GDPR and Data Processing Addendum Summary
Last updated: 13 March 2026
This page explains controller/processor responsibilities when using Scrubix under UK GDPR and Data Protection Act 2018.
1. Roles
Customer account holder (your business): generally the controller for personal data entered and processed in your customer workflows.
Scrubix: processor for service data handled on your instruction, and controller for account/security/billing/support data it must process itself.
2. Processing scope
Scrubix processes personal data strictly to provide platform workflows: customer records, jobs, quotes, invoices, communications, payment metadata, reconciliation tools and limited app activity records such as last app open, last seen, current page and app foreground/background state where needed for support and service reliability.
3. Security and confidentiality
Scrubix implements technical and organisational measures including access controls, audit trails, authentication controls and secure transport.
Access to personal data is restricted to authorised staff and subprocessors with a need to know.
4. Subprocessors
Scrubix may use vetted subprocessors for hosting, communications, payment infrastructure and diagnostics.
Subprocessors are bound by written data protection obligations.
5. International transfers
Where personal data leaves the UK, Scrubix applies transfer safeguards required by UK GDPR.
6. Data subject rights support
Scrubix provides tooling and support to help controller customers respond to access, rectification, deletion and portability requests.
7. Breach response
Scrubix maintains incident response procedures. Where legally required, affected controller customers are notified without undue delay.
8. Retention and deletion
Customer data is retained in line with service settings and legal obligations, then deleted or anonymised per policy.
9. Reconciliation data
Where connected bank account reconciliation is enabled, transaction feed data is processed to provide matching and finance workflow outputs.
10. Requests and contact
Data protection requests: data@scrubix.co.uk.