This agreement applies whenever Glow Digital (Sophia Pedley, sole trader — "I") stores or handles personal data on your behalf as part of building, hosting, maintaining or supporting your website or systems — for example your customers' orders, accounts, bookings and enquiries. It forms part of your agreement with me, together with your accepted quote and the Terms of Service. The details for your project — whose data, what data, and which providers are used — are set out in your quote.
1. Who's who
- For your customers' personal data, you are the controller (you decide why and how it's used) and I am your processor (I handle it for you, on your instructions).
- My own use of your details as my client is covered by my Privacy Policy, where I'm the controller.
2. The law this follows
- "Data protection law" means the UK GDPR and the Data Protection Act 2018, the EU GDPR where it applies, and any other data protection law that applies to the processing.
- You're responsible for having a lawful basis for collecting your customers' data, for telling them how you use it (your privacy notice), and for making sure your instructions to me are lawful.
3. What I process
- Purpose and nature: hosting, running, maintaining and supporting your website and its systems, as described in your quote — which can include storing, backing up, retrieving, correcting, exporting and deleting records.
- Whose data and what data: as listed in your quote.
- Sensitive data: I only handle health information or other special category data if your quote expressly says so.
- How long: for as long as I provide services to you, and then as set out in section 11.
4. Your instructions
- I only process the data on your documented instructions: your quote, the Terms of Service, this agreement, and anything further you ask in writing (by email or through your client portal) — including about transfers outside the UK or EEA.
- If the law requires me to do something else, I'll tell you first, unless the law prevents me from doing so.
- If I think an instruction breaks data protection law, I'll tell you straight away.
5. Confidentiality
- I keep your customers' data confidential.
- I'm the only person who works on it. If anyone else ever needs access (for example a contractor), they'll be bound by confidentiality, and I'll treat them as a sub-processor under section 7.
6. Keeping it secure
I take appropriate technical and organisational measures to protect the data, including:
- encrypted connections (HTTPS) to your website and its systems;
- using established hosting and database providers that encrypt stored data;
- limiting access to what's needed, with strong, unique passwords and two-factor authentication on the accounts that hold your data;
- the routine updates, security checks and backup checks described in your quote.
7. Sub-processors
- You authorise me to use the providers listed in your quote (for example hosting, database and email providers) to store or handle the data.
- Before I add or replace one, I'll tell you in writing, normally at least 14 days in advance, so you can object. If you object on reasonable grounds and we can't find a solution, you can end the affected services without having to give the usual notice.
- Each sub-processor is bound by data protection obligations that protect the data at least as well as this agreement, and I remain responsible to you for them.
- Services you sign up to directly (for example your own Stripe or email marketing account) are your own providers, not my sub-processors.
8. Transfers outside the UK and EEA
Some providers may process data outside the UK or EEA (for example in the United States). I only use providers that protect those transfers with a lawful safeguard — such as an adequacy decision or regulations, or standard contractual clauses and the UK addendum — as set out in their own terms.
9. Helping you meet your obligations
- If one of your customers contacts me to use their data rights (for example to see, correct or delete their data), I'll pass it to you without undue delay and help you respond — such as finding, exporting, correcting or deleting their records.
- I'll help you, using the information available to me, with keeping the data secure, dealing with breaches, data protection impact assessments and any consultation with a regulator.
- Routine help is included. If a request needs substantial work, I'll agree a price with you before starting.
10. If something goes wrong
If I become aware of a personal data breach affecting your data, I'll tell you without undue delay, and within 48 hours of becoming aware of it — with what I know about what happened, the data and people affected, the likely consequences, and the steps taken — and keep you updated as I learn more. This is so you can meet your own deadlines for reporting to a regulator or telling your customers.
11. When the services end
- Before your final service date, you can ask for a copy of the data in standard file formats (see the Terms of Service).
- Within 30 days after your final service date, I'll delete the data I hold, unless the law requires me to keep it. Copies inside providers' backups are removed as those backups expire under the provider's normal cycle.
12. Showing I'm complying
I'll give you the information you reasonably need to show that I'm meeting this agreement, and allow and contribute to audits, including inspections, by you or an auditor you appoint — with reasonable notice, during working hours, and with the auditor bound by confidentiality.
13. Responsibility
- Each of us is responsible for our own compliance with data protection law.
- The limits of liability in the Terms of Service apply to this agreement, to the extent the law allows.
14. How this fits with your other terms
- If this agreement and the Terms of Service or your quote ever disagree about personal data, this agreement applies.
- New versions apply to quotes issued after they're published. If a change in the law means this agreement has to change, I'll tell you.
- This agreement is governed by the laws of England and Wales, without affecting any rights your customers have under the data protection law that applies to them.
15. Contact
Questions about this agreement, or anything about your customers' data? Email me at .