Skip to content

Data Processing Agreement

Version 1.1 · Issued 15 September 2026 · Business client agreement

This agreement applies only where Website Ready processes personal data on a client's behalf, for example during hosting support, maintenance access or troubleshooting. It is signed together with a private, service-specific Processing Record that completes Schedules 1 to 3. It does not cover enquiries sent through this website's own contact form, which are handled as a controller under the Privacy Notice.

Please agree this document and the Processing Record before any client customer data is made available.

1. Parties and interpretation

  • 1.1 This agreement is between David Bray trading as Website Ready (the “Processor”, “we” or “us”), at 13 Aspect House, Hatfield, AL10 8FL, email David@websiteready.co.uk, telephone 07375080076, and the business customer identified in the accepted Order and Processing Record (the “Controller” or “you”). It applies only where we process personal data on your behalf. The effective date is the date of the parties’ documented acceptance of this agreement and the Processing Record.
  • 1.2 “Data Protection Law” means the UK GDPR and Data Protection Act 2018, as amended and in force from time to time, and other applicable UK laws governing the processing under this agreement. “Personal data”, “processing”, “controller”, “processor”, “personal data breach” and “data subject” have their meanings in that law. “Client Data” means the personal data we process on your behalf under the services described in Schedule 1.
  • 1.3 “Main Agreement” means the accepted Order and the Website Ready Business Client Terms and, where applicable, Maintenance Subscription Terms identified in the Processing Record. “Processing Record” means the service-specific written record agreed privately by both parties containing the particulars required by Schedules 1 to 3; it forms part of those schedules and this agreement. “Sub-processor” means a separate person or organisation we engage to process Client Data on your behalf. A working day is Monday to Friday excluding public holidays in England; duties stated to apply without undue delay are not limited to working days.

2. Scope, duration and precedence

  • 2.1 You determine why Client Data is processed and its essential means; we process it on your behalf for the agreed services. Schedule 1 records the subject matter, duration, nature, purposes, data types and categories of people. You retain the rights and duties of a controller, including deciding lawful purposes, retention and disclosures and assessing whether the selected services provide sufficient guarantees.
  • 2.2 This agreement applies throughout the processing, including authorised retention after services end. It does not govern enquiries submitted through Website Ready’s own contact form or our own business contact, billing and administration records, which we handle as a controller under our Privacy Notice. We will not relabel Client Data as our own records to avoid this agreement.
  • 2.3 On personal data matters, this agreement and its completed schedules take priority over the Main Agreement. Mandatory provisions of any applicable international transfer instrument take priority over conflicting provisions here. No Order or instruction permits unlawful processing or removes mandatory obligations.
  • 2.4 Before processing starts, the parties must agree the Processing Record completing the particulars required by Schedules 1 to 3. Changes to scope or instructions must be recorded in writing, including authenticated email or an agreed portal. Supplier changes follow clause 6. Merely publishing these terms or an updated version does not establish client instructions or amend an existing agreement.

3. Instructions and permitted use

  • 3.1 We will process Client Data only on your documented instructions, including instructions about transfers outside the UK, unless applicable UK law requires otherwise. Where legally permitted, we will tell you about a legal requirement before processing and limit processing to what it requires. The agreed services and Schedule 1 are the initial instructions; only your identified authorised contacts may vary them.
  • 3.2 We will immediately inform you if, in our opinion, an instruction infringes Data Protection Law. We may pause the affected processing while the concern is resolved and will not knowingly follow an unlawful instruction. We will notify you if we can no longer comply with this agreement.
  • 3.3 We will not sell Client Data, use it for our own marketing, combine it with other clients’ data for unrelated purposes, or use it to train general AI models. An AI or development tool may receive Client Data only for an expressly documented service purpose, with appropriate contractual safeguards, supplier approval and lawful transfer arrangements. General permission to use AI-assisted development is not permission to disclose Client Data to any AI service.
  • 3.4 You will supply lawful instructions, necessary notices and permissions, minimise the data made available, and identify any special requirements. We remain responsible for our own statutory and contractual duties; your instructions or approval do not excuse our breach.

