Purpose of this page. BOBcloud is a business-to-business service. Resellers and their end customers regularly need to satisfy data-protection assessments (DPIA screening forms, DPIA Part B, data sharing agreements, vendor questionnaires) before onboarding. This page contains the information a data controller and their DPO need to complete those exercises using BOBcloud as a data processor.
We do not sign bilateral DPAs, DSAs, or third-party DPIA templates — see why we publish standard terms — but everything an assessor needs is set out below and in our Privacy Notice and Terms.
1. Our role and legal identity
BOBcloud is operated by SCDC Ltd (company number 08461684), a company registered in England and Wales, registered office The Old Royal Mail Sorting Office, Stokes Road, Corsham, Wiltshire, SN13 9AA. We are registered with the Information Commissioner’s Office (ICO) under reference ZA272871.
In relation to personal data, SCDC Ltd holds two distinct roles under UK GDPR, depending on which category of data is under consideration.
Controller — in relation to reseller account data (business contact details, billing records, portal login credentials, ticket history, marketing consent). This is data that SCDC Ltd collects directly from resellers to operate the commercial relationship and, where the reseller has explicitly opted in, to send marketing communications. Our Privacy Notice covers this role in detail.
Processor — in relation to any personal data that a reseller, or a reseller’s end customer, places into the backup service or the reseller portal: end-customer identifiers, backup content, and operational metadata generated in the course of running backups.
The chain of responsibility for this data depends on the reseller’s setup:
- Where the reseller is itself the data controller (for example, an MSP backing up its own business data), the reseller is the controller and BOBcloud is the processor.
- Where the reseller is providing IT services to an end customer (for example, an MSP backing up a school’s or business’s data on the customer’s instructions), the end customer is the controller, the reseller is the processor, and BOBcloud is a sub-processor engaged by the reseller with the end customer’s authorisation. Under Article 28 UK GDPR it is the reseller’s responsibility to secure that authorisation.
- Depending on the degree of independent decision-making the reseller exercises over purposes and means, they may in some setups be a joint controller with the end customer rather than a processor. The reseller and their end customer are best placed to determine this on the facts of their arrangement.
This dual role is standard for a business-to-business cloud service and is the same pattern used by Microsoft, Google, AWS, and other B2B providers. It does not require separate ICO registration; SCDC Ltd’s existing ICO registration covers both roles.
We do not share personal data with any third party for that third party’s own purposes. We do not sell personal data. We do not use customer backup content or portal metadata to train machine-learning models.
2. Categories of data we process
It helps to distinguish three categories, because they have very different characteristics under UK GDPR.
2a. Reseller account data — BOBcloud is controller
BOBcloud is the controller of this data.
Reseller business name, contact name(s), contact email, contact phone where provided, billing details, portal login credentials for the reseller’s nominated portal users, marketing consent status, and support ticket history. This is data SCDC Ltd collects directly from resellers to operate the commercial relationship. Handling of this category is governed by our Privacy Notice.
SCDC Ltd is also the controller of prospect and enquirer contact details, website analytics data, marketing subscribers, and its own staff records. These categories fall under the same Privacy Notice and are not further described on this page because they are not relevant to a controller’s DPIA of BOBcloud as a processor.
2b. Operational metadata — BOBcloud is processor
BOBcloud is a processor of this data, acting on the reseller’s instructions.
Usernames, IP addresses, machine names, operating system versions, backup schedules, backup sizes, file counts, timestamps, and system logs. This is generated as a by-product of the service running. Metadata may incidentally include end-customer identifiers — for example, an email address appearing as the label of a mailbox backup set (“backed up mailbox of davejones@company.com”). The reseller controls what identifiers are used when a backup account is set up; BOBcloud does not solicit or require end-customer personal data.
2c. Backup content — BOBcloud is processor; content is encrypted and inaccessible
BOBcloud is a processor of this data, acting on the reseller’s instructions.
