SmartRep Data Processing Agreement
Effective when accepted electronically
1. Parties and status
The Controller is the elected representative or office identified in the SmartRep account.
The Processor is Robert Treacy, an individual sole trader established in Ireland and the provider of the SmartRep service.
Contact: [email protected] or the monitored website contact form.
This Data Processing Agreement forms part of the SmartRep Terms of Service. The administrator who accepts it confirms that they are authorised to bind the Controller. Electronic acceptance is recorded with the version, document hash, accepting user, time, IP address and browser user agent.
2. Scope and duration
The Processor processes Customer Personal Data only to host and provide SmartRep's constituency-casework, contact, task, file, reporting, mapping, collaboration, import, export, security, support and maintenance functions.
Processing begins when the Controller first supplies Customer Personal Data and ends when it is returned or deleted in accordance with this agreement, except for limited records that must or may lawfully be retained.
The details required by Article 28(3) GDPR are set out in Annex A.
For Eircode-based casework mapping, the Controller instructs the Processor to normalise an Eircode, send that normalised Eircode to the external geocoding providers enabled for the service, and store the returned latitude and longitude with the Controller's data. If an enabled provider does not return an acceptable map point, the Processor may send the same normalised Eircode to the next enabled provider.
Providers may classify returned coordinates at different precision levels. The Processor stores that classification where supplied for operational diagnostics.
An enabled provider receives only the normalised Eircode and ordinary request metadata needed to answer and secure the request, such as the SmartRep server's IP address, request time and API-account information. The Processor does not include a constituent's name, phone number, email address, case notes, case category or case details in a geocoding request.
3. Documented instructions
The Processor will process Customer Personal Data only on the Controller's documented instructions, including these Terms, settings and ordinary authorised use of the service, unless Irish or EU law requires otherwise. If law requires processing outside those instructions, the Processor will inform the Controller beforehand unless the law prohibits that notice.
The Processor will inform the Controller if, in its reasonable opinion, a documented instruction infringes GDPR or applicable Irish or EU data-protection law. The Controller remains responsible for the purposes, lawful bases, notices, data entered, retention decisions and disclosures it determines.
4. Confidentiality and personnel
The Processor will ensure that each person authorised to process Customer Personal Data is subject to an appropriate duty of confidentiality and receives access only as needed for their work.
SmartRep does not routinely inspect casework. Limited provider access may occur to deliver support requested by the Controller, investigate a security or availability incident, comply with law, or maintain the service.
5. Security
The Processor will maintain the measures in Annex B, taking account of the nature, scope, context and purposes of processing and the risks to individuals. The service's access controls support the Controller's obligation to prevent unauthorised access to sensitive casework.
The Controller will use individual accounts, manage staff access promptly, require reasonable device security and keep authenticator and recovery information secure.
6. Sub-processors
The Controller gives general authorisation for the sub-processors listed in Annex C. The Processor will ensure that substantially equivalent Article 28 obligations apply to those sub-processors.
The Processor will notify the Controller by email before adding or replacing a sub-processor that will process Customer Personal Data. The Controller may object on reasonable data-protection grounds. The parties will work in good faith to resolve an objection; if they cannot, the Controller may stop using the affected service.
7. Data-subject requests
Taking account of the nature of the processing, the Processor will provide reasonable assistance with the Controller's obligations to respond to data-subject requests. SmartRep includes per-person export and erasure tools, case restriction and a complete office ZIP export containing portable JSON records and available uploaded files.
Exports reproduce information entered by the office. The Controller must review them for third-party information and decide what may lawfully be disclosed. If the Processor receives a request about Customer Personal Data directly, it will refer the requester to the Controller unless legally required to respond.
8. Security incidents and compliance assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information reasonably required for the Controller's assessment and notifications.
Taking account of the information available and the nature of processing, the Processor will provide reasonable assistance with Articles 32 to 36 GDPR. The Controller remains responsible for deciding whether its processing requires a data protection impact assessment or consultation with a supervisory authority.
9. Information and audit
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. On reasonable notice, the Controller may conduct a proportionate remote review or request relevant evidence. On-site inspection is available where remote evidence is insufficient, subject to reasonable security, confidentiality and disruption controls.
The Controller bears its own audit costs unless an audit identifies a material breach by the Processor.
10. Return and deletion
During the subscription and read-only period, the Controller may use SmartRep's export tools. The Processor will provide reasonable assistance with another available format where needed to return Customer Personal Data.
After cancellation, the service remains read-only and export-only. On the Controller's request, or through the provider's manual closure process, operational Customer Personal Data is deleted within 90 days unless the Controller resubscribes or law requires a particular item to be retained.
Deletion removes operational data from the live service. Existing backups, if any, are not selectively edited and instead age out through their normal operational cycle. If a backup is restored during that cycle, the deletion instruction continues to apply.
Account identifiers, billing records, legal-acceptance evidence and erasure evidence may be retained where reasonably necessary for tax, contract, security and legal-record purposes. They will not be used to resume operational processing of Customer Personal Data.
11. Location and transfers
The application, database and uploaded Customer Personal Data are hosted in the European Union by Hetzner Online GmbH. The Processor will not transfer Customer Personal Data outside the EEA unless a lawful Chapter V GDPR mechanism and the required safeguards are in place.
Stripe and Proton support billing and transactional email. SmartRep does not send constituent casework to those services unless a user puts it in an email.
