Data processing agreement
Your campers give their details to you, not to us. This is the contract that lets us hold that data on your behalf, and it is the one your own compliance depends on.
Last updated 21 August 2026.
The short version
- You are the controller of your guests' booking data. PitchDesk is your processor.
- This applies automatically from the day you open an account. Nothing to sign, though we will sign a copy if you need one.
- We process guest data only on your instructions, never for our own purposes, and never to market to your guests.
- Three sub-processors, listed in Annex C, with 30 days notice before any change and a right to object.
- A breach affecting your guests is reported to you within 48 hours of us becoming aware, with what you need for your own 72 hour deadline.
- Data is deleted 30 days after your account closes, and out of backups within a further 35 days.
This box is a summary, not the agreement. The sections below are what counts.
1. This agreement and when it applies
This data processing agreement forms part of the terms of service between PitchDesk and the campsite that holds the account. You do not have to sign it. It applies automatically from the moment you open an account, and it is the Article 28 contract you need in order to be compliant yourself.
If your own compliance process needs a signed copy on your letterhead, email hello@pitchdesk.co.uk and we will sign one. The terms will be these terms.
It applies to personal data that PitchDesk processes on your behalf, which in practice means your campers' booking data. It does not apply to your own account data, because for that we are the controller in our own right and the privacy notice covers it.
2. Definitions
"UK GDPR", "controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018.
"Data protection law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any legislation that replaces or amends them.
"You" and "the controller" mean the campsite. "We", "us" and "the processor" mean PitchDesk.
3. Subject matter, duration, nature and purpose
- Subject matter: the provision of online booking software to a campsite.
- Duration: for as long as your PitchDesk account is open, plus the 30 day deletion window in section 12.
- Nature of the processing: collection, recording, organisation, storage, retrieval, use, transmission by email, and erasure, all by automated means.
- Purpose: to take and manage bookings for your campsite, to price them, to work out availability, to send booking correspondence to your guests on your behalf, to initiate payments and balance collections on your own Stripe account, and, where you choose to use it, to publish a calendar feed of your bookings at an address you control and share.
- Types of personal data and categories of data subject: set out in Annex A.
4. What we must do
We will:
- process personal data only on your documented instructions, which are these terms, the settings you choose in the product, and any further written instruction you give us, unless UK law requires otherwise, in which case we will tell you before processing unless the law forbids it;
- tell you if, in our opinion, an instruction you give us breaches data protection law;
- make sure everyone we allow to process the data is under a duty of confidence;
- take the security measures required by Article 32, as set out in Annex B;
- respect the conditions in Article 28(2) and 28(4) for engaging another processor;
- help you respond to data subject requests, as set out in section 10;
- help you with your obligations under Articles 32 to 36, which cover security, breach notification, data protection impact assessments and prior consultation, taking into account what we know and what is available to us;
- delete or return the data at the end, as set out in section 12;
- make available the information you need to show compliance with Article 28, and allow and contribute to audits, as set out in section 11.
We do not process your guests' personal data for our own purposes. We do not sell it, we do not market to your guests, and we do not use it to train machine learning models.
5. What you must do
You confirm that:
- you have a lawful basis for the processing you instruct us to carry out, which for a booking is normally performance of a contract with the guest, and for reminders and arrival information is normally that same contract;
- you have given your guests the privacy information Articles 13 and 14 require, including that a processor sends their booking email on your behalf, and that you keep your own privacy notice available. Your booking page has a field for it;
- you will not use the free text fields to collect special category data, such as health information, unless you have your own lawful basis under Article 9 for doing so. The product is not designed for it;
- your instructions to us will comply with data protection law;
- you will keep the personal data in your own account accurate, and delete what you no longer need;
- if you use the calendar feed, you accept that giving its address to anyone is your disclosure of the guest surnames, references, dates and party sizes it contains, and that you are responsible for who you give it to and for withdrawing it when a channel relationship ends. The address carries its own private key that appears on no public page, but it is an address rather than a login, so whoever holds it can read the feed. It is a feature you switch on and share, not something we do to your data on our own initiative.
6. Sub-processors
You give us general written authorisation to engage the sub-processors listed in Annex C.
If we intend to add or replace a sub-processor we will tell every account holder by email at least 30 days before the change. If you reasonably object on data protection grounds, tell us within those 30 days and we will either propose a workable alternative or, if we cannot, you may terminate your subscription without penalty and we will refund any unused part of the month.
We impose data protection obligations on every sub-processor that are no less protective than these, and we remain fully liable to you for their performance.
7. International transfers
Your guests' booking data is stored in Cloudflare's Western European region. Some processing takes place at Cloudflare's edge locations worldwide, for example filtering an attack on your booking page.
Where personal data is transferred outside the United Kingdom we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment. We will give you a copy of the relevant mechanism on request.
8. Security
We implement and maintain the technical and organisational measures in Annex B, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risk to individuals. We may update those measures, but not in a way that materially reduces the level of protection.
9. Personal data breach
If we become aware of a personal data breach affecting personal data we process for you, we will:
- notify you without undue delay and in any event within 48 hours of becoming aware;
- describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose to take;
- give you the information you reasonably need to notify the Information Commissioner within your own 72 hour deadline, and to tell affected guests if that is required;
- take reasonable steps to contain it and to stop it happening again.
Reporting to the Information Commissioner and to affected guests is your decision and your obligation, because you are the controller. We will not do it in your name, and we will not notify your guests directly unless you ask us to in writing.
