Data Processing Addendum
Article 28 UK GDPR terms for customers who are controllers of personal data we process on their behalf.
This is version 1.0, archived on 26 July 2026. It is kept for reference and is not the current document — read the current version.
- Version
- 1.0
- Effective
- 26 July 2026
- Applies to
- Drentova Group Ltd
- History
- 1 version
When this applies
This addendum applies where you use our service to process personal data about your own users, customers or staff. In that arrangement you are the controller and Drentova Group Ltd is your processor. It forms part of our Terms of Service and takes effect automatically — you do not need to sign a separate copy, though we will countersign one on request to [email protected].
Where we determine the purposes of processing ourselves — for example your own account and billing data — we are the controller and our Privacy Policy applies instead.
Definitions
- UK GDPR
- Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland, together with the Data Protection Act 2018.
- Controller, processor, personal data, processing
- As defined in the UK GDPR.
- Customer Personal Data
- Personal data we process on your behalf under this addendum.
Subject matter and duration
We process Customer Personal Data to provide the service described in our Terms of Service, for as long as your account is active and for the retention period stated in our Privacy Policy afterwards. The categories of data subject and of personal data are determined by you, through what you choose to put into the service.
Our obligations
We will:
- process Customer Personal Data only on your documented instructions, including as to transfers, unless required otherwise by law — in which case we will tell you first unless the law prohibits it;
- ensure that people authorised to process it are bound by confidentiality;
- take the technical and organisational measures set out below;
- engage a subprocessor only under the conditions in the next section;
- assist you, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights;
- assist you with data protection impact assessments and prior consultation, and with your obligations under Articles 32 to 36;
- on termination, delete or return Customer Personal Data at your choice, and delete existing copies unless the law requires us to keep them;
- make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits as set out below.
Technical and organisational measures
We take the measures below to protect personal data, as required by Article 32 of the UK GDPR. They are reviewed as the service changes, and we publish the current position in our Trust Centre rather than describing a state we hope to reach.
- Data in transit is encrypted using TLS. Data at rest is encrypted by our hosting and database providers.
- Access to production systems is restricted to the people who need it, protected by multi-factor authentication, and removed when it is no longer needed.
- Administrative access to customer data is limited to what is necessary to operate and support the service.
- Backups are taken by our database provider and restoration is tested.
- Changes to production go through review and automated checks before release.
- Third parties are assessed before they process personal data on our behalf, and are engaged under written terms that meet Article 28.
No service can promise perfect security. If we become aware of a personal data breach we will assess it without undue delay, notify the PLACEHOLDER — ICO registration-registered supervisory authority within 72 hours where the breach is notifiable, and tell affected people directly where the breach is likely to result in a high risk to them.
Subprocessors
You give general authorisation for us to engage the subprocessors listed below. We impose data protection obligations on each of them that are no less protective than those in this addendum, and we remain fully liable to you for their performance.
We will give at least 30 days’ notice before adding or replacing a subprocessor, by publishing the change here and notifying you by email if you have asked us to. If you have a reasonable objection on data protection grounds, tell us within that period; we will work with you to resolve it, and if we cannot you may terminate the affected part of the service without penalty and receive a refund for the unused period.
Subprocessors
| Subprocessor | Purpose | Location | Transfer safeguard | Data |
|---|---|---|---|---|
| Resend | Transactional email delivery | United States | UK Addendum to the EU SCCs | Recipient email address and message content |
| Supabase | Managed PostgreSQL database hosting | United Kingdom | No transfer — processed in the UK | All application data, including account details and submitted content |
| Vercel | Application hosting, content delivery and file storage | United States | UK Addendum to the EU SCCs | IP address, request metadata and server logs; uploaded media stored in Vercel Blob |
International transfers
We are based in the United Kingdom and process personal data here wherever we can. Some of the providers we rely on operate outside the UK.
Where personal data is transferred outside the UK, we rely on one of the safeguards permitted by Chapter V of the UK GDPR: UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. The safeguard applying to each provider is named in the subprocessor table, and we carry out a transfer risk assessment before relying on any of them.
You can ask us for a copy of the safeguards in place for a particular transfer by writing to [email protected].
Breach notification
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken or proposed. We will not notify your data subjects or a supervisory authority on your behalf unless you ask us to or the law requires it of us.
Audits
On reasonable notice, and no more than once in any twelve months unless a supervisory authority requires otherwise or a breach has occurred, you may audit our compliance with this addendum. In the first instance we will respond with our security documentation and a completed security questionnaire; where that is genuinely insufficient we will accommodate an audit, conducted during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs.
Liability
Each party’s liability under this addendum is subject to the limitations in our Terms of Service, except where the UK GDPR provides otherwise.
How to contact us
- Legal notices
- [email protected]
- Privacy and data protection
- [email protected]
Change log
- v1.0 · 26 July 2026First published version.