Get free quotes

MoverBook — Data Processing Agreement

Last updated: 1 October 2026


1. Parties and scope

This Data Processing Agreement (“DPA”) is between GlobalFormBook Limited (company number 138516C, registered office 35 Fairfield Avenue, Onchan, IM3 4BG, Isle of Man) trading as MoverBook (“we”, “us”, the “Processor”) and the removal business that subscribes to the Service (the “Customer”, the “Controller”).

It forms part of, and is governed by, the Terms of Service. You accept it when you create an account. Where this DPA and the Terms of Service conflict on the subject of personal data, this DPA prevails.

It applies only to Customer Data — the personal data of your own customers, enquirers, employees and crew that you put into the Service, or that reaches the Service on your behalf. For your own account data (your name, your email address, your billing details) we are the controller, and our Privacy Policy governs it, not this DPA.

2. Roles

You are the controller. We are your processor. You decide whose data goes into the Service and why; we process it to provide the Service and on your instructions.

This split is not a formality — it decides who does what:

⚠️ We never use Customer Data to market to your customers, to sell to them, or to train our own models.

3. Your instructions

Your instructions to us are: this DPA, the Terms of Service, the settings you choose in the Service, and the actions you take in it. Using a feature is an instruction to carry it out — sending a quote emails your customer; enabling a retention period instructs us to anonymise data when it expires.

We will tell you if we believe an instruction breaks data protection law, and we may pause that processing until it is resolved. We will not process Customer Data for any other purpose unless the law requires it — and if the law does, we will tell you first unless we are legally prohibited from doing so.

4. Duration

This DPA runs for as long as we process Customer Data for you: from the moment you create an account until the data is deleted, returned or anonymised under Section 11.

5. What we process

Set out in full in Annex 1, as required by Article 28(3) of the UK GDPR and the Isle of Man Data Protection (Application of GDPR) Order 2018. In summary: the names, contact details, addresses, move details, photographs and correspondence of your customers and prospective customers, and the names, contact details and work records of your staff and crew.

⛔ Photographs of the inside of people’s homes are the most sensitive thing on this platform — video walkthroughs, survey stills and job photos taken in a customer’s house. They are treated as such throughout: stored privately, never public, and never used for anything but showing them back to you.

6. Confidentiality

We keep Customer Data confidential. Access is limited to people who need it to provide or support the Service, each bound by confidentiality obligations, and it is logged. As of the date above MoverBook is operated by a single named individual; if that changes, the obligation does not.

7. Security

We apply appropriate technical and organisational measures under Article 32. The measures in force are listed in Annex 2 and include per-tenant data isolation enforced in the database itself, encryption in transit, hashed passwords, role-based access control, audit logging and encrypted off-site backups.

We may change a measure for an equivalent or better one. We will not materially weaken the protection described in Annex 2 while this DPA is in force.

⚠️ What we do not claim. We are not ISO 27001 or SOC 2 certified, and nothing here should be read as implying an external audit or certification. We say so plainly because a DPA that implies assurances it does not hold is worse than one that states exactly what exists.

8. Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex 3. Each is engaged under a written contract imposing data protection obligations equivalent to those in this DPA, and we remain responsible to you for their performance.

Changes. We will give you at least 30 days notice before adding or replacing a sub-processor, by email to your account address and on this page. If you reasonably object on data protection grounds, tell us within that 30 days: we will try to find a workable alternative, and if we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of fees paid in advance.

9. Assisting you

We will, taking into account the nature of the processing:

10. International transfers

We host Customer Data in the United Kingdom (DigitalOcean, London). Some sub-processors in Annex 3 process limited data outside the UK and the EEA — chiefly in the United States. Where they do, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent lawful mechanism, together with the supplementary measures described in that Annex.

11. Deletion and return

During the subscription, retention is under your control: the Service’s retention settings decide when Customer Data is anonymised. Anonymisation permanently removes names, contact details, addresses, messages and photographs, and keeps a financial skeleton — job, quote and invoice numbers, amounts, dates and status — which is no longer personal data. Anonymisation is irreversible.

On termination, you may export your Customer Data from the Service at any time before the account closes. We will delete or anonymise the Customer Data remaining in the live system within 90 days of termination, and it will age out of encrypted backups within a further 90 days.

⚠️ Two exceptions, stated because they are real:

  1. Records we must keep by law. Invoices, payments and the financial skeleton are retained to meet tax and accounting obligations — typically at least six years. This is a legal requirement on us, not a choice, and a DPA promising total erasure would simply be untrue.
  2. Documents already sent to your customer. A quote PDF we archived when it was emailed is kept as the record of what that customer was actually offered. It is excluded from every automatic deletion sweep on purpose: it is the evidence of an agreement, and deleting it would destroy your own position in a dispute. It is deleted with the rest of the account under this Section.

12. Liability

The limitations and exclusions of liability in the Terms of Service apply to this DPA, and the liability cap there is a single combined cap across the Terms and this DPA — it does not apply twice.

Nothing in this DPA limits either party’s liability where the law does not allow it to be limited.

13. Changes to this DPA

We may update this DPA where the law, our sub-processors or the Service change. We will post the updated version here with a new “Last updated” date and, for a change that materially reduces your rights or our obligations, give you at least 30 days notice by email before it takes effect. We keep a record of which version you accepted and when; you can see it in the Service under Settings → Company → What you’ve agreed to.

