Data Processing Agreement
Version 2.2 · 21 September 2026 · Spruce Energy Limited. This version supersedes version 2.1 (8 September 2026) and version 2.0 (17 August 2026). Previous versions are available from Spruce on request (legal@spruce.eco).
This Spruce Data Processing Agreement and its Annexes (“DPA”) sets out the parties’ agreement on the Processing of Personal Data by Spruce on behalf of the Subscriber in connection with the Services provided under the Spruce Platform Terms and Conditions (the “Platform T&Cs”). This DPA is incorporated into and forms part of the Platform T&Cs by clause 6.3 of the Platform T&Cs.
1. Definitions and interpretation
1.1 The following definitions apply in this DPA:
Anonymised Property Data: has the meaning given in the Platform T&Cs (clause 4.4).
Business Day: has the meaning given in the Platform T&Cs.
Business Purposes: the Services to be provided by Spruce to the Subscriber as described in the Platform T&Cs and any other purpose specifically identified in Annex A.
Compliance Pages: has the meaning given in the Platform T&Cs.
contract year: has the meaning given in clause 10.3(h) of the Platform T&Cs.
Data Protection Legislation: all applicable laws relating to data protection, privacy and electronic communications in force from time to time, including, to the extent applicable to the relevant party or to the relevant Processing of Personal Data under this DPA: (a) the UK GDPR and the Data Protection Act 2018, each as amended (including by the Data (Use and Access) Act 2025), and regulations made under them; (b) Regulation (EU) 2016/679 (the “EU GDPR”) together with applicable national implementing or supplementing legislation, including in the Republic of Ireland the Data Protection Acts 1988 to 2018; (c) the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426); and (d) the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011) of Ireland; in each case as amended, replaced or supplemented from time to time.
Controller, Processor, Data Subject, Personal Data Breach, Processing (and “process”, “processes”, “processed”): have the meanings given in Article 4 of the UK GDPR or, where the Subscriber is established in the European Economic Area, Article 4 of the EU GDPR. (“Personal Data” is separately defined below with the scope specific to this DPA, and that definition prevails.)
EEA: the European Economic Area.
Personal Data (as used in this DPA): any information relating to an identified or identifiable living individual that is processed by Spruce on behalf of the Subscriber as a result of, or in connection with, the provision of the Services under the Platform T&Cs. It does not include Anonymised Property Data, or personal data that Spruce processes as an independent Controller under clause 6.2(b) of the Platform T&Cs.
Records: has the meaning given in clause 13.
Sub-processor: any third party appointed by Spruce to process Personal Data on behalf of the Subscriber.
Sub-processor List: the list of Sub-processors published by Spruce at spruce.eco/legal/sub-processors (or a replacement address notified to the Subscriber), as updated in accordance with clause 9.
Supervisory Authority: the supervisory authority with competence over the processing under this DPA, being: (a) the Information Commissioner’s Office (“ICO”) or its statutory successor (including, on and from commencement of the relevant provisions of the Data (Use and Access) Act 2025, the Information Commission) where the Subscriber is established in the United Kingdom; (b) the Data Protection Commission (“DPC”) where the Subscriber is established in the Republic of Ireland; and (c) otherwise, the competent supervisory authority determined in accordance with the Data Protection Legislation.
Term: the term of this DPA as described in clause 11.
UK GDPR: has the meaning given in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.
1.2 Where the Subscriber is established in the United Kingdom, references in this DPA to the Data Protection Legislation are to be read primarily as references to the UK GDPR and the Data Protection Act 2018; where the Subscriber is established in the EEA, primarily as references to the EU GDPR and applicable national law. Where the Subscriber operates in both, both regimes apply to the processing they respectively govern.
1.3 The Annexes form part of this DPA. In case of conflict: (a) the body of this DPA prevails over the Annexes; (b) this DPA prevails over the Platform T&Cs in respect of the processing of Personal Data, except that clause 10 of the Platform T&Cs and clause 18 of this DPA govern liability under both documents.
1.4 A reference to writing or written includes email.
1.5 Capitalised terms used but not defined in this DPA have the meanings given in the Platform T&Cs.
2. Relationship of the parties
2.1 For the purposes of the Data Protection Legislation, the Subscriber is the Controller and Spruce is the Processor of the Personal Data. Where the Subscriber processes Personal Data in the Services on behalf of, or jointly with, another business (for example a manufacturer or merchant Subscriber whose jobs concern the customers of an installer it works with), the Subscriber may itself be a Processor or a joint Controller of that Personal Data; in that case the Subscriber warrants that it has the authority of the relevant Controller to appoint Spruce as its Processor on the terms of this DPA and to give the instructions it gives, references in this DPA to the Subscriber as Controller include the Subscriber acting with that authority, and Spruce’s obligations under this DPA are owed to the Subscriber alone. The Subscriber is responsible for satisfying itself that the terms of this DPA meet any obligation it owes to the relevant Controller (including under Article 28(4) of the UK GDPR or EU GDPR) and that the relevant Controller has authorised the general appointment of Sub-processors under clause 9.1; Spruce owes no obligation under any contract between the Subscriber and that Controller.