4. Confidentiality and access

  • 4.1 Access is limited to authorised people who need Client Data for the service and are bound by confidentiality commitments or appropriate statutory duties. We will give relevant privacy and security guidance, review permissions and remove access promptly when no longer needed. These duties continue after access or the services end.
  • 4.2 We will use Client Data only within approved systems and maintain appropriate separation between clients. We will not place Client Data or secrets in public repositories, publicly accessible previews or unapproved shared accounts.

5. Security measures

  • 5.1 We will implement and maintain appropriate technical and organisational measures meeting Article 32 of the UK GDPR, taking account of the state of the art, implementation costs, the processing and risks to individuals. Schedule 2 sets the agreed minimum controls and their implementation for this service.
  • 5.2 Measures will address confidentiality, integrity, availability and resilience; appropriate encryption or pseudonymisation; timely restoration after an incident; and regular checks of effectiveness. The appropriate backup and recovery arrangements must be recorded in Schedule 3. No system is guaranteed immune from a breach, but that does not reduce our obligations.
  • 5.3 We may improve or replace measures without reducing the overall protection. Material reductions require prior written agreement and must still comply with law. We will keep proportionate records of controls, relevant incidents, instructions and compliance, including processing records required by law, and cooperate with the competent supervisory authority.

6. Sub-processors

  • 6.1 You give general written authorisation for the sub-processors recorded in Schedule 3, including any specifically identified, dated downstream register incorporated into it. No blank entry or generic reference to “cloud providers” grants authorisation. We will assess that each supplier provides sufficient guarantees and enter into a binding written contract imposing equivalent applicable data protection obligations before it receives Client Data.
  • 6.2 We remain fully liable to you for a sub-processor’s performance of its data protection obligations as required by Article 28. A supplier’s standard terms do not reduce our duties to you. We will ensure that further delegation is subject to equivalent controls and an effective change-notice and objection process.
  • 6.3 We will give at least 30 calendar days’ written notice before a new or replacement sub-processor receives Client Data. The notice identifies the entity, purpose, locations, relevant safeguards and any overseas transfer mechanism. You may object on reasonable data protection grounds within 14 calendar days of the notice. Without objection, the change is authorised when the notice period expires. An accelerated change requires your express written approval.
  • 6.4 We will work in good faith to address a timely objection, for example through another provider or avoiding the affected processing. We will not disclose Client Data to the disputed provider while the objection remains unresolved. If no workable solution is available before the proposed change, either party may end the affected service without an early termination penalty; unused prepaid service fees will be refunded and clause 10 applies.
  • 6.5 A supplier contracted directly by you is not automatically our sub-processor. Schedule 3 must record the actual role and contracting arrangement. We still follow your lawful instructions and protect data when configuring or accessing that supplier. The contracting label does not override the facts of the processing.

7. International transfers

  • 7.1 We will process Client Data only in the locations and through the access arrangements documented in Schedule 3. Before making a restricted transfer, including overseas access where it constitutes such a transfer, we will ensure it is instructed or authorised and a valid route under UK transfer law is in place.
  • 7.2 The schedule must identify any applicable UK adequacy arrangement or the executed safeguards, such as an appropriate UK International Data Transfer Agreement or EU Standard Contractual Clauses with the UK Addendum. Where required, the responsible party will complete and document the data protection test or transfer risk assessment and implement necessary supplementary measures. We will provide reasonable information and assistance and comply with our own transfer duties.
  • 7.3 This agreement and your general approval are not themselves a transfer safeguard. Naming the UK Addendum does not execute it. Required instruments and their annexes must be completed and binding before the transfer. We will reassess relevant changes and suspend the affected transfer if a lawful basis or required protection ceases to be available.

8. Personal data breaches

  • 8.1 We will notify your incident contact without undue delay after becoming aware of a personal data breach affecting Client Data. We will not wait for a completed investigation or defer notification to the next working day. If the primary contact cannot be reached, we will use the agreed alternative contact route.
  • 8.2 The initial notice will provide what is then known about the incident, affected systems, categories and approximate numbers of people and records, likely consequences, containment or remedial actions, and our contact for follow-up. Missing information will follow in stages without undue delay, with updates as material facts become available.
  • 8.3 We will take prompt reasonable steps to contain and remedy the breach, preserve appropriate evidence and assist your assessment, record keeping and any required notifications. We will provide an incident account and corrective actions when reasonably available.
  • 8.4 You decide whether and how to notify individuals and the supervisory authority in your controller role. We will not make those notifications on your behalf without instructions unless legally required, and will inform you where permitted. Nothing here delays or restricts either party’s own legal duties.