14. Governing law

This DPA is governed by the law of the Isle of Man, and the courts of the Isle of Man have exclusive jurisdiction, matching the Terms of Service. This does not deprive you or your customers of the protection of mandatory data protection law in their own jurisdiction.

15. Contact

Data protection contact: privacy@moverbook.co.uk Postal: GlobalFormBook Limited, 35 Fairfield Avenue, Onchan, IM3 4BG, Isle of Man


Annex 1 — Details of the processing

Subject matter. Provision of the MoverBook removals management platform.

Duration. As set out in Section 4.

Nature and purpose. Hosting, storing, organising, transmitting, displaying and deleting Customer Data so that you can run your removals business: recording enquiries, producing and sending quotes, surveying properties and estimating volume, scheduling jobs and crews, capturing job photographs and signatures, invoicing and collecting payment, issuing waste transfer notes, and communicating with your customers by email and (where you enable it) SMS or WhatsApp.

Automated processing. Enquiry text is sent to our AI sub-processor to extract structured details (names, addresses, dates, item lists), and survey video frames — extracted on your own device, not by sending us the video — are analysed to suggest an inventory. Both produce suggestions for a human to check. ⛔ Neither makes a decision about a person, and nothing on this platform performs automated decision-making with legal or similarly significant effects.

Types of personal data

Category Examples
Identity and contact Name, email address, telephone number
Address and property Collection and delivery addresses, postcodes, property type, floor, access and parking notes
Move details Dates, times, inventory of belongings, volume estimates, special items
Images and recordings Survey video frames, walkthrough video clips where a surveyor uploads one, survey and inventory photographs, job progress photographs, photographs of the inside of a property, signatures
Correspondence Emails, SMS and WhatsApp messages exchanged about a job, and notes recorded against a customer
Financial Quote and invoice amounts, payment status and references. ⛔ No card details — card payments are processed by SumUp under your own account and never reach us
Staff and crew Name, email address, telephone number, role, driving and survey capabilities, job assignments, vehicle checks, odometer readings, expenses and receipts

Categories of data subjects. Your customers and prospective customers; people at a collection or delivery address; your employees, crew, drivers and surveyors; other firms’ staff where you use the backload marketplace or lead features.

Special category data. The Service is not designed for special category data (Article 9) and you should not enter it. Photographs taken inside a home may incidentally reveal such information; we apply the security measures in Annex 2 to all images and do not analyse them for that purpose.

Children’s data. The Service is not intended to collect data about children. A child’s name may appear incidentally in move details; do not use free-text fields to record information about children.

Annex 2 — Security measures

Measure What is in force
Tenant isolation Every tenant’s data is separated in the database itself, not only in application code: tenant-scoped views and a session-bound tenant identifier, so a query that forgets its filter returns nothing rather than someone else’s rows
Access control Role-based access control; least privilege; separate roles for owners, managers, office staff and drivers; a separate capability model for who may drive or survey
Authentication Passwords stored as salted BCrypt hashes; checked against known-breached password lists at sign-up and change; short-lived access tokens with rotating refresh tokens
Encryption in transit HTTPS/TLS everywhere, with HSTS on all web and API hosts
Encryption at rest Backups encrypted before leaving the server; uploaded files stored privately, never publicly readable
Injection resistance Parameterised database access throughout; no string-built SQL
Audit logging Security-relevant and financial actions recorded with actor, time, IP address and user agent. Entries are never amended — nothing in the platform can edit one — and are retained for 7 years, after which they are purged. A tenant cannot switch this off or shorten it
Backups Automated database backups every 5 minutes, encrypted and stored off-site in a separate facility, with restoration tested rather than assumed
Segregation of duties Uploaded files stored separately from the database, so one compromise does not yield both
Vulnerability management Automated dependency vulnerability alerts; secret scanning on the code repository
Deletion Retention sweeps that anonymise expired personal data irreversibly; per-record deletion available to you in the Service

Annex 3 — Sub-processors

Provider Purpose Location Transfer mechanism
DigitalOcean, LLC Cloud hosting, object storage and encrypted backups United Kingdom (London) UK — no transfer
Twilio SendGrid Transactional and lifecycle email to you and your customers United States / EU UK IDTA to the EU SCCs
Twilio Inc. SMS and WhatsApp messaging, only where you enable it United States / EU UK IDTA to the EU SCCs
SumUp Limited Card payment processing for your customers, and our own subscription billing EU EU adequacy
Anthropic PBC AI extraction of enquiry details, and AI-assisted inventory from survey frames extracted on your device United States UK IDTA to the EU SCCs. ⛔ Content is not used to train models
Cloudflare, Inc. Bot and spam protection on the public quote form (Turnstile); DNS and CDN Global CDN UK IDTA to the EU SCCs

⚠️ The video is never sent to the AI sub-processor, and usually never leaves the device at all. Survey walkthrough video is processed on your own phone or computer, and only the selected still frames are sent to us and on to the AI sub-processor — a 172 MB recording becomes about 3 MB of stills. That is a deliberate design choice and it materially reduces what leaves your possession.

A surveyor may also choose to upload a walkthrough clip itself (up to 105 MB per clip), so that the office can watch the room back while pricing the job. Where that happens:


⚠️ A note on this document. It is written to state accurately what MoverBook actually does, and the measures in Annex 2 describe the system as built. It has not been reviewed by a solicitor. If your own legal or compliance team needs changes, or your own DPA signed instead, write to privacy@moverbook.co.uk — we would rather agree wording you can rely on than have you rely on wording nobody checked.