2.2 The Subscriber retains control of the Personal Data and remains responsible for its own compliance obligations under the Data Protection Legislation, including providing any required notices to and obtaining any required consents from Data Subjects, and for the lawfulness of the written processing instructions it gives to Spruce.
2.3 Annex A describes the subject matter, duration, nature and purpose of the processing, the categories of Personal Data, and the types of Data Subject.
2.4 This DPA is intended to constitute the contract required by Article 28(3) of the UK GDPR and, where the Subscriber is established in the EEA, Article 28(3) of the EU GDPR and, where the Subscriber acts as a Processor so that Spruce is a sub-processor, the contract required by Article 28(4), imposing on Spruce data protection obligations of the same substance as those required of the Subscriber by the relevant Controller (subject to the Subscriber’s responsibility under clause 2.1 to satisfy itself that this is so). The Subscriber confirms that Spruce’s appointment is covered by the prior written authorisation required by Article 28(2) where that Article applies. The parties agree that this DPA is binding on Spruce and contains each of the matters required by Article 28(3)(a) to (h), and that neither party will contend that it fails to satisfy Article 28(3) or Article 28(4) by reason only of its governing law.
3. Processing instructions
3.1 Spruce will process the Personal Data only to the extent, and in such a manner, as is necessary for the Business Purposes and in accordance with the Subscriber’s documented instructions, which are: the Platform T&Cs (including clause 4.4 on Anonymised Property Data), this DPA, and the Subscriber’s configuration and use of the Services. Spruce will not process the Personal Data for any other purpose. The Business Purposes include operating, monitoring, securing, supporting and troubleshooting the Services (which may involve Personal Data appearing in monitoring, error and support records) and creating Anonymised Property Data in accordance with clause 4.4 of the Platform T&Cs. Spruce’s use of Anonymised Property Data after its creation is not processing of Personal Data on behalf of the Subscriber and is outside this DPA; the Subscriber’s instruction under clause 4.4 includes any further anonymisation or deletion required by that clause.
3.2 Spruce will immediately inform the Subscriber if, in its opinion, an instruction infringes the Data Protection Legislation.
3.3 Spruce will comply promptly with any reasonable written instruction from the Subscriber to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorised processing. Clause 4.2 applies to instructions requiring work beyond the standard functionality of the Services.
4. Spruce’s general obligations
4.1 Spruce will maintain the confidentiality of the Personal Data and will not disclose it to third parties unless the Subscriber or this DPA specifically authorises the disclosure, or disclosure is required by law, a court, or a Supervisory Authority. Where lawfully permitted, Spruce will inform the Subscriber of any such requirement before disclosure and give the Subscriber an opportunity to object or challenge it.
4.2 Spruce will reasonably assist the Subscriber with meeting the Subscriber’s compliance obligations under the Data Protection Legislation, taking into account the nature of the processing and the information available to Spruce, including in relation to Data Subject rights, data protection impact assessments, and consultation with or reporting to a Supervisory Authority. Routine assistance is provided at no additional cost; Spruce may charge a reasonable fee for assistance that is manifestly excessive, repetitive or disproportionate in scale.
5. Personnel
5.1 Spruce will ensure that all personnel authorised to process the Personal Data: (a) are informed of its confidential nature and are bound by written confidentiality obligations; (b) have undertaken training on the Data Protection Legislation and its application to their duties; and (c) process the Personal Data only on the Subscriber’s documented instructions.
6. Security
6.1 Spruce will implement and maintain appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, disclosure, copying, modification, loss, destruction or damage of the Personal Data, including without limitation the measures set out in Annex B. Spruce may update the Annex B measures from time to time, provided no update materially reduces the overall level of security of the Services. Spruce publishes the current Annex B on the Compliance Pages, keeps previous versions available on request, and notifies Subscribers of material changes by email to their notice address.
6.2 Those measures will ensure a level of security appropriate to the risk, including as appropriate: (a) pseudonymisation and encryption of Personal Data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems; (c) the ability to restore availability and access to Personal Data in a timely manner following a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of the measures.
