Renew Gas Cert
Data Processing Schedule — Version 1.1
Version date: 10 August 2026
This Schedule forms part of the Renew Hub Terms where Ian Cooke trading as EvenAI, 11 Church Road, Great Plumstead, Norwich, NR13 5AB, United Kingdom (the Processor), processes personal data on behalf of a Renew Hub business customer (the Controller).
Privacy/data-protection contact: [email protected].
1. Roles
For customer-controlled personal data processed to provide Renew Hub, the Renew Hub business customer is the Controller and Ian Cooke trading as EvenAI is the Processor.
The Controller determines the purposes and means of its processing and remains responsible for selecting and documenting an appropriate lawful basis for the personal data it controls.
The Processor may separately act as controller for its own account administration, security, billing, legal/compliance and service-governance records, as described in the Renew Gas Cert Privacy Notice v1.1.
2. Processing details
Subject matter
Provision of Renew Hub, including storage and handling of customer-supplied renewal-management information and execution of enabled service functions on documented customer instructions.
Duration
For the duration of the applicable customer relationship and any controlled return/deletion period, subject to lawful retention requirements.
Nature and purpose
Processing is limited to operating, securing, supporting and evidencing Renew Hub for the Controller's renewal-management purposes.
Types of personal data
- client/contact names;
- business email addresses and telephone numbers;
- property/premises/site addresses or references;
- engineer/account contact details;
- certificate/compliance type and renewal/expiry dates;
- reminder/communication preferences;
- service-delivery, communication-status and support metadata; and
- identifiers needed to relate records within the Controller's tenant.
No special-category data, criminal-offence data or full payment-card credentials are intended to be processed under this Schedule unless separately agreed under a documented lawful and technical control.
Categories of data subjects
As applicable: the Controller's customers/clients and business contacts; Controller personnel and engineers; site/premises contacts; and authorised account users.
3. Documented instructions
The Processor will process Controller personal data only on documented instructions from the Controller, including instructions concerning transfers, unless UK law requires otherwise.
The service Terms, this Schedule, configured service settings and subsequent written or controller-recorded instructions together constitute documented instructions to the extent they are consistent.
If the Processor believes an instruction infringes applicable UK data-protection law, it will inform the Controller without undue delay unless prohibited by law.
4. Confidentiality
The Processor will ensure that persons authorised to process Controller personal data are subject to appropriate confidentiality obligations and access the data only as necessary for authorised duties.
5. Security
The Processor will implement appropriate technical and organisational measures proportionate to the risk, including as applicable role/access restrictions, authentication and credential controls, tenant/data isolation, secure transport/storage mechanisms, audit/logging and evidence controls, backup/recovery controls, vulnerability/change management and incident-response procedures.
The precise implementation may evolve provided the overall protection is not materially reduced without appropriate review.
6. Sub-processors
The Controller gives the Processor general written authorisation to appoint and replace sub-processors necessary to provide Renew Hub, subject to this section and the current Renew Hub Sub-processor Schedule v1.0.
Before a new sub-processor begins processing Controller personal data, or an existing sub-processor is materially replaced, the Processor will give reasonable advance notice and an opportunity to object on reasonable data-protection grounds.
Unless a shorter period is reasonably necessary to address an urgent security, legal or service-continuity issue, the Processor will aim to provide at least 14 days' advance notice.
If an objection on reasonable data-protection grounds cannot reasonably be resolved before the proposed processing starts, the Processor will not use the disputed sub-processor for the Controller's affected data unless the parties agree another lawful solution. Where no solution is available, either party may terminate the affected service in accordance with the Terms.
The Processor will ensure each sub-processor is bound by data-protection obligations providing materially equivalent protection for the relevant processing and remains responsible for sub-processor performance to the extent required by applicable law.
7. Data-subject rights
Taking account of the nature of the processing, the Processor will assist the Controller through appropriate technical and organisational measures, insofar as possible, to respond to requests by individuals exercising applicable data-protection rights.
If the Processor receives a request relating to Controller personal data, it will route or notify the Controller as appropriate unless authorised or required to respond directly.
8. Security incidents and personal-data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller personal data and provide information reasonably available to help the Controller assess and meet applicable notification, communication and remediation obligations.
The Processor may take immediate containment/security action where reasonably necessary and will preserve appropriate incident evidence.
9. Assistance with compliance
Taking account of the nature of processing and information available, the Processor will provide reasonable assistance with the Controller's obligations concerning security of processing, breach assessment/notification, data-protection impact assessments and prior consultation with the ICO where applicable.
10. Return and deletion
At the end of the processing relationship, the Processor will, at the Controller's choice and subject to the service's controlled exit procedure, delete or return Controller personal data and delete remaining active-service copies unless UK law requires retention.
The operational target is deletion of customer-controlled client/certificate data from the active service within 30 days after a valid termination/deletion instruction, subject to Controller instruction and lawful retention requirements.
Infrastructure recovery history may remain temporarily recoverable for the applicable Cloudflare D1 Time Travel lifecycle. It must not be deliberately used to restore data that should remain deleted except for a documented legitimate recovery purpose. If a restore reintroduces data that should have been deleted, the deletion must be reapplied promptly.
This does not require deletion of information lawfully held by the Processor in a separate controller capacity, such as necessary billing, legal, security or audit records, provided unnecessary Controller content is not retained within those records.
11. Audit and compliance information
The Processor will make information reasonably necessary to demonstrate compliance with this Schedule available to the Controller and allow proportionate audits/inspections by the Controller or an appropriately mandated auditor, subject to reasonable notice, confidentiality, security, non-disruption and avoidance of access to other customers' data.
The parties should use existing independent reports, evidence and documentation where reasonably sufficient before requiring intrusive inspection.
12. International transfers
The Processor will not make a restricted transfer of Controller personal data outside the UK unless the transfer complies with applicable UK data-protection requirements and the Controller's documented instructions/contractual arrangements permit it.
The current production D1 database is configured with no jurisdiction restriction and is running in Cloudflare's ENAM — Eastern North America region, with read replication disabled. The current Phase 11 architecture retains that location and discloses it rather than claiming UK/EU residency.
The applicable provider contractual and transfer safeguards are maintained as part of the Renew governance record. Meta/WhatsApp remains disabled for participant 1 unless its separate account/entity/transfer gate is closed.
13. Controller obligations
The Controller confirms that it has authority to give the Processor the instructions in this Schedule; has determined and documented an appropriate lawful basis for personal data it controls; will provide required privacy information; will not instruct unlawful processing; will supply only adequate, relevant and necessary data; and will not intentionally provide excluded sensitive data without a separately approved basis and control.
14. Liability interaction
The commercial liability allocation between the parties is set out in section 16 of the Renew Hub Terms v1.7.
To the fullest extent permitted by law, the agreed commercial position is that no contractual damages are payable by the Processor to the Controller solely for breach of this Schedule or the confidentiality obligations incorporated into the Terms.
Nothing in this Schedule purports to remove statutory or regulatory rights, remedies, compensation rights, enforcement powers or liabilities that exist independently of the contract, or to exclude/restrict liability where applicable law does not permit that result.
15. Precedence and versioning
If there is a conflict between this Schedule and general service Terms on matters concerning Processor obligations for Controller personal data, this Schedule prevails to the extent of that conflict unless an approved later agreement expressly states otherwise.
The exact version accepted by each customer is recorded. Historical versions and acceptance evidence are preserved where necessary for contractual and audit integrity.