Legal
Data Processing Agreement
This DPA governs how WeekOne Software Limited processes personal data on behalf of organisations using the WeekOne platform, in accordance with UK GDPR and the Data Protection Act 2018.
Effective date: 1 July 2026
1. Parties and Definitions
This Data Processing Agreement (“DPA”) is between WeekOne Software Limited, a company registered in England and Wales (“WeekOne”, the Processor), and the organisation subscribing to the WeekOne platform (the Controller).
In this DPA, “personal data”, “data subject”, and “processing” have the meanings given in the UK GDPR.
2. Nature and Purpose of Processing
WeekOne processes personal data on behalf of the Controller solely to provide the WeekOne CRM and business management platform as described in the Terms of Service. Personal data is processed only on documented instructions from the Controller (including via use of the platform) unless required by law.
3. Types of Personal Data and Data Subjects
WeekOne may process the following categories of personal data:
- Names, email addresses, and contact details of the Controller’s employees and users
- Names, email addresses, and contact details of the Controller’s customers and leads
- Financial data (invoice amounts, payment records) relating to the Controller’s customers
- Any personal data stored by the Controller in the platform’s fields and file attachments
4. Obligations of WeekOne (Processor)
WeekOne shall:
- Process personal data only on the Controller’s documented instructions
- Ensure persons authorised to process the data are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Not engage sub-processors without prior written consent (or general authorisation, as below)
- Assist the Controller in responding to data subject rights requests
- Delete or return all personal data at the end of the service relationship
- Provide information necessary to demonstrate compliance with this DPA
5. Sub-processors
The Controller hereby grants general authorisation for WeekOne to use the following sub-processors, who are contractually bound to data protection obligations no less protective than this DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database and storage | EU (Ireland) |
| Vercel Inc. | Application hosting | EU / UK |
| Resend Inc. | Transactional email | US (SCCs) |
| Cloudflare Inc. | CDN and security | Global |
WeekOne will notify the Controller of any changes to sub-processors with at least 30 days’ notice.
6. Security
WeekOne implements appropriate technical and organisational measures including encryption in transit (TLS), encryption at rest (AES-256), row-level database security, access controls, and regular security assessments. See our Security page for details.
7. Data Breaches
WeekOne will notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting the Controller’s data, providing sufficient information for the Controller to meet its obligations to the ICO.
8. Requesting a Signed DPA
If your organisation requires a countersigned DPA for compliance purposes, please email legal@weekoneapp.com with your organisation name and we will send a signed copy within 5 business days.