7. Personal Data Breach and security incidents
7.1 Spruce will notify the Subscriber in writing without undue delay and in any event within 24 hours after becoming aware of any Personal Data Breach. Spruce will also notify the Subscriber within 24 hours after becoming aware of any other security incident that has, or is reasonably likely to have, a significant adverse effect on the availability, integrity or confidentiality of the Services used by the Subscriber, whether or not Personal Data is affected, and will provide updates at reasonable intervals until resolved. Spruce is “aware” of a Personal Data Breach when it has a reasonable degree of certainty that a security incident has compromised Personal Data. Spruce will also notify the Subscriber without undue delay of any other accidental or unlawful processing of Personal Data that does not amount to a Personal Data Breach. Notification under this clause 7 is not an acknowledgement of fault or liability.
7.2 Spruce’s notification obligations under this clause are designed to enable the Subscriber to meet its own obligation to notify the competent Supervisory Authority within 72 hours under Article 33(1) of the UK GDPR or EU GDPR (as applicable). Spruce will reasonably co-operate with any reporting the Subscriber is required to make to its regulators in respect of an incident notified under clause 7.1.
7.3 The notification will include, or be supplemented without undue delay by: (a) a description of the nature of the incident, including the categories and approximate numbers of Data Subjects and Personal Data records concerned; (b) the name and contact details of Spruce’s point of contact; (c) the likely consequences; and (d) the measures taken or proposed to address the incident and mitigate its possible adverse effects. Notices are sent to the Subscriber’s notice address and to any security contact nominated under clause 22.1 of the Platform T&Cs.
7.4 Following any such incident, the parties will co-ordinate to investigate the matter, and Spruce will reasonably co-operate with the Subscriber at no additional cost, including: assisting with any investigation; making available relevant records, logs and information; facilitating reasonable discussions with relevant personnel; and taking reasonable and prompt steps to mitigate the effects of the incident.
7.5 Spruce will not name the Subscriber, or disclose the Subscriber’s Personal Data, in any communication about the incident to a third party without the Subscriber’s written consent, except: (a) where required by law or a Supervisory Authority; (b) to Spruce’s professional advisers, insurers, incident-response and forensic providers and affected Sub-processors, in confidence; (c) to other affected customers, without identifying the Subscriber; and (d) in Spruce’s own notifications as Controller of personal data for which it is responsible.
7.6 The Subscriber has the sole right to determine: (a) whether and how to notify Data Subjects, Supervisory Authorities, regulators, law enforcement or others; and (b) whether to offer any remedy to affected Data Subjects. Where any remedy offered to Data Subjects is to be borne by Spruce (whether as Data Protection Losses under the Platform T&Cs or otherwise), the Subscriber will consult Spruce before offering it and will not offer any remedy beyond that required by the Data Protection Legislation without Spruce’s written consent (not to be unreasonably withheld).
7.7 Spruce will cover all reasonable expenses associated with its obligations under this clause 7, unless the incident arose from the Subscriber’s specific written instructions, negligence, wilful default or breach of this DPA, in which case the Subscriber will cover such expenses.
8. International transfers
8.1 Spruce (and any Sub-processor) will not transfer or otherwise process the Personal Data outside the United Kingdom or the EEA except: (a) under clause 8.3; (b) to a country, territory or recipient covered by adequacy regulations under the UK GDPR or an adequacy decision under Article 45 of the EU GDPR (as applicable); (c) under appropriate safeguards pursuant to Article 46 of the UK GDPR or EU GDPR (as applicable), supported by any transfer risk assessment the Data Protection Legislation requires; or (d) with the Subscriber’s prior written consent. Occasional remote access by Spruce personnel from outside the UK/EEA, using Spruce-managed devices and access controls, is not a transfer to a third party for the purposes of this clause 8 and is permitted provided it is not from a country subject to UK or EU sanctions; Spruce remains responsible for that access under this DPA and will identify the countries concerned on request.
8.2 The parties acknowledge that: (a) transfers of Personal Data from the EEA to the United Kingdom are permitted on the basis of the European Commission’s adequacy decisions in respect of the United Kingdom adopted under Article 45 of the EU GDPR on 19 December 2025, in force until 27 December 2031 subject to ongoing Commission monitoring; and (b) transfers of Personal Data from the United Kingdom to the EEA (for example, to Spruce’s backup storage in Frankfurt) are permitted under the United Kingdom’s adequacy regulations in respect of EEA states. If either basis ceases to apply to the processing under this DPA, the parties will without undue delay put in place an alternative lawful transfer mechanism: for (a), the European Commission’s Standard Contractual Clauses (Module Two: controller to processor) with Annex A and Annex B of this DPA as their annexes, which the parties agree apply from the date the adequacy decisions cease to apply and will sign on request; for (b), the ICO’s International Data Transfer Agreement or Addendum.
