Data Processing Terms
The Article 28 terms that apply when we process personal data on a customer’s behalf, and who we use to do it.
When these terms apply
These terms apply where an organisation (the “customer”) uses the service and we process personal data on its behalf. The customer is the controller; we are the processor. They form part of the End User Licence Agreement and satisfy Article 28 of the UK GDPR. Where a customer has signed a separate data processing agreement with us, that one applies instead.
What we process, and why
- Subject matter and purpose: providing the service the customer has signed up for, and nothing else.
- Duration: for as long as the customer uses the service, plus the short period needed to delete the data afterwards.
- Nature of the processing: storing, organising, transmitting, displaying, exporting and deleting.
- Categories of data subject: the customer’s personnel who use the service, and anyone they name in the content they create.
- Categories of personal data: account identifiers and usernames; sign-in identifiers, and any name or email address the customer’s sign-in system sends us; content created in the service; records of activity; operational and security records.
- Special category data: none is requested, and the service is not designed to hold it.
What we undertake
- To process personal data only on the customer’s documented instructions, of which the agreement and its own use of the service are the whole set, unless the law requires otherwise — in which case we will tell it first if we are permitted to.
- To keep it confidential, and to ensure the people handling it are bound to do the same and are trained for it.
- To apply appropriate technical and organisational security measures, described at Security, and not to weaken them during the agreement.
- To notify the customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting its data, with the information it needs to meet its own obligations.
- To assist it, at its cost where the work is substantial, in responding to requests from data subjects, and with data protection impact assessments and consultations with a regulator.
- To delete or return the data at the end of the agreement, on request, except where we must keep it by law.
- To make available the information needed to demonstrate compliance, and to allow an audit — by way of our documentation and answers to reasonable questions, or an on-site inspection where a regulator requires one.
Sub-processors
The customer gives general authorisation for the sub-processors below. We remain responsible for their performance and impose equivalent obligations on them.
- Cloudflare, Inc. (United States, with a global network) — hosting, storage and delivery of the service. This is the only sub-processor with access to customer personal data.
We will give at least 30 days’ notice before adding or replacing a sub-processor. If the customer reasonably objects on data protection grounds, it may terminate the affected part of the service without penalty.
A customer’s own sign-in provider is not our sub-processor: the customer chooses and controls it, and it acts for the customer, not for us.
Transfers
Personal data may be processed outside the United Kingdom. Where it is, we put in place the UK International Data Transfer Agreement or the Addendum to the European Commission’s standard contractual clauses, unless the destination is covered by adequacy regulations, and we assess whether the safeguards are effective in practice.
Last updated 29 July 2026.