Data Processing Agreement
Version 2026-10-02 · Effective date: 8 September 2026
1. What this document is
This Data Processing Agreement (the "DPA") is the written processor contract required by Article 28(3) of the UK GDPR and of the EU GDPR. It forms part of our Terms of Service and applies automatically whenever we process personal data contained in your Customer Data. You do not need to sign a separate copy, and you accept it when you accept the Terms.
Supplier details pending. Railyard is operated from England and Wales. The registered name, company number and registered office of the company that supplies the Service are being finalised and will be published here before Railyard takes payment from new customers. Until then, write to [email protected] for the current contracting party, and treat these Terms as a draft rather than a concluded contract.
In this DPA, "you" and "Customer" mean the organisation or person that is our customer under the Terms, acting as controller; "we" and "us" mean the supplier identified above, acting as processor. "Customer Personal Data" means personal data within Customer Data that we process on your behalf. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR and any other data protection law that applies to that processing. Terms defined in the Terms of Service have the same meaning here.
Where this DPA does not apply. We are an independent controller, not your processor, for the account, billing, security, log and feedback data described in our Privacy Policy. That data is ours to be responsible for, and this DPA does not change that split.
If you need a signed, countersigned copy on your own paper for procurement, email [email protected] and we will provide one.
2. Roles, and each party's own duties
You are the controller of Customer Personal Data and we are your processor. You decide what goes into your designs and who may see them.
You confirm that:
- you have a lawful basis for the Customer Personal Data you put into the Service, and have given the people concerned whatever notice Data Protection Law requires;
- your instructions to us, including those given by configuring the Service, do not require us to break Data Protection Law; and
- you will not put special category data (Article 9) or criminal offence data (Article 10) into the Service. It is an infrastructure design tool and is not built for that data. If you need to, contact us first so we can agree the additional measures.
We are responsible for complying with the obligations Data Protection Law places on processors, and for this DPA.
3. Our instructions (Article 28(3)(a))
We process Customer Personal Data only on your documented instructions, including in relation to transfers. Your instructions are:
- this DPA and the Terms of Service;
- your use and configuration of the Service — the organisations, projects, members, roles, access grants, invitations, exports, integrations and connected clients you set up; and
- any further written instruction we accept.
We process for no other purpose. We do not sell Customer Personal Data, use it for our own marketing or advertising, or use it to train machine-learning models.
We will tell you if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is resolved. If we are required by law to process Customer Personal Data otherwise than on your instructions, we will tell you before doing so unless the law forbids us from telling you — in which case we will tell you as soon as we lawfully can, challenge an over-broad or unlawful demand, and disclose only the minimum required.
4. Confidentiality (Article 28(3)(b))
We keep Customer Personal Data confidential. Access is limited to the people who need it to provide, secure or support the Service; each of them is bound by a written confidentiality obligation that survives the end of their engagement, and is trained on handling personal data. We maintain a record of who has administrative access and review it.
5. Security (Article 28(3)(c) and Article 32)
We implement technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Those measures are described on our Security page, which is Annex II to this DPA and is incorporated into it.
We may update the measures as the Service develops, but will not reduce the overall level of security during the term. Where we make a material change we update the Security page and, on request, will summarise what changed.
6. Sub-processors — general authorisation (Article 28(2))
You give us general written authorisation to engage sub-processors, subject to clause 7. Those currently engaged are listed in Annex III below, and maintained at railyard.sh/subprocessors.
We impose on each sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and we remain fully liable to you for a sub-processor's performance as if it were our own.
7. Changing sub-processors, and your right to object
7.1 We will publish any intended addition or replacement of a sub-processor on the sub-processors page, and will email organisation owners who have asked us to notify them. Ask to be added to that notice list at [email protected].
7.2 We give at least 30 days' notice before a new sub-processor begins processing Customer Personal Data, except where a shorter period is unavoidable to maintain the security or availability of the Service — in which case we will tell you as soon as we can and explain why.
7.3 You may object within that notice period on reasonable grounds relating to data protection, by writing to [email protected]. We will work with you in good faith to find a solution — for example a different provider, a different configuration, or additional safeguards.
7.4 If we cannot resolve your objection, you may terminate the affected part of the Service without penalty by notice, and we will refund fees you have paid for the period after termination. That is your remedy for an unresolved objection.
8. Helping you answer people's requests (Article 28(3)(e))
The Service is built so you can answer most requests yourself: you can read, correct, export and delete Customer Data directly, and the export described in Terms §17 produces a structured, machine-readable copy suitable for a portability request.
