Data Processing Agreement
Last updated: 5 June 2026
This Data Processing Agreement forms part of the BossOps Terms where Mackintosh Projects processes personal data on behalf of a customer using BossOps.
Roles
The customer is the controller for personal data entered into its BossOps workspace. Mackintosh Projects is the processor for that workspace data, except where it acts as controller for account administration, billing, support, security and legal compliance.
Processing instructions
Mackintosh Projects will process customer personal data only to provide, secure, maintain and support BossOps, or as otherwise instructed by the customer or required by law.
Data processed
Workspace data may include staff names, emails, roles, rota, leave, attendance, HR documents, payroll export data, supplier contacts, uploaded files, product records, recipes, menus, stock counts, audit logs and support content.
Security
Mackintosh Projects will use appropriate technical and organisational measures including HTTPS, secure sessions, access controls, tenant separation, audit logs, restricted administrative access and provider security controls.
Subprocessors
Mackintosh Projects may use subprocessors to host, store, process payments, send messages, provide AI extraction and support BossOps. The current list is published at /legal/subprocessors. Customers may object to a new subprocessor on reasonable data protection grounds.
Assistance
Mackintosh Projects will provide reasonable assistance for data subject requests, deletion/export requests, security questions, DPIAs and regulator queries where the request relates to BossOps processing.
Breach notice
Mackintosh Projects will notify affected customers without undue delay after becoming aware of a personal data breach affecting their workspace data and will provide reasonable information to support the customer’s assessment.
Deletion and return
On termination, customers may request export or deletion of workspace data. Some data may be retained where required for legal, billing, security, backup or audit reasons, then deleted according to retention schedules.
International transfers
Where personal data is transferred outside the UK, Mackintosh Projects will rely on appropriate safeguards such as UK-approved contractual transfer mechanisms or equivalent provider terms.
Contact
Email: [email protected]