Skip to content
MediumLink
FeaturesCP12 softwareHow it worksPricingVerify a certificateFAQ
Sign inStart free trial
MediumLink
FeaturesCP12 softwareHow it worksPricingVerify a certificateFAQ
Appearance
Start your free trial Sign in
Back to home

Data Processing Addendum

Last updated: 8 July 2026

This addendum forms part of your agreement with Mediumlink UK Ltd. It applies whenever you put another person's data into Mediumlink: a tenant's name on a CP12, a landlord's address on an invoice, a customer's phone number in your contacts.

1. Who is who

You are the data controller for that information. You decide whose details go in, what they are used for, and how long you keep them. Mediumlink UK Ltd is your processor. We hold and process it to run the service you signed up for, and for nothing else.

For your own account data, the position reverses: we are the controller, and the Privacy Policy governs it.

2. What we process, and why

Subject matterProviding Mediumlink: storing, rendering, emailing and verifying the documents you create
DurationFor as long as your account is open, then as set out in section 8
Nature and purposeStorage, retrieval, PDF generation, sending documents to recipients you name, renewal reminders you switch on
Categories of dataNames, postal addresses, email addresses, phone numbers, property details, appliance details, inspection findings, amounts owed
Categories of data subjectYour customers, tenants, landlords and letting agents
Special category dataNone. Do not enter health, biometric or other special category data into Mediumlink

3. Our instructions come from you

We process your customers' data only on your documented instructions. Using the app is an instruction: creating a certificate tells us to store it, pressing Email tells us to send it.

We will tell you if the law requires us to process it some other way, unless that same law stops us from saying so.

4. Confidentiality

Everyone at Mediumlink UK Ltd who can reach customer data is bound by a duty of confidence. Access is limited to the people who need it to run or support the service, and every admin action requires two-factor authentication.

5. Security

We apply the measures set out in section 11 of the Privacy Policy. In summary: TLS on every connection, encryption at rest, row-level security policies so one engineer's records are unreachable from another engineer's session, short-lived access tokens, two-factor authentication on administrative access, and error monitoring that alerts us to failures.

6. Sub-processors

You give us general authorisation to use the sub-processors listed in section 5 of the Privacy Policy. Each one is bound by terms no weaker than these. We stay liable to you for what they do.

We will give you 30 days' notice before adding or replacing one. Email [email protected] to object. If we cannot resolve your objection, you may end your subscription and we will refund any unused period.

7. Helping you meet your own duties

We will help you with:

  • Requests from your customers to see, correct, delete or move their data. Export All under Settings does most of this yourself, in seconds, and the archive includes a machine-readable copy
  • Your obligations under Articles 32 to 36, including security, breach notification and impact assessments
  • Any question from the Information Commissioner's Office that touches data we hold for you

If we discover a breach affecting your customers' data, we will tell you without undue delay and give you what you need to notify the ICO inside the 72 hours the law allows.

8. When you leave

Delete your account and we delete your customers' data within 30 days, across every sub-processor, except anything the law requires us to keep. Export All gives you a complete copy first. Take it before you delete: after 30 days we cannot get it back for you.

9. Where the data goes

Section 6 of the Privacy Policy names the providers who process data outside the UK and the transfer mechanism we rely on for each.

10. Audits

On written request, once a year, we will answer reasonable questions about how we meet this addendum and share the compliance documentation our sub-processors publish. Write to [email protected].

11. Conflicts

Where this addendum and the Terms & Conditions disagree about the processing of your customers' data, this addendum wins.

MediumLink

Gas safety certificate software, made in the UK for UK Gas Safe registered engineers and the businesses they run.

Product

FeaturesCP12 certificate softwareCommercial gas certificatesInvoicing and quotesPricingHow it worksVerify a certificateFAQ

Company

ContactPrivacy PolicyTerms & ConditionsData Processing Addendum

Get started

Sign upSign in
MEDIUMLINK
© 2026 Mediumlink UK Ltd.Checking statusMade in the UK 🇬🇧