Last updated: 2026

Data Processing Agreement

This Data Processing Agreement sets out the terms under which DLR Media acts as a Processor of personal data on behalf of the Controller, in accordance with the UK GDPR and applicable Data Protection Legislation.

Data Processing Agreement

BY & BETWEEN

Both parties acknowledge that for the purposes of Data Protection the Controller is the Controller and DLR Media is the Processor.

The contact details of the Processor Contact Person is: sales@dlrmedia.co.uk, ICO Reg ZB641897

Duration of Agreement

Start Date: April 2024

End Date: March 2025

Background & Scope

The Controller determines the purposes and means of processing personal data in connection with its business activities.

The Processor processes personal data on behalf of the Controller.

The Controller wishes to engage the services of the Processor to process personal data on its behalf.

The UK GDPR provide that, where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of the Regulation and ensure the protection of the rights of the data subject.

The UK GDPR provides that, the Processor shall not engage another Processor without prior specific or general written authorisation of the Controller.

The UK GDPR provides that, the Processor and any person acting under the authority of the Controller or of the Processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by law.

In compliance with the above-mentioned provisions of The UK GDPR the Controller and Processor wish to enter into this processing agreement.

The parties hereby mutually agree the following:

Definitions and Interpretation

In this agreement the following words and phrases shall have the following meanings, unless inconsistent with the context or as otherwise specified:

"Appendix 1" means the appendix to this agreement and which forms part of this agreement.

"Law(s)" means all laws or statutes of any jurisdiction and any other regulation, ordinance, order, decree, or rule having the force of law, whether in in existence as of the Effective Date or promulgated thereafter, as amended, or superseded, to the explicit exclusion of Customer specific legal sources.

"Personal Data" means any information relating to a Data Subject. The relevant categories of personal data that are provided to the Controller.

"Controller/Data Controller" means the main decision maker when it comes to how an individual's personal data is handled and kept safe.

"Processor/Data Processor" means any person (other than an employee of the data controller) who processes the data on behalf of the data controller.

"Data Subject" means the identified or identifiable living individual to whom personal data relates.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

"Supervisory Authority" is an authority responsible for monitoring the application of GDPR in order to protect the fundamental rights and freedoms of individuals in relation to processing, and to facilitate the free flow of personal data within the EU.

"Processing" means gathering or use of personal data by a Processor in accordance with the instructions of the controller based on a contract.

"Confidential data" means all data disclosed by a party to the other party pursuant to this agreement which is either designated as proprietary and/or confidential, or by its nature or the nature of the circumstances surrounding disclosure, should reasonably be understood to be confidential, including (but not limited to), data on products, customer lists, price lists and financial data.

"Special Categories of Personal Data (i.e., sensitive Personal Data)" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the process of genetic data, biometric data for the purpose of uniquely identifying an individual, data concerning health or data concerning an individual's sex life or sexual orientation.

"Sub-processor" means any subcontractor engaged by the Processor to perform a part of the services and who agrees to receive personal data intended for processing on behalf of the Customer.

"EU GDPR" means REGULATION (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

"UK GDPR" means regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act of 2018.

"Data Protection Legislation" means the data protection and privacy legislation which is in force in the UK, and it includes the Data Protection Act 2018, the UK GDPR and the Privacy and Electronic Communications Regulations 2003.

"Services" means business support the services is described more in detail in Appendix 1.

"Sub-contract" and "sub-contracting" shall mean the process by which either party arranges for a third party to carry out its obligations under this agreement.

2. Consideration

In consideration of the Controller engaging the services of the Processor to process personal data on its behalf, the Processor shall comply with the security, confidentiality and other obligations imposed on it under this agreement and any applicable Data Protection Legislation.

3. Processing Details

3.1 Purpose of the processing

DLR Media provides Hosting, Infrastructure, technical and branding design support to the Controller to enable specific functionality of the digital virtual sites as directed by the Controller. This includes but is not limited to the following: -

Social Media Services: Managing and optimising social media accounts and content to enhance digital presence.

Graphic Design and Content Services: Creating and designing graphics and content to support branding and marketing efforts.

Marketing & Lead Generation Services: Executing and managing paid advertising & communication campaigns, including Google Ads, SEO, and Meta Ads.

Email/SMS Campaigns: Email or SMS design, management and distribution using business or personal data supplied and collected by the Controller i.e. Mailchimp, Klaviyo etc.

CRM Design and Management: Set up, design & management of CRM system, including potential input or management of business or personal data supplied and collected by the Controller.

Outbound Email Campaigns (B2B): Connection of outsourced data sources, set up and management of domains and outbound B2B email prospecting campaigns.

Website Development and Maintenance: Designing, developing, and maintaining websites to ensure optimal functionality and user experience.

