Data Processing Agreement
Last updated: 27 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Sephton Connect ("we", "us", "Processor") and the client named in your service agreement ("you", "Controller") for the website design, build and hosting services we provide. It applies wherever we process personal data on your behalf as part of those services, such as personal data submitted through your website's enquiry or quote form.
1. Roles
You're the data controller for personal data collected through your website, such as your customers' names, phone numbers and email addresses submitted via enquiry or quote forms. We act as your data processor for that data, processing it only on your instructions and for the purpose of providing you with your website and hosting service.
2. Subject matter and duration
This DPA applies for as long as we provide you with website design, build, hosting or related services, and ends when that relationship ends, subject to clause 7 below.
3. Nature and purpose of processing
We process personal data submitted through your website's forms in order to build, host, operate and maintain your website, including receiving, storing, and where relevant forwarding enquiry or quote form submissions to you.
4. Categories of data and data subjects
Personal data processed typically includes names, phone numbers, email addresses, and any other information your customers choose to include in an enquiry or quote form. Data subjects are visitors to your website who submit a form.
5. Our obligations as processor
We will:
- Process personal data only on your documented instructions, unless required to do otherwise by law.
- Keep personal data confidential and ensure our staff are subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures to protect personal data.
- Assist you, where reasonably possible, in responding to data subject requests, such as access or erasure requests, and in meeting your other obligations under UK GDPR.
- Notify you without undue delay if we become aware of a personal data breach affecting your data.
- Delete or return personal data to you at the end of our services, except where we're required to retain it by law.
6. Sub-processors
We use third party sub-processors to help deliver your website and hosting service, such as form handling providers, for example Netlify Forms or Formspree, and our hosting infrastructure provider. These sub-processors are bound by their own data protection obligations. We'll give you reasonable notice of any new sub-processor so you can raise any objections.
7. International transfers
Where a sub-processor stores or processes data outside the UK, appropriate safeguards are used, such as Standard Contractual Clauses or the UK International Data Transfer Addendum, as provided by that sub-processor.
8. Audits
On reasonable request, we'll provide you with the information reasonably necessary to demonstrate compliance with this DPA.
9. Liability
This DPA doesn't create any additional liability beyond what's set out in our Terms of Service.
10. Contact
Questions about this DPA can be sent to sephtonconnect@gmail.com.