8.3 Where a Sub-processor on the Sub-processor List necessarily involves a transfer of Personal Data outside the UK or the EEA (including remote access for support purposes), that transfer is made under the transfer mechanism identified for that Sub-processor in the Sub-processor List (being an adequacy decision or regulations, the EU-US Data Privacy Framework and its UK Extension, or Standard Contractual Clauses with the UK Addendum or the International Data Transfer Agreement, supported by any transfer risk assessment required by the Data Protection Legislation), and the Subscriber’s agreement to this DPA constitutes consent to those transfers on those terms. Spruce will notify the Subscriber promptly if a transfer mechanism relied on ceases to be valid and will implement an alternative lawful mechanism or suspend the affected transfer.
9. Sub-processors
9.1 The Subscriber grants Spruce general authorisation to appoint the Sub-processors on the Sub-processor List, subject to this clause 9. The Sub-processor List identified in the Schedule or Order Details (or, if none is identified, the version in force when the Subscriber accepts the Platform T&Cs) is deemed approved by the Subscriber. The Sub-processor List identifies, for each Sub-processor, its name and legal entity, the service it provides, the categories of Personal Data it processes, the location of processing, the transfer mechanism relied on (where applicable) and a privacy contact.
9.2 Before appointing a new Sub-processor or replacing an existing one, Spruce will update the Sub-processor List and notify the Subscriber in writing, by email to the Subscriber’s notice address under clause 16, at least 14 Business Days before the new Sub-processor begins processing Personal Data. The Subscriber may object within that period on reasonable and documented grounds relating to data protection compliance or to a material adverse effect on the Subscriber; an objection may not be made on arbitrary grounds or to circumvent the Subscriber’s commitments under the Platform T&Cs. Absent a timely objection, Spruce may deploy the new Sub-processor on expiry of the notice period. If the Subscriber objects, the parties will discuss the objection in good faith for up to 30 days (the discussion period); pending resolution Spruce may deploy the new Sub-processor for its other customers and will, where technically feasible, refrain from using it to process the Subscriber’s Personal Data (where that is not technically feasible Spruce will say so in its response to the objection, and the Subscriber may then terminate under clause 11.3 of the Platform T&Cs without waiting for the end of the discussion period). If the objection is not resolved within the discussion period, the Subscriber may terminate the Platform T&Cs (or, where Spruce agrees, the affected part of the Services) in accordance with, and within the time limit and subject to the refund and sole-remedy provisions of, clause 11.3 of the Platform T&Cs, unless Spruce has confirmed in writing within the discussion period that the new Sub-processor will not process the Subscriber’s Personal Data, in which case the appointment proceeds for other customers only. Spruce may appoint a like-for-like replacement for an existing Sub-processor on shorter notice where reasonably necessary to address a security or continuity risk, provided it notifies the Subscriber as soon as reasonably practicable and the objection right applies from that notice.
9.3 Spruce will: (a) enter into a written contract with each Sub-processor imposing data protection obligations no less protective in substance than those required by Article 28(3) of the UK GDPR and EU GDPR, in particular regarding appropriate technical and organisational security measures, and provide relevant excerpts to the Subscriber on written request; (b) maintain control over all Personal Data it entrusts to a Sub-processor; and (c) ensure that the Sub-processor ceases processing the Subscriber’s Personal Data promptly upon termination of this DPA.
9.4 Spruce remains liable to the Subscriber for the performance of each Sub-processor’s obligations, subject to clause 18.
9.5 Spruce will keep the Sub-processor List current and dated, will keep previous versions, and will provide a copy of the version in force on any given date on request. Notifications under clause 9.2 are sent by email to the Subscriber’s notice address.
10. Data Subject rights and complaints
10.1 Spruce will take appropriate technical and organisational measures and promptly provide such information as the Subscriber reasonably requires to enable the Subscriber to comply with: (a) Data Subject rights under the Data Protection Legislation (including access, rectification, erasure, portability, objection, restriction, and rights concerning automated decision-making); and (b) information or assessment notices served on the Subscriber by a Supervisory Authority.
10.2 Spruce will notify the Subscriber promptly, and in any event within 3 Business Days, if it receives a request from a Data Subject to exercise any of their rights, and will not respond to the Data Subject other than to acknowledge receipt and refer them to the Subscriber, unless the Subscriber instructs otherwise or the law requires.
10.3 Spruce will notify the Subscriber promptly in writing if it receives any complaint, notice or communication from a Supervisory Authority or Data Subject relating to the Personal Data, and will give the Subscriber reasonable co-operation and assistance in responding.
11. Term and termination
11.1 This DPA remains in force for so long as: (a) the Platform T&Cs remain in effect; or (b) Spruce retains any Personal Data related to the Platform T&Cs in its possession or control (the “Term”).
11.2 Any provision of this DPA that expressly or by implication should continue in force after termination in order to protect the Personal Data will remain in full force and effect.
