In plain English. When we host your website or pass on its form messages, we handle your customers' personal data for you. You stay in charge as the "controller". We act only on your instructions as your "processor". We keep the data secure and only use the providers on our sub-processor list. We give you 30 days' notice before adding a new one. We tell you about any breach without undue delay, and we aim to do it within 48 hours. We help you answer your customers' requests, and we delete or return the data within 30 days after our work ends. The numbered clauses below are the binding terms.
1. About this addendum
1.1 This Data Processing Addendum ("DPA") is Schedule 3 to our Terms of Business. It is made between Northpin Studio (an independent studio; the person who runs it is named in the Order Form) ("we", "us"), and the business named in the Order Form ("you").
1.2 It applies whenever we process Client Personal Data for you while providing the services in your Order Form. For example, when we host your website, pass on its form messages, keep backups, make changes under a care plan or hand your website over.
1.3 It becomes part of the Agreement when you sign the Order Form, so you don't need to sign it separately. It is the written contract required by Article 28(3) and 28(9) of the UK GDPR and, where it applies, the EU GDPR.
2. Definitions
2.1 Words defined in the Terms of Business have the same meaning here. In addition:
- "Agreement" means your Order Form, our Terms of Business and their schedules.
- "Client Personal Data" means personal data we process for you under the Agreement, as described in Annex 1.
- "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018 (as amended, including by the Data (Use and Access) Act 2025), the Privacy and Electronic Communications Regulations 2003 and, where they apply to the processing, the EU GDPR (Regulation (EU) 2016/679) and national laws implementing the EU ePrivacy Directive.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorised disclosure of or access to, Client Personal Data.
- "Sub-processor" means another processor we engage to process Client Personal Data.
- "Transfer Clauses" means, as relevant: the International Data Transfer Agreement issued by the UK Information Commissioner ("IDTA"); the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner ("UK Addendum"); and the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 ("EU SCCs").
- "Working day" means Monday to Friday, except public holidays in England.
2.2 "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the Data Protection Laws.
3. Roles and scope
3.1 For Client Personal Data, you are the controller and we are your processor.
3.2 For the personal data we use to run our own business, such as your staff's contact details, our emails with you and billing records, we are a controller, not your processor. Our privacy notice covers that data.
3.3 Annex 1 sets out the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects.
4. Instructions and confidentiality
4.1 We process Client Personal Data only on your documented instructions, including about transfers outside the UK or the European Economic Area, unless the law requires us to do otherwise. If it does, we'll tell you before we process the data, unless the law forbids that on important grounds of public interest.
4.2 Your instructions are the Agreement and any further instructions you give us in writing. An email from a contact named in your Order Form counts as writing. Instructions that change the scope or cost of our services follow the change process in the Terms of Business.
4.3 We'll tell you straight away if we think an instruction breaks the Data Protection Laws. We may pause that instruction until you confirm or change it.
4.4 Everyone we authorise to process Client Personal Data, whether us or a freelancer working on your project, is bound by a duty of confidentiality. They only get access to the data they need for their task.
5. Security
5.1 We'll take appropriate technical and organisational measures to protect Client Personal Data, as Article 32 requires. We'll take into account the state of the art, the costs, the nature, scope, context and purposes of the processing, and the risks to people's rights and freedoms. Annex 2 lists the minimum measures we apply.
5.2 We may update our measures over time, but we won't lower the overall level of protection.
6. Sub-processors
6.1 You give us general written authorisation to use the sub-processors on our sub-processor list on the date you sign the Order Form. You also authorise any freelancer named in your Order Form or approved by you later in writing.
6.2 We'll email you at least 30 days before we add or replace a sub-processor that processes Client Personal Data. The email will say who it is, what it will do and where it will process the data. We'll update the list at the same time.
6.3 You may object on reasonable data protection grounds by emailing us within those 30 days. We'll discuss it with you in good faith and try to offer a reasonable alternative. If we can't resolve it, you may end the affected services by written notice before the change takes effect. We'll refund any fees you've paid in advance for the period after they end, and no early-exit charge or remaining minimum-term payment will apply to those services. This doesn't cancel amounts payable for a Build. On a No-Build-Fee Plan, clause 10.9 of the Terms applies.
6.4 If we must replace a sub-processor urgently, for example for security reasons or because a provider stops its service, we may give shorter notice. We'll tell you as soon as we can, and your right to object in clause 6.3 still applies.
6.5 We'll have a written contract with each sub-processor that gives Client Personal Data protection at least equivalent to this DPA, including sufficient guarantees about security. We remain fully responsible to you for how our sub-processors meet those obligations.
7. International transfers
7.1 We're based in the UK. Where the EU GDPR applies to your data and you send it to us, the European Commission's adequacy decision for the UK covers that transfer. If that decision stops applying, the EU SCCs (Module 2, controller to processor) will apply between us, and are incorporated into this DPA by reference.