Where you still need us, we will give you reasonable assistance — taking account of the nature of the processing and the information available to us — to respond to requests to access, rectify, erase, restrict, port or object, and to any other communication from a data subject. We will do so within a timescale that lets you meet your own statutory deadline.
If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance ourselves. We will tell them to contact you, and pass the request on to an organisation owner without undue delay.
Assistance is included in your subscription. We would only charge for work that is genuinely disproportionate, and we would agree it with you in writing first.
9. Personal data breaches (Article 28(3)(f) and Article 33(2))
9.1 We will notify you of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it. The 48 hours is our own commitment; the law requires only "without undue delay", and we hold ourselves to the shorter period so you can meet your own 72-hour deadline to your regulator.
9.2 The notification goes to the organisation's owners by email, and will describe — to the extent we know it, and with further information as it emerges rather than waiting for a complete picture:
- the nature of the breach, and when and how we became aware of it;
- the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures we have taken or propose to take, including to mitigate adverse effects; and
- a contact point at us for further information.
9.3 We will not require you to approve a notification before we make it to our own regulator where we are obliged to, and we will not tell a data subject about a breach of Customer Personal Data on your behalf unless you ask us to or the law requires it of us.
9.4 We keep an internal record of every personal data breach as Article 33(5) requires, and will make the entries relating to your data available to you on request.
9.5 Unsuccessful attempts that we blocked — a repelled denial-of-service attempt, a failed sign-in, a rate-limited scan — are not breaches and are not notified individually. We report them to you if you ask, and in any security summary we publish.
10. Impact assessments and prior consultation (Article 28(3)(f))
We will give you reasonable assistance with a data protection impact assessment and with any prior consultation with a supervisory authority that relates to our processing, so far as it concerns the Service and is information only we hold. Our Security page, this DPA and the annexes below are designed to answer most of what such an assessment needs.
11. Deletion and return at the end (Article 28(3)(g))
11.1 You can export Customer Data throughout the term and after it, as Terms §17 describes. That is how return is normally achieved, and it costs nothing.
11.2 On the earlier of your request and the end of the retrieval period in Terms §17.2, we will delete Customer Personal Data from the live Service. We will confirm deletion in writing if you ask.
11.3 Backups. Copies in our encrypted backups are not individually deletable. They age out within the backup retention period published in our Privacy Policy, remain subject to this DPA until they do, and are never used to restore deleted data except to recover the Service as a whole after an incident — in which case we re-apply the deletion afterwards.
11.4 We may keep Customer Personal Data where UK or EU law requires us to, and only for as long and for the purpose that law requires. We will tell you what we are keeping and why.
12. Information and audits (Article 28(3)(h))
12.1 We will make available the information reasonably necessary to demonstrate our compliance with this DPA. In the first instance that is this DPA, the Security page, the sub-processors page, and our written answers to your security questionnaire — which we will complete on request at no charge.
12.2 If that is not enough for you to satisfy your own obligations, you may audit our processing, or appoint an independent auditor who is not our competitor to do so. An audit must be on at least 30 days' written notice, during business hours, no more than once a year unless we have had a breach affecting your data or a regulator requires it, and conducted so as not to disrupt the Service or to give access to another customer's data. Each party bears its own costs.
12.3 We do not currently hold an ISO 27001 certification or a SOC 2 report, and we say so plainly rather than pointing at a certification we do not have. If we obtain one we will offer it in place of an on-site audit.
13. International transfers
13.1 Customer Personal Data is stored and processed in the United Kingdom. There is no transfer of the stored data outside the United Kingdom for the purpose of hosting it.
13.2 Some sub-processors in Annex III process limited Customer Personal Data outside the UK and EEA — in practice transactional email, the edge network, and payment data for paid plans. For each such onward transfer we have in place, as applicable:
- the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Three (processor to processor);
- the UK International Data Transfer Addendum to those clauses, or the UK IDTA; or
- reliance on an adequacy regulation where one covers the transfer.
13.3 Where you are an EEA controller and we are a UK processor, the EU Standard Contractual Clauses, Module Two (controller to processor), apply between us and are incorporated into this DPA, with: this DPA and its annexes completing Annexes I and II; clause 7 (docking) included; clause 9 option 2 (general authorisation) with the notice period in clause 7.2 above; clause 11(a)'s independent dispute resolution option not selected; clause 17 governed by the law of Ireland; and clause 18(b) naming the courts of Ireland. For a UK-exporter transfer, the UK Addendum applies with Tables 1 to 4 completed by the equivalent information in this DPA, and no party may end the Addendum under section 19.
