Data Processing Agreement (DPA)
Last Updated: 18 September 2026
This Data Processing Agreement forms part of the service relationship between the operator of webdesigninwigan.co.uk and any client where personal data is processed on the client’s behalf as part of WordPress web design, website development, website maintenance or related digital services.
This agreement sets out the responsibilities that apply when personal data is processed in connection with those services.
It is intended to support compliance with applicable UK data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018, as amended from time to time.
Throughout this agreement, “we”, “us” and “our” refer to the operator of webdesigninwigan.co.uk.
“Client” refers to the business, organisation or individual engaging our services.
- Roles and Responsibilities
The data protection role of each party depends on the nature of the processing being carried out.
Where we process personal data solely on behalf of and under the documented instructions of the client:
- The client will normally act as the Data Controller
- We will normally act as the Data Processor
The client determines the purposes and essential means of processing the relevant personal data.
We process that data only as necessary to provide the agreed services and in accordance with the client’s documented instructions, unless applicable law requires otherwise.
There may also be circumstances where we act as an independent Data Controller for our own business administration, accounting, enquiries, contractual records or other processing carried out for our own purposes.
- Scope of Processing
The nature and extent of personal data processing will depend on the services being provided.
Processing may take place when carrying out work such as:
- WordPress website design and development
- Website redesigns
- Website migration
- Contact-form configuration
- WooCommerce development
- Booking or appointment system integration
- CRM or email marketing integration
- Website hosting or management
- Website maintenance and support
- Analytics and conversion tracking setup
- Technical website troubleshooting
- Database or content migration
Processing will be limited to what is reasonably necessary to perform the agreed work.
- Types of Personal Data Processed
Depending on the website and services involved, we may process personal data such as:
- Names
- Email addresses
- Telephone numbers
- Postal addresses
- Website enquiry information
- Customer or account information
- Order information
- Booking information
- Website user account information
- Website analytics information
- IP addresses and technical information
- CRM records
- Email marketing records
- Information contained within website databases or backups
The precise categories of data will depend on the client’s website and the scope of services.
The client should not provide special category or highly sensitive personal data unless this is necessary for the agreed service and suitable safeguards have been discussed.
- Categories of Data Subjects
Personal data processed on behalf of a client may relate to individuals such as:
- Website visitors
- Potential customers and enquiries
- Existing customers
- Registered website users
- Subscribers
- Employees or contractors of the client
- Suppliers
- Customers placing ecommerce orders
- People making bookings or appointments
The categories involved will depend on the purpose and functionality of the client’s website.
- Purpose of Data Processing
Personal data may be processed where necessary to design, develop, maintain, migrate, troubleshoot or support a client’s website.
Examples include:
- Configuring contact forms
- Migrating customer or enquiry information between websites
- Configuring ecommerce functionality
- Setting up booking systems
- Integrating CRM or email marketing systems
- Diagnosing website or database problems
- Creating website backups
- Restoring website data
- Configuring analytics or conversion tracking
- Providing ongoing website maintenance
We will not use client-controlled personal data for unrelated purposes.
- Documented Processing Instructions
Where we act as a Data Processor, personal data will only be processed in accordance with the client’s documented instructions.
Instructions may be contained within:
- The project agreement
- The agreed website specification
- Email correspondence
- Support requests
- Written project instructions
If we believe that an instruction may breach applicable data protection legislation, we may inform the client and request clarification before carrying out the instruction.
Where processing is required by applicable law rather than by the client’s instructions, the client will be informed where legally permitted.
- Website Platforms and Systems
Providing WordPress web design and website-support services may require access to or interaction with platforms such as:
- WordPress
- WooCommerce
- Website hosting control panels
- Website databases
- Content delivery networks
- Google Analytics
- Google Search Console
- Contact-form systems
- Booking platforms
- Payment gateways
- Email marketing platforms
- CRM systems
- Backup and security platforms
The particular systems used will depend on the client’s website and project requirements.
Third-party platforms operate subject to their own privacy, security and data-processing arrangements.
- Confidentiality
Personal data accessed while providing services will be treated as confidential.
Any person authorised to process client personal data on our behalf will be required to respect its confidentiality.
Client data will not be disclosed to another party unless:
- This is necessary to provide the agreed service
- The client has authorised the disclosure
- A suitable sub-processor is being used
- Disclosure is required by law
Login credentials and other confidential client information will also be handled with appropriate care.
- Data Security
Reasonable and proportionate technical and organisational measures will be used to protect personal data processed on behalf of clients.
Depending on the circumstances, measures may include:
- HTTPS encrypted connections
- Secure account authentication
- Strong password practices
- Restricted administrative access
- WordPress security controls
- Software updates
- Website backups
- Secure hosting arrangements
- Access controls
- Malware or security monitoring where included in the service
Security measures will be proportionate to the nature of the services and the risks associated with the data being processed.
No online or computer system can provide an absolute guarantee against every possible security incident.
- Sub-Processors
Third-party providers may sometimes be required to process personal data when delivering website services.
Potential categories of sub-processors may include:
- Website hosting providers
- Cloud infrastructure providers
- Backup providers
- Security services
- Email delivery services
- Website form providers
- CRM platforms
- Booking systems
- Ecommerce or payment-related platforms
Where we engage a sub-processor to process client-controlled personal data on our behalf, this will be subject to the client’s prior specific or general written authorisation where required.
Appropriate contractual obligations will be put in place with the sub-processor so that relevant data protection obligations continue to apply.