10. Helping you with data subject rights
The product is built so that most requests need no help from us. You can view, correct, export and delete a booking's personal data yourself from your dashboard, which covers access, rectification, erasure and portability for a single guest.
If a guest contacts us directly, we will not answer on your behalf. We will tell them to contact you, and pass the request on to you promptly.
Where you need more than the product provides, for example a full export in a particular format or the restriction of processing on a specific record, ask us and we will help within the time the law allows you. We do not charge for this unless a request is manifestly excessive or repetitive, in which case we will agree a reasonable fee with you first.
11. Audit and information
On request we will give you the information you reasonably need to show that we meet our obligations under Article 28, including our current security description, our sub-processor list and our answers to a standard security questionnaire.
If that is not enough, you may audit us once in any twelve month period, on 30 days written notice, in working hours, under confidentiality, and in a way that does not disrupt the service or put other customers' data at risk. You bear your own costs and our reasonable costs of supporting the audit. A supervisory authority may audit at any time on its own terms.
We are a small company. We do not currently hold ISO 27001 or SOC 2 certification, and we say so plainly on the security page rather than let an audit request discover it.
12. Deletion and return
You can export your bookings, guests and payment records to CSV at any time while your account is open, including during the notice period after you cancel.
When your account closes we keep the data for 30 days so you can come back or take an export, then we delete it from the live database. Copies in backups are overwritten within a further 35 days. Ask us to delete it sooner and we will, within five working days.
We keep only what UK law requires us to keep, which is the billing record of what you paid us, for six years. That record is about you, not about your guests.
13. Liability and precedence
The limits on liability in the terms of service apply to this agreement, except where data protection law does not allow them to.
If this agreement conflicts with the terms of service on the subject of processing personal data, this agreement wins. It is governed by the law of England and Wales.
Annex A: details of the processing
Categories of data subject
- People who book a stay at your campsite.
- People who start a booking and do not finish it, whose details are held only while the hold lasts and then expire.
- Other members of a booking party, insofar as the person booking gives their details.
- People who contact you through a booking, for example to change or cancel it.
Types of personal data
- Identity: name.
- Contact: email address, phone number, postal address, postcode.
- Booking: arrival and departure dates, pitch type and named pitch, number of adults, children, infants, dogs and vehicles.
- Unit details where you ask for them: caravan or motorhome type and length, vehicle registration number, club membership number.
- Free text: the guest's notes and requests, and any notes you add.
- Financial: amounts, currency, payment status, balance due date, and Stripe identifiers for the payment. Not the card number, which never reaches us.
- Records of consent: which version of your terms was accepted, and when.
- The mandate for a later balance payment: the exact wording agreed, the amount, the date, the card brand and last four digits, and the Stripe identifiers.
- Technical: the IP address the booking was made from, recorded to prevent one person holding repeated pitches with unfinished checkouts and as part of the evidence of what was agreed.
- Correspondence: the booking emails we send on your behalf, and their delivery status.
Special category data
None is requested and none is intended. Free text fields could receive it if a guest volunteers it, for example a mobility requirement. If you deliberately collect health or other special category data you need your own Article 9 condition, and you should tell us so we can agree how to handle it.
Frequency
Continuous, for as long as your account is open.
Duration
For the term of your subscription, plus the deletion window in section 12.
Annex B: technical and organisational measures
- All traffic over TLS. Encryption in transit between our service and every sub-processor.
- Data encrypted at rest by the hosting platform.
- Passwords stored as PBKDF2-HMAC-SHA512 hashes at 210,000 iterations, with a random salt for each.
- Sessions held in HttpOnly, Secure, SameSite=Lax cookies with an opaque random identifier, revocable server side and expiring after 30 days.
- Double submit CSRF tokens on every state changing form.
- Output escaped by default in the templating layer, and parameterised SQL everywhere, so untrusted input cannot become code.
- Every Stripe webhook signature verified, with a timestamp tolerance to stop replay.
- Card data out of scope: payment happens in Stripe Checkout, so card numbers never reach our servers.
- Logical separation of every campsite's data, with every query scoped to the site that owns the row.
- Access to production limited to the people who need it, on multi-factor authenticated accounts.
- Automatic backups of the database, with point in time restore.
- Dependencies kept deliberately few, so there is less to go wrong and less to patch.
- Rate limiting on the endpoint that reserves a pitch, keyed on the originating IP address, so a single actor cannot take a site's inventory off the market.
- The mandate for a later balance payment recorded immutably with the exact amount and date, so a payment outside its scope cannot be taken.
- Availability and integrity: the platform is distributed and self healing, and the database is replicated by the provider.
The security page says the same thing in more detail, and also says what we have not built yet.
Annex C: sub-processors
| Who | What they do for us | Where the data sits |
|---|---|---|
| Cloudflare, Inc. | Hosting, the database that holds your account and your bookings, and protection against attacks | Western Europe, with edge processing worldwide |
| Stripe Payments Europe, Ltd. | Payments. Your subscription on our account, and your guests' payments on your own connected account | Ireland, with transfers to the United States |
| Brevo (Sendinblue SAS) | Sending transactional email, including booking confirmations and reminders | European Union |
This list is current at 21 August 2026. Changes come with 30 days notice by email, as set out in section 6.
The rest of the small print
Questions about any of this go to hello@pitchdesk.co.uk and a person will answer.