Backup content is encrypted client-side using AES-256 before it leaves the customer’s device. The encryption key is held only by the customer and is never transmitted to BOBcloud or to any of our sub-processors. We hold only the ciphertext. We have no technical means to read the underlying data. This means that even in the event of a full compromise of our infrastructure or of a storage provider, backup content cannot be read without the customer’s key.
The practical consequence for a school DPIA is that categories of data inside the backup (pupil records, staff records, safeguarding notes, financial records, images, and so on) are not visible to BOBcloud or its sub-processors. Where a DPIA asks about the security of those categories in transit and at rest with the processor, the answer is: encrypted end-to-end with a customer-held key.
3. Data residency and international transfers
Where each category is held
| Category | Location | Provider |
|---|---|---|
| Backup content (ciphertext) | Customer-selected region — see note below | Microsoft Azure or Wasabi Technologies |
| Reseller portal — account records, operational metadata, logs | Germany (EEA) | Hetzner Online GmbH |
| Helpdesk & support tickets | United Kingdom | Fasthosts Internet Ltd (Gloucester, UK) |
| Transactional email (system notifications) | EEA data centres (SMTP2GO Ltd is NZ-headquartered; UK adequacy applies) | SMTP2GO |
Beyond what a customer chooses to place into the portal or into their backup sets, we do not hold personal data subject to UK GDPR.
How the region is chosen for backup content
BOBcloud makes all of the storage regions offered by Microsoft Azure and Wasabi available to the reseller. When a reseller (or a reseller’s end customer) creates a backup set, the destination region is selected at that point and is visible in the reseller portal. The default for UK-based schools and MATs is a UK region. A reseller who has selected a non-UK or non-EEA region has done so deliberately and is aware of the location their ciphertext is written to.
Transfer mechanism
Data flows between the United Kingdom and the EEA (portal in Germany, and any EEA storage regions selected by the reseller) rely on the UK’s recognition of EEA countries as providing an adequate level of protection for personal data. This adequacy was retained under the Data Protection Act 2018 (as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) at the point of EU exit. No further transfer mechanism (UK IDTA or UK Addendum to the EU SCCs) is required for the UK↔EEA leg. Where a reseller has selected a UK region for backup content, the ciphertext does not leave the UK. Where a reseller has selected a region outside the UK/EEA, that choice sits with the controller / reseller and any additional safeguards required under UK GDPR are their responsibility to assess.
Non-EEA sub-processors. Two fixed sub-processors sit outside the UK/EEA and warrant explicit mention:
Cloudflare, Inc. (United States) provides the Web Application Firewall, DDoS protection, and Zero Trust access gateway for administrative systems. Personal data transferred to Cloudflare is limited to visitor IP addresses and, for gated administrative surfaces, staff identity claims and access logs. This transfer relies on Cloudflare’s certification under the UK Extension to the EU–US Data Privacy Framework (DPF), which the UK Government recognised as providing an adequate level of protection with effect from 12 October 2023.
SMTP2GO Ltd (New Zealand) provides transactional email delivery for system notifications. New Zealand is one of the third countries for which UK adequacy regulations have been made (retained under the Data Protection Act 2018), so no separate transfer mechanism is required for the contractual/corporate leg. Mail is processed through SMTP2GO’s European data centre infrastructure.
Notification of changes
Any material change to these arrangements — a new sub-processor, a change of storage region, a change of transfer mechanism — would be communicated to resellers before it takes effect, with sufficient notice for the reseller to raise objections or, if necessary, discontinue use. We have no current plans to change the arrangements described above.