Domain Name Registration and Renewals: Managing the registration, renewal, and administration of domain names.

Hosting Services: Providing reliable hosting solutions to ensure the availability and performance of digital platforms.

3.1a) Platform Providers & AI-Assisted Services

The Processor may utilise third-party platforms, hosting providers, infrastructure providers, artificial intelligence systems, APIs and integrated software services in the delivery of the Services.

Such platforms and systems may process, host, transfer or store Personal Data on behalf of the Controller.

The Controller acknowledges that certain Services may involve AI-assisted development, automated workflows, authentication systems, analytics tools and cloud-hosted infrastructure.

DLR Media undertakes to only process personal data for the purposes outlined above.

3.2 Nature of the processing

Social Media Services: Reviewing and aggregating user engagement data from various social media platforms, analysing metrics such as likes, shares, comments, and follower growth using analytic profiling, creating, and scheduling content, optimising post timing, content relevance, and continuously monitoring based on performance insights and trends.

Graphic Design and Content Services: Gathering brand requirements and market research data, using design software to create visually appealing graphics, drafting content that aligns with branding guidelines & profiling data, iterating designs based on feedback, optimising files for various media formats, and coordinating the distribution of the final materials across marketing channels.

Marketing & Lead Generation Services: Conducting research and competitive analysis, creating, and targeting ad content, setting up and configuring campaigns across platforms like Email, CRM's Google Ads, SEO, and Meta Ads, monitoring ad performance metrics such as click-through rates and conversions, optimising bids and budgets based on real-time data, A/B testing ad variations, and generating detailed performance reports to refine and improve future campaigns.

Email/SMS Campaigns: Reviewing and aggregating user engagement data platforms, analysing metrics such as open rate, click throughs and user type using analytic profiling. Creating and scheduling content, optimising distribution timing, content relevance, and continuously monitoring based on performance insights and trends.

CRM Design and Management: Analysing, profiling and categorising data and customer classification to enable efficient provision of products and services, and administration of customer accounts.

Outbound Email Campaigns (B2B): Reviewing and aggregating user engagement data platforms, analysing metrics such as open rate, click throughs and user type using analytic profiling. Creating and scheduling content, optimising distribution timing, content relevance, and continuously monitoring based on performance insights and trends.

Website Development and Maintenance: Gathering end user feedback and conducting usability research, resolving technical issues, and continuously monitoring site analytics to enhance user experience and functionality.

Domain Name Registration and Renewals: Searching for available domain names, registering chosen domains through accredited registrars, securely storing registration details, monitoring expiration dates, executing timely renewals to prevent lapses, updating DNS settings as needed, managing domain transfers, and ensuring compliance with relevant policies and regulations.

Hosting Services: Configuring and managing server hardware and software, setting up and maintaining network infrastructure, monitoring server performance and uptime, implementing security measures to protect against cyber threats such an encryption, providing regular backups and recovery solutions, scaling resources to meet traffic demands, and offering technical support to resolve hosting-related issues promptly.

3.2a) Controller Responsibility for Personal Data

The Controller remains solely responsible for determining:

the categories of Personal Data collected;

the purposes for which Personal Data is processed;

the lawful basis for processing;

retention periods;

access permissions and user roles;

privacy disclosures; and

compliance with applicable Data Protection Legislation.

Where the Processor configures, develops or supports applications, websites or systems on behalf of the Controller, such activities shall be carried out solely in accordance with the Controller's instructions.

The Processor shall not be responsible for determining whether the Controller's intended processing activities comply with applicable Data Protection Legislation.

3.2B AI-Assisted Outputs

Certain Services may involve the use of artificial intelligence or automated systems to generate content, workflows, code, recommendations or configurations.

The Controller remains responsible for reviewing, testing and approving all outputs prior to use.

3.3 Categories of Personal Data Delete as needed.

Personal

Professional Life

Sensitive Data

Special Category

Criminal Offence

It is not intended to capture sensitive or special category data in enquiry forms however it may be provided in the free text part of the form by the potential or existing customer.

3.3a) Restricted Categories of Data

Unless expressly agreed in writing by the Processor, the Controller shall not use the Services to process or store:

special category personal data;

protected health information;

payment card information;

biometric data;

criminal offence data; or

any highly regulated or sensitive information.

Where such data is processed without written agreement, the Controller accepts full responsibility for compliance with applicable Data Protection Legislation.

3.4 Access

Access is restricted to 4 people Access is limited and managed through our password management application as well as IT security policies & procedures.

