
Data Processing Agreement (DPA)
Last Updated: 31st August 2026
This Data Processing Agreement ("DPA") applies where personal data is stored or processed within a MIDAS system that we host on our servers. This includes both "cloud-hosted" subscriptions and free trials of MIDAS. It forms part of, and should be read alongside, our Cloud Hosted Terms & Conditions, our Free Trial Terms & Conditions, our Software Privacy Policy, our Data Retention Policy, and our GDPR Statement. References below to your "hosted MIDAS system" apply equally to a cloud-hosted subscription and to a trial system.This DPA reflects the requirements of Article 28 of the UK GDPR. Terms such as "controller", "processor", "sub-processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given to them in the UK GDPR and the Data Protection Act 2018.
1. Roles of the parties
- In respect of any personal data contained within your hosted MIDAS system, you (the customer) are the controller and we are the processor. You determine the purposes and means of processing that data; we process it only on your behalf.
- You confirm that you have a lawful basis for the processing of any personal data you place within your hosted MIDAS system, that the data has been collected lawfully, and that you are entitled to provide it to us for processing under this DPA.
2. Subject matter and details of processing
- Subject matter: the provision of the hosted MIDAS room booking and resource scheduling service, whether by way of a cloud-hosted subscription or a free trial.
- Duration: for the duration of your active cloud-hosted subscription or trial period, followed by the retention periods set out in our Data Retention Policy.
- Nature and purpose: the hosting, storage, and processing of data necessary to operate your room booking and resource scheduling system.
- Types of personal data: typically the names and contact details of your MIDAS users and of persons associated with bookings, together with any other personal data you or your users choose to enter into your MIDAS system.
- Categories of data subjects: typically your staff, your MIDAS users, and individuals associated with bookings made within your system.
3. Our obligations as processor
We shall:- process the personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we will inform you of that legal requirement before processing, unless the law prohibits us from doing so). Your instructions are constituted by this DPA and your use of the features and configuration options within your MIDAS system;
- ensure that persons authorized to process the personal data are subject to an appropriate duty of confidentiality;
- implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing;
- taking into account the nature of the processing, assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under the UK GDPR;
- assist you in ensuring compliance with your obligations relating to security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with the Information Commissioner's Office, taking into account the nature of processing and the information available to us;
- notify you of a personal data breach affecting your data without undue delay, and in any event within seventy-two (72) hours, after we become aware of it. Our notification will describe, so far as is known to us at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed to address it. Where that information is not all available to us at the time of notification, we will provide it in phases as it becomes available. Notification will be sent to the Primary Contact we hold on record for your MIDAS system, and it is your responsibility to ensure those contact details are kept up to date. Where a breach originates within the infrastructure or systems of a sub-processor, our obligation to notify you arises when we ourselves become aware of it;
- at your choice, delete or return all the personal data to you after the end of the provision of services relating to processing, and delete existing copies unless we are required by law to retain a copy. The applicable timescales for deletion and the availability of data export are set out in our Data Retention Policy; and
- make available to you all information necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR, and allow for and contribute to audits conducted by you or another auditor mandated by you, in accordance with section 4 below.
4. Information and audits
- Where you require assurance as to our compliance with this DPA, we will in the first instance satisfy such requests by making available our existing documentation and by responding to reasonable written questions or security questionnaires. We consider this to be sufficient to demonstrate compliance in the great majority of cases.
- Where the means described above are genuinely insufficient for you to verify our compliance, we will allow for and contribute to an audit, subject to all of the following: that no more than one audit is carried out in any twelve (12) month period, unless otherwise required by a supervisory authority or following a personal data breach affecting your data; that you give us at least thirty (30) days' prior written notice; that the audit is conducted remotely wherever it can reasonably be conducted remotely; that its scope is limited to the processing carried out under this DPA; that any auditor mandated by you is not a competitor of ours and enters into confidentiality undertakings acceptable to us; that the audit is carried out during normal business hours and in a manner that does not unreasonably disrupt our business; and that you bear both your own costs and our reasonable costs of participating.
