Data Processing Agreement
Version 1.0 · 19 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between FranchiseMS ("we", "us", the "Processor") and the franchisor network that uses the platform ("you", the "Controller"). It sets out how we handle personal data you entrust to us. Where this DPA and our Terms of Use conflict on a data protection matter, this DPA takes precedence.
In this DPA, "UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018, and "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in it.
1. Who controls what
The platform holds three distinct sets of data, and our role differs in each.
- Your network's operating data. Franchise candidates, franchisees, their staff, agreements, royalty and sales records, audits, training records, certifications and communications. You are the controller. We are your processor.
- Your franchisees' own end customers. Job records, quotes, customer invoices, proof photographs, customer signatures and messages sent to those customers. The franchisee is the controller of its own customers. You are a controller for the narrower purposes your franchise agreement gives you, being royalty verification, quality audit, brand compliance and benchmarking. We are the processor for both. You confirm that your franchise agreement permits that access, and that your franchisees are told about it.
- Our own business data. The identity records behind each login, our billing records, and our correspondence with you. We are the controller of these, and our Privacy Notice explains them.
2. What we may and may not do
We will:
- process personal data only to provide and support the platform, on your instructions, and as this DPA and the Terms of Use permit;
- not use your data, or your franchisees' customers' data, for our own purposes, and never sell it or share it for anyone's marketing;
- not use it to train any artificial intelligence or machine learning model, and require the same of our suppliers (see section 7);
- keep it confidential, and bind everyone with access to the same duty;
- only allow access by people who need it to do their job.
Aggregated, anonymised statistics that cannot identify any person or single unit may be used to operate, secure and improve the platform.
3. Security
We apply technical and organisational measures appropriate to the risk, including:
- strict separation between networks, enforced centrally in the platform so that one network's users cannot reach another network's data, including by direct link;
- role-based access within your network, so a franchisee sees its own unit and an operative sees only their own work;
- encryption in transit for all traffic, and encryption of third-party integration credentials at rest;
- passwords stored only as salted, memory-hard hashes, never in readable form, held in our own database rather than with a third-party identity provider;
- optional two-factor authentication for every user;
- an audit trail recording who changed what, and when, for every change;
- backups with restoration testing;
- support access by our staff only when needed to operate or support the platform, always recorded in the audit trail.
A fuller description is available on request for your own due diligence.
4. Where your data is stored
- The database holding all platform records is hosted in Amsterdam, the Netherlands (European Union).
- Documents, photographs and signature images are stored in Western Europe.
- Transactional and customer email is sent from London, United Kingdom.
- Login identities and passwords are held in our own database, not with a third-party identity provider.
A small number of named suppliers process limited data outside the UK and EU, listed in Annex 3. Each is covered by a data processing agreement and, where required, the UK International Data Transfer Addendum or equivalent safeguards.
5. Sub-processors
You authorise us to appoint the sub-processors listed in Annex 3. Each is bound by written terms no less protective than this DPA, and we remain responsible for their performance. We will give you reasonable notice before adding or replacing a sub-processor that processes your data, and if you reasonably object on data protection grounds we will work with you to find an alternative or, failing that, you may terminate the affected part of the service.
6. Data subject rights
Requests from individuals are yours to answer, and ours to help with. If we receive a request that relates to your data we will not answer it ourselves. We will:
- forward it to you within 2 working days of identifying it as yours; and
- give you the assistance and information you reasonably need to answer it within 7 working days of your request for help.
7. Artificial intelligence
The platform includes optional AI features: an assistant for head office, a coach for franchisees, and drafting and review help inside the Communications, Operations manual, Training and Analytics modules.
- You can switch them off. "AI services" is a module you control from the Modules screen. Set it to off and no data of any kind is sent to the AI provider from anywhere in the platform, by any user, through any feature.
- What is sent when they are on. Only what the feature needs: your network name and sector, unit names with their performance figures, the text a user is working on such as a manual section or a draft announcement, and whatever the user types into the assistant. Customer names, addresses, telephone numbers, photographs and signatures are never sent.
- No training on your data. Our AI provider is contractually bound not to use what we send, or what it returns, to train its models.
- Where it is processed. The AI provider is named in Annex 3, with the country of processing and the transfer safeguard that applies.
- AI output is a draft, never a decision. The platform makes no decision about any individual by automated means. Everything an AI feature produces is presented to a person to review, edit and approve before it is used.
