GDPR and Data Processing
GDPR position for shops using Manage Repairs.
Last updated: 14 August 2026
Controller and processor roles
Shops are normally the controller for their own customer, sales, inventory and repair records. Manage Repairs acts as processor for that shop data and controller for platform account, billing and support data.
Processor instructions
We process shop customer data only to provide, secure, support and improve the service, or as otherwise instructed by the shop account owner. Shops must ensure they have a lawful basis for storing their own customer data, product images and repair photos where used.
Customer responsibilities as controller
The shop is responsible for explaining its own privacy practices to customers, collecting only necessary information, setting staff permissions carefully, responding to customer rights requests and deciding how long its own repair, sale and customer records should be kept.
Inventory metadata sharing
The shared GTIN catalogue uses only non-personal product metadata such as GTIN/barcode, product name, brand and category. Customer records, repair records, staff data, supplier data, prices, costs, stock levels, notes and photos are excluded from this shared catalogue.
Security measures
The platform is designed around tenant separation, authenticated access, encrypted passwords, sensitive-field encryption, audit-ready records, least-privilege administration, controlled backups and secure deployment practices.
Administrative controls
Where available, shop owners should use staff accounts, role separation, branch-level controls, export controls and prompt removal of old staff access to reduce the risk of unauthorised access.
Audit and monitoring
We may record security, login, error, analytics and operational events to diagnose faults, investigate misuse, protect accounts and understand platform reliability. These records should be kept proportionate and protected from unnecessary access.
Sub-processors
We may use carefully selected hosting, email, payment, analytics, storage and support providers to deliver the service. These providers should only process data for the service purpose and should apply appropriate confidentiality and security controls.
Sub-processor oversight
When choosing or changing important providers, we aim to consider the provider’s security posture, privacy terms, processing role, data location, business need and available contractual protections.
Data subject requests
Shops should handle requests from their own customers. We can support account owners with export or deletion workflows where technically possible.
Personal data breaches
If we become aware of a confirmed personal data breach affecting shop customer data, we will investigate, take reasonable containment steps and inform affected account owners without undue delay so they can meet their legal duties. Where notification to a regulator is required, UK GDPR expects this to happen within 72 hours of awareness where feasible.
International services
Some infrastructure, email or payment providers may process data outside the UK. Appropriate safeguards should be used where required.
Records and accountability
Manage Repairs may keep internal records of product decisions, provider use, security events, support access and policy changes so we can explain how the service is operated and improved.