- Where an on-site inspection is required by law and cannot be satisfied by the means described above, it will be conducted by an independent third-party auditor rather than by your own personnel, will be limited to those parts of any premises operated by us at which processing under this DPA is actually carried out, and will be arranged at a date, time, and in a manner agreed between us.
- The hosting of your personal data is carried out at data centers operated by our sub-processors. We have no ability to grant you or your auditors access to those facilities, and any request relating to them will be referred to the relevant sub-processor. Publicly available information regarding those facilities is linked from our Sub-Processors & Third Party Services page.
5. Sub-processors
- By entering into this DPA, you authorize us to engage sub-processors to assist in providing the hosted service. A current list of the sub-processors we use, together with their purpose and location, is maintained at our Sub-Processors & Third Party Services page.
- We ensure that each sub-processor we engage is bound by data protection obligations equivalent to those set out in this DPA. We remain responsible to you for the performance of each sub-processor's obligations.
- We will inform you of any intended changes concerning the addition or replacement of sub-processors involved in providing your hosted MIDAS system, thereby giving you the opportunity to object to such changes. Where you object, we will work with you in good faith to address your concerns, which may include making available any alternative configuration that avoids the sub-processor in question (where one exists). If we are unable to resolve your objection and the sub-processor is essential to the service, you may discontinue the affected service.
6. Disclosure requests and preservation of data
- We will not disclose the personal data within your hosted MIDAS system to any third party, except on your instructions, as otherwise provided for in this DPA, or where we are required to do so by law.
- Where we receive a legally binding request from a law enforcement agency, court, regulator, or other public authority for personal data within your hosted MIDAS system, we will notify you of that request promptly, unless we are prohibited from doing so by law. Where it is lawful and reasonable for us to do so, we will challenge any request which appears to us to be unlawful, overbroad, or improperly made.
- Where any other third party, including a data subject, makes a request directly to us in respect of personal data within your hosted MIDAS system, we will refer that request to you rather than responding to it ourselves, unless we are required by law to respond.
- At your written request, and for the purposes of a legal hold, investigation, regulatory request, or litigation, we will preserve a copy of the personal data within your hosted MIDAS system, suspend the routine deletion of backups relating to that data for the duration of the hold, and provide you with an export of the preserved data. Such requests should be sent to [email protected], should specify the scope and expected duration of the hold, and should allow us reasonable notice. Note that you may also export the data within your hosted MIDAS system yourself at any time while your subscription remains active, as described in our Data Retention Policy.
7. International transfers and data residency
- We offer a choice of data center locations for your live MIDAS database. Where personal data is transferred outside the UK, such transfers will be protected by an appropriate safeguard recognised under the UK GDPR, such as the standard data protection clauses adopted or approved for use in the UK.
- You select the data center location in which your live MIDAS database will reside. You are responsible for determining whether the storage and processing of your data in that location, and in the locations in which our off-site backups are held, is permissible under the laws and regulatory requirements applicable to you. The locations of our sub-processors, including those used for off-site backup, are set out on our Sub-Processors & Third Party Services page.
- Where you are subject to a data residency requirement which none of our available data center locations can satisfy, you should not subscribe to a "cloud-hosted" edition of MIDAS, and should instead consider our "self-hosted" edition, which allows you to run our software on infrastructure of your own choosing.
8. Liability
- The limitations and exclusions of liability set out in our Cloud Hosted Terms & Conditions (for cloud-hosted subscriptions) or our Free Trial Terms & Conditions (for trials) apply equally to this DPA, save to the extent that any liability cannot lawfully be limited or excluded.
9. Governing law
- This DPA is governed by the law of England and Wales, and is subject to the exclusive jurisdiction of the courts of England and Wales.
We reserve the right to amend this Data Processing Agreement at any time without prior notification
← Return to the Knowledge Base