

"Data Subject Request" means a request made by a Data Subject to exercise any right under UK Data Protection Legislation.

1.2 Roles of the parties

The parties agree that, in relation to Customer Personal Data:

(a) the Customer is the Controller; and

(b) Corality is a Processor acting on the Customer's documented instructions.

Nothing in this DPA relieves the Customer of any responsibilities it has as a Controller under UK Data Protection Legislation, including the lawfulness of its instructions and of its own collection and use of Customer Personal Data.

2. Processing of Customer Personal Data

2.1 Corality shall process Customer Personal Data only:

(a) on the documented instructions of the Customer, including with regard to transfers of Customer Personal Data to a third country, unless required to do otherwise by UK or applicable law (in which case Corality shall, to the extent permitted by law, inform the Customer of that legal requirement before processing);

(b) as set out in Annex 1 (Details of Processing); and

(c) as otherwise agreed in writing by the parties.

2.2 Corality shall immediately inform the Customer if, in its opinion, an instruction given by the Customer infringes UK Data Protection Legislation. This does not affect the Customer's own responsibility for the lawfulness of its instructions.

2.3 The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects, are set out in Annex 1.

3. Confidentiality

3.1 Corality shall ensure that any person it authorises to process Customer Personal Data (including its staff, agents and Sub-processors) is subject to a binding written obligation of confidentiality (whether contractual or statutory) and only processes Customer Personal Data as necessary for the purposes of the Agreement.

4. Security

4.1 Corality shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, in accordance with Article 32 UK GDPR.

4.2 The measures currently in place are set out in Annex 2 (Technical and Organisational Security Measures). Corality may update these measures from time to time, provided that the updated measures do not materially reduce the overall level of security.

5. Use of staff and personnel

5.1 Corality shall ensure that access to Customer Personal Data is limited to those staff and contractors who need access in order to perform the Agreement, on a least-privilege basis.

6. Assistance to the Customer

6.1 Taking into account the nature of the processing, Corality shall provide reasonable assistance to the Customer, by appropriate technical and organisational measures, insofar as this is possible, to enable the Customer to respond to requests from Data Subjects seeking to exercise their rights under UK Data Protection Legislation (including rights of access, rectification, erasure, restriction, portability and objection).

6.2 If Corality receives a Data Subject Request directly in relation to Customer Personal Data, it shall, without undue delay, notify the Customer and shall not itself respond to that request unless required to do so by law or expressly authorised to do so by the Customer.

6.3 Corality shall provide reasonable assistance to the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 UK GDPR, including in relation to security of processing, notification of Personal Data Breaches to the Information Commissioner's Office ("ICO") and affected Data Subjects, and data protection impact assessments ("DPIAs"), taking into account the nature of processing and the information available to Corality.

6.4 [SOLICITOR/CORALITY TO CONFIRM] Corality shall, on reasonable request and at reasonable intervals, make available to the Customer a standard DPIA information pack describing the platform's processing activities, to assist the Customer in preparing its own DPIA where required.

7. Sub-processors

7.1 The Customer provides Corality with general written authorisation to engage the Sub-processors listed in Annex 3 as at the date of this DPA.

7.2 Corality shall not engage a new Sub-processor, or replace an existing Sub-processor, without giving the Customer at least [SQUARE BRACKET: e.g. 30] days' prior written notice (which may be given by email or via a notification in the Corality platform), to allow the Customer a reasonable opportunity to object on reasonable, documented grounds relating to data protection.

7.3 If the Customer objects within that notice period, the parties shall discuss the objection in good faith. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Agreement (or, where reasonably practicable, Corality will offer the Customer a reasonable alternative) without penalty, by written notice, provided such notice is given within [SQUARE BRACKET] days of the original notice.

7.4 Where Corality engages a Sub-processor to carry out specific processing activities on behalf of the Customer, Corality shall impose, by way of a contract, the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing will meet the requirements of UK Data Protection Legislation.

7.5 Corality remains fully liable to the Customer for the performance of each Sub-processor's obligations in relation to the processing of Customer Personal Data.

7.6 The current list of Sub-processors, including the purpose of their engagement, the categories of data they may access, their processing location, and the applicable international transfer mechanism, is set out in Annex 3.

8. International transfers

8.1 Corality shall not transfer Customer Personal Data outside the United Kingdom unless it ensures that appropriate safeguards are in place in accordance with Chapter V of the UK GDPR, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a valid UK adequacy regulation or data bridge, as applicable to the destination country and receiving party, as identified in Annex 3.

8.2 [SOLICITOR/CORALITY TO CONFIRM] The parties will review and, if necessary, update the transfer mechanisms referenced in Annex 3 to reflect changes in UK Data Protection Legislation or in the Sub-processors' own locations or arrangements.