7.2 We'll only transfer Client Personal Data outside the UK and the European Economic Area, or let a sub-processor do so, where the transfer is lawful. For example:
- to a country covered by UK adequacy regulations or an EU adequacy decision, including US organisations certified under the UK Extension to the EU–US Data Privacy Framework or the EU–US Data Privacy Framework
- under the IDTA or the UK Addendum, for UK data, or the EU SCCs (Module 3, processor to processor), for EU data, with any extra measures needed
7.3 Our sub-processor list shows the safeguard used for each sub-processor.
7.4 Where the EU SCCs apply under this DPA, the details they need come from this DPA. Annex 1 completes their Annex I, and Annex 2 completes their Annex II. Sub-processors are covered by general authorisation with the notice period in clause 6.2. The EU SCCs are governed by the law of Ireland, and disputes under them go to the courts of Ireland. Where the IDTA or the UK Addendum applies, it is governed by the law of England and Wales.
8. Helping you meet your duties
8.1 Requests from individuals. Taking into account the nature of the processing, we'll help you respond to people who use their data protection rights, such as access, correction, deletion, restriction, portability and objection. We'll do this through appropriate technical and organisational measures, as far as possible. If someone sends a request to us directly, we won't answer it ourselves, except to say we've passed it on. We'll forward it to you within 5 working days.
8.2 Security, breaches and assessments. Taking into account the nature of the processing and the information available to us, we'll help you meet your duties under Articles 32 to 36. These cover security, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
8.3 Cost. Reasonable help under this clause is included in your plan. If a request needs significant time, we'll give you an estimate first and may charge our hourly rate of £60. We won't charge if the help is needed because we broke this DPA.
9. Personal data breaches
9.1 If we become aware of a Personal Data Breach affecting Client Personal Data, we'll tell you without undue delay. Our target is to tell you within 48 hours of becoming aware of it.
9.2 We'll tell you, as far as we know it:
- what happened and when
- the categories and approximate number of people and records affected
- the likely consequences
- what we've done, or plan to do, to deal with it and reduce any harm
- who you can contact for more information
If we don't have all this information at once, we'll send it in stages, without further undue delay.
9.3 We'll take reasonable steps to contain and investigate the breach, record it in our breach log and work with you. You decide whether to report it to the ICO or another supervisory authority, and whether to tell the people affected. We won't do either for you unless you ask us to or the law requires it.
9.4 Telling you about a breach is not an admission of fault or liability.
10. Deletion or return at the end
10.1 When our services involving Client Personal Data end, we'll delete or return the data, as you choose, within 30 days. If you haven't told us your choice by the end date, we'll delete it. This happens alongside the handover described in the Terms of Business. Where clause 27.3 of the Terms applies (fees unpaid when the Care Plan ended), the 30 days start when the time in that clause runs out.
10.2 Our backups are overwritten on a rolling 30-day cycle, so backup copies are also gone within 30 days of the end.
10.3 We'll only keep a copy where the law requires us to. If we do, this DPA keeps protecting it, and we'll only use it for that legal purpose.
10.4 If you ask, we'll confirm the deletion in writing.
11. Audits and information
11.1 We'll give you all the information reasonably needed to show that we meet Article 28 and this DPA. We'll allow, and contribute to, audits and inspections by you or an independent auditor you appoint.
11.2 To keep audits proportionate for a small business:
- we'll first answer your reasonable written questions and share relevant documents, such as our security measures and our sub-processors' certifications or audit reports
- if that isn't enough, you may carry out an audit with at least 30 days' written notice, during normal working hours, no more than once in any 12 months, with your auditor bound by confidentiality
- the once-a-year limit doesn't apply after a Personal Data Breach, or when a supervisory authority requires an audit
- you pay your own costs and our reasonable time at our hourly rate, unless the audit shows we materially broke this DPA
11.3 We audit our sub-processors, such as Cloudflare, through the reports and certifications they publish or provide. We'll share these with you where their terms allow.
11.4 We'll tell you straight away if we think an instruction under this clause breaks the Data Protection Laws.
12. Your responsibilities
12.1 As the controller, you're responsible for having a lawful basis for the processing you ask us to do, and for your other duties under the Data Protection Laws. These include your website's privacy notice, any cookie consent your website needs, and answering your customers' requests.
12.2 Your instructions to us must comply with the Data Protection Laws.
12.3 Tell us in writing before your website collects special category data, such as health information in a clinic's booking form, or data about criminal offences, so we can agree any extra safeguards. We won't set up forms to collect that data unless you ask and we've agreed it in writing.
12.4 Any privacy or cookie notice templates we supply for your website are for convenience only. They are not legal advice, and you remain responsible for your own compliance.
