Effective 2 August 2026 · Version 2026-08-02
Data Processing Agreement
These terms apply when Arxela processes property-management personal data on a customer’s behalf. They form part of the Arxela Terms of Use.
1. Parties and status
This Data Processing Agreement (the “DPA”) is between Sanderson x Holdings Ltd trading as Arxela Property Management (“Arxela”, “processor”, “we” or “us”) and the landlord, company or other organisation accepting the Arxela Terms of Use (“Customer” or “controller”).
Sanderson x Holdings Ltd is registered in England and Wales under company number 16576471. Its registered office is 2 Worthington View, Hartford, Northwich, England, CW8 2HF. Its ICO registration number is ZB617526.
This DPA is effective when Customer accepts the Terms and DPA during signup or otherwise agrees to it in writing. If Customer is itself a processor for another controller, Arxela acts as Customer’s subprocessor and the controller obligations in this DPA apply to Customer as processor.
2. Definitions and priority
“Data Protection Laws” means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and other applicable UK data-protection legislation, each as amended or replaced. “Customer Personal Data”, “controller”, “processor”, “data subject”, “personal data breach” and “processing” have the meanings given by Data Protection Laws.
If this DPA conflicts with the Terms on personal-data processing, this DPA prevails. Applicable mandatory Data Protection Laws prevail over both.
3. Processing details
- Subject matter: provision of Arxela’s property-management software, portals, document, compliance, maintenance, communication and related support functions.
- Duration: for the term of Customer’s account and the limited return, deletion, backup and legal-hold periods described in this DPA and the Data Retention Schedule.
- Nature and purpose: receiving, structuring, storing, securing, retrieving, displaying, transmitting, rendering, backing up and deleting Customer Personal Data to provide features selected by Customer.
- Data subjects: landlords, property owners, tenants, guarantors, occupants, applicants where entered, contractors, tradespeople, emergency contacts, authorised users and other people connected to a property, tenancy or maintenance workflow.
- Personal data: identity, contact and account data; property and occupancy records; tenancy and agreement records; rent, deposit, invoice and payment records; compliance documents; messages; maintenance reports, photographs and files; appointment and contractor information; portal activity and audit records.
- Sensitive data: the launch service is not intended for health, disability, pregnancy, criminal-offence or other special-category data. Customer must not enter that information into maintenance descriptions, uploads, messages or documents.
4. Customer instructions and responsibilities
Customer instructs Arxela to process Customer Personal Data to provide and secure the service, comply with Customer’s authorised use of features, provide support, and carry out the processing described in this DPA. Customer may give additional documented instructions that are consistent with the Terms and the service.
Customer is responsible for the lawfulness, fairness, accuracy and minimisation of Customer Personal Data; its lawful bases and Article 9 or 10 conditions; privacy information to data subjects; user permissions; and the legality of its instructions. Customer must not instruct Arxela to violate Data Protection Laws.
If we reasonably believe an instruction infringes Data Protection Laws, we will notify Customer unless prohibited by law and may suspend the affected processing while the parties resolve it.
5. Arxela’s processing obligations
Arxela will process Customer Personal Data only on documented instructions from Customer, including for international transfers, unless UK law requires other processing. Where legally permitted, we will tell Customer about that requirement before processing.
We will ensure people authorised to process Customer Personal Data are bound by confidentiality, receive appropriate instruction and access only what they need for their role.
Arxela will not sell Customer Personal Data or use it for advertising. We do not use customer property, tenancy, document, message or maintenance data to train foundation models.
6. Security measures
Taking account of the nature of the processing, available technology, implementation cost and risk to people, Arxela will maintain appropriate technical and organisational measures. The current baseline includes:
- role-, tenancy- and property-scoped access controls with server-owned authorisation;
- password hashing, signed HTTP-only sessions, email verification, expiring single-use tokens and rate limiting;
- private object storage, scoped file delivery and signed or expiring contractor access where applicable;
- separation of self-managed customer accounts and denial of cross-account access;
- audit events for material actions and secret-safe operational logging;
- provider access controls, encrypted transport and provider-managed encryption at rest;
- backup, restoration, vulnerability-management and incident-response procedures proportionate to the service risk.
Security measures may evolve, but we will not materially reduce the overall protection of Customer Personal Data during the term.
7. Subprocessors
Customer gives Arxela general written authorisation to use the subprocessors listed at arxela.co.uk/subprocessors. Arxela remains responsible for each subprocessor’s performance of its data-protection obligations to the extent required by law.
We will contractually require each subprocessor to protect personal data to a standard consistent with this DPA. We will give at least 15 days’ notice of an intended new or replacement subprocessor where reasonably practicable. For an urgent security, continuity or legal change, we will give notice as soon as practicable.
Customer may object during the notice period on reasonable data-protection grounds. We will consider the objection in good faith and try to offer a reasonable solution. If none is available, either party may end the affected service without penalty.
8. International transfers
Arxela will ensure a restricted transfer is covered by UK adequacy regulations or an appropriate safeguard permitted by Data Protection Laws. Safeguards may include the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary measures where required.
Provider locations and the applicable transfer position are recorded in the Subprocessor Register. Customer authorises those transfers as part of its instructions under this DPA.
9. Data-subject rights
Taking account of the nature of processing and information available to us, Arxela will provide reasonable assistance for Customer to respond to requests for access, correction, deletion, restriction, portability, objection and safeguards relating to automated decisions.
If we receive a request relating primarily to Customer Personal Data, we will direct it to Customer or notify Customer unless prohibited by law. Customer remains responsible for deciding and communicating the response.
10. Breaches, DPIAs and regulators
Arxela will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will provide available information about the nature of the breach, likely consequences, affected data and people, and measures taken or proposed, and will provide updates as the investigation develops.
We will provide reasonable assistance with Customer’s security obligations, breach notifications, data-protection impact assessments and prior consultation with the ICO, taking account of the processing and information available to us.
11. Deletion and return
During the account term, Customer can download individual documents and records using available features. On closure, Customer must identify any records it requires before access ends.
At Customer’s choice and subject to technical feasibility, Arxela will return available Customer Personal Data or delete it after the service ends. We may retain data where UK law requires it or while a documented legal hold applies. Data remaining in protected backups will be isolated from ordinary use and deleted as the backups rotate, normally no later than 90 days after deletion from active systems.
The public Data Retention Schedule describes the standard operational periods. A lawful Customer instruction or legal duty may require a different period.
12. Information, audits and compliance
Arxela will make available information reasonably necessary to demonstrate compliance with this DPA. This may include policies, provider assurances, test evidence, independent reports or written responses.
If that information is not reasonably sufficient, Customer may request one audit in a 12-month period by an independent auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours and without accessing another customer’s data. Additional audits may be requested following a material breach or regulator requirement. Customer bears its audit costs unless the audit identifies a material breach by Arxela.
13. Liability and termination
Liability arising from this DPA is subject to the liability provisions in the Terms, except to the extent Data Protection Laws require otherwise. Ending this DPA does not remove duties that continue by their nature, including confidentiality, deletion, return, audit evidence and liability.
14. Law and contact
This DPA is governed by the law of England and Wales and the courts of England and Wales have jurisdiction, subject to mandatory Data Protection Laws.
Data-protection questions and instructions should be sent to hello@arxela.co.uk.