Data Processing Agreement
Version 1.0 / 16 August 2026
This is the standard Data Processing Agreement that forms part of all Obrix client contracts. It sets out how we handle your customers' personal data when we build and host your website.
1. Parties
This agreement is between:
- The Client (“Controller”): the business named in the accompanying service agreement.
- Obrix / Castlegate Property Solutions Ltd (“Processor”): Company Number 16122339, registered at 38 Hanover Crescent, Shotton Colliery, DH6 2NR.
2. Background
The Processor provides web design, development, hosting, and related digital services to the Controller. In delivering these services, the Processor may process personal data on behalf of the Controller. This agreement sets out the terms of that processing in line with Article 28 of UK GDPR and the Data Protection Act 2018.
3. Definitions
- Personal data, processing, data subject, controller, processor have the meanings given in UK GDPR.
- Services means the web design, hosting, and management services described in the service agreement.
- Sub-processor means any third party engaged by the Processor to process personal data on behalf of the Controller.
4. Scope of Processing
4.1 Subject matter and duration
The Processor will process personal data for the duration of the service agreement, plus any retention period required by law or agreed in writing.
4.2 Nature and purpose
The processing is carried out to deliver the Services. This typically includes:
- Hosting and serving the Controller's website
- Storing and forwarding contact form submissions
- Sending transactional emails on behalf of the Controller
- Managing client portal accounts and authentication
- Processing payments through integrated payment providers
4.3 Types of personal data
- Contact details (name, email, phone number, address)
- Business information (business name, website URL)
- Messages and enquiries submitted through forms
- Account credentials (hashed passwords, login tokens)
- Payment references (no full card numbers are stored)
- Website usage data (pages visited, IP addresses in logs)
4.4 Categories of data subjects
- The Controller's customers and website visitors
- The Controller's employees or representatives
- Potential customers who make enquiries
5. Processor Obligations
The Processor will:
- Only process personal data on the Controller's documented instructions, unless required by law.
- Make sure anyone who handles the data is bound by confidentiality.
- Put in place appropriate technical and organisational security measures, including encryption in transit (HTTPS/TLS), database access controls, and security headers.
- Only use sub-processors with the Controller's prior authorisation (see Section 7).
- Help the Controller respond to data subject requests (access, deletion, correction, portability) without undue delay.
- Help the Controller meet its obligations around data protection impact assessments and prior consultation with the ICO, where relevant.
- Notify the Controller without undue delay (and within 72 hours where feasible) if the Processor becomes aware of a personal data breach.
- At the end of the service agreement, delete or return all personal data to the Controller, unless the law requires the Processor to keep it.
- Make available to the Controller all information needed to show compliance with this agreement, and allow for audits or inspections at reasonable notice.
6. Controller Obligations
The Controller will:
- Make sure there is a lawful basis for any personal data processed through the Services (for example, consent from website visitors or legitimate interest).
- Provide clear privacy information to data subjects about the processing (a privacy policy on their website).
- Give the Processor documented instructions about what processing to carry out.
- Notify the Processor promptly of any data subject requests that require the Processor's assistance.
7. Sub-Processors
The Controller gives general authorisation for the Processor to use sub-processors listed in the sub-processor register.
The Processor will notify the Controller by email at least 14 days before adding a new sub-processor. The Controller may object in writing within that period. If no resolution can be reached, the Controller may terminate the affected service on 30 days' notice.
The Processor will enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this agreement. The Processor remains fully liable for the acts of its sub-processors.
8. International Transfers
Where personal data is transferred outside the UK, the Processor will make sure appropriate safeguards are in place. This may include Standard Contractual Clauses (SCCs) approved by the ICO, or reliance on an adequacy decision.
Details of each sub-processor's location and transfer safeguards are in our sub-processor register.
9. Security Measures
The Processor maintains the following security measures:
- All data in transit encrypted via TLS/HTTPS
- Database encrypted at rest
- Row-level security policies on database tables
- Security headers on all hosted sites (HSTS, X-Frame-Options, CSP, Referrer-Policy, Permissions-Policy)
- Access limited to authorised personnel only
- Regular review of sub-processor security certifications
- No full payment card data stored on our systems
10. Data Breach Notification
If the Processor becomes aware of a breach of personal data processed under this agreement, the Processor will:
- Notify the Controller without undue delay and within 72 hours where feasible.
- Provide the Controller with enough information to fulfil their reporting obligations to the ICO and affected data subjects.
- Take reasonable steps to contain the breach and minimise any damage.
- Cooperate with the Controller in investigating the breach and meeting regulatory obligations.
11. Data Subject Rights
The Processor will assist the Controller in responding to requests from data subjects exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability, objection). The Processor will respond to such requests from the Controller within 5 working days.
12. Deletion and Return of Data
On termination of the service agreement, or at the Controller's request, the Processor will:
- Return all personal data to the Controller in a common, machine-readable format (such as CSV or JSON), or
- Securely delete all personal data and confirm deletion in writing.
This will be completed within 30 days of the request or termination, unless the law requires the Processor to retain certain records.
13. Liability
Each party's liability under this agreement is subject to the limitation of liability set out in the service agreement between the parties. Nothing in this agreement limits either party's liability for breach of UK GDPR where the law does not permit such limitation.
14. Term
This agreement comes into effect on the start date of the service agreement and continues for as long as the Processor processes personal data on behalf of the Controller. Obligations around deletion, confidentiality, and breach notification survive termination.
15. Governing Law
This agreement is governed by the laws of England and Wales. Any disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.
Signing
This DPA is incorporated into and forms part of the service agreement between the parties. By signing the service agreement, both parties agree to the terms of this Data Processing Agreement.
Controller (Client)
Signed: ________________________________
Name: ________________________________
Date: ________________________________
Processor (Obrix)
Signed: ________________________________
Name: Ryan Whiting
Date: ________________________________