11.3 Spruce’s material failure to comply with this DPA which (where remediable) is not remedied within 14 days of written notice is a material breach of the Platform T&Cs, entitling the Subscriber to terminate any part of the Platform T&Cs involving the processing of Personal Data with immediate effect on written notice.
11.4 If a change in the Data Protection Legislation prevents either party from fulfilling its obligations, the parties may agree to suspend the affected processing; if compliance cannot be restored within 60 days, either party may terminate the Platform T&Cs on not less than 14 Business Days’ written notice.
12. Return and deletion
12.1 At the Subscriber’s written request at any time before deletion under clause 12.2, Spruce will within 15 Business Days provide the Subscriber (or a nominated third party) with a copy of or access to all or part of the Personal Data in its possession or control, in a commonly used, machine-readable format (structured data as CSV or JSON; documents as PDF, or another format the parties reasonably agree). Up to two requests per contract year are fulfilled at no additional charge; Spruce may charge a reasonable fee for further requests and for requests requiring work beyond Spruce’s standard export formats. Nothing in this clause limits the Subscriber’s use of any self-service export features of the Services.
12.2 On termination or expiry of the Platform T&Cs, Spruce will, at the Subscriber’s written direction, securely delete or destroy, or return and not retain, all or any of the Personal Data in its possession or control. If the Subscriber gives no direction within 30 days of termination, Spruce will securely delete the Personal Data from its production systems no later than 90 days after termination, with backup media handled under clause 12.3 and subject to first completing any export requested under clause 12.1.
12.3 Deletion from production systems takes effect promptly. Copies within encrypted backup media age out in the ordinary course of the backup cycle described in Annex B and are deleted no later than 12 months after deletion from production systems. Backup media are encrypted and are not accessed for any purpose other than restoration testing and disaster recovery; if a disaster-recovery restoration reinstates Personal Data previously deleted, Spruce will re-delete it within 7 days. Spruce’s long-term business archives (financial and statutory records) do not contain Personal Data processed on behalf of Subscribers; the de-identified job archive under clause 12.4 is held separately under that clause.
12.4 Spruce may retain Personal Data after the periods in this clause 12 only: (a) to the extent required by law or by a Supervisory Authority, in which case Spruce will notify the Subscriber in writing of the requirement, the legal basis and the specific timeline for deletion once the requirement ends; or (b) where a legal claim relating to the Services has been notified to or by Spruce, or Spruce reasonably anticipates such a claim, to the limited extent strictly necessary to establish, exercise or defend that claim, in which case Spruce will (i) notify the Subscriber in writing (unless legally prevented) of the categories of Personal Data retained and the claim concerned, (ii) act as an independent controller for that retention and comply with the Data Protection Legislation in doing so, (iii) keep the data securely, restrict access to it and use it for no other purpose, and (iv) delete it within 30 days after the claim is concluded or becomes time-barred. Separately, the Subscriber acknowledges and agrees that Spruce may retain a de-identified copy of each job record (inputs, configuration and Outputs, with names, contact details, full addresses, UPRNs, EPC or BER certificate numbers and other direct identifiers removed and location reduced as described in clause 4.4 of the Platform T&Cs, keyed only by the job reference held by the Subscriber) in a restricted-access archive for up to 6 years after the relevant Output was generated, so that either party can respond to any dispute about the design. Spruce will link such a record to an identified job only at the Subscriber’s request or where clause 12.4(b) applies, and will not otherwise attempt to re-identify it. To the extent any such record is Personal Data, Spruce acts as an independent controller of it, complies with the Data Protection Legislation in doing so, keeps it securely with restricted access, uses it for no other purpose, and will delete or fully anonymise it (under clause 4.4 of the Platform T&Cs) no later than 6 years after the Output was generated; while it remains Personal Data it is not Anonymised Property Data.
12.5 On the Subscriber’s written request, Spruce will confirm deletion or destruction in writing.
13. Records
13.1 Spruce will keep detailed, accurate and up-to-date written records of its processing of the Personal Data, including the categories of processing, approved Sub-processors, and a general description of the security measures in Annex B (“Records”), sufficient to enable the Subscriber to verify Spruce’s compliance with this DPA, and will provide copies on request.
13.2 Spruce will keep the Annexes and the Sub-processor List under review and update them from time to time to reflect current practice (clause 6.1 applies to updates to Annex B; clause 9 applies to the Sub-processor List).