4. Sub-processors
The sub-processors listed below carry out clearly defined functions. Where a sub-processor holds personal data on our behalf, it is bound by contractual obligations equivalent to those set out in Article 28 UK GDPR.
| Sub-processor | Function | Location | Certifications |
|---|---|---|---|
| Microsoft Azure Blob Storage | Encrypted object storage for backup content | Reseller-selectable — regions across the UK, EEA, and worldwide | ISO 27001, SOC 1/2/3, UK data residency where selected, extensive public-sector accreditations |
| Wasabi Technologies | Encrypted object storage for backup content | Reseller-selectable — regions across the UK, EEA, and worldwide | ISO 27001, SOC 2 |
| Hetzner Online GmbH | Hosting for the reseller portal and management systems | Germany (EEA) | ISO 27001 |
| Fasthosts Internet Ltd | UK hosting for the WHMCS helpdesk system | Gloucester, United Kingdom | ISO 27001 |
| SMTP2GO Ltd | Transactional email delivery for system notifications | New Zealand (UK adequacy) — European data centre routing | ISO 27001 |
| Cloudflare, Inc. | Web Application Firewall, DDoS protection, and Zero Trust access gateway for administrative systems | Global CDN with UK/EEA edge nodes; processes visitor IP addresses and, for gated admin surfaces, staff identity claims and access logs | ISO 27001, SOC 2, PCI DSS |
Publicly available trust centres for the storage sub-processors:
- Wasabi — wasabi.com/company/trust-center
- Microsoft Azure — learn.microsoft.com/en-us/azure/compliance
5. Technical and organisational security measures
SCDC Ltd is Cyber Essentials certified
SCDC Ltd holds a current Cyber Essentials certification (whole-organisation scope), assessed by the FIG Group under the IASME certification body.
Authenticity of the certificate can be verified via the QR code on the certificate itself, or through the IASME register.
Cyber Essentials is the UK Government-backed scheme that assesses an organisation’s technical controls against commodity cyber-attack (secure configuration, boundary firewalls, access control, patch management, malware protection). SCDC Ltd holds the Cyber Essentials certification and does not, at present, hold Cyber Essentials Plus (which adds independent hands-on technical audit) or ISO 27001. Where a controller’s procurement policy requires Cyber Essentials Plus or ISO 27001 at the processor level, this is usually satisfied in combination with the certifications of the storage sub-processors listed in Section 4, together with the client-side encryption model.
Encryption
- At rest and in transit: backup content is encrypted with AES-256 before it leaves the customer’s device (client-side encryption). Ciphertext is then transferred over TLS to the storage sub-processor.
- Key custody: the encryption key is generated on and held by the customer. It is not transmitted to BOBcloud. It is not held by any sub-processor. If the customer loses the key, the backup cannot be recovered — this is by design.
- Portal traffic: all reseller-portal and end-customer-portal traffic is served over HTTPS with modern TLS. Administrative access to BOBcloud infrastructure is gated by Cloudflare Zero Trust with hardware-token authentication.
Access controls
- Reseller portal access is per-user, with role-based permissions (Owner, Admin, Staff) set by the reseller.
- Multi-factor authentication (TOTP) is available for portal users and can be enforced at organisation level. Owners can require MFA for all staff and can revoke individual user sessions.
- All portal sign-in attempts are logged and available to the reseller Owner (24-hour, 7-day, and 30-day views, exportable to CSV).
- Administrative access to production servers is restricted to named engineers and gated by Cloudflare Zero Trust; there is no shared administrative account.
Monitoring and logging
- System logs are retained for operational and security-monitoring purposes and used to investigate incidents.
- Backup job records (start time, end time, status, byte count, destination) are retained for the life of the account and made available to the reseller through the portal.
Backups of our own systems
BOBcloud infrastructure is itself backed up to write-only, object-locked storage (governance-mode object lock, 90-day retention) held in a separate provider and region from the primary system, so that a routine compromise of the primary environment cannot delete or overwrite the disaster-recovery copy. The upload path holds only write permissions, without the ability to bypass the object lock.
6. Retention and deletion
Backup content
The retention period for backup content is set by the reseller (or by the end customer, where the reseller allows it) through the retention policy configured on each backup set. BOBcloud does not impose a retention period on customer content; the customer decides. Where the ICO or a data controller requires a specific retention schedule, this is enforced by the customer’s own configuration of the backup software.
When a backup set is deleted through the portal, the corresponding ciphertext is removed from primary storage. Storage sub-processors’ own deletion timelines then apply to any residual copies held for object-storage housekeeping.