- Your responsibility. Please tell your users not to type personal data about identifiable individuals into the assistant. It does not need it, and nothing in the platform requires it.
8. Personal data breaches
If a personal data breach affects your data we will notify you without undue delay and within 24 hours of becoming aware of it, with what we know: what happened, whose data and how many people are affected, the likely consequences, and what we are doing about it. We will keep you updated, and give you the information you need to meet your own obligation to report to the Information Commissioner's Office within 72 hours. Notifying you is not an admission of fault by either of us.
9. How long we keep data
We keep personal data for as long as needed to provide the service, then according to our published retention schedule. Records kept because the law requires it, such as financial records for tax, and the audit trail that evidences accountability, are retained for their own periods regardless of deletion of the underlying record. Deleted records may persist in encrypted backups until those backups age out, which is within 35 days.
10. If our agreement ends
On the end of your agreement you may request a full export of your data. You have 30 days from the end date to ask, and we will provide it within 14 days of your request, in a structured, commonly used, machine-readable format. We then permanently delete your data within 90 days of the end date, except where the law requires us to keep it, and confirm the deletion in writing on request.
11. Audit and information
We will give you the information you reasonably need to satisfy yourself that we are meeting this DPA, including our security description, our sub-processor list and our residency evidence. Where a formal audit is required, it will be at a reasonable time, no more than once a year unless there has been a breach, on reasonable notice, subject to confidentiality, and at your cost.
12. General
This DPA is governed by the laws of England and Wales. Liability under it is subject to the limits in our Terms of Use. If we update this DPA we will publish the new version here and, where the change is material, tell you before it takes effect.
Annex 1 — What is processed
Subject matter and duration. Provision of the FranchiseMS franchise management platform, for the term of your agreement plus the periods in sections 9 and 10.
Nature and purpose. Hosting, storing, organising, displaying, analysing and transmitting personal data so that a franchisor network and its franchisees can be run: franchise recruitment, onboarding, operations, training, audit, communications, job and customer management, royalty calculation and billing.
Categories of data subject. Franchise candidates and applicants; franchisees and their owners and directors; head-office staff; franchisee staff and field operatives; your franchisees' end customers; website enquirers.
Types of personal data. Names; business and personal contact details; postal addresses and postcodes; job titles and roles; login credentials and authentication data; session records including IP address and browser; training, certification and audit records; performance and sales figures; job records and notes; photographs taken as proof of work; customer signature images; the location and time of a job completion; payment references and amounts; document and signing records.
Special category data. None is required by the platform, and none should be entered into it. If your sector involves health or care data, tell us before onboarding so it can be assessed properly first; we do not accept special category data by default.
Children's data. None is required or expected.
Annex 2 — Security measures
As described in section 3, together with: segregation of the production environment; least-privilege credentials; secret material held only in server-side configuration; validation of every uploaded file with executable and script-carrying formats refused; rate limiting and abuse protection on public forms; secure, rotatable tokens for any private feed; and versioned, recorded acceptance of the platform terms.
Annex 3 — Sub-processors
Data stored in the UK or EU:
- Railway — application hosting and the PostgreSQL database. Amsterdam, Netherlands (EU).
- Cloudflare R2 — storage of documents, photographs and signature images. Western Europe (EU).
- Amazon Web Services (SES) — sending transactional and customer email. London, United Kingdom.
- The SMS Works — sending text messages. United Kingdom.
- Ideal Postcodes — address lookup from a postcode. United Kingdom.
Processing outside the UK and EU, each under a data processing agreement and the UK International Data Transfer Addendum or equivalent safeguards:
- Stripe — subscription billing, and card payments taken by franchisees. Card details are handled by Stripe and never reach our systems. United Kingdom and United States.
- Anthropic — the optional AI features described in section 7. United States. Contractually bound not to train on what is sent. Switched off entirely if you set the AI services module to off.
- Google (Analytics and Tag Manager) — website analytics on our public marketing website only. Never used inside the platform, and only with the visitor's consent. United States.
Used only if you choose to connect them, in which case the provider is also a controller in its own right and its own terms apply to you: Xero (accounting sync), Square (card payments), Microsoft 365 or Resend (email sending from your own tenant or domain).
We will keep this Annex current. The date at the top of this document is the date it was last reviewed.
Related documents
Terms of use — the platform terms every user accepts.
Privacy & cookies — what this website does, and your choices.
For a countersigned copy of this agreement, or for your own due-diligence questions, email hello@franchise.ms.