13. Liability, duration and precedence
13.1 Each party's liability under or in connection with this DPA is subject to the limits and exclusions in the Terms of Business, except where the Data Protection Laws or the Transfer Clauses don't allow it to be limited. Nothing in this DPA limits either party's liability to data subjects under the Transfer Clauses.
13.2 This DPA lasts for as long as we process Client Personal Data for you. That includes the time after the Agreement ends until deletion or return is complete. Clauses 9 to 11 and this clause 13 continue after it ends, for as long as they are needed.
13.3 If documents conflict, this order of precedence applies:
- the Transfer Clauses, where they apply, prevail over this DPA
- this DPA prevails over the rest of the Agreement for anything about the processing of personal data
- the English version of this DPA prevails over any translation
13.4 This DPA is governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, as set out in the Terms of Business, except where the Transfer Clauses say otherwise.
13.5 We may update this DPA to keep it in line with the Data Protection Laws or guidance from a supervisory authority. We'll email you at least 30 days before a change takes effect. Any change that reduces the protection of Client Personal Data needs your written agreement.
Annex 1: Details of the processing
The processing
- Subject matter: the personal data we need to process to provide the website services in your Order Form.
- Duration: the term of the Agreement, plus up to 30 days afterwards for deletion or return (clause 10), or longer where clause 27.3 of the Terms applies.
- Nature: hosting, storing, transmitting and forwarding, backing up, retrieving, changing (when we make edits you ask for) and deleting data. This includes hosting business mailboxes and forwarding email for your domain, where your plan includes them. We only collect data through your website's forms as you ask us to set them up.
- Purpose: to host, secure, maintain and support your website, to deliver messages sent through its forms to you, to run business mailboxes and email forwarding for your domain where your plan includes them, and to hand the website over when our services end.
- Frequency: continuous, for as long as the services run.
- Retention: with our standard setup, form messages are passed to the inbox you choose and not stored by us after delivery. Backups are kept for 30 days on a rolling basis. Everything else is kept until our services end, then handled under clause 10.
Categories of data subjects
- visitors to your website
- your customers and potential customers who contact you or book through your website
- people who email you at addresses on your domain that we host or forward for you
- your staff, and anyone else whose details or photos appear on your website
Types of personal data
- technical data our hosting provider uses to deliver and protect your website: IP address, browser and device details, pages requested, date and time
- anything people send through your website's forms, such as name, phone number, email address, postal address, message and booking details
- emails sent to or from business mailboxes or forwarding addresses we set up for you, including their contents and attachments
- personal data in your website's content, such as staff names, photos and short biographies, and any reviews you choose to show
- visitor statistics, if you ask us to switch on cookieless analytics (totals only, no cookies)
Special category data: none, unless agreed in writing under clause 12.3. Any extra safeguards we agree will be recorded in your Order Form.
Sub-processors and contacts
- Sub-processors: as shown on our sub-processor list, plus any freelancer you approve under clause 6.1.
- Our contact: privacy@northpin.studio
- Your contact: the person named in your Order Form.
Annex 2: Security measures
Access control
- Multi-factor authentication on every account that can reach Client Personal Data, including hosting, DNS, domain registrar, email, code repositories and our password manager.
- Least privilege: only people who need access for your project get it, at the lowest level they need. We remove access within 1 working day when it's no longer needed.
- Individual accounts, never shared logins.
- Your passwords and access details are kept only in an encrypted password manager, never in email or chat.
Encryption
- Every website we host uses HTTPS (TLS 1.2 or higher).
- Data is encrypted at rest by our hosting and storage providers.
- Work laptops and phones use full-disk encryption and an automatic screen lock.
- Backups are encrypted.
Backups and recovery
- Versioned backups of website files and content, kept for 30 days on a rolling basis.
- We test restoring a website from backup at least every 6 months.
Updates and patching
- Operating systems, browsers and apps update automatically.
- Critical and high-risk security updates are installed within 14 days of release.
- Website code dependencies are checked for known vulnerabilities at least once a month. Critical issues are fixed, or safely worked around, within 14 days.
Website and network security
- Cloudflare protection against denial-of-service attacks, plus its firewall and bot protection, on every website we host.
- Where possible, websites are built as static pages, with no database or public admin login to attack.
- Form spam is caught with hidden fields and server-side checks, not tracking tools.
Keeping data to a minimum
- Forms collect only the fields you ask for.
- We don't put Client Personal Data into AI tools.
- Tests and demos use made-up data, never real customer data.
People and process
- Everyone with access is bound by confidentiality and a written contract with data protection terms.
- We follow a written breach response plan and keep a breach log (clause 9).
- We review these measures at least once a year, and after any significant incident.
- Devices are wiped securely before they are reused or disposed of.