Last updated: [09 February 2026]

1. Purpose of This Agreement

This Data Processing Agreement (“Agreement”) explains how personal data is processed by the website development and maintenance agency (“the Data Processor”) on behalf of website owners or operators (“the Data Controller”), in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Agreement applies to all websites supported, built, or maintained by the Data Processor, unless otherwise agreed in writing.

2. Roles and Responsibilities

The Data Processor does not act as an independent controller and does not use personal data for its own marketing or commercial purposes.

3. Scope of Processing

The Data Processor may process personal data strictly as necessary to provide website-related services, including:

4. Categories of Personal Data and Data Subjects

4.1 Categories of Personal Data

4.2 Categories of Data Subjects

5. WordPress, Plugins, and Consent Management

Websites supported by the Data Processor typically operate on WordPress and may use plugins and third-party tools, including contact forms, analytics, security tools, and cookie consent management platforms.

Where a cookie consent solution is in place, it is used to manage consent preferences, control script loading based on user choices, and present cookie information to website visitors. The Data Processor may configure and maintain these tools on behalf of the Data Controller.

The Data Processor does not control the content of form submissions or communications between the Data Controller and website users.

6. Sub-Processors

The Data Controller authorises the Data Processor to engage sub-processors where necessary to deliver website services.

The Data Processor ensures that sub-processors are subject to appropriate data protection obligations.

7. Security Measures

The Data Processor implements appropriate technical and organisational measures to protect personal data, including:

8. Personal Data Breach Management

If the Data Processor becomes aware of a personal data breach affecting a supported website, it will notify the Data Controller without undue delay.

The Data Controller remains responsible for determining whether notification to the ICO or affected individuals is required, unless otherwise agreed.

9. Assistance With Data Subject Rights

The Data Processor will reasonably assist the Data Controller with requests relating to data subject rights, including access, rectification, erasure, restriction, and objection, where technically feasible.

If the Data Processor receives a request directly from a data subject, it will forward the request to the Data Controller unless legally prohibited from doing so.

10. Data Retention, Return, and Deletion

The Data Processor does not independently determine retention periods for website data. Retention settings are controlled by the Data Controller through website configuration, plugins, or hosting environments.

Upon termination of services, the Data Processor will, at the Data Controller’s request and where reasonably practicable, remove access and delete or return personal data within its control.

11. Confidentiality

The Data Processor ensures that any individuals authorised to process personal data are subject to appropriate confidentiality obligations.

12. Liability

Nothing in this Agreement limits liability where such limitation is not permitted by law. Any liability arising under this Agreement is subject to the limitations set out in the applicable service terms between the Data Controller and the Data Processor.

13. Governing Law

This Agreement is governed by the laws of England and Wales.

What This Means for Website Owners

This Data Processing Agreement explains how your website agency may handle personal data strictly for technical and support-related purposes, such as maintaining your website, managing plugins, improving performance, and ensuring security. You remain the Data Controller and are responsible for deciding what personal data is collected and how it is used. The agency does not use your website visitors’ data for its own purposes and only processes personal data in line with your instructions and applicable data protection laws.

Schedule 1 – Typical Website Tools and Services

The following tools and services may be used on websites supported by the Data Processor. Not all tools are used on every website.

Tool / ServicePurposeType of Data Processed
WordPress CMSWebsite content managementContact form data, technical logs
Divi Theme / BuilderWebsite layout and designNo direct personal data
Contact Form 7 (or similar)Handling enquiriesName, email, telephone, message content
Form database storage (where enabled)Storing form submissionsContact form data
Wordfence (or similar)Website security and firewallIP addresses, access logs
Independent AnalyticsPrivacy-focused analyticsAnonymous or pseudonymised usage data
Complianz (or similar)Cookie consent managementConsent preferences
Google services (where enabled)Analytics, spam prevention, maps, fontsIP address, usage data
Website hosting providerInfrastructure and hostingServer logs, IP addresses

Acceptance

By using or continuing to use websites supported by the Data Processor, the Data Controller acknowledges and accepts the terms of this Data Processing Agreement.

Before you go...

Claim Your Complimentary Website SEO Review Now