14. Audit
14.1 Spruce will permit the Subscriber and its third-party representatives (not being competitors of Spruce and bound by confidentiality obligations), and any regulator of the Subscriber or Supervisory Authority to the extent it requires access, to audit Spruce’s compliance with this DPA on at least 30 days’ notice during the Term, no more than once in any 12-month period (except under clause 14.2), at the Subscriber’s reasonable cost, subject to reasonable security and confidentiality requirements, and satisfied in the first instance by Spruce’s completed security questionnaires, certifications and assurance documentation where reasonably sufficient. Audits are conducted during Normal Business Hours, do not extend to other customers’ data or Spruce’s proprietary methods, and Spruce may charge its reasonable costs for on-site time exceeding one Business Day. After termination or expiry of the Platform T&Cs (notwithstanding that the Term continues under clause 11.1(b)), Spruce’s audit obligation is satisfied by written confirmation under clause 12.5 and, in respect of any Personal Data retained under clause 12.4, by the Records under clause 13.1 on request; clause 14.2 continues to apply to that Personal Data. Audits required by a Supervisory Authority or other regulator of the Subscriber do not count towards the once-per-12-months limit, and where an audit identifies a material non-compliance with this DPA Spruce bears the reasonable costs of the audit (including its own) and no on-site charge applies. Spruce will provide reasonable assistance with any such audit.
14.2 The notice requirement in clause 14.1 does not apply where the Subscriber reasonably believes that a Personal Data Breach affecting the Subscriber’s Personal Data has occurred or is occurring, or that Spruce is in material breach of this DPA in respect of the Subscriber’s Personal Data, in which case the Subscriber will give as much notice as is reasonably practicable and any audit will be conducted so as to minimise disruption to Spruce’s operations and other customers.
14.3 If a Personal Data Breach affecting the Subscriber’s Personal Data occurs, Spruce will promptly investigate to determine the cause, provide the Subscriber with a summary of its findings and remediation plans, and remediate identified deficiencies within a reasonable period, prioritised by severity.
15. Warranties
15.1 Spruce warrants that: (a) its personnel accessing the Personal Data are subject to confidentiality obligations and appropriately trained (Sub-processors being addressed by clause 9); (b) it will process the Personal Data in compliance with the Data Protection Legislation applicable to it as a Processor; (c) it has no reason to believe the Data Protection Legislation prevents it from providing the Services; and (d) it will maintain the technical and organisational measures in Annex B (as updated in accordance with clause 6.1), appropriate to the harm that might result from unlawful processing and the nature of the data protected.
15.2 The Subscriber warrants that Spruce’s expected use of the Personal Data for the Business Purposes, as specifically instructed by the Subscriber, complies with the Data Protection Legislation, and that all notices required for that processing have been given to Data Subjects and all required consents obtained, whether by the Subscriber or by the Controller on whose behalf or with whose authority it acts (including for the creation of Anonymised Property Data under clause 4.4 of the Platform T&Cs and for the sharing of Personal Data with Guest Users and other businesses given access to a job).
16. Notices
16.1 Any notice under or in connection with this DPA must be in writing and delivered in accordance with clause 22 of the Platform T&Cs (including deemed receipt under clause 22.2) (Spruce: legal@spruce.eco; Subscriber: the notice address used on signing up to the Services, or an address substituted in writing). Data protection enquiries may also be sent to dataprotection@spruce.eco. Spruce’s representative in the European Union for the purposes of Article 27 of the EU GDPR is Euverify Ltd, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland (gdpr@euverify.com).
16.2 Clause 16.1 does not apply to the service of proceedings or other documents in any legal action.
17. Governing law and jurisdiction
17.1 This DPA and any dispute or claim arising out of or in connection with it is governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, in each case in accordance with clauses 23 and 24 of the Platform T&Cs; where the Subscriber has entered into the Ireland version of the Platform T&Cs (published at spruce.eco/legal/terms-ireland), this DPA is instead governed by the laws of Ireland and subject to the exclusive jurisdiction of the courts of Ireland, as clause 23 of that version provides. Nothing in this clause: (a) limits any right of a Data Subject to lodge a complaint with a supervisory authority or to bring proceedings under Articles 77 to 82 of the EU GDPR or UK GDPR (as applicable), including before the courts or supervisory authority of the Member State of the Data Subject’s habitual residence; (b) affects the competence of any supervisory authority under the Data Protection Legislation; or (c) relieves either party of obligations arising under the Data Protection Legislation of the jurisdiction in which the Subscriber is established.
18. Liability
18.1 Each party’s liability arising under or in connection with this DPA (whether in contract, tort (including negligence), breach of statutory duty, under an indemnity or otherwise) is subject to the exclusions and limitations of liability in clause 10 of the Platform T&Cs, which apply to this DPA as if set out in it.
18.2 Nothing in this DPA (including any statement that Spruce is or remains liable for a Sub-processor or third party) increases either party’s liability beyond, or otherwise affects, those exclusions and limitations. Clause 1.3(b) does not apply to this clause 18 or to clause 10 of the Platform T&Cs.
