Parts Requester ← Back to site

Legal

Data Processing Addendum

Last updated: 9 August 2026

This addendum sets out how Zylair Ltd processes personal data on behalf of a Customer when providing Parts Requester. It forms part of our Terms of Service and applies where we process personal data as a processor under UK data protection law, including the UK GDPR and the Data Protection Act 2018.

In plain terms: your organisation decides what staff data goes into Parts Requester and why. That makes you the controller and us your processor. This addendum is our Article 28 commitment on how we look after that data.

1. Roles

The Customer is the controller and Zylair Ltd is the processor for the personal data described below. We only process it on the Customer's documented instructions, which include these terms and normal use of the Service.

2. Subject matter and duration

We process personal data to provide Parts Requester and its features to the Customer, for as long as the Customer's subscription is active, plus the short wind down period in section 9.

3. Nature and purpose of processing

Hosting, storing, organising, displaying, analysing and transmitting Customer Data so that Users can raise and track requests, add photos and comments, receive notifications, use AI part identification and the stores brief, and view reporting and spend.

4. Types of personal data

5. Categories of data subjects

The Customer's employees, workers, contractors and other authorised Users, and any individuals identifiable in the content that Users upload.

6. Our obligations

We will:

  1. Process personal data only on the Customer's documented instructions, unless the law requires otherwise, in which case we will tell the Customer where permitted.
  2. Ensure people authorised to process the data are under a duty of confidentiality.
  3. Put in place appropriate technical and organisational security measures (section 7).
  4. Respect the conditions in section 8 for engaging sub-processors.
  5. Help the Customer, so far as reasonable, respond to requests from individuals exercising their rights.
  6. Help the Customer meet its obligations on security, breach notification, impact assessments and prior consultation, taking account of the information available to us.
  7. Delete or return personal data at the end of the service (section 9).
  8. Make available information needed to show compliance with Article 28, and allow and contribute to audits as set out in section 10.

7. Security measures

We maintain measures appropriate to the risk, including encryption of data in transit, role based access controls, restricted administrative access, two factor authentication for privileged accounts, hosting with reputable providers, and logging to detect and respond to incidents. We review these measures as the Service develops.

8. Sub-processors

The Customer gives general authorisation for us to use the sub-processors below to provide the Service. We will impose data protection terms on each of them that are no less protective than this addendum, and we remain responsible for their performance.

Sub-processorPurposeLocation
SupabaseDatabase, authentication and file storage.EU (Frankfurt, Germany)
VercelApplication hosting and content delivery.EU and USA
StripeSubscription billing and payments.EU and USA
OpenAIAI part identification and the AI stores brief.USA
ResendSending status notification and account emails.USA

We will give the Customer prior notice before adding or replacing a sub-processor that materially affects the processing. If the Customer reasonably objects on data protection grounds, we will work with them in good faith and, if we cannot resolve it, the Customer may terminate the affected part of the Service.

9. International transfers

Where a sub-processor processes personal data outside the UK, we rely on an appropriate safeguard, such as the UK Addendum to the EU Standard Contractual Clauses or the UK Extension to the EU-US Data Privacy Framework.

10. Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide the information the Customer reasonably needs to meet its own notification duties.

11. Deletion or return

On termination, we will delete or, if the Customer asks, return the Customer's personal data within a reasonable period (normally 30 days), unless the law requires us to keep it. Routine backups are overwritten on our normal cycle.

12. Audits

We will make available the information reasonably needed to demonstrate compliance with this addendum, and allow the Customer, or an independent auditor it appoints, to audit our processing on reasonable prior notice, no more than once a year unless a regulator requires more or following a breach, subject to confidentiality and without disrupting our operations.

13. Priority

If there is any conflict between this addendum and the Terms of Service on the processing of personal data, this addendum takes precedence.

14. Contact

Data protection queries: chris@zylair.com.

© 2026 Zylair Ltd. Parts Requester is a product of Zylair Ltd. Contact: chris@zylair.com