HOROBENCH
Data processing terms
Last updated: 24 September 2026
These terms form part of the HoroBench subscription agreement between the workshop (the controller) and Bimodal Ltd (the processor) when the workshop enters customer or job personal data into HoroBench. They apply for the duration of the workshop account and only to that workshop’s customer data.
Processing instructions
The subject is the customer and job information the workshop enters or shares. Processing includes storage, retrieval, display, backup, sending workshop-directed transactional messages, making customer links available and supporting the service. Data may include customer names, contact details, addresses, watch details, photographs, communications, quotes, invoices and payment status. Data subjects may include customers, watch owners, workshop contacts and message recipients.
We process this data only on the workshop’s documented instructions, including its use of HoroBench and these terms, unless UK law requires otherwise. We will tell the workshop before legally required processing unless the law prohibits notice. We will inform the workshop if, in our opinion, an instruction infringes applicable data protection law.
Our commitments
- People authorised to handle the data must be bound by confidentiality.
- We will use appropriate technical and organisational security measures, including access controls, tenant separation and protected storage, and review them as risks change.
- Taking account of the nature of processing and the information available to us, we will help the workshop respond to data-subject requests and meet its security, breach notification and impact-assessment obligations.
- We will tell the workshop without undue delay after becoming aware of a personal-data breach affecting its data and provide information reasonably needed for its response.
- At the end of service, we will return or delete the data at the workshop’s choice, subject to legal retention requirements and normal backup deletion cycles. Contact us to arrange an export and deletion.
- We will provide information reasonably needed to demonstrate compliance with these terms and allow proportionate audits or inspections on reasonable notice, subject to protecting other workshops and confidential systems.
Service providers and transfers
The workshop gives general authorisation for us to use Microsoft Azure for application hosting and private storage and Resend for transactional email. We will impose equivalent data-protection obligations on subprocessors and remain responsible for their performance. We will notify the workshop of intended subprocessor changes and give a reasonable opportunity to object before the change. Stripe processes customer payment information when a workshop chooses to connect its own account; its role and separate terms depend on that connection.
We will not transfer workshop customer data outside the UK except on the workshop’s documented instructions or with a valid transfer mechanism under applicable law. Ask hello@horobench.com for current subprocessor locations and transfer details.
Workshop responsibilities
The workshop decides what customer data to enter, the purposes and lawful basis, what to share with customers, and how long its records are needed. It must give required privacy information to its customers and use HoroBench in accordance with applicable law.