9. Assistance, information and audits

  • 9.1 Taking account of the nature of processing, we will assist through appropriate technical and organisational measures, insofar as possible, with requests to exercise data subjects’ rights. We will forward requests concerning Client Data without undue delay and normally within two working days. We will not decide their merits or respond substantively without your instructions unless required by law.
  • 9.2 Taking account of the processing and information available to us, we will assist with your obligations under Articles 32 to 36, including security, breach notification, data protection impact assessments and prior consultation with the supervisory authority. We will respond in time to support applicable legal deadlines, which you should communicate promptly.
  • 9.3 We will make available the information necessary to demonstrate compliance with Article 28 and this agreement and allow and contribute to audits, including inspections, by you or an auditor you appoint. Documentary review may be used first where it meets the purpose, but does not replace an inspection where needed.
  • 9.4 Routine audits should have at least 10 working days’ notice, occur at reasonable times and protect other clients’ confidentiality and security. Shorter notice and additional audits are permitted where needed because of a breach, reasonable compliance concerns, a regulator’s requirement or a legal deadline. Confidentiality arrangements and reasonable site safeguards must not prevent effective oversight.
  • 9.5 Routine compliance information and assistance are included. Substantial additional work may be charged only at reasonable rates agreed in advance, excluding work required to remedy our breach. A fee dispute will not block mandatory assistance, an audit right or urgent action necessary to meet a legal deadline. You normally bear the costs of your chosen auditor; liability for loss caused by breach remains governed by clause 11.

10. Return, deletion and retention

  • 10.1 At the end of the relevant services or on your lawful instruction, you choose whether we return or securely delete Client Data. Unless Schedule 3 expressly records another period, we will provide the agreed usable export and/or delete active copies within 30 calendar days. On return, we will subsequently delete remaining copies except as set out below. We will also instruct relevant sub-processors to return or delete the data.
  • 10.2 Schedule 3 records your exit choice. If none was recorded, we will promptly seek instructions and protect and isolate the data pending them. If no reply is received within 30 days after service end, we will give a final 14-day written notice before secure deletion; this fallback does not override a timely return request or a legal duty.
  • 10.3 Backup copies that cannot reasonably be erased individually must remain protected and beyond ordinary use and expire on the finite deletion cycle recorded and justified in Schedule 3 before processing starts. We will ensure that this arrangement complies with Data Protection Law; a supplier’s convenience does not justify indefinite retention. If restored for disaster recovery, deleted data must be removed again before ordinary use resumes.
  • 10.4 If applicable UK law requires retention, we will identify the legal basis and period where permitted, isolate the retained data and use it only for that requirement. An ordinary preference to retain data is not a legal requirement. We will confirm completion of return or deletion in writing and state any protected residual copies and their deletion dates.
  • 10.5 Client Data will not be withheld as security for unpaid invoices. Basic return and deletion are included; additional migration work may be quoted separately but will not prevent the required return or deletion. Protection, confidentiality and relevant audit duties continue while any Client Data remains.

11. Responsibility and general provisions

  • 11.1 Each party remains responsible for its own obligations under Data Protection Law. Contractual limits in the Main Agreement apply between the parties only to the extent lawful and consistent with mandatory obligations. They do not bind the supervisory authority, restrict data subjects’ statutory rights or reduce protections in a mandatory transfer instrument. No provision authorises unlawful reimbursement of a regulatory penalty.
  • 11.2 You may require suspension of affected processing where we are in breach. If a material breach cannot be remedied or remains unremedied after the cure period in the Main Agreement, you may terminate the affected service. No cure period requires continued unsafe or unlawful processing. Return, deletion, refunds and accrued rights remain applicable.
  • 11.3 Notices may be sent to the agreed email addresses; urgent breach notifications use the routes in Schedule 1. Both parties must keep those details current. This agreement may be accepted electronically and forms part of the Main Agreement. If a provision is unenforceable, the remainder continues so far as legally possible.
  • 11.4 The law of England and Wales and the dispute provisions of the Main Agreement apply, subject to mandatory data protection law and applicable transfer instruments. An ordinary contractual dispute procedure must not delay urgent protective action, assistance or cooperation with the supervisory authority.