9. Data Protection Impact Assessments

9.1 Corality shall provide the Customer with reasonable cooperation and information as the Customer reasonably requires to carry out a DPIA in relation to the Customer's use of the platform, to the extent that such information is reasonably available to Corality and the Customer does not otherwise have access to it. [SOLICITOR/CORALITY TO CONFIRM scope.]

10. Personal Data Breach notification

10.1 Corality shall notify the Customer without undue delay, and in any event within [SQUARE BRACKET: proposed 48 hours] of becoming aware, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 Such notification shall, to the extent the information is available to Corality at the time (and supplemented as further information becomes available), include:

(a) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Customer Personal Data records concerned;

(b) the name and contact details of a point of contact at Corality where more information can be obtained;

(c) a description of the likely consequences of the Personal Data Breach; and

(d) a description of the measures taken or proposed to be taken by Corality to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

10.3 Corality shall cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the Personal Data Breach.

10.4 Corality's obligation to notify under this clause 10 does not apply where the Personal Data Breach relates to data for which the Customer, rather than Corality, is the processor or otherwise does not involve Customer Personal Data processed under this DPA.

11. Audit rights

11.1 Corality shall make available to the Customer, on reasonable written request and no more than once in any 12 month period (save where required following a Personal Data Breach or by a supervisory authority), such information as is reasonably necessary to demonstrate Corality's compliance with its obligations under this DPA, including summaries of relevant audit or certification reports where available.

11.2 Where such information is not sufficient, the Customer (or its appointed third-party auditor, subject to confidentiality obligations and not being a competitor of Corality) may carry out an audit of Corality's relevant policies, procedures and records relating to the processing of Customer Personal Data, on reasonable prior written notice (at least [SQUARE BRACKET] days) and during normal business hours, at the Customer's own cost, and in a manner that does not unreasonably disrupt Corality's business or compromise the security or confidentiality of other customers' data.

12. Deletion or return of data

12.1 On termination or expiry of the Agreement, or earlier on the Customer's written request, Corality shall, at the Customer's election, delete or return all Customer Personal Data to the Customer, and delete existing copies, within [SQUARE BRACKET: e.g. 30] days, save to the extent that applicable law requires Corality to retain some or all of the Customer Personal Data, in which case Corality shall isolate and protect that data from further processing except to the extent required by that law.

12.2 The export and deletion process is further described in the Agreement's exit provisions.

13. General

13.1 This DPA shall remain in effect for as long as Corality processes Customer Personal Data on the Customer's behalf under the Agreement.

13.2 This DPA is governed by the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction, consistent with the Agreement.

13.3 In the event of any conflict between the terms of this DPA and the Agreement, this DPA shall prevail in relation to the processing of Customer Personal Data.


Annex 1: Details of Processing

Subject matter

The provision of the Corality SaaS platform to the Customer for field operations management in connection with housing stock condition, EPC and damp-and-mould surveys, including resident communication, survey booking, surveyor field data capture, client reporting, and (where applicable) consultancy invoicing.

Duration

For the duration of the Agreement, plus any period during which Corality retains Customer Personal Data in accordance with clause 12 of this DPA or applicable law.

Nature and purpose of processing

Hosting, storage, retrieval, organisation, structuring, transmission and deletion of Customer Personal Data in order to:

  • send SMS and email campaigns to residents/tenants inviting them to book a survey appointment;
  • allow residents/tenants to self-book survey appointments via personal booking links and QR codes;
  • enable surveyors to capture field data via a mobile application, including photographs of property exteriors and doors, timestamps, no-access evidence, and free-text notes;
  • provide client portals allowing each housing association or local authority customer to view its own data;
  • generate reports and (where applicable) invoices for surveying consultancy customers;
  • provide customer support, platform administration, and AI-assisted import of customer-supplied data.

Categories of Data Subjects

  • Residents / tenants of properties managed by the Customer or the Customer's clients;
  • Surveyor and other staff users employed or engaged by the Customer or the Customer's clients;
  • Administrative users of the Customer (e.g. housing association or consultancy staff) with access to the platform.

Categories of Customer Personal Data

  • Name;
  • Address, including Unique Property Reference Number (UPRN);
  • Telephone number;
  • Email address;
  • Appointment and booking data (date, time, status, booking source);
  • Photographs of property exteriors and doors taken during survey visits;
  • Surveyor field notes and no-access evidence, which may in limited and unintended circumstances include Special Category Data if entered as free text by a Customer user;
  • Account and login data for surveyor and administrative users (for example, name, email, role, activity/audit log of actions taken in the platform).

