Beta v1.1 — FranchiseMapp is in active beta. Features and data may change, and consultant payouts aren’t available yet — commission keeps accruing and will be paid out once payouts go live.
Legal

Consultant Data Processing Agreement

Last updated 17 August 2026 · Draft, pending solicitor review — see the note at the bottom of this page.

1. What this agreement is, and who it's between

This agreement applies whenever a franchisor using FranchiseMapp (the Franchisor) grants a Referral Scheme consultant (the Consultant) delegated access to their account. It is between the Franchisor and the Consultant — the Franchisor is the controllerof the personal data in their account (their franchisees’ names, contact details and territory records), and the Consultant is a processor, processing that data on the Franchisor’s behalf and only for as long as access is granted. Article 28 UK GDPR requires that relationship to be governed by a written contract before the processing starts — this is that contract.

[ENTITY NAME] (“we”, “us”), which operates FranchiseMapp, is not a party to this specific agreement. We provide the platform that makes the access possible — the account, the permission controls, and the ability for the Franchisor to revoke access at any time — and we are separately the Franchisor’s own processor for their account data generally, under our Terms of Service and Privacy Policy. This agreement governs what the Consultant does with the Franchisor’s data once they have it, not what we do.

This agreement takes effect automatically, on these terms, from the moment a Franchisor grants a Consultant access and that Consultant accepts it inside FranchiseMapp, without either side needing to sign anything separately — the grant and its acceptance, both recorded by the platform, are what forms it.

2. Subject matter, duration and nature of the processing

Subject matter and purpose.The Consultant processes the Franchisor’s personal data solely to provide the consultancy or advisory services the Franchisor has engaged them for — reviewing territories, franchisee records and performance data inside FranchiseMapp on the Franchisor’s behalf.

Duration.Processing may take place only while the grant is active — from acceptance until it expires, is revoked by either side, or the Consultant’s own Referral Scheme participation ends, whichever happens first. A grant is time-limited by design (the Franchisor sets and controls its expiry) and either side can end it immediately; the platform itself stops the Consultant’s access the moment that happens, which is what makes “duration” here a technical fact, not just a contractual promise.

Nature of the processing. Viewing, and — only where the grant is the Consultant (full access) role rather than Consultant (view only)— editing territory, franchisee and performance records inside the Franchisor’s account, strictly within FranchiseMapp itself. The Consultant does not receive a copy, export or separate store of this data as a condition of the grant; access is to the Franchisor’s account as it exists on the platform.

3. Categories of data and data subjects

  • Data subjects:the Franchisor’s franchisees, and any individual named as a contact on a territory or franchisee record.
  • Categories of personal data: names, email addresses and other contact details of franchisees; territory assignment and status; franchisee business and revenue figures where the Franchisor has recorded them against a named individual. No special category data (Article 9) is intended or expected to be processed through this access, and no payment card or bank data is ever visible through it — that data is handled separately by Stripe, described in our Privacy Policy.

4. The Consultant's obligations

4.1 Process only on instructions.The Consultant will process the Franchisor’s personal data only on the Franchisor’s documented instructions — which, in practice, means only within the scope of the role (full access or view only) the Franchisor has granted, and only for the purpose in section 2. Acting outside that scope is processing without instructions.

4.2 Confidentiality.The Consultant will keep the Franchisor’s data confidential, consistent with Referral Scheme §14, and will not disclose it to anyone else without the Franchisor’s consent, except where the law requires it.

4.3 Security.Because processing happens inside FranchiseMapp itself rather than on the Consultant’s own systems, the platform-level security controls (access limited to the granted role, a login the Franchisor can revoke at any time, and access logging) are the primary technical and organisational measures in place. The Consultant will still take reasonable steps on their own side — for example, keeping their own FranchiseMapp login credentials secure — proportionate to the fact that no copy of the data leaves the platform as part of this access.

4.4 No further processors.The Consultant will not engage anyone else to process the Franchisor’s data on their behalf without the Franchisor’s prior written authorisation.

4.5 Assisting the Franchisor.The Consultant will give the Franchisor reasonable help in responding to a data subject exercising their rights (for example, a franchisee asking what data is held about them), and in meeting the Franchisor’s own security, breach-notification and impact-assessment obligations, so far as those relate to data the Consultant has accessed under this agreement.

4.6 Telling the Franchisor about a breach. If the Consultant becomes aware of a personal data breach affecting data accessed under this agreement, they will tell the Franchisor without undue delay.

4.7 Deletion at the end.Because the Consultant never holds a separate copy of the data, ending or revoking the grant is itself what satisfies this requirement — the Consultant’s access to the data on the platform simply stops. If the Consultant has, in breach of this agreement, kept any copy outside the platform, they will delete it once the grant ends.

4.8 Audit. The Consultant will make available to the Franchisor the information reasonably needed to show compliance with this section, and will allow for, and contribute to, an audit or inspection the Franchisor carries out or commissions, on reasonable notice.

5. Our role

We provide and operate the platform this processing takes place on, act as the Franchisor’s own processor for their account data generally (see Terms of Service and Privacy Policy), and enforce the access boundaries this agreement describes technically — a Consultant cannot see a Franchisor’s account without an active, accepted grant, and a revoked or expired grant stops access immediately. We are not a party to, and do not arbitrate, the consultancy relationship between the Franchisor and the Consultant itself.

6. International transfers

This processing takes place on infrastructure operated for us, which we intend to keep within the UK/EEA. If that changes, our Privacy Policy will be updated to describe the safeguard used, and that update applies here too.

7. How this fits with the Referral Scheme terms

This agreement is the “separate data processing agreement” referred to in Referral Scheme §15.3. It governs the data-protection side of delegated access specifically; it does not change anything else about the commercial relationship between a Franchisor and a Consultant, which remains a matter between them.

Contact us

Questions about this agreement: [email protected]

This is a first-pass draft, written to describe how delegated access actually works on the platform today — not a template. It has not yet been reviewed by a solicitor and, as noted above, accepting it is not yet a required step before a grant becomes active, so it should not be treated as fully “operating” in the sense Referral Scheme §15.3 promises until both of those are done. [ENTITY NAME], registered in England and Wales, company number [company number], registered office [address]. Placeholder — fill in before publishing.