Skip to content
NewFree build & growth audit — we scope it, price it, no obligation.
All systems operationalUK · WORLDWIDETalk to us
Legal · Last updated 3 October 2026

Data Processing Addendum

The terms that apply when we handle personal data on your behalf, for example in hosting, CRM and software products, website management or marketing work. They set out the commitments UK GDPR Article 28 requires.

1. Scope and how this addendum applies

This Data Processing Addendum ("DPA") forms part of the agreement between you, our client, and Devute Ltd, a private limited company registered in England and Wales (company number 14301159), whose registered office is at 53 Leafield Avenue, Bradford, England, BD2 3SE ("we", "us"), including our Terms of Business, Subscription Terms and any proposal, order or statement of work (together, the "Main Agreement").

It applies whenever we process personal data on your behalf in providing services to you, including managed hosting, email services, our CRM and other software products, website and eCommerce management, and marketing and advertising management. It does not apply to personal data we process for our own purposes as a controller, such as your account and billing details, which are covered by our Privacy Policy.

If there is a conflict between this DPA and the Main Agreement about the processing of personal data, this DPA takes priority. Terms such as "controller", "processor", "personal data", "personal data breach", "processing" and "data subject" have the meanings given in the UK GDPR.

2. Roles of the parties

For the personal data covered by this DPA, you are the controller and we are your processor. Where you are yourself a processor acting for another controller, we act as your sub-processor and you confirm you have that controller's authority to appoint us.

You are responsible for making sure you have a lawful basis for the processing, that you have given data subjects any notices required, and that your instructions to us comply with data protection law. We are responsible for complying with the obligations that the UK GDPR and the Data Protection Act 2018 place on processors.

3. Details of the processing

ItemDetails
Subject matterThe provision of the services described in the Main Agreement.
DurationFor the term of the Main Agreement and any period afterwards until we delete or return the personal data as described below.
Nature and purposeHosting, storing, backing up, transmitting, organising, displaying and otherwise processing personal data as needed to provide, support, secure and maintain the services; building and maintaining websites, applications and integrations; sending email on your instruction; and setting up, managing and reporting on advertising and marketing campaigns.
Types of personal dataDepending on the service: names and contact details; account and login data; enquiry, order and transaction records; communications content; website usage, device and online identifiers; and any other personal data you or your users choose to store in or send through the services.
Categories of data subjectsYour website visitors, customers, prospects and leads, staff and contractors, users of your systems, email recipients and any other individuals whose data you store in or send through the services.
Special category dataNot expected unless agreed in writing. If you need us to process special category or criminal offence data, you must tell us first so that we can agree suitable safeguards.

4. Processing only on your instructions

We will process the personal data only on your documented instructions, including with regard to transfers outside the UK, unless UK law requires us to do otherwise. In that case we will tell you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

The Main Agreement, this DPA and your use and configuration of the services are your documented instructions. Additional instructions must be given in writing, for example by email or through the client portal. If we believe an instruction breaches data protection law, we will tell you promptly. Instructions that go beyond the agreed scope of the services may be chargeable, and we will quote before doing the work.

5. Confidentiality

We will make sure that everyone we authorise to process the personal data, including our staff and contractors, is under a written or statutory duty of confidentiality and only has access to the extent needed to provide the services.

6. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing and the risks to individuals, we will put in place appropriate technical and organisational measures as required by Article 32 of the UK GDPR. These include, as appropriate to the service:

  • encryption of data in transit and, where supported by the platform, at rest;
  • role-based access controls, least-privilege access and strong authentication for our staff;
  • regular backups and the ability to restore access to data in a timely manner after an incident;
  • keeping systems and software we manage patched and up to date;
  • monitoring and logging to detect and respond to security events;
  • regularly reviewing these measures and the providers we use.

You are responsible for the security of anything under your control, including your users' credentials, the permissions you grant, and content or software you install yourself.