Account termination
When a reseller account is closed, or an end-customer account is removed by a reseller, backup content associated with that account is removed from primary storage. Operational metadata (billing records, audit logs, ticket history) is retained only for as long as is required to comply with UK statutory and tax obligations, then deleted.
Early deletion / erasure requests
A data controller can, through the reseller, request early deletion of specific backup sets, portal user records, or ticket history at any time. Because the reseller controls the portal, the reseller can normally satisfy such requests directly through the portal without contacting BOBcloud.
7. Personal data breach notification
In the event of a personal data breach affecting a reseller’s or end customer’s personal data:
- BOBcloud will notify the affected reseller without undue delay once we become aware of the breach, and in any event within the timeframe required by the regulator in force at the time (currently the ICO).
- The notification will contain the information the regulator requires at the time, which currently includes: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed to address the breach; and contact details for further information.
- BOBcloud will assist the reseller (as data controller in relation to their end-customer relationship) with their own obligations under UK GDPR, including ICO reporting under Article 33 and communication with affected data subjects under Article 34 where required.
- BOBcloud will co-operate with the ICO and other regulators as required by law.
Our commitment is to comply with the regulator’s requirements in force at the time, rather than to incorporate specific legal wording into our terms. This is a deliberate choice: statutory notification requirements change, and standard commercial terms that fix specific timeframes or specific content risk falling out of step with the law. Compliance with the current law is a legal obligation on BOBcloud regardless of contractual wording.
8. Assisting with data subject rights
Because backup content is encrypted with a key held only by the customer, BOBcloud cannot itself execute subject access requests, rectification requests, erasure requests, or portability requests against the content of backups. The data controller (or the reseller as processor) is technically able to do so using their own key and their own tooling.
Where a data controller receives an individual’s request that relates to backup content or to portal metadata held by BOBcloud, we will provide reasonable and prompt assistance to the controller (through the reseller). This typically takes the form of:
- confirming what portal metadata exists in relation to a named account;
- providing tooling or instructions for the reseller / controller to locate, restore, extract, or delete data within a specific backup set;
- executing deletion of specific portal records at the reseller’s written instruction, and confirming that the deletion has been carried out.
9. Staff, training, and access control
BOBcloud is operated from the United Kingdom. Access to production infrastructure is restricted to named engineers. All staff with access to production systems are contractually bound to confidentiality obligations that survive termination of their engagement. Staff receive data-protection briefings appropriate to their role and access level, and the whole organisation is in scope of the Cyber Essentials certification detailed in Section 5.
Because backup content is encrypted with a customer-held key, no member of BOBcloud staff can read backup content. Access to operational metadata is limited to what is necessary for the engineer’s current task and is logged.
10. Why we publish standard terms rather than sign bilateral agreements
BOBcloud publishes standard Terms of Service and a Privacy Notice that apply uniformly to all resellers and, through them, to all end customers. We do not enter into bilateral, individually-negotiated Data Processing Agreements or Data Sharing Agreements with individual resellers or their end customers.
This is the same operating model used by Microsoft, Google, Amazon Web Services, Wasabi, and other business-to-business cloud providers: a single, standard set of terms — including the processor commitments required by Article 28 UK GDPR — that every customer accepts on onboarding, in place of individually negotiated bilateral agreements. There are three practical reasons for it:
- Consistency across the customer base. A single published set of terms means every reseller and every end customer is on the same version at the same time. Bilateral agreements drift out of date; ours cannot.
- Ability to update in response to regulatory change. UK GDPR, the ICO’s guidance, and the underlying transfer mechanisms have changed materially since 2018 and will change again. Standard, versioned terms can be updated for the whole base at once; a portfolio of bilateral agreements cannot.
- Regulatory position. The obligations that a school or a controller needs to satisfy under Article 28 UK GDPR are, on our side, satisfied by our published terms taken together with the operating facts set out on this page. There is no legal requirement that they be re-stated in a bilateral document.
