Data processing agreement
Version 1.0 · Last updated: 28 August 2026
Read this first
This agreement is published in full so you can read it before you sign up, and so your own adviser can read it without asking us for a copy. It applies automatically to every CampSuite® account: there is nothing to request and nothing to countersign.
If your adviser needs a signed copy on paper, or wants a term negotiated, tell us and we will sort it out with them.
1. Parties, and who is who
This data processing agreement ("DPA") is between:
- You, the campsite, park or site operator with a CampSuite account, acting as the controller; and
- WorkBee Limited, a company registered in England and Wales under company number 13120552, whose registered office is 2 Eden Bank, Etterby, Carlisle, CA3 9QS, trading as CampSuite, acting as the processor.
It forms part of, and is governed by, our terms of service. Where this DPA and those terms conflict on the handling of personal data, this DPA prevails.
You are the controller of your guests' personal data. You decide what you collect, why, and how long you keep it. We process it on your instructions in order to provide CampSuite. Where we process data about you - your account, your billing, your support conversations - we are the controller of that, and our privacy policy explains it.
2. Subject matter and duration
Subject matter. Our processing of guest and customer personal data on your behalf so that we can provide the CampSuite booking and site management platform.
Duration. For as long as you have a CampSuite account, and then for the period in clause 10 while data is returned or deleted.
3. Nature and purpose of the processing
We process personal data on your behalf in order to:
- take and hold bookings, including online bookings made by your guests;
- maintain your booking diary, pitch and accommodation allocations;
- send booking confirmations, reminders and the guest messages you configure;
- process card payments through your own connected Stripe account;
- produce your invoices, reports and check-in and check-out records;
- keep your connected booking channels in step with your availability;
- provide support to you, including looking at a booking when you ask us to;
- back up, secure and restore the service.
We do not use your guest data for our own purposes. We do not sell it, share it with advertisers, use it to train models, or use it to market to your guests.
4. Categories of personal data
The data you can hold in CampSuite about a guest:
- name;
- contact details: email address, telephone number, postal address;
- vehicle registration number, where you record it;
- booking details: dates, pitch or unit, party size, prices paid, deposits, extras;
- payment records: transaction references, amounts and status. Card numbers are handled by Stripe and never reach CampSuite;
- anything you choose to type into a booking note or a guest record.
Special category data. CampSuite has no field designed to hold special category data (health, and the other categories in Article 9 UK GDPR). A free-text note will hold whatever is typed into it, so if you record, for example, an accessibility requirement, you are the controller of that and it is your lawful basis it rests on. We ask you not to use booking notes for information of that kind unless you have to.
5. Categories of data subject
- your guests, and the members of their party whose details you record;
- people who enquire but do not book;
- your own staff who hold CampSuite logins.
6. Your instructions
We process personal data only on your documented instructions. Your instructions are:
- this DPA and our terms of service;
- your use of the features and settings in the CampSuite application; and
- anything else you ask us in writing, which we will follow where we can lawfully and technically do so.
If we are required by law to process your data in some other way, we will tell you before we do it, unless the law forbids us from telling you.
If we think an instruction of yours would breach data protection law, we will tell you and we may pause that processing until it is resolved. We will not simply carry it out.
7. Confidentiality
Everyone who has access to your data is bound by a duty of confidence, and access is limited to the people who need it to run the service or to answer a support request. That duty survives the end of their involvement with CampSuite.
8. Security
We take appropriate technical and organisational measures under Article 32 UK GDPR. What is actually in place, described honestly and without marketing language, is on our security page, which is part of this agreement by reference and which we keep current.
In summary: data is encrypted in transit and at rest, access is restricted and authenticated, each site's data is separated from every other site's, we take regular backups, and card data is handled by Stripe rather than by us.
The security page also sets out which third-party certifications CampSuite does and does not hold, so you can see the position rather than infer it.
9. Subprocessors
You give us general authorisation to appoint subprocessors. The current list, with what each one does and where it processes data, is at Subprocessors.
Before we add or replace a subprocessor we will update that page and give you at least 30 days’ notice by email. If you object on reasonable data protection grounds within that period, tell us and we will work with you to find a solution; if we cannot, you may terminate the affected part of the service without penalty and we will refund any fees you have paid for a period after termination.
We impose data protection obligations on every subprocessor that are no less protective than those in this DPA, and we remain liable to you for what they do.
10. Assisting you with data subject rights
You can serve almost every request yourself, without asking us and without waiting for us. From within CampSuite you can find a guest, correct their record, export their data and delete it.
Where you cannot, we will help. If a guest contacts us directly with a rights request about data we hold for you, we will not answer it ourselves: we will pass it to you promptly, because it is yours to answer.
Taking into account the nature of the processing, we will provide reasonable assistance with requests for access, rectification, erasure, restriction, portability and objection, at no charge for a reasonable volume.
11. Assisting you with security and breach obligations
We will help you meet your obligations under Articles 32 to 36 UK GDPR, taking into account the nature of the processing and the information available to us. That includes information you reasonably need for a data protection impact assessment.
Personal data breaches. If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and, in any event, in time for you to meet your own 72-hour obligation to the ICO. Our notification will describe what happened, the categories and approximate numbers affected, the likely consequences and what we are doing about it, so far as we know it at the time. We will keep you updated as we learn more.
Report a suspected security problem to security@campsuite.net.
12. Deletion or return of data
You can export your data at any time while your account is open, and you should do so before you close it.
When your account ends, we delete the personal data we hold for you, and any existing copies, within 30 days, unless we are required by law to keep it. Where we are, we keep only what the law requires, for only as long as it requires, and we stop processing it for any other purpose.
Backups are overwritten on their own cycle in the ordinary course of running the service. Data that has been deleted is not restored to live use from a backup, and a backup is used only to recover the service after a failure.
13. Audits and compliance information
We will make available the information reasonably necessary to demonstrate that we comply with this DPA, and we will co-operate with an audit or inspection you or your auditor conducts.
In practice we would expect most questions to be answered by the security page, this agreement and the subprocessor list, and we would rather answer a specific question properly than send a generic questionnaire back. An on-site audit is available on reasonable notice, no more than once a year unless a regulator requires otherwise or there has been a breach.
14. International transfers
Your guest data stays in the UK and the EEA. The booking and guest personal data we process on your behalf is stored in the United Kingdom and the European Economic Area, and it is not transferred outside them.
Two things sit outside that. Stripe processes payment data in the United States and India as well as in Europe, as its own privacy policy sets out; that is inherent in taking card payments and applies to your own Stripe account. And the analytics, chat, forms and font providers that run on our marketing website process visitor data in the United States. Those have no access to the CampSuite application and never see your guests’ booking data.
Where a provider processes personal data outside the UK and the EEA, we rely on an adequacy decision where one applies to that country, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. The subprocessor list states, provider by provider, where each one processes data.
15. Liability and general
Liability under this DPA is subject to the limits in our terms of service. This DPA is governed by the law of England and Wales.
16. Changes to this agreement
If we change this DPA in a way that materially affects you, we will tell you by email or in the application before it takes effect. The version number and date at the top change every time it does.
17. Contact
Questions about this agreement, or about how we handle data: hello@campsuite.net, or 01228 581035.
WorkBee Limited, a company registered in England and Wales, company number
13120552.
Registered office: 2 Eden Bank
Etterby
Carlisle
CA3 9QS
See also: Subprocessors · Security · Privacy policy · Terms of service