7. Sub-processors

You give general authorisation for us to engage sub-processors. The categories we currently use are: cloud and application hosting (for example Vercel), database hosting (for example Supabase), hosting infrastructure providers (for example 20i), email and communication providers, and, for advertising work, the advertising platforms you instruct us to use. We will give you details of the sub-processors relevant to your services on request.

We will give you at least 14 days' notice before adding or replacing a sub-processor, by email or through the client portal. You may object on reasonable data protection grounds within that period. If you do, we will discuss your concerns in good faith. If we cannot resolve them, either of us may end the affected service by written notice, and we will refund any fees you have paid in advance for the period after it ends.

We will impose data protection obligations on each sub-processor that give at least the same level of protection as this DPA, as required by Article 28(4) of the UK GDPR, and we remain responsible to you for their performance of those obligations.

Advertising platforms such as Google, Meta and TikTok may act as independent controllers for some of the data they receive, in which case their own terms apply between you and them.

8. Help with data subject rights and compliance

Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures where possible, to respond to requests from individuals exercising their rights under the UK GDPR, such as access, rectification, erasure, restriction, portability and objection. If we receive such a request directly, we will pass it to you without undue delay and will not respond to it ourselves except on your instructions.

We will also give you reasonable help, taking into account the information available to us, with your obligations on security, personal data breach notification, data protection impact assessments (DPIAs) and prior consultation with the Information Commissioner's Office. Help that goes beyond what is reasonably included in the services may be charged at our usual rates, and we will tell you before doing chargeable work.

9. Personal data breaches

If we become aware of a personal data breach affecting the personal data we process for you, we will notify you without undue delay and in any event within 48 hours of becoming aware of it.

Our notice will include, as far as the information is available at the time: a description of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take to address the breach and reduce its effects; and a contact point for more information. Where information is not available at first, we will provide it in stages as it becomes available.

We will take reasonable steps to contain and investigate the breach and will co-operate with you so that you can meet your own obligations, including any notification to the Information Commissioner's Office within 72 hours and to affected individuals. Our notifying you of a breach is not an admission of fault or liability.

10. International transfers

Some of our sub-processors are based in, or process data in, the United States or other countries outside the UK. We will only transfer personal data outside the UK, or allow a sub-processor to do so, where the transfer complies with Chapter V of the UK GDPR, for example because:

  • the country is covered by UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework for certified US organisations; or
  • the transfer is covered by the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed following a transfer risk assessment.

You authorise these transfers for the purpose of providing the services.

11. Deletion or return at the end of the services

When the services that involve the processing end, we will, at your choice, return the personal data to you in a commonly used format or delete it. Please tell us your choice within 30 days of the end of the services. If you do not, we will delete it.

We will delete existing copies within a reasonable time, except where UK law requires us to keep them. Data in backups will be deleted in line with our normal backup cycle, and until then it will remain protected by this DPA and will not be actively processed.

12. Information and audits

We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR and this DPA, and will allow for and contribute to audits, including inspections, carried out by you or an independent auditor you appoint who is bound by confidentiality.

To keep audits proportionate, we will first try to answer your questions in writing. Any on-site audit must be requested with at least 30 days' written notice, take place during normal business hours, avoid disrupting our business or breaching our obligations to other clients, and normally take place no more than once in any 12 months unless a regulator requires it or there has been a personal data breach. Each party will bear its own costs unless the audit reveals a material breach by us.

13. Liability and general terms

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Main Agreement, except where the law does not allow liability to be limited.

This DPA continues for as long as we process personal data on your behalf, even after the Main Agreement ends. If any part of it is found to be invalid, the rest will continue to apply. We may update this DPA to reflect changes in the law or our services, and will give you reasonable notice of any change that materially affects you. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

For any question about this DPA, or to request a signed copy, email info@devute.com.

Devute Ltd · Registered in England and Wales, company number 14301159 · Registered office: 53 Leafield Avenue, Bradford, England, BD2 3SE · info@devute.com