Back to Privacy Policy

Data Processing Agreement

Version 1.0 / 16 August 2026

This is the standard Data Processing Agreement that forms part of all Obrix client contracts. It sets out how we handle your customers' personal data when we build and host your website.

1. Parties

This agreement is between:

2. Background

The Processor provides web design, development, hosting, and related digital services to the Controller. In delivering these services, the Processor may process personal data on behalf of the Controller. This agreement sets out the terms of that processing in line with Article 28 of UK GDPR and the Data Protection Act 2018.

3. Definitions

4. Scope of Processing

4.1 Subject matter and duration

The Processor will process personal data for the duration of the service agreement, plus any retention period required by law or agreed in writing.

4.2 Nature and purpose

The processing is carried out to deliver the Services. This typically includes:

4.3 Types of personal data

4.4 Categories of data subjects

5. Processor Obligations

The Processor will:

  1. Only process personal data on the Controller's documented instructions, unless required by law.
  2. Make sure anyone who handles the data is bound by confidentiality.
  3. Put in place appropriate technical and organisational security measures, including encryption in transit (HTTPS/TLS), database access controls, and security headers.
  4. Only use sub-processors with the Controller's prior authorisation (see Section 7).
  5. Help the Controller respond to data subject requests (access, deletion, correction, portability) without undue delay.
  6. Help the Controller meet its obligations around data protection impact assessments and prior consultation with the ICO, where relevant.
  7. Notify the Controller without undue delay (and within 72 hours where feasible) if the Processor becomes aware of a personal data breach.
  8. At the end of the service agreement, delete or return all personal data to the Controller, unless the law requires the Processor to keep it.
  9. Make available to the Controller all information needed to show compliance with this agreement, and allow for audits or inspections at reasonable notice.

6. Controller Obligations

The Controller will:

  1. Make sure there is a lawful basis for any personal data processed through the Services (for example, consent from website visitors or legitimate interest).
  2. Provide clear privacy information to data subjects about the processing (a privacy policy on their website).
  3. Give the Processor documented instructions about what processing to carry out.
  4. Notify the Processor promptly of any data subject requests that require the Processor's assistance.

7. Sub-Processors

The Controller gives general authorisation for the Processor to use sub-processors listed in the sub-processor register.

The Processor will notify the Controller by email at least 14 days before adding a new sub-processor. The Controller may object in writing within that period. If no resolution can be reached, the Controller may terminate the affected service on 30 days' notice.

The Processor will enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this agreement. The Processor remains fully liable for the acts of its sub-processors.

8. International Transfers

Where personal data is transferred outside the UK, the Processor will make sure appropriate safeguards are in place. This may include Standard Contractual Clauses (SCCs) approved by the ICO, or reliance on an adequacy decision.

Details of each sub-processor's location and transfer safeguards are in our sub-processor register.

9. Security Measures

The Processor maintains the following security measures:

10. Data Breach Notification

If the Processor becomes aware of a breach of personal data processed under this agreement, the Processor will:

  1. Notify the Controller without undue delay and within 72 hours where feasible.
  2. Provide the Controller with enough information to fulfil their reporting obligations to the ICO and affected data subjects.
  3. Take reasonable steps to contain the breach and minimise any damage.
  4. Cooperate with the Controller in investigating the breach and meeting regulatory obligations.

11. Data Subject Rights

The Processor will assist the Controller in responding to requests from data subjects exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability, objection). The Processor will respond to such requests from the Controller within 5 working days.

12. Deletion and Return of Data

On termination of the service agreement, or at the Controller's request, the Processor will:

This will be completed within 30 days of the request or termination, unless the law requires the Processor to retain certain records.

13. Liability

Each party's liability under this agreement is subject to the limitation of liability set out in the service agreement between the parties. Nothing in this agreement limits either party's liability for breach of UK GDPR where the law does not permit such limitation.

14. Term

This agreement comes into effect on the start date of the service agreement and continues for as long as the Processor processes personal data on behalf of the Controller. Obligations around deletion, confidentiality, and breach notification survive termination.

15. Governing Law

This agreement is governed by the laws of England and Wales. Any disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.

Signing

This DPA is incorporated into and forms part of the service agreement between the parties. By signing the service agreement, both parties agree to the terms of this Data Processing Agreement.

Controller (Client)

Signed: ________________________________

Name: ________________________________

Date: ________________________________

Processor (Obrix)

Signed: ________________________________

Name: Ryan Whiting

Date: ________________________________