3.5 Storage & Processing

BWF Hosting Ltd, Unit 8c Kilroot Business Park, Carrickfergus, BT38 7PR. ICO registration ZB664270

Data Centre Location:

Maidenhead data centre UK & East Antrim Data Centre (Northern Ireland) provides state of the art security measures to ensure data integrity and security, all our UK data centres comply with ISO 9001, ISO 27001, ISO 22301, and PCI DSS standards.

CRM System - Capsule (Ziesta Ltd), 20 Dale Street, Manchester, M1 1EZ, info@zestia.com, Data Centre - AWS, ICO Z2696014.

Payments - Stripe Payments, 9th Floor, 107 Cheapside, London, EC2V 6DN, privacy@stripe.com, Data Centre - AWS, ICO ZB223812

GoCardless, Sutton Yard, 65 Goswell Road, London EC1V 7EN, privacy@gocardless.com, ICO ZA024862

The Processor may also utilise cloud hosting providers, software platforms, AI-assisted development systems, authentication providers and integrated infrastructure services as part of the Services. Such providers may act as sub-processors in accordance with this Agreement.

3.6 Retention Data

DLR Media do not manage the retention of the data held on behalf of the Controller. The Controller has direct access to manage this data.

3.7 Sharing & International

All significant decisions about data processing by the Processor will be made using UK GDPR & EU GDPR as part of the services offered to you. Some sub-processors, cloud infrastructure providers, software platforms and integrated services used by the Processor may host, process and/or store Personal Data outside the UK or European Economic Area, including the United States, which will contain categories deemed low risk such as Personal, Professional & in some cases Sensitive (pseudonymized financial data as part of a blockchain). However special category data which the Processor collects on behalf of the Controller will not be transferred to countries outside the UK without the explicit consent of the Controller.

3.8 Legal Basis

Legal Basis - The processor uses both contractual and legitimate basis for processing data on behalf of the controller.

4. Responsibility & Cooperation of the Processors

4.1 The Processor will, insofar as is reasonably possible, provide all reasonable cooperation to the Controller in fulfilling its obligation pursuant to the UK GDPR to respond to requests for exercising rights of data subjects, in particular the right of access, rectification, erasure, restriction, data portability and the right to object.

4.2 The Processor will forward a complaint or request from a data subject regarding the processing of personal data to the Controller as soon as reasonably possible following receipt thereof, as the Controller is responsible for handling the request. Processor is entitled to charge any costs associated with the cooperation of the Controller with respect to any terms of this Data Processing Agreement.

4.3 Security Breach - The Processor is committed to the protection, privacy and security of the personal data it holds and continues to monitor compliance through implementing policies & procedures to safeguard data and by setting regular reviews to manage these policies and procedures. In the event the Processor becomes aware of any incident that may have a material impact on the protection of personal data processed under this agreement the Processor will immediately contact the Controller. The Processor has implemented the ICO guidance framework on managing a security breach. Containment & Recovery; Assessing the Risk/Impact; Notification of Breaches; Evaluation & Response.

4.3a) Third-Party Platform Security. The Controller acknowledges that third-party platforms, infrastructure providers, AI systems and integrations used in connection with the Services are outside the direct control of the Processor.

The Processor does not warrant that such third-party systems will be uninterrupted, error-free or immune from vulnerabilities, unauthorised access or security incidents.

4.4 The Controller will be responsible for the (timely and correct) notification obligation to the relevant supervisor and/or data subjects.

4.5 The Processor will co-operate with the Controller and take such reasonable commercial steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.

4.6 The Processor will assist the Controller in meeting its obligation to consult with the supervisory authority where a DPIA indicates there is an unmitigated high risk to the processing.

4.7 The Controller will be solely responsible for applicable costs under this section, including - but not limited to additional work to support at an hourly rate of £100 per hour to the Processor for time spent on requests, DPIA's, Investigations under this section.

4.8 The Data Controller hereby grants the Data Processor a general approval to enter into agreements with sub-Data Processors. The Data Processor will notify the Data Controller of any changes concerning the addition or replacements of sub-data. The Data Controller can make reasonable and relevant objections against such changes.

4.9 The processor undertakes to ensure sub - processors it commissions to provide services on behalf of the Data controller will be subject to a Sub Processor - Data Processing Agreement that considers & where appropriate incorporates terms agreed with the Data Controller. The processor will remain responsible for the obligations carried out by its sub processors.

4.10 The processor undertakes to carry out regular compliance reviews on sub-processors commissioned by the processor to undertake work on behalf of the Data controller.

4.11 The Data processor will immediately inform the data controller if in the Data Processors opinion an instruction infringes the UK GDPR, UK Data Protection Legislation or EU GDPR including the data protection provision of an EU member state.