Cloudflare provides the HTTPS reverse proxy, content-delivery and security layer for SmartRep, as well as public-signup abuse protection. Cloudflare terminates the user's HTTPS connection and forwards requests to SmartRep over an encrypted connection. It therefore processes request and response content in transit, which can include Customer Personal Data, together with traffic and security metadata. Cloudflare does not host SmartRep's operational database or uploaded-file store. Cloudflare operates a global network, and its processing outside the EEA is subject to the applicable lawful Chapter V transfer mechanism and safeguards.
ArcGIS by Esri, HERE and Google are approved for Eircode geocoding as listed in Annex C. Only providers that are configured and enabled receive requests. Where a provider processes Customer Personal Data outside the EEA, the Processor will use an applicable lawful Chapter V transfer mechanism and required safeguards.
12. Purpose limitation
The Processor does not use Customer Personal Data for its own purposes. In particular, it does not use it for advertising, product analytics, behavioural profiling, cross-customer benchmarking, model training or a provider-owned dataset. Adding such processing would require a new agreement.
13. Responsibility and liability
The Controller is responsible for the lawfulness of the purposes and processing it determines and instructs. The Processor is responsible for processing in accordance with this agreement and for its own statutory obligations.
Nothing in this agreement limits a data subject's rights, a supervisory authority's powers, or either party's statutory liability. Contractual liability between the parties is governed by the SmartRep Terms of Service.
14. Changes and governing law
A material change to this agreement will be issued as a new version and notified to the Controller with reasonable notice. Irish law governs this agreement. The Irish Data Protection Commission is the lead supervisory authority for the Processor's establishment.
Annex A: Processing details
| Item | Details |
|---|---|
| Subject matter | Hosting and operation of the Controller's constituency-casework service |
| Duration | Subscription, read-only period and deletion period described in section 10 |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, updating, export, restriction and deletion on the Controller's instructions; normalisation of an Eircode, geocoding through enabled providers and storage of returned coordinates and provider precision classification |
| Purpose | Constituency casework and related office administration |
| Data subjects | Constituents, people acting for them, third parties mentioned in casework, office users and collaboration participants |
| Personal data | Identity and contact data; case requests and correspondence; notes, actions, tasks and outcomes; attachments; Eircodes, returned latitude and longitude, and register-match fields when lawfully enabled; user and access records; collaboration content |
| Sensitive information | Free-text casework and attachments may contain health, disability, political, religious, ethnic, trade-union, sexual-life, immigration, financial, housing or other sensitive information supplied by the Controller |
Annex B: Technical and organisational measures
| Measure | Current implementation |
|---|---|
| Tenant isolation | Application queries scope Customer Data, including every imported electoral-register row and join, by organisation. The authenticated session supplies the organisation context; client-supplied organisation identifiers are not trusted for access. |
| Access control | Administrator and staff roles. Restricted cases are visible only to administrators and the assigned caseworker. Administrative exports, imports, merging, staff management and erasure are role-restricted. |
| Authentication | Per-user TOTP MFA is available and optional; SmartRep does not currently provide an office-wide MFA requirement. Passwords are bcrypt-hashed. Reset tokens and MFA recovery codes are stored only as hashes and are single-use. Deactivation, role change, password reset and revoke-all invalidate existing sessions. |
| Transport security | HTTPS/TLS protects browser traffic in production and certificates are managed by the reverse proxy. |
| Audit records | The application records account, access, case, export, import, erasure, collaboration and billing events with an actor, entity and timestamp. These are application audit records; no claim of cryptographic immutability is made. |
| Retention and erasure | Per-person and organisation-wide tools remove operational casework and stored files. Organisation closure and post-cancellation deletion are manual provider processes. Existing backups are not selectively edited and age out on their normal cycle. |
| Availability | The application and database containers restart after unexpected process failure. No uptime SLA, multi-host failover or restore-time guarantee is provided. |
| Rate limiting | Authentication, signup, upload, feedback and API traffic are rate-limited. Signup abuse dimensions are stored as keyed hashes rather than raw email or IP values. |
| No tracking or reuse | No advertising analytics, product-analytics SDK, behavioural segmentation, cross-customer benchmarking, model training or provider-owned Customer Data set is operated. |
Annex C: Approved sub-processors
Only a geocoding provider that is configured and enabled receives a request. The provider receives the normalised Eircode and ordinary request metadata, not names, contact details or case notes. Provider processing locations can depend on the service configuration; section 11 applies to any processing outside the EEA.
| Sub-processor | Service | Customer Personal Data | Location |
|---|---|---|---|
| Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany | Hosting of the application, database and uploaded case documents | All Customer Personal Data stored in SmartRep | Helsinki, Finland (hel1-dc2), European Union |
| Cloudflare, Inc. | HTTPS reverse proxy, content delivery, traffic security and public-signup abuse prevention | Request and response content in transit, which can include Customer Personal Data; IP address, request metadata and browser or network security signals | Cloudflare's global network under the applicable data-processing terms and transfer safeguards |
| Esri (ArcGIS) | Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata | Provider infrastructure under the applicable service terms and transfer safeguards |
| HERE | Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata | Provider infrastructure under the applicable service terms and transfer safeguards |
| Eircode geocoding, only when configured and enabled | Normalised Eircode and ordinary server request metadata | Provider infrastructure under the applicable service terms and transfer safeguards |