For the same reason, we do not complete third-party DPIA forms, DSA templates, or vendor questionnaires on behalf of a controller or their advisor. The controller’s DPO is the appropriate person to complete their own organisation’s DPIA; the information on this page, together with our published Terms and Privacy Notice, is intended to give them everything they need to do so.
Where a controller has a specific concern that is not addressed by our published position, we will consider amending the published terms rather than signing a side letter. Requests of that kind should be sent through the normal support channel.
11. Mapping to a school DPIA (Part B, Section 1)
The following table maps the standard prompts in a typical school / MAT DPIA template (Part B, Section 1) to the section of this page that answers each one.
| DPIA prompt | Answered in |
|---|---|
| Security measures — encryption, access controls, monitoring, certifications | Section 5 (includes Cyber Essentials cert detail) |
| Data retention — retention policy, deletion timeframes, ability to request early deletion | Section 6 |
| Data transfer — transfers to third parties, sub-contractors, sub-processors; encryption in transit; school control over sharing | Section 4 and Section 5 |
| Offsite storage & cloud computing — where data is held, jurisdiction, international transfers, migration plan | Section 3 |
| Purpose of processing — how the activity supports the school’s objectives | To be completed by the school. BOBcloud provides the technical service; the purpose is defined by the school’s data retention and business-continuity policies. |
| Data deletion & retention — identifying stale data, deleting old accounts, verifying deletion within third-party systems | Section 6 |
| Data sharing — written agreements with third parties, security during and after transfer | Section 10 (why standard terms), plus our Terms and Privacy Notice |
| Practical steps — staff training on the system | To be completed by the school in relation to its own staff. BOBcloud staff training is covered in Section 9. |
| Data rights compliance — SAR, erasure, central log | Section 8 |
| Transparency & consultation — privacy notices, how individuals raise concerns | To be completed by the school. The school’s own privacy notice should reference BOBcloud as a processor and link to this page and our Privacy Notice. |
12. Mapping to the ICO / Judicium DSA checklist
The ICO’s Data Sharing Code of Practice, as reflected in typical DSA guidance, sets out a minimum list of matters that a data sharing arrangement should address. The following table shows how each is dealt with.
| DSA checklist item | Position |
|---|---|
| Purpose(s) of sharing | BOBcloud is a processor, not a data-sharing counterparty. Backup content and operational metadata are processed on behalf of the controller for the purpose of providing the backup service. No onward sharing for any third party’s own purposes takes place. |
| Potential recipients / circumstances of access | Recipients are the sub-processors listed in Section 4, each acting solely on our instructions. |
| Basis for sharing | Article 28 UK GDPR (processor engaged by controller). The lawful basis for the underlying processing is set by the controller. |
| The data to be shared | See Section 2. Content is encrypted; BOBcloud cannot read it. |
| Data quality — accuracy, relevance, usability | BOBcloud takes an unmodified copy of data supplied to it by the controller’s backup client. Accuracy is a matter for the controller. On restore, the same ciphertext is returned unchanged and is decrypted with the customer’s key. |
| Data security | See Section 5. |
| Retention of shared data | See Section 6. Retention is controller-configured. |
| Individuals’ rights — SAR, complaints | See Section 8. |
| Information governance — termination of the arrangement | On termination, backup content is removed from primary storage; operational metadata is retained only for the period required by UK tax and statutory obligations. |
| Review | This page is reviewed at least annually and whenever a material change is made to sub-processors, data residency, or security posture. The review date is shown at the top of this page. |
13. Contact
Questions about this page, or requests for information a controller’s DPO needs in order to complete an assessment, should be sent to your reseller in the first instance. Where the reseller is unable to answer, they should raise a ticket through our helpdesk and the query will be routed to the appropriate person.
For matters that need to reach us directly rather than via the reseller — for example, a controller’s DPO seeking confirmation of a sub-processor change, or a data subject rights query relating to portal metadata — email support@bobcloud.net.
SCDC Ltd (company number 08461684) · The Old Royal Mail Sorting Office, Stokes Road, Corsham, Wiltshire, SN13 9AA · ICO registration ZA272871.