Data Processing

Data Processing

Data Processing

Data Processing

Payaable Ltd (Trading As Nook) Is A Company Incorporated And Registered In England And Wales Under Company Number 12921042 And Its Registered Office At 3 Park View Mews, London, England, SW9 0AG (Nook, We, Us Or Our). 

We Provide Payment And Invoicing Management Software Services To UK Businesses Seeking To Simplify Their Payment Processes (Our Customer, You Or Your). We Cannot Perform Our Services Unless You Provide Personal Data To Us. Except As Specified In Our Privacy Policy (Available At Https://Nook.Io/Privacy), Nook Is The Processor And You Are The Controller For Personal Data Processed By Nook When We Provide Our Services To You. 

Whenever There Is A Controller-Processor Relationship, UK Data Protection Law Requires Any Processing By A Processor To Be Governed By A Contract. This Data Processing Addendum (Addendum) Sets Out Our Respective Obligations Under Data Protection Law. When You Sign Up To Use Nook Services, You Agree To Be Bound By The Addendum So You Should Read This Document Carefully Before Registering As A Customer.

‍1. Definitions

Controller

The organisation or person that makes decisions about what and why personal data is being collected.

Data protection laws

Any laws and regulations relating to privacy or processing of personal data, including:


  1. Eu directive 2002/58/ec (as amended by 2009/136/ec) and the privacy and electronic communications (ec directive) regulations 2003 (pecr);

  2. Eu regulation 2016/679 (gdpr)

  3. The gdpr as amended by schedule 1 of the data protection, privacy and electronic communications (amendments etc) (eu exit) regulations 2019 (uk gdpr) and data protection act 2018 (dpa);

  4. Any laws or regulations supplementing or replacing pecr, the gdpr, uk gdpr or dpa; and 

  5. Any relevant guidance or codes of practice issued by a regulator.

Personal data

Any information which can (or could be used to) identify a living person.

Process

Any actions in relation to personal data – ranging from actively using or analysing the information to simply having access to or storing the information. Processing, processed and processes shall be interpreted accordingly.

Processor

The organisation or person that carries out a task for the controller which requires them to process personal data.

Personal data breach

A security incident in which personal data has been accidentally or illegally destroyed, lost, changed or shared with, accessed or used by someone who did not have permission.

Service

The services provided by nook to you under the terms https://nook.io/terms.

1.1. a reference to writing or written includes email.


1.2. any words following the phrases including, include, such as, for example or any similar expression are intended to be illustrative only.


1.3. use of the singular shall include the plural and vice versa.

2. Status of the parties

2.1. Where we receive personal data from you or we are required to process personal data to deliver our service to you, you are the controller of that personal data and we are the processor. we will only process personal data in line with your instructions.


2.2. We state in our privacy policy (available at https://nook.io/privacy) where we act as the controller for any personal data.

3. Providing information to individuals

3.1. It is your responsibility as the controller to inform individuals how their personal data is used and maintain the mandatory records required under data protection laws.


3.2. Our privacy policy provides basic information to individuals about how their personal data will be used when it is in input by our customers but the specific details will vary from customer to customer depending on how that customer uses our service.

4. Obligations to you

4.1. Where We Process Personal Data For Which You Are The Controller (As Set Out In Schedule 1), Nook Shall:

a) Process personal data in line with your written instructions;


b) Ensure that any of our staff who have access to personal data are bound by obligations of confidentiality (which are included in our employment contract or equivalent contract with them);


c) Have technical and organisational measures and procedures which ensure an appropriate level of security for personal data and reduce the risk of a personal data breach;


d) Only appoint third parties (who we instruct to help us deliver our service) after we have notified you in writing and you have not objected within fourteen (14) days;


e) Not transfer personal data outside the uk until after we have notified you in writing and you have not objected within fourteen (14) days;


f) Promptly inform you if there has been a personal data breach which impacts the personal data we process under this addendum;


g) At the end of our contractual relationship, or any earlier written request from you, delete or return personal data;


h) Assist you and provide the information required to ensure you can comply with your obligations under the data protection laws;


i) Promptly inform you if we receive a request from or on behalf of an individual who wishes to exercise their rights under the data protection laws, and provide assistance so you can respond to the request;

j) Not disclose personal data without your written permission unless we are legally required to make the disclosure (in which case, we will promptly notify you unless we are prohibited from doing so); and


k) Allow you to access our premises or records to audit our compliance with the data protection laws, provided you give us seven (7) days’ notice.

6. Aggregated information

6.1. We Collate Information Input By Users Of Our Software To Identify Trends And Improve Our Service. This Information Is Aggregated In A Way That Means It Is No Longer Possible To Identify Any Individual User And Is Therefore No Longer Personal Data. That Aggregated Information Falls Outside The Scope Of This Addendum.

Schedule 1

This table sets out the personal data that we receive from you or that we process as part of the provision of our service to you.

Subject matter of processing


The service that we will provide to you

Nook provides a software-as-a-service which allows you to:

  • Add users to a verified customer profile (to associate user accounts with the businesses they operate under)

  • Input contact and payment details for accounts payable and receivable

  • Automate late payment chaser communications

Duration of processing


The period of time beginning from when nook first accesses personal data until we delete or return such personal data to you.

From The Date That You First Register With Nook Until The Date That You Or We End The Contract In Accordance With The Terms And The Main Business Account (And All Associated User Accounts) Are Deleted. 

Nature of processing


The ways in which nook will process the personal data on your behalf

We create user credentials when you (and users associated with your account) register to use our service.


We store and can access personal data you input to use our service (such a payee contact details).


