Data Processing Agreement
Table of Contents
Scope and roles
This Data Processing Agreement (“DPA”) applies where we process personal data on your behalf in the course of providing services, and forms part of our Terms of Service.
- You are the Controller — you decide why and how personal data is processed.
- We are the Processor — we process it on your documented instructions.
Where we process data for our own purposes — our marketing, our own website analytics, our business records — we act as Controller and our Privacy Policy applies instead of this DPA.
“Applicable Data Protection Law” means any law governing the processing, which may include the EU and UK GDPR, the California Consumer Privacy Act as amended, and other US state privacy laws.
What we process, and why
| Item | Detail |
|---|---|
| Subject matter | Provision of ecommerce development, integration, analytics, tracking and lifecycle marketing services described in your statement of work. |
| Duration | The term of the engagement, plus the retention period in section 9. |
| Nature and purpose | Collection, structuring, storage, transmission, analysis and deletion of personal data as necessary to build, integrate, measure and operate the systems described in the statement of work. |
| Categories of data subjects | Your customers and prospective customers; your staff who use the systems we build; where relevant, service providers and appointment attendees. |
| Categories of personal data | Contact details (name, email, phone, address); order and transaction records; appointment and service history; online identifiers (cookie IDs, device identifiers, advertising click identifiers, IP address); hashed identifiers used for conversion matching; marketing consent and preference records. |
| Special category data | Not processed, unless expressly agreed in writing with appropriate additional safeguards. CONFIRM — health-adjacent data can arise in medspa or wellness engagements |
Our obligations as processor
- Process personal data only on your documented instructions, including the statement of work, this DPA, and reasonable instructions given during the engagement — unless required otherwise by law, in which case we will tell you first unless the law forbids it.
- Tell you if in our opinion an instruction infringes Applicable Data Protection Law.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement and maintain the technical and organisational measures in section 5.
- Assist you, taking account of the nature of processing, with data subject requests, impact assessments and prior consultation with a supervisory authority.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
We will not sell or share personal data as those terms are defined under US state privacy law, and will not retain, use or disclose it for any purpose other than performing the services.
Your obligations as controller
You are responsible for:
- Having a lawful basis for the processing you instruct, and for obtaining and recording any consent required — including marketing and cookie consent.
- Providing the required privacy notices to your data subjects.
- Ensuring your instructions comply with Applicable Data Protection Law.
- The accuracy of personal data you provide or direct us to collect.
Worth stating plainly: where we implement conversion tracking or lifecycle marketing, the lawful basis and consent for that processing are yours to establish. We build the mechanism and configure it to respect consent signals. We do not warrant that your use of it is lawful.
Security measures
We maintain technical and organisational measures appropriate to the risk, including:
Access control
- Least-privilege access, granted per engagement and reviewed on change.
- Multi-factor authentication on all systems that hold or reach client data.
- Credentials held in a managed secrets store — never in code, tickets, email or chat.
- Access revoked promptly when an engagement ends or a person’s role changes.
Data protection
- Encryption in transit (TLS 1.2 or above) and at rest where the platform supports it.
- Client data kept in your systems and accounts wherever technically possible, rather than copied into ours.
- Production data not used in development or testing environments unless masked or synthetic.
- Hashing of identifiers before transmission to advertising platforms where the integration supports it.
Operational
- Change management with peer review and staging before production deployment.
- Logging and monitoring of access to systems holding personal data.
- Confidentiality obligations and security expectations in all staff and contractor agreements.
- Documented incident response, tested FREQUENCY.
Sub-processors
You give general authorisation for us to engage sub-processors. Each is bound by written terms offering no less protection than this DPA, and we remain fully liable to you for their performance.
Our current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| HOSTING PROVIDER | Application and infrastructure hosting | region |
| CLOUD / STORAGE | Storage and compute for build environments | region |
| ERROR / MONITORING TOOL | Error tracking and uptime monitoring | region |
| COMMUNICATION TOOL | Project communication and file exchange | region |
| ADD ALL OTHERS | — | — |
We will give you 30 days’ written notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is workable, either party may terminate the affected services without penalty.
This table must list every third party that can touch client personal data. An incomplete sub-processor list is one of the most common findings in a client’s vendor security review
International transfers
We are established in the United States and personal data may be processed there and in other countries where our sub-processors operate.
Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer relies on the EU Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail over it in the event of conflict.
We carry out transfer impact assessments where required and apply supplementary measures — including encryption and data minimisation — where appropriate.
Personal data breaches
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting data we process for you.
The notification will describe, as far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. We will provide further detail as the investigation progresses.
We will not make any public statement identifying you in connection with a breach without your prior written consent, unless legally required.
Notifications go to the contact you nominate in the statement of work. Keep it current.
Return and deletion
On termination or expiry of the engagement, at your choice, we will return or delete the personal data we process on your behalf.
- You may request return or deletion within 30 days of the engagement ending.
- After that period we will delete it within a further N days, except where retention is required by law.
- Backups are deleted on their normal rotation cycle rather than individually; until then they remain protected by the measures in section 5.
Because we work in your systems wherever possible, in many engagements we hold little or no client personal data of our own — which is deliberate, and the strongest form of data minimisation available.
Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by you or an auditor you appoint.
- Audits require 30 days’ written notice, occur during business hours, and no more than once in any 12-month period unless required by a supervisory authority or following a breach.
- The auditor must be bound by confidentiality and must not be our competitor.
- You bear your own audit costs. We may charge reasonable fees for time spent beyond N hours.
Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Applicable Data Protection Law does not permit that limitation.
In the event of conflict, the order of precedence is: (1) the Standard Contractual Clauses where they apply, (2) this DPA, (3) the Terms of Service, (4) the statement of work.
Questions, notices and requests under this DPA: contact@aqsashahzad.com, or REGISTERED ADDRESS.