Last updated: [09 February 2026]
1. Purpose of This Agreement
This Data Processing Agreement (“Agreement”) explains how personal data is processed by the website development and maintenance agency (“the Data Processor”) on behalf of website owners or operators (“the Data Controller”), in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Agreement applies to all websites supported, built, or maintained by the Data Processor, unless otherwise agreed in writing.
2. Roles and Responsibilities
- The Data Controller is the business or individual that owns or operates the website and determines the purposes and means of processing personal data.
- The Data Processor is the digital agency providing website-related services and processes personal data solely on the documented instructions of the Data Controller.
The Data Processor does not act as an independent controller and does not use personal data for its own marketing or commercial purposes.
3. Scope of Processing
The Data Processor may process personal data strictly as necessary to provide website-related services, including:
- Website design, development, and maintenance
- Theme and plugin installation, configuration, and updates
- Managing contact and enquiry form functionality (including delivery and storage where enabled)
- Website security monitoring and troubleshooting
- Analytics configuration and performance monitoring
- Cookie consent configuration and script control using consent management tools
4. Categories of Personal Data and Data Subjects
4.1 Categories of Personal Data
- Names
- Email addresses
- Telephone numbers
- Contact or enquiry form submissions
- IP addresses
- Device and browser information
- Website usage and log data
4.2 Categories of Data Subjects
- Website visitors
- Prospective customers
- Individuals submitting enquiries via the website
5. WordPress, Plugins, and Consent Management
Websites supported by the Data Processor typically operate on WordPress and may use plugins and third-party tools, including contact forms, analytics, security tools, and cookie consent management platforms.
Where a cookie consent solution is in place, it is used to manage consent preferences, control script loading based on user choices, and present cookie information to website visitors. The Data Processor may configure and maintain these tools on behalf of the Data Controller.
The Data Processor does not control the content of form submissions or communications between the Data Controller and website users.
6. Sub-Processors
The Data Controller authorises the Data Processor to engage sub-processors where necessary to deliver website services.
- Website hosting providers
- Security and performance service providers
- Analytics and measurement tools
- Third-party integrations enabled by the Data Controller (for example maps, fonts, or spam protection services)
The Data Processor ensures that sub-processors are subject to appropriate data protection obligations.
7. Security Measures
The Data Processor implements appropriate technical and organisational measures to protect personal data, including:
- Restricted access to administrative systems
- Secure authentication methods
- Use of reputable security tools and monitoring solutions
- Regular updates to website software, themes, and plugins
8. Personal Data Breach Management
If the Data Processor becomes aware of a personal data breach affecting a supported website, it will notify the Data Controller without undue delay.
The Data Controller remains responsible for determining whether notification to the ICO or affected individuals is required, unless otherwise agreed.
9. Assistance With Data Subject Rights
The Data Processor will reasonably assist the Data Controller with requests relating to data subject rights, including access, rectification, erasure, restriction, and objection, where technically feasible.
If the Data Processor receives a request directly from a data subject, it will forward the request to the Data Controller unless legally prohibited from doing so.
10. Data Retention, Return, and Deletion
The Data Processor does not independently determine retention periods for website data. Retention settings are controlled by the Data Controller through website configuration, plugins, or hosting environments.
Upon termination of services, the Data Processor will, at the Data Controller’s request and where reasonably practicable, remove access and delete or return personal data within its control.
11. Confidentiality
The Data Processor ensures that any individuals authorised to process personal data are subject to appropriate confidentiality obligations.
12. Liability
Nothing in this Agreement limits liability where such limitation is not permitted by law. Any liability arising under this Agreement is subject to the limitations set out in the applicable service terms between the Data Controller and the Data Processor.
13. Governing Law
This Agreement is governed by the laws of England and Wales.
What This Means for Website Owners
This Data Processing Agreement explains how your website agency may handle personal data strictly for technical and support-related purposes, such as maintaining your website, managing plugins, improving performance, and ensuring security. You remain the Data Controller and are responsible for deciding what personal data is collected and how it is used. The agency does not use your website visitors’ data for its own purposes and only processes personal data in line with your instructions and applicable data protection laws.
Schedule 1 – Typical Website Tools and Services
The following tools and services may be used on websites supported by the Data Processor. Not all tools are used on every website.
| Tool / Service | Purpose | Type of Data Processed |
|---|---|---|
| WordPress CMS | Website content management | Contact form data, technical logs |
| Divi Theme / Builder | Website layout and design | No direct personal data |
| Contact Form 7 (or similar) | Handling enquiries | Name, email, telephone, message content |
| Form database storage (where enabled) | Storing form submissions | Contact form data |
| Wordfence (or similar) | Website security and firewall | IP addresses, access logs |
| Independent Analytics | Privacy-focused analytics | Anonymous or pseudonymised usage data |
| Complianz (or similar) | Cookie consent management | Consent preferences |
| Google services (where enabled) | Analytics, spam prevention, maps, fonts | IP address, usage data |
| Website hosting provider | Infrastructure and hosting | Server logs, IP addresses |
Acceptance
By using or continuing to use websites supported by the Data Processor, the Data Controller acknowledges and accepts the terms of this Data Processing Agreement.