Where a general authorisation has been provided, reasonable notice may be given before adding or replacing a material sub-processor where appropriate.
- Assistance With Data Subject Rights
The client remains responsible for responding to requests from individuals exercising their data protection rights.
Depending on the circumstances, these rights may include:
- Access to personal data
- Correction of inaccurate information
- Erasure of information
- Restriction of processing
- Data portability
- Objection to certain processing
Where reasonably possible and relevant to the services being provided, we will assist the client in responding to valid data-subject requests relating to data processed on the client’s behalf.
If we receive a request directly concerning client-controlled personal data, we will normally refer the request to the client rather than responding independently unless authorised or legally required to do otherwise.
- Assistance With Data Protection Compliance
Taking into account the nature of the processing and the information available to us, reasonable assistance may be provided where relevant to help the client meet applicable data protection obligations.
This may include assistance relating to:
- Website security
- Personal data breaches
- Data subject requests
- Data Protection Impact Assessments where relevant
- Information about technical website processing
The client remains responsible for its own compliance as Data Controller.
- Personal Data Breaches
If we become aware of a personal data breach affecting personal data processed on behalf of the client, we will notify the client without undue delay.
Where available, the notification may include relevant information about:
- The nature of the incident
- The data potentially affected
- The systems involved
- Measures taken or proposed
The client, as Data Controller, remains responsible for assessing whether notification to the Information Commissioner’s Office or affected individuals is required.
We will provide reasonable assistance where relevant information is available to us.
- International Data Transfers
Some hosting, software, analytics, email, CRM or other third-party services may process data outside the United Kingdom.
Where we initiate a restricted international transfer of client personal data as a processor, appropriate measures will be taken to ensure the transfer complies with applicable UK data protection requirements.
This may include relying on:
- UK adequacy regulations
- Approved contractual safeguards
- The UK International Data Transfer Agreement
- Approved UK additions to recognised contractual clauses
- Other lawful transfer mechanisms where available
Any international transfer made on behalf of a client will remain subject to the client’s documented instructions and applicable legal requirements.
- Data Retention
Personal data processed on behalf of a client will not be intentionally retained for longer than is reasonably necessary to provide the agreed services, subject to legal or contractual requirements.
Retention can depend on:
- The type of website service provided
- Hosting arrangements
- Backup retention periods
- The client’s instructions
- Third-party platform settings
- Legal or accounting obligations
Temporary copies of website data used for migration, testing or troubleshooting will be removed when no longer reasonably required.
- Return or Deletion of Data When Services End
When services involving processing on behalf of the client end, personal data will, at the client’s choice and where technically and legally possible, be:
- Returned to the client
- Deleted
- Removed from systems under our control
Existing copies will also be deleted where appropriate unless applicable law requires their continued retention.
Some information may remain temporarily in automated backup systems until those backups are overwritten in accordance with normal retention schedules.
Access to client systems will normally be removed when it is no longer needed.
- Information, Audits and Compliance
Where we act as a Data Processor, we will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.
Where required by applicable data protection law and subject to reasonable notice, confidentiality and security considerations, we will cooperate with reasonable audits or inspections relating specifically to personal data processed on the client’s behalf.
Any audit request should be proportionate to the nature of the processing and avoid unnecessary disruption to services or the security of other clients.
- Client Responsibilities
The client is responsible for ensuring that it has a lawful basis for collecting and processing the personal data made available through its website or provided to us.
The client is also responsible for matters including:
- Providing lawful processing instructions
- Maintaining an appropriate Privacy Policy
- Providing cookie information and obtaining consent where required
- Responding to data-subject requests
- Determining appropriate data-retention periods
- Ensuring website forms collect only information genuinely required
- Managing permissions for email or direct marketing
- Ensuring employees and authorised users handle personal data appropriately
Website design or technical configuration does not replace the client’s responsibility for its own legal compliance.
- Ecommerce and Payment Information
Where an ecommerce website accepts online payments, payment-card information should normally be processed directly through the chosen payment gateway rather than stored unnecessarily within the WordPress website.
Payment providers operate under their own contractual, security and data-protection arrangements.
Where WooCommerce or another ecommerce platform stores customer details, the client remains responsible for determining appropriate retention periods and ensuring lawful use of that information.
- Website Backups and Development Copies
Website development, migration and maintenance can involve creating temporary staging websites, database exports or backups containing personal data.
Where such copies are created, reasonable steps will be taken to:
- Restrict access
- Avoid unnecessary public accessibility
- Protect login credentials
- Remove temporary copies when no longer needed
Clients should inform us where a website contains particularly sensitive data that requires additional handling arrangements before a copy or migration is undertaken.
- Termination of Services
When the relevant services end:
- Administrative access to client systems will normally be removed where no longer required
- Ongoing processing on behalf of the client will cease
- Personal data will be returned or deleted as described in this agreement
- Temporary development or migration copies will be removed where appropriate
Certain business, contractual, financial or legal records may be retained where we act as an independent Data Controller and where retention is required or justified.
- Changes to This Agreement
This Data Processing Agreement may be updated where necessary to reflect:
- Changes to applicable data protection legislation
- Changes to regulatory guidance
- Changes to WordPress or website services
- Changes to third-party platforms
- Changes to operational or security practices
The latest version will be published on this page together with the current revision date.
Where a separate signed or expressly agreed Data Processing Agreement applies to a particular client, that agreement may take precedence over this general website version to the extent stated within it.
- Contact
If you have any questions regarding this Data Processing Agreement or the way personal data is handled while providing WordPress web design or related website services, please contact me through:
