Data Processing Agreement
Your customers' details pass through our systems, so the law requires a written agreement about it. This is that agreement — and it forms part of your contract with us automatically, whether or not you ever read it.
- Version
- 1.0
- In force from
- 2026-08-05
01 Why this exists
When our system texts back a missed call, sends a review request, or takes a booking, it handles the personal data of your customers. Under UK GDPR that makes you the controller — you decide why it happens — and us the processor, acting on your instructions.
Article 28 of the UK GDPR says that relationship has to be in a written contract. This is it. It applies from the moment you become a client and sits alongside our Service Terms.
Plainly Your customers' data belongs to your business. We hold it to run the service you bought, we do nothing else with it, and you can have it back or have it deleted whenever you ask.
02 What we process, and for how long
Subject matter and purpose: operating the system you bought — capturing enquiries, texting back missed calls, taking bookings, sending appointment reminders, and requesting reviews.
Duration: for as long as you are a client, plus the retention periods in clause 8.
Categories of data subject: your customers and enquirers, and the staff of your business who use the system.
Types of personal data: names, phone numbers, email addresses, vehicle or job details submitted with an enquiry, appointment times, message content, and the IP address a form was submitted from.
We do not ask for and do not want special category data — health information, and anything else in Article 9. Don't route it through our forms.
03 What you're promising us
This clause is the one that matters most, and it is the one most agencies leave out.
You confirm that you have a lawful basis for every phone number and email address you give us or collect through the system, and that you are entitled to have us contact those people on your behalf.
That matters because texting and emailing people is governed by PECR as well as UK GDPR. Booking confirmations and reminders for an appointment someone actually made are service messages. A request for a Google review is closer to marketing, and the safe position is that it needs consent. So:
- Our booking forms capture that consent at the point the customer books, with an unticked box and clear wording. Leave it switched on.
- If you hand us a list of past customers to import, you are confirming they agreed to be contacted. We will ask you to confirm that in writing before we import anything.
- Every message we send on your behalf carries an opt-out, and we honour it immediately and permanently.
Plainly If you're not sure whether you can text a particular list, tell us and we won't send to it. A complaint to the ICO lands on your business, not ours — we'd much rather send fewer messages.
04 What we promise you
We will:
- Process personal data only on your documented instructions — this agreement, the service you bought, and anything you tell us in writing afterwards. If the law forces us to do something else, we'll tell you first unless we're legally barred from doing so.
- Tell you if we think an instruction of yours breaks data protection law, rather than quietly doing it anyway.
- Keep it confidential, and make sure anyone with access is under the same duty.
- Never sell it, never share it for anyone else's marketing, and never use it to train an AI model.
- Delete or return it when you leave, as set out in clause 8.
05 Security
The measures we take, so you can see them rather than take our word for it: encryption in transit on every site and endpoint we run; access limited to the people who need it, protected by strong unique credentials and two-factor authentication wherever the platform offers it; daily backups; and sites hardened against the common web attacks — output escaping, subresource integrity, and a broken-link and accessibility audit on every deploy.
We are a small studio and we'd rather be honest about the shape of that: security here rests on a deliberately small number of systems and a short list of people with keys, not on a compliance department.
06 Sub-processors
You agree to us using these, and we'll give you 30 days' notice before adding any other:
- Cloudflare — hosting and delivery (UK/EU edge).
- Stripe — payments.
- <SMS provider> [TO CONFIRM: name the SMS provider] — booking reminders and review requests.
- Google — Business Profile and Search Console, under the access you grant.
- Anthropic — drafting review replies and chatbot answers. Data sent is not retained for training.
Each is bound by terms at least as protective as these, and we stay responsible to you for what they do. If you object to a new one on reasonable data protection grounds, you can leave without notice and we'll refund the unused part of the month.
07 When something goes wrong, or someone asks
Breaches.If personal data we hold for you is breached, we will tell you without undue delay and within 48 hours of becoming aware, with what we know, what we're doing about it, and what we think you need to do. Reporting to the ICO is your call as controller — we'll give you everything you need to make it.
Requests from your customers.If one of your customers asks us directly for their data or asks to be deleted, we will not answer them ourselves — we'll pass it to you within 3 working days and help you respond.
Showing our workings.On reasonable notice, and no more than once a year unless something has gone wrong, we'll give you the information you need to satisfy yourself we're doing what this agreement says.
08 Getting your data back
When you stop being a client, we will give you an export of your data — enquiries, bookings, reviews and customer records — in a standard format, free, on request. No buyout fee, no ransom, no “the data stays with the platform”.
We then delete it, along with backups, within 90 days. The 90-day gap is deliberate: it means changing your mind, or realising a fortnight later that you needed something, doesn't cost you the records. Ask us to delete sooner and we will.
The only exception is anything we're legally required to keep, such as financial records for HMRC.
09 International transfers
Some sub-processors above operate outside the UK. Where they do, the transfer relies on a UK adequacy decision or on the International Data Transfer Addendum to the EU Standard Contractual Clauses. We will not move your data to a new jurisdiction without a lawful transfer route in place.
10 The boring bits
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. If it ever conflicts with our Service Terms, this agreement wins on anything to do with personal data. Nothing here limits either side's obligations under UK GDPR.
The parties are Cawley Digital, a sole trader established in the United Kingdom, of Dene House, Dene Lane, Farnham GU10 3PW, as processor, and you — the business named on the invoice — as controller. No signature is needed: it takes effect when you become a client, and the version in force is the one recorded against your payment.
Questions about any of this? Email [email protected] and you'll get a straight answer from a person.
Straight to a person: [email protected] · +44 7546 894333