13.4 We will tell you if we become subject to a law or practice that prevents us from complying with those clauses, and we have implemented the supplementary measures described on our Security page — encryption in transit, data minimisation, and challenging unlawful access requests.
14. Liability, term and precedence
14.1 This DPA lasts as long as we process Customer Personal Data, and clauses 4, 9.4, 11 and 13 survive its end for as long as they need to.
14.2 Each party's liability under this DPA is subject to the limits and exclusions in the Terms of Service, except that nothing limits a liability that Data Protection Law does not permit to be limited, including a data subject's right to compensation under Article 82. Note that our liability for breaching this DPA is not subject to the data-loss exclusion in Terms §13.4, which expressly carves it out.
14.3 Where this DPA conflicts with the rest of the Terms of Service, this DPA prevails on data protection matters. Where it conflicts with the Standard Contractual Clauses or the UK Addendum, those prevail.
Annex I — Details of the processing
Subject matter. Our provision of the Railyard service to you under the Terms of Service.
Duration. For as long as you use the Service, plus the retrieval period in Terms §17.2 and the backup period in clause 11.3.
Nature and purpose. Hosting, storing, transmitting, displaying, backing up, indexing, validating and exporting the designs and working records you create, and delivering the collaboration, review, notification and integration features you switch on — all in order to provide the Service to you.
Type of personal data. Names and email addresses of your members and invitees; identifiers and role or permission records; authorship, presence and attribution records; review decisions and comment text; project access events; and any personal data your people choose to enter into free-text fields such as names, labels, notes, tags and serials.
Categories of data subject. Your employees, contractors and other personnel who use or are named in the Service; people you invite to an organisation; and any individual your people identify in design content.
Special category data. None. The Service is not intended for it, and clause 2 asks you not to submit it.
Frequency. Continuous, for as long as the Service is in use.
Controller contact. The organisation's owners, as recorded in the Service. Processor contact: [email protected].
Annex II — Technical and organisational measures
Our Security page is Annex II and is incorporated into this DPA. It describes, with enough specificity for an assessment: encryption in transit and the position on encryption at rest; passwordless authentication and how credentials are stored; session and token handling and revocation; role-based access control and tenant isolation; the browser security headers the application sets; audit logging and its retention; abuse and rate-limiting controls; backup and deletion behaviour; and how to report a vulnerability to us.
Measures relating to this DPA specifically: access to production systems is limited to named administrators; confidentiality obligations are in writing (clause 4); breaches are handled under a documented runbook with a named incident owner, which produces the notification in clause 9; and we do not use Customer Personal Data outside the instructions in clause 3.
Annex III — Authorised sub-processors
Current as at 2 October 2026. The maintained version, which is the one that counts, is at railyard.sh/subprocessors.
| Sub-processor | Processing carried out | Location | Transfer safeguard |
|---|---|---|---|
| Hosting and managed database provider — to be confirmed | Application hosting, the PostgreSQL database that stores your account and designs, and encrypted backups of it | United Kingdom | No transfer out of the UK: processing and backups stay in the United Kingdom. |
| Cloudflare, Inc. | Authoritative DNS, TLS termination at the edge, denial-of-service protection, and inbound email routing for our published addresses | Global edge network, United States parent | UK International Data Transfer Addendum and EU Standard Contractual Clauses under Cloudflare's data processing addendum. Requests from the UK and EU are normally served from a UK or EU edge location. |
| Resend (Plus Five Five, Inc.) — to be confirmed | Sending transactional email: sign-in codes, organisation invitations, security and account notices, billing and dunning notices, trial and plan notices, review and merge-request notifications, and email-change confirmations | United States | UK International Data Transfer Addendum and EU Standard Contractual Clauses under the provider's data processing agreement. |
| Stripe Payments Europe, Ltd. and Stripe, Inc. | Taking payment, running subscriptions and issuing invoices — only if you choose a paid plan. Stripe is also an independent controller when it uses payment data for its own fraud prevention, anti-money-laundering and regulatory obligations, which we do not direct and cannot switch off | Ireland, with group processing in the United States | EU Standard Contractual Clauses and the UK Addendum under Stripe's data processing agreement. For Stripe's own controller processing, see Stripe's privacy policy. |
Contact
Questions about this DPA, requests for a countersigned copy, sub-processor notice subscriptions, objections under clause 7.3 and audit requests under clause 12.2 all go to [email protected].