18.3 Nothing in this clause 18 limits either party’s liability to Data Subjects under Article 82 of the UK GDPR or EU GDPR. Any claim between the parties for contribution, indemnity or recovery in respect of such liability (including under Article 82(5)) is a liability between the parties to which clause 10.3(c) or 10.3(e) of the Platform T&Cs applies.
ANNEX A — Personal Data processing purposes and details
Subject matter of processing: Spruce will process Personal Data as necessary to provide the Services pursuant to the Platform T&Cs and as further instructed by the Subscriber in its use of the Services.
Duration of processing: for the duration of the Term. Retention and deletion after termination are governed by the Subscriber’s instructions and clause 12 (in the absence of a direction, deletion from production systems no later than 90 days after termination).
Nature and purpose of processing: collection, storage, organisation, disclosure (as permitted by this DPA) and deletion of Personal Data for the purposes of providing the Services, including the generation of surveys, proposals, reports, compliance paperwork and related documents; the sending of communications to Homeowners and Guest Users at the Subscriber’s direction; monitoring, error diagnosis, security and customer support (Personal Data may appear in monitoring, error and support records, which are access-restricted and retained for limited periods as described in Annex B); and, as agreed under clause 4.4 of the Platform T&Cs, the creation of Anonymised Property Data from Property Attributes. Once created, Anonymised Property Data is not Personal Data and falls outside this DPA.
Categories of Personal Data:
Contact information (name, address, email address, telephone number)
Property Attributes (as defined in the Platform T&Cs): information about the physical, thermal and energy characteristics of a property that is the subject of a job (including floorplans and dimensional data, room-by-room heat-loss calculations, system design and specification data for heat pumps, solar PV, battery storage, air conditioning and other systems, energy consumption and generation data, and EPC- or BER-related data), for so long as it relates to an identified or identifiable individual (including by association with a name, contact details, address, postcode, UPRN, EPC or BER certificate number or other identifier)
Account and usage data of Authorised Users and Guest Users to the extent processed on the Subscriber’s behalf within a job
Any other Personal Data submitted to the Services by or on behalf of the Subscriber, its Authorised Users or Guest Users
Categories of Data Subject:
Homeowners: owners, occupiers and prospective owners or occupiers of properties that are the subject of jobs, whether or not they are customers of the Subscriber (they may, for example, be customers of another business, such as an installer, that the Subscriber works with, or occupiers of a property owned by someone else)
Authorised Users: the Subscriber’s employees, contractors, subcontractors and agents, and personnel of other businesses (for example installers, merchants, distributors or manufacturers) to whom the Subscriber has allocated a Seat on its account
Guest Users invited by the Subscriber or an Authorised User to jobs in the Subscriber’s account (for example installers, surveyors, electricians, merchants’, distributors’ or manufacturers’ personnel, and Homeowners given visibility of their own job)
Staff and contacts of other businesses whose details the Subscriber records in a job (for example installers, merchants, distributors and manufacturers)
Special category data: none. The Services are not designed or intended for special category Personal Data, and the Subscriber agrees not to submit it.
Sub-processors: the Sub-processor List approved under clause 9.1, as updated in accordance with clause 9, including each Sub-processor’s legal entity, service, data processed, location, transfer mechanism and privacy contact, is published at spruce.eco/legal/sub-processors and is incorporated into this Annex A. Clause 9 (including the objection right in clause 9.2) applies to it. Spruce’s primary production systems are hosted in the United Kingdom (London), with encrypted backups in the EEA (Frankfurt), and product analytics is hosted in the EEA (Frankfurt); named Sub-processors process Personal Data in the United States (transactional email delivery, error monitoring, and Spruce’s internal business tools other than its messaging tool, which is UK-hosted), and certain UK/EEA-hosted providers have support access from the United States, in each case under the transfer mechanisms stated in the Sub-processor List.
Spruce’s own service providers: providers that process personal data for which Spruce is an independent Controller (for example payment processing, CRM and outreach tools) are not Sub-processors, are not subject to clause 9, and are described in the Spruce Privacy Policy and listed for transparency alongside the Sub-processor List.
ANNEX B — Technical and organisational security measures
These measures describe Spruce’s security programme as currently operated. Spruce keeps them under review and may update them in accordance with clause 6.1; no update will materially reduce the overall level of security described in this Annex.
Hosting and infrastructure. Production compute and databases run on DigitalOcean cloud infrastructure in the LON1 (London, UK) region; object storage and backups reside in DigitalOcean Spaces, FRA1 (Frankfurt, Germany, EEA). All systems sit within VPCs, behind firewalls, on hardened configurations, with no on-premises infrastructure.
