Data Processing Agreement

Data Processing Agreement

Version: 2026-10-04 · Effective: 4 October 2026

This Data Processing Agreement forms part of the Terms of Service between Cromalt Ltd, a company registered in Scotland (company no. SC891350), registered office 48 West George Street, Glasgow G2 1BP ("Processor") and the customer ("Controller") for the use of xpense.events (the "Service"). It is accepted together with those terms.

1. Definitions

"UK GDPR", "personal data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meanings in the UK GDPR and Data Protection Act 2018.

2. Roles

The Controller is the controller and Cromalt Ltd is the processor in respect of the personal data contained in Customer Data: the expenses, receipts and related records the Controller's users put into its workspace, and the details of those users as members of that workspace ("Customer Personal Data").

This agreement does not cover personal data for which Cromalt Ltd is itself the controller, such as the account, billing and support details of the people who deal with us on the Controller's behalf. That is described in our Privacy Policy.

3. Subject matter and details of processing

See Annex 1 (subject matter, duration, nature and purpose, types of personal data, categories of data subjects).

4. Processor obligations

The Processor shall:

  • (a) process Customer Personal Data only on the Controller's documented instructions, including this agreement and the Controller's use of the Service, and including for transfers outside the UK. If UK law requires the Processor to process it otherwise, the Processor will tell the Controller of that requirement before processing, unless the law prohibits telling them;
  • (b) ensure persons authorised to process it are bound by confidentiality;
  • (c) implement appropriate technical and organisational security measures (Annex 2);
  • (d) respect the conditions for engaging sub-processors (clause 5);
  • (e) assist the Controller, by appropriate measures, to respond to data-subject requests;
  • (f) assist the Controller with security, breach notification, data protection impact assessments and prior consultation (UK GDPR Articles 32 to 36);
  • (g) at the Controller's choice, delete or return Customer Personal Data at the end of the services as set out in clause 9, save where law requires retention;
  • (h) make available information needed to demonstrate compliance, and allow and contribute to audits.

The Processor will tell the Controller immediately if, in its opinion, an instruction infringes data-protection law.

5. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed at /legal/subprocessors. The Processor remains liable for its sub-processors and imposes equivalent obligations on them by contract.

Before adding or replacing a sub-processor, the Processor will give at least 30 days' notice by updating that list and emailing the Controller's workspace administrators. The Controller may object on reasonable data-protection grounds by emailing privacy@xpense.events within that period. The parties will then discuss the objection in good faith. If it cannot be resolved before the change takes effect, the Controller may end the agreement by closing its workspace, and the Processor will refund any period the Controller has paid for but not used. The Processor will not use the new sub-processor to process that Controller's Customer Personal Data: if the 30 days in clause 9 would run past the date the change takes effect, the Processor will delete the retained data before that date, and will tell the Controller the date by which to download it.

6. International transfers

Where Customer Personal Data is transferred outside the UK, the Processor will ensure an appropriate transfer mechanism is in place (the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses).

7. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the detail available to help the Controller meet its own obligations.

8. Data-subject rights

The Processor will, taking account of the nature of the processing, assist the Controller by appropriate technical and organisational measures to fulfil data-subject requests. A request the Processor receives directly about Customer Personal Data is passed to the Controller.

9. Deletion and return

At the end of the services the Controller chooses whether Customer Personal Data is returned or deleted.

  • Return. For 30 days after the Controller closes its workspace, its administrators can download an export: a spreadsheet of every expense, including who submitted it, and an archive of every receipt file. Customer Personal Data that the export does not contain, such as the list of workspace members and the record of approval decisions, is provided on request to privacy@xpense.events made within those 30 days. Where a request is made in time, the Processor will supply the data before deleting the workspace, and will postpone the deletion if that is needed to do so.
  • Deletion. After those 30 days the Processor permanently deletes all Customer Personal Data in the workspace from its live systems, whether or not it was exported.

Copies in database history expire within 7 days of deletion, and error reports within 90 days. The Processor keeps only its own billing records for the Controller's subscription, as tax law requires.

10. Audit

The Processor will make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and frequency limits.

11. Liability, term and law

Liability and term follow the Terms of Service. This agreement is governed by the law of Scotland and subject to the exclusive jurisdiction of the Scottish courts.


Annex 1: Details of processing

  • Subject matter: provision of the xpense.events expense-capture Service.
  • Duration: while the Controller's workspace is open, plus the 30 days after it is closed.
  • Nature and purpose: capture, reading by AI, storage, approval, finalisation and reporting of expenses on the Controller's instructions.
  • Types of personal data: names, email addresses, expense amounts and dates, merchant and location, and the contents of receipt images.
  • Categories of data subjects: the Controller's staff and contractors who submit expenses, and individuals named on receipts.

Annex 2: Technical and organisational measures

See /legal/security, incorporated by reference.

Annex 3: Sub-processors

See /legal/subprocessors, incorporated by reference.