Schedule 1 — Processing instructions

  • The privately agreed Processing Record identifies the Controller’s legal name and address, covered website, Order reference, effective date, relevant Main Agreement versions, authorised instruction contacts, primary and alternative incident contacts, and agreed communication channels. Website Ready’s contact is David Bray at David@websiteready.co.uk or 07375080076.
  • It specifies the subject matter, nature and purposes of processing, service duration and access frequency, types of personal data, categories of data subjects, approximate scale, collection and disclosure arrangements, and retention instructions. It identifies only operations needed for the agreed service, such as website hosting, maintenance access, troubleshooting, export or deletion. No processing is authorised merely because it is technically possible.
  • Special category data, criminal offence data, identity documents, full payment card details, children’s data and client legal case files are excluded unless expressly agreed with the necessary lawful basis and safeguards. Unexpected sensitive information must be contained and referred to the Controller for instructions. Any use of live data for development or AI tools requires specific documented authorisation under clause 3.

Schedule 2 — Security arrangements

We will implement the following measures for the agreed processing. The Processing Record specifies the systems, responsibilities and implementation details, including any adequate alternatives needed for a particular platform. Measures must be appropriate to the actual risks before Client Data is processed.

  • Access and devices: limit access to authorised people who need it; use named accounts and multi-factor authentication for administrative systems where supported; protect credentials in a suitable password or secrets manager; review permissions regularly and remove unnecessary access promptly. Keep devices supported, updated, access-controlled and encrypted where they store Client Data, with screen locking and appropriate malware protection.
  • Data handling and development: use encrypted connections for administration, transfers and website collection of personal data. Apply encryption at rest where appropriate to the risks. Restrict exports, separate client permissions and prevent public access to private data, backups, repositories and previews. Use synthetic or appropriately de-identified test data where practical. Any authorised live-data copy must have limited access and retention; secrets must not be included in code or logs.
  • Maintenance and recovery: apply supported security updates within timescales appropriate to the risk and address critical known exposures promptly or isolate affected processing. Maintain appropriate availability, resilience and recovery measures under clause 5. The Processing Record must identify backup coverage, responsibilities, retention and restoration arrangements appropriate to the processing, with proportionate restoration checks. A platform’s version history must not be treated as a verified backup of all Client Data.
  • People and verification: maintain confidentiality commitments, proportionate security guidance, supplier checks, incident procedures and secure deletion arrangements. Review the effectiveness of controls regularly and after material changes or significant incidents. Retain proportionate evidence of reviews, incidents and remedial action without unnecessarily duplicating personal data.

Schedule 3 — Suppliers and data lifecycle

  • Before any supplier receives Client Data, the Processing Record identifies its legal entity, service, actual role and contracting party, purpose, data categories, storage locations and remote-access countries. It identifies binding processing terms and their acceptance, authorised downstream suppliers or a dated incorporated register, and applicable change-notice arrangements. Generic references to a platform or cloud service do not authorise an unidentified sub-processor.
  • For each restricted international transfer, the record identifies the applicable adequacy route or executed transfer instrument, relevant parties and dates, any required assessment and supplementary safeguards. No restricted transfer may start until its lawful arrangements are in place.
  • The record sets live-data retention, temporary-copy deletion, backup coverage and expiry, recovery responsibilities, restoration arrangements, the Controller’s return-or-delete choice, a usable export format and secure delivery route, and any legally required retention. Active return and deletion follow the 30-day default in clause 10.1 unless a different lawful period is expressly agreed. Backup expiry must be finite and verified with the relevant provider before processing starts.

Acceptance

The parties accept this agreement version 1.1 and the privately completed Processing Record by signature, authenticated email or an equivalent documented acceptance identifying the complete agreement and its attachments. Each person accepting confirms authority to bind their party. Each party retains a dated copy. The Processing Record supplies the client-specific particulars of Schedules 1 to 3 and is part of the binding agreement.