5. Audit & Inspection

The Processor agrees to make available to the Controller all data necessary to demonstrate compliance with the obligations laid down in this agreement and Article 28

6. Confidentiality

6.1 The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6.2 In particular, the Processor agrees that, save with the prior written authorisation of the Controller, it shall not disclose any personal data supplied to the Processor by, for, or on behalf of, the Controller to any third party.

6.3 The Processor shall not make any use of any personal data supplied to it by the Controller otherwise than in connection with the provision of services to the Controller and as agreed in this agreement.

6.4 Nothing in this agreement shall prevent either party from complying with any legal obligation imposed by a regulator or court. Both parties shall however, where possible, discuss together the appropriate response to any request from a regulator or court for disclosure of information.

7. Term and Termination

7.1 - This agreement shall continue in full force and effect for 1 year from the date of the signature of this agreement.

7.2 - Either Party shall have the right to terminate the Agreement, partially or entirely, forthwith by sending a written notice of termination to the other Party specifying the reasons for the termination, if any of the following events occur:

7.2.1 The other party materially breaches any of its obligations under this agreement.

7.2.2 The other party breaches any of its obligations under this agreement and, notwithstanding a written request from the non-breaching party to remedy such a breach, fails to comply with such a request within a period of thirty [30] days following such notice.

7.2.3 The other party becomes insolvent or enters liquidation, a petition in bankruptcy is filed for it or a receiver is appointed.

7.3 - Upon the termination or expiry of this agreement, any rights, and obligations of the parties, accrued prior to the termination or expiry thereof shall continue to exist.

7.4 - Within 30 days following termination of this agreement the Processor shall, at the direction of the Controller, either (a) return all personal data passed to the Processor by the Controller for processing, or (b) on receipt of instructions from the Controller, destroy all such data unless the Processor is prohibited from doing so by any applicable law.

7.5 - The Processor may retain Controller personal data to the extent required by Data Protection Legislation and only to the extent and for such period as required by Data Protection Legislation and always provided that the Processor and any sub-processor shall ensure the confidentiality of all such Controller personal data and shall ensure that such Controller personal data is only processed as necessary for the purpose(s) specified in the Data Protection Legislation requiring its storage and for no other purpose.

7.6 - The Processor shall provide written certification to the Controller that it and any sub-processor has fully complied with this section 7 within 30 days of the termination date.

8. Governing Law (where your customer is based needs to be considered)

This agreement shall be governed by and construed exclusively in accordance with the national law of the Member state in which the Controller is established.

9. Entire agreement

9.1 This agreement contains the entire agreement and understanding between the parties with respect to the subject matter hereof and supersedes and replaces all prior agreements or understandings, whether written or oral, with respect to the same subject matter that are still in force between the parties.

9.2 Any amendments to this agreement, as well as any additions or deletions, must be agreed in writing by both the parties.

9.3 Whenever possible, the provisions of this agreement shall be interpreted in such a manner as to be valid and enforceable under the applicable law stated as per clause 8 above.

AS WITNESS this agreement has been signed on behalf of each of the parties by its duly authorised representative on the day and year first above written.

SIGNED on behalf of the Controller

(Authorised signatory)

(Print name and title)

SIGNED on behalf of the Processor

(Authorised signatory)

(Print name and title)

APPENDIX 1: Description of the services

Social Media Services

Graphic Design and Content Services

Marketing & Lead Generation Services

Email/SMS Campaigns

CRM Design and Management

Outbound Email Campaigns (B2B)

Website Development and Maintenance

Domain Name Registration and Renewals

Hosting Services

2. Technical and Organisational Measures

2.1 DLR Media has implemented and will maintain appropriate technical and organisational measures intended to protect personal data against accidental, unauthorised, or unlawful access, disclosure, alteration, loss, or destruction. These measures shall include the following measures.

2.1.1 The prevention of unauthorised persons from gaining access to systems processing personal data (Physical access control)

2.1.2 The prevention of systems processing personal data from being used without authorisation (logical access control) through the use of advanced monitoring tools such as Immunity 360 to prevent malicious code and craft to prevent csrf attacks.

2.1.3 Ensuring that persons entitled to use a system processing personal data gain access only to such personal data as they are entitled to access in accordance with their access rights, and that, in the course of processing, personal data cannot be read, copied, modified, or deleted without authorisation (data access control)

2.1.4 Ensuring that personal data cannot be read, copied, modified, or deleted without authorisation during electronic transmission, transport, or storage on storage media, and that the target entities for any transfer of personal data by means of data transmission facilities can be established and verified (data transfer control)

2.1.5 Ensuring the establishment of an audit trail to document whether and by whom personal data has been entered, modified in, or removed from systems processing personal data (entry control)

2.1.6 Ensuring that personal data is protected against accidental destruction or loss (availability control)

2.1.7 Ensuring that personal data collected for different purposes can be processed separately (separation control)