Processor Terms
Version 1.0, 12 September 2026
These terms apply whenever we handle personal data on your behalf. They form part of our agreement with you, and they exist because Article 28 of the UK GDPR requires both of us to have them in writing.
That obligation runs in both directions. You need these terms with us as much as we need them with you, so nothing here is us asking you to take on something extra. It is the two of us closing the same gap.
Terms in capitals carry the meanings given in the UK GDPR. Where these terms conflict with the rest of our agreement on anything to do with data protection, these ones win.
1. Which of us is which
You are the Controller of the personal data we handle for you, and we are the Processor of it. You decide what is collected and why. We act on what you tell us.
Separately, we are our own Controller of the data we hold for our own purposes, such as our business records and the contact details of people we approach about our services. These terms do not cover that, and our privacy policy does.
2. We act on your instructions
We process your data only on your documented instructions, including on any transfer out of the United Kingdom, unless the law requires otherwise. If the law does require otherwise, we tell you before we act unless we are prohibited from telling you.
Our agreement, these terms and section 10 below are your starting instructions. You can give us further instructions in writing at any time, email included. Work that falls outside what we agreed may be chargeable.
If we think an instruction breaks data protection law, we say so. We may pause the affected work until the instruction is confirmed, corrected or withdrawn.
3. Confidentiality
We keep your data confidential. Anyone we authorise to handle it is under a duty of confidentiality that continues after their involvement ends. Access goes to those who need it for the work, and is withdrawn when it is no longer needed.
4. Security
We apply appropriate technical and organisational measures to protect your data against loss, destruction, alteration and unauthorised access, judged against the risk to the people the data is about. What we actually do is listed in section 11, written to describe our real practice rather than to sound impressive. We can change those measures, but not in a way that lowers the protection.
5. Sub-processors
You give us general authorisation to use the providers named on our sub-processor page, which is part of these terms.
We give you at least fourteen days' written notice before adding or replacing one. You can object on reasonable data protection grounds within that time, and if we cannot resolve it, you can end the affected part of the work without penalty beyond what you already owe.
Each provider is bound by written terms no less protective than these, and we remain responsible to you for what they do.
6. Sending data outside the UK
We do not move your data outside the United Kingdom unless a transfer mechanism recognised by UK law is in place, such as adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses, together with any risk assessment required. The position for each provider is set out on the sub-processor page.
7. Requests from the people the data is about
We help you respond to people exercising their rights under the UK GDPR, as far as we are able and taking into account the nature of the work we do for you.
If someone comes to us directly about your data, we do not answer on the substance. We pass it to you without undue delay.
8. If something goes wrong
We tell you without undue delay, and within twenty four hours at the latest, once we become aware of a personal data breach affecting your data.
We tell you what we know: what happened, roughly how many people and records are affected, what the likely consequences are, what we have done and propose to do, and who to speak to. Anything we do not know yet follows as we establish it.
We do not report a breach of your data to the Information Commissioner or to anyone affected unless you instruct us to, or the law requires it of us directly. That call is yours to make.
We also help you with data protection impact assessments and any prior consultation with the Information Commissioner, taking into account what we know and what we do for you.
9. Getting your data back, and audits
When the work ends, we delete or return your data, whichever you choose, and delete our copies, unless the law requires us to keep something. Tell us which you want within thirty days of the end. If you do not, we delete it.
We are not required to pull data out of routine backups before those backups expire on their normal cycle. Anything still sitting in backup stays covered by these terms until it goes.
Where your site or mailbox runs on accounts you own, what we owe you is to give up our access rather than to delete your own records.
We make available the information you need to check we are doing what this page says, and we allow audits, including inspections. In practice: reasonable written notice of at least thirty days, during business hours, no more than once a year unless there has been a breach or a regulator asks, and confidential. We may answer with current documentation or a provider's own audit reports where those actually answer the question. You cover your own costs, and ours where an audit goes beyond handing over what we already have.
10. What we process for you
Article 28 asks for this in writing, so here it is. Where our agreement with you describes something different, that description applies instead.
- Subject matter and duration
- The design, build, hosting and maintenance of your website, and the automation of your business processes, as set out in our agreement. It runs for as long as that agreement does, plus any period we hold data afterwards under section 9.
- Nature and purpose
- Hosting and serving your website. Receiving and delivering enquiries submitted through forms on it. Holding your site and its content in version control. Building and running automations across systems you use, where you have engaged us for that. Providing support that needs access to any of the above.
- Types of personal data
- Name, email address, telephone number, postal address, the content of an enquiry or message, IP address and other data in server request logs, and anything further you choose to put into a system we build or maintain.
- Categories of people
- Visitors to your website, people who submit an enquiry, your customers and prospective customers, and your own staff where they use a system we build or maintain.
- Special category data
- None is instructed. Health data, and anything else in the special categories or relating to criminal offences, does not go into a system we run without us agreeing it in writing first, so the extra protections it needs can be put in place.
11. What we actually do to keep it safe
- Access control
- Individual named accounts on every service we use, with multi factor authentication switched on. No shared logins. Credentials live in a password manager, never in a repository, a document or a message.
- Least privilege
- We ask for the lowest level of access that lets us do the work, and we give it up when the work ends. We ask to be removed rather than waiting to be removed.
- Encryption
- Every site we host is served over HTTPS with a valid certificate and a redirect from plain HTTP. We do not put a form on a page that is not served over HTTPS. Encryption at rest is provided by the services on our sub-processor page. Our working machine has full disk encryption.
- Collecting less
- Your data is not copied to local storage except where a task needs it, and it is removed when the task is done. Forms are built to collect what you need rather than what a template offers.
- Secrets and changes
- API keys and connection strings are held as environment variables in the hosting platform, and repositories are checked for committed secrets before they are pushed. Work is tracked in version control, deploys are tied to a commit, and any deploy can be rolled back.
- Monitoring
- We rely on the alerting the platforms give us, including sign in alerts and deployment notifications. We do not run a security operations centre and we are not going to claim we do.
- People
- We are a small company. The duty of confidentiality in section 3 is a personal one. Any contractor is put under written confidentiality and data protection terms before being given access to anything of yours.
- Review
- These measures and the sub-processor list are reviewed at least once a year, and whenever a service is added or replaced.
12. Your side of it
You confirm that you have a lawful basis for what you ask us to do, that you have told people what you are doing with their data as Articles 13 and 14 require, and that your instructions do not put us in breach of data protection law.
You are responsible for the accuracy of the data you give us, and for getting any consent needed before we send marketing on your behalf.
13. Term, liability and law
These terms start when our agreement does and continue for as long as we hold your data. Sections 3, 9 and 11 carry on afterwards.
Liability under these terms follows the limits and exclusions in the rest of our agreement, so far as the law allows. Where our agreement says nothing about it, liability is limited to the total fees paid in the twelve months before the claim, except where the law does not permit a limit.
These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
14. Talking to us about this
Data protection questions go to hello@staxxd.co.uk. If you want these terms as a signed document alongside your contract rather than a page on our website, ask and we will send one.
STAXXD LTD, registered in England and Wales under company number 17309142, registered office 128 City Road, London, EC1V 2NX. Registered with the Information Commissioner's Office under reference ZC242922 (as Staxxd Ltd), which you can check on the ICO register of fee payers.