We transfer and send personal data to facilitate your payment instructions (for example to send an invoice to your customer).


We use personal data to communicate and provide our service to you.


We delete personal data on your instruction or when our contract with you ends.

Purpose of processing


As the controller, only you can determine the lawful basis.

Below we have suggested common lawful bases used by our customers:


Legitimate interest – to effectively manage payments made to or by your business, including recovering debts owed to you


Contractual performance – to fulfil the conditions of a contract where you have entered into an agreement with an individual or unincorporated business (such as a sole trader)

Types of personal data


The types of information we anticipate we will process when we provide our service to you

  • First name, last name

  • Email address

    • Financial details (where personal account or unincorporated business)

    • Postal address (where personal address or unincorporated business)

    • Other contact details (where these are included on invoices, purchase orders or otherwise input by you)

    • Job title and employer  

  • Analytical and technical data such as ip address and how users interact with our services

  • User credentials

  • Any other personal data input by you 

Types of special category data


Types of personal data which are sensitive and have additional protections under UK law (e.g. health data)

We never seek to process special category data but this may sometimes happen if you input special category data or special category data could be inferred from information (for example, where you are a caterer and an invoice is addressed to an individual for services provided at a religious celebration).

Categories of data subjects


Types of individuals’ whose personal data will be processed by nook

  • You (if you are an unincorporated business, such as a sole trader)


  • Your staff


  • Any individual that can be identified on an invoice or purchase order (your customers or their staff, your suppliers or their staff etc)

You’re in great company

Hear from some of our amazing customers who love using Nook

  • Nook supports our clients to run their weekly and monthly payment runs. The result is my team are happier, and our clients are happier

    Edward Kirkby

    Sleek

  • Truly one of the best products in the AP world, massive help in keeping on top of all the invoices we pay and ensuring authorisation prior to payment being released. Very user friendly and the team are a joy to work with.

    Nathan Humphreys

    Jiminny

  • Nook has been a huge benefit to both our team and our clients, making the AP process much quicker and more efficient

    Karen Garrattley

    COS Consultancy

  • Great people, great ethic, always improving their product for customers. Glad to be on board and working alongside you guys

    Anthony Chung

    YardLink

  • Has dramatically reduced the time I spend paying our supplier bills. It used to be a painful part of the month, and now it's easy

    Naz

    Clara

  • Nook supports bulk payment functionality so that we can pay 100s of invoices at once

    Olly Dix

    Prift

Ready to step into the future of payments?

Try Nook for free for 30 days or book a demo with the team to see how it could help your business

Ready to step into the future of payments?

Try Nook for free for 30 days or book a demo with the team to see how it could help your business

Ready to step into the future of payments?

Try Nook for free for 30 days or book a demo with the team to see how it could help your business

Ready to step into the future of payments?

Try Nook for free for 30 days or book a demo with the team to see how it could help your business

© Nook 2023 - Nook is a trading name of Payaable Limited


Payaable Limited (T/A Nook) is an EMD Agent of The Currency Cloud Limited. Payment and e-money  services are provided by The Currency Cloud Limited. Registered in England No. 06323311. Registered Office: Stewardship Building 1st Floor, 12 Steward Street London E1 6FQ. The Currency Cloud Limited is authorized by the Financial Conduct Authority under the Electronic Money Regulations 2011 for the issuing of electronic money (FRN: 900199); 

All testimonials, reviews, opinions or case studies presented on our website may not be indicative of all customers. Results may vary and customers agree to proceed at their own risk.


*Confirmation of Payee is only available in the UK

© Nook 2023 - Nook is a trading name of Payaable Limited


Payaable Limited (T/A Nook) is an EMD Agent of The Currency Cloud Limited. Payment and e-money  services are provided by The Currency Cloud Limited. Registered in England No. 06323311. Registered Office: Stewardship Building 1st Floor, 12 Steward Street London E1 6FQ. The Currency Cloud Limited is authorized by the Financial Conduct Authority under the Electronic Money Regulations 2011 for the issuing of electronic money (FRN: 900199); 

All testimonials, reviews, opinions or case studies presented on our website may not be indicative of all customers. Results may vary and customers agree to proceed at their own risk.


*Confirmation of Payee is only available in the UK

© Nook 2023 - Nook is a trading name of Payaable Limited


Payaable Limited (T/A Nook) is an EMD Agent of The Currency Cloud Limited. Payment and e-money  services are provided by The Currency Cloud Limited. Registered in England No. 06323311. Registered Office: Stewardship Building 1st Floor, 12 Steward Street London E1 6FQ. The Currency Cloud Limited is authorized by the Financial Conduct Authority under the Electronic Money Regulations 2011 for the issuing of electronic money (FRN: 900199); 

All testimonials, reviews, opinions or case studies presented on our website may not be indicative of all customers. Results may vary and customers agree to proceed at their own risk.


*Confirmation of Payee is only available in the UK

© Nook 2023 - Nook is a trading name of Payaable Limited


Payaable Limited (T/A Nook) is an EMD Agent of The Currency Cloud Limited. Payment and e-money  services are provided by The Currency Cloud Limited. Registered in England No. 06323311. Registered Office: Stewardship Building 1st Floor, 12 Steward Street London E1 6FQ. The Currency Cloud Limited is authorized by the Financial Conduct Authority under the Electronic Money Regulations 2011 for the issuing of electronic money (FRN: 900199); 

All testimonials, reviews, opinions or case studies presented on our website may not be indicative of all customers. Results may vary and customers agree to proceed at their own risk.


*Confirmation of Payee is only available in the UK