Monitoring, error diagnosis and product analytics. Spruce monitors the Services to keep them secure and reliable and to resolve customer issues, using self-hosted infrastructure monitoring (Grafana, UK), application error monitoring (Sentry, US-hosted) and product analytics (PostHog, EU-hosted, Frankfurt). Records in these tools may include limited Personal Data from the Services (for example a Homeowner’s name or address within an error record or a user action) where necessary to diagnose and resolve an issue. Spruce minimises this where practicable (credentials and payment data are never captured; fields not needed for diagnosis are masked), restricts access to engineering personnel, and retains error and analytics records for no longer than the periods in the Logging and monitoring section below. Project and incident tracking (Linear, US-hosted) and internal documentation (Notion, US-hosted) are used for metadata and internal notes only; Spruce’s policy prohibits Homeowner Personal Data in either. Business email and documents (Google Workspace, US-hosted) contain Personal Data only where a Subscriber includes it in correspondence with Spruce.
Tenant segregation. The Services are multi-tenant. Subscriber Data is logically segregated by organisation identifier enforced in the application and data layers; cross-tenant access controls are included in the scope of each annual penetration test commissioned after the date of this DPA.
Encryption. All Personal Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent. Full disk encryption applies on production systems and is enabled as standard on company devices. Backup media are encrypted.
Access control. Role-based access control on a least-privilege, need-to-know basis. Multi-factor authentication is enforced on all cloud services that support it and for all administrative and privileged access by Spruce personnel. Strong password policy including breached-password screening, lockout and rate limiting. Administrative access is restricted to senior engineers and logged. Access permissions are reviewed at least quarterly and privileged access recertified at least annually; access is revoked promptly on role change or termination.
Logging and monitoring. Authentication, administrative and audit logs are retained for 12 months; operational logs for 90 days; application error records (Sentry) for 6 months; product analytics event data (PostHog) for 60 days, after which only aggregated statistics remain. Logs and records are access-controlled and do not contain Personal Data beyond what is necessary to identify and resolve the affected record or issue.
Environment separation. Production, staging and test environments are isolated by separate infrastructure, credentials and configuration. Production Personal Data is not intentionally used in non-production environments; staging and test use anonymised or synthetic data, and any inadvertent copy is deleted on discovery.
Backups, resilience and recovery. Automated encrypted backups on a tiered cycle (currently daily, retained 7 days, and weekly, retained 52 weeks), stored in Frankfurt (EEA), a separate geographic region from production. Long-term archives (retained up to 6 years for Spruce’s own financial and statutory business records) do not contain Personal Data processed on behalf of Subscribers; the de-identified job archive under clause 12.4 is held separately under that clause. Backup restoration is tested regularly (currently monthly). Recovery point objective: up to 24 hours (daily backup). Recovery time objective: 60 minutes for instance or service failure within the primary region, measured during Business Hours (Monday–Friday 08:00–20:00 UK time, Spruce’s operational hours, which are not the Normal Business Hours defined in the Platform T&Cs) or otherwise from the time the engineering team is alerted (critical alerts page the team at all hours); recovery from loss of the primary region uses the Frankfurt backups, and a tested region-loss objective is under development. Deleted data ages out of backup media in the ordinary cycle and within 12 months at the latest, and is not restored except for disaster recovery.
Secure development. Secure coding aligned with OWASP guidance; mandatory peer review of all production changes via pull request, with implementer/approver segregation and documented rollback; automated dependency scanning in the development workflow; platform-level automated OS and security patching. Critical security patches are applied within 24 hours as an internal target, and high within 7 days as a target; both are applied in any event within 14 days, as Cyber Essentials requires.
Vulnerability management and assurance. Regular internal vulnerability assessments (quarterly by policy) and an annual penetration test of the web application and API by an independent tester holding CREST individual certifications (certificate available to the Subscriber on request; report summaries and remediation status available under NDA); authenticated testing of role and tenant segregation is included in the scope of each test commissioned after the date of this DPA. Remediation is prioritised by severity against internal target timescales (critical 24 hours, high 7 days, medium 30 days). Once per contract year on request, Spruce will provide a written assurance summary covering certifications held, penetration test date and remediation status, and material security incidents.
Personnel. Confidentiality obligations in all employment contracts; annual data protection and security training; role-specific training for privileged users; identity, right-to-work and reference checks; prompt access revocation on termination.
Organisational. Documented incident management (Spruce’s Incident Management Policy is available to the Subscriber on request) including 24-hour Controller notification of Personal Data Breaches and significant security incidents; documented retention and disposal schedule; Sub-processor management per clause 9. Spruce holds Cyber Essentials certification as at the date of this version, intends to renew it annually, and will notify the Subscriber within 10 Business Days if it lapses.