Special Category Data

The platform is not designed or intended to process Special Category Data. The Customer shall not knowingly input Special Category Data save as strictly necessary and in compliance with Article 9 UK GDPR and Schedule 1 DPA 2018, and shall ensure appropriate safeguards where it does so. [SOLICITOR TO CONFIRM wording.]

Annex 2: Technical and Organisational Security Measures

Corality maintains the following categories of technical and organisational measures. These may be updated from time to time provided the overall level of security is not materially reduced.

  1. Encryption. Customer Personal Data is encrypted in transit (TLS) between the Customer's and Data Subjects' devices and Corality's platform, and encrypted at rest by Corality's hosting and database providers.

  2. Tenant isolation. The platform is multi-tenant. Each Customer organisation's data is logically separated using row-level security (RLS) policies enforced at the database layer, so that one Customer's data cannot be accessed by another Customer's users.

  3. Access control. Access to Customer Personal Data within Corality's platform is controlled via role-based access control, so that users (for example, surveyors, administrators, and super-administrators) only have access to the data and functions appropriate to their role.

  4. Multi-factor authentication. Multi-factor authentication is available for user accounts and is [SQUARE BRACKET: mandatory for / available to] administrative and super-administrator accounts.

  5. Audit logging. State-changing actions taken within the platform (for example, status updates, bookings, data imports) are recorded in an audit log, including the identity of the user and the time of the action, to support traceability and incident investigation.

  6. Backups. Customer Personal Data is backed up on a regular basis by Corality's database hosting provider, with restoration tested periodically.

  7. Least-privilege service credentials. Service-level credentials used by Corality's own infrastructure (for example, between the application and the database, or for scheduled background jobs) are scoped to the minimum level of access required for their function, and are stored securely as environment-level secrets rather than in source code.

  8. Secure development practices. Code changes are reviewed before deployment, and automated and manual security review tools are used on significant changes.

  9. Staff confidentiality and access. Access to production Customer Personal Data by Corality personnel is limited to those who need it to provide or support the platform, and is subject to confidentiality obligations.

  10. Sub-processor due diligence. Corality selects Sub-processors that provide appropriate contractual and technical guarantees in relation to the security of processing, as further described in Annex 3.

[SOLICITOR/CORALITY TO CONFIRM: whether more specific detail is required, e.g. encryption standards/algorithms, backup retention periods, incident response plan reference, penetration testing cadence once the planned VAPT (vulnerability assessment and penetration test) exercise has taken place.]

Annex 3: Sub-processors

The following table lists Corality's current Sub-processors as at the date of this DPA. Corality will update this Annex in accordance with clause 7.

Sub-processor Purpose Categories of data Processing location Transfer mechanism
Supabase Database hosting, authentication, and file storage for the platform All categories of Customer Personal Data described in Annex 1, including photographs EU (Ireland region) [SOLICITOR/CORALITY TO CONFIRM current hosting region is maintained] Processing within the EU; if any processing occurs outside the UK/EU, the applicable UK transfer mechanism will be identified here [SOLICITOR/CORALITY TO CONFIRM]
Vercel Application hosting and serverless function execution for the platform All categories of Customer Personal Data that pass through the application layer, including in transit [SOLICITOR/CORALITY TO CONFIRM] likely United States, with possible edge processing in other regions [SOLICITOR/CORALITY TO CONFIRM] likely UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, or reliance on the UK-US Data Bridge if Vercel is a certified participant
Resend Transactional email delivery (for example, notifications, password resets, and certain customer communications) Name, email address, and the content of transactional emails sent via the platform [SOLICITOR/CORALITY TO CONFIRM] likely United States [SOLICITOR/CORALITY TO CONFIRM] likely UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, or UK-US Data Bridge if applicable
TextMagic SMS delivery for resident/tenant campaign and booking messages Name, telephone number, and the content of SMS messages sent via the platform [SOLICITOR/CORALITY TO CONFIRM] [SOLICITOR/CORALITY TO CONFIRM]
Anthropic PBC AI-assisted data import: suggesting column mappings and interpreting admin instructions when a customer uploads a spreadsheet Column headers and a sample of up to 15 rows of the uploaded spreadsheet as supplied, which may include resident/tenant name, address, telephone number, email address and UPRN; project and client name United States [SOLICITOR/CORALITY TO CONFIRM] [SOLICITOR/CORALITY TO CONFIRM] UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, or UK-US Data Bridge if applicable
TidyCal Booking of survey appointments for customers and flows not yet moved to Corality's native booking engine. Being retired; this entry will be removed under clause 7 once retirement is complete Resident/tenant name, telephone number, email address and appointment details United States [SOLICITOR/CORALITY TO CONFIRM] [SOLICITOR/CORALITY TO CONFIRM] UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, or UK-US Data Bridge if applicable