Data Processing Agreement
ThisWebDesign Ltd · Effective 28 June 2026
This Data Processing Agreement (the “DPA”) governs our processing of personal data on your behalf when you use TWD Platform. It forms part of our Terms of Service and applies where, in using the platform, you act as a controller and ThisWebDesign Ltd acts as your processor, for example, the personal data you hold about your own customers, clients and contacts. It is designed to meet Article 28 of the UK GDPR.
1. Roles and scope
You are the controller and we are the processor in respect of the Customer Data you process through the platform. Each party will comply with its obligations under UK data protection law. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex A.
2. Our obligations as processor
We will:
- Process on your instructions. Process Customer Data only on your documented instructions, which include your configuration and use of the platform, unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it.
- Confidentiality. Ensure that personnel authorised to process Customer Data are bound by confidentiality.
- Security. Implement appropriate technical and organisational measures to protect Customer Data, as described in Annex B.
- Sub-processors. Engage sub-processors only under the terms of section 3.
- Assistance with data-subject rights. Taking into account the nature of the processing, assist you with appropriate measures to respond to requests from data subjects exercising their rights.
- Assistance with compliance. Assist you in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to us.
- Breach notification. Notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information you reasonably need to meet your own notification obligations.
- Deletion or return. On the end of the service, delete or return Customer Data at your choice, and delete existing copies unless the law requires us to keep them.
- Audits. Make available the information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, on reasonable notice and subject to confidentiality.
3. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our sub-processors page. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give you reasonable notice of any intended addition or replacement of a sub-processor so you can object on reasonable data-protection grounds.
4. International transfers
Customer Data is stored in the United Kingdom (Amazon Web Services Europe (London) Region (eu-west-2)). Where a sub-processor processes Customer Data outside the UK, that transfer is made under an appropriate transfer mechanism. Where a sub-processor processes personal data outside the UK (for example payment or communications providers operating in the United States), that transfer is made under the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with the provider’s own data processing agreement and technical safeguards such as encryption in transit and at rest.
5. Your obligations as controller
You confirm that you have a lawful basis for the personal data you process through the platform, that you have given any privacy notices and obtained any consents required, and that your instructions to us comply with data protection law. You are responsible for the accuracy, content and legality of the Customer Data.
6. Liability and precedence
This DPA is subject to the limitations and exclusions of liability in the Terms of Service. If there is a conflict between this DPA and the rest of the Terms on the processing of personal data, this DPA prevails.
Annex A: Details of processing
- Subject matter: provision of the TWD Platform service to you.
- Duration: for the term of your subscription and any agreed deletion/return period after it.
- Nature and purpose: hosting, storage, organisation, retrieval, transmission and other processing operations needed to provide the platform’s modules you use (for example contact records, billing documents, messaging, forms, scheduling and websites).
- Types of personal data: as determined by you, typically identification and contact details, account and transaction data, communications content, and any other data you choose to enter.
- Categories of data subjects: as determined by you, typically your customers, clients, contacts, staff and other individuals whose data you process.
Annex B: Technical and organisational measures
We maintain measures appropriate to the risk, including:
- encryption of personal data in transit and at rest;
- role-based access controls on a least-privilege basis, with authentication and the option of multi-factor or one-time-code sign-in;
- logical separation of each workspace’s data and entitlement-gated access to modules;
- audit logging of significant actions and security events;
- resilient, access-controlled cloud infrastructure in the United Kingdom with managed backups;
- processes to detect, report and respond to personal data breaches.
Annex C: Sub-processors
The current list of authorised sub-processors is maintained at our sub-processors page.
To raise a data-protection matter under this DPA, contact privacy@thiswebdesign.co.uk.