WebPolisher Data Processing Agreement
Version: dpa-v4.1
Legal set: webpolisher-legal-set-2026-08-27-v8
Status: Candidate.
1. Parties and scope
This Data Processing Agreement (DPA) forms part of the WebPolisher service contract between:
- the customer identified in an accepted Checkout Order and Commercial Schedule, as controller or as processor acting for another controller (Customer); and
- PeckUK Limited, trading as WebPolisher, as processor (WebPolisher).
This DPA applies only where WebPolisher processes personal data on the Customer's documented instructions in connection with the service (Covered Data).
Examples include personal data in hosted contact forms, Customer Content and service features configured by the Customer.
PeckUK Limited remains a separate controller for its own sales, billing, security, legal, fraud-prevention and service-administration processing.
2. Definitions
Controller, processor, personal data, personal-data breach, processing, special-category data and supervisory authority have the meanings given in applicable UK data-protection law.
Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any binding replacement or amendment that applies to the processing.
Subprocessor means another processor engaged by WebPolisher to process Covered Data.
3. Processing details
The subject matter, duration, nature, purpose, personal-data types and data-subject categories are set out in Annex 1.
The Customer retains control of the purposes and essential means of the processing. Nothing in this DPA transfers that responsibility to WebPolisher.
4. Documented instructions
WebPolisher will process Covered Data only:
- on the Customer's documented lawful instructions, including the service contract, Order Schedule, configured service and saved written instructions;
- as necessary to provide, secure and support the service; or
- where UK law requires processing, in which case WebPolisher will inform the Customer before processing unless the law prohibits notice.
The instruction requirement includes any restricted international transfer of Covered Data.
WebPolisher will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. WebPolisher may pause the affected instruction while the parties resolve the issue.
If WebPolisher determines the purposes and means of processing outside the Customer's instructions, it will be a controller for that processing and must comply with the obligations applying to a controller.
5. Customer responsibilities
The Customer is responsible for:
- having a lawful basis for the processing;
- giving all required privacy information;
- ensuring its instructions are lawful, fair and limited to what is necessary;
- ensuring Covered Data is accurate and appropriate;
- responding to data subjects as controller;
- deciding retention and deletion requirements; and
- obtaining any controller authority needed where the Customer acts as a processor.
The Customer must not instruct WebPolisher to process special-category or criminal-offence data unless the parties first agree the purpose and document suitable legal, security and policy safeguards.
6. Confidentiality and people
WebPolisher will ensure that people authorised to process Covered Data:
- access it only where required for their role;
- are bound by an enforceable duty of confidentiality;
- receive appropriate privacy and security guidance; and
- process it only in accordance with this DPA and the Customer's instructions.
7. Security
WebPolisher will implement and maintain appropriate technical and organisational measures under Article 32 UK GDPR, taking account of the state of the art, implementation cost, nature and purpose of processing, and risk to individuals.
The current minimum measures are described in Annex 2.
WebPolisher may improve or replace a measure where the overall level of protection is not materially reduced.
8. Personal-data breaches
WebPolisher will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Covered Data and, where practicable, within 48 hours.
The notification will provide available information about:
- the nature of the breach;
- affected data and categories and approximate numbers of people and records;
- likely consequences;
- containment, mitigation and remedial action;
- a contact point; and
- any information reasonably needed for the Customer's notification duties.
Information may be supplied in phases where it is not available at the same time.
WebPolisher will take reasonable steps to contain, investigate and mitigate the breach, preserve appropriate evidence and assist the Customer with any required regulator or individual notification.
A notification is not an admission of fault or liability.
9. Data-subject rights
Taking account of the nature of processing, WebPolisher will use appropriate technical and organisational measures to help the Customer respond to requests for access, correction, erasure, restriction, portability, objection and other applicable rights.
If WebPolisher receives a request relating only to Covered Data, it will direct the requester to the Customer or notify the Customer and will not respond substantively unless instructed or legally required.
10. Compliance assistance
Taking account of the nature of processing and information available, WebPolisher will reasonably assist the Customer with:
- security obligations;
- personal-data breach assessment and notification;
- data-protection impact assessments;
- prior consultation with the Information Commissioner's Office; and
- information reasonably needed to demonstrate compliance with Article 28 UK GDPR.
11. Subprocessors
The Customer gives general written authorisation for the subprocessors identified as active and approved in the published WebPolisher Subprocessor Schedule.
WebPolisher will:
- carry out proportionate due diligence before appointing a Subprocessor;
- enter a written contract imposing the same Article 28 obligations or an equivalent level of protection;
- remain fully liable to the Customer for the Subprocessor's performance of those data-protection obligations; and
- keep the Subprocessor Schedule and non-public provider register current.
WebPolisher will give at least 30 days' written notice before a new Subprocessor begins processing Covered Data.
The Customer may object within 14 days on reasonable data-protection grounds. The parties will work in good faith to use a reasonable alternative.
If no reasonable alternative is available, either party may end only the affected service. The Customer will receive a refund or credit for any paid but unprovided period and no Early Termination Charge applies to that affected service.
Where an urgent replacement is reasonably necessary to protect availability, security or legal compliance, WebPolisher may appoint the replacement before the full notice period but will notify the Customer as soon as reasonably possible and preserve the objection process.
12. International transfers
WebPolisher will not make a restricted transfer of Covered Data unless:
- the Customer's instructions authorise the transfer through the service contract and provider schedule;
- a lawful transfer mechanism applies;
- required contractual details have been completed; and
- any required transfer risk assessment or data protection test and supplementary measures have been documented.
Transfer mechanisms may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, Binding Corporate Rules or another mechanism permitted by law.
13. Audit and compliance information
WebPolisher will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer.
WebPolisher may first satisfy a routine request using current independent reports, certifications, policies, security summaries, provider evidence and written responses.
The Customer may conduct, or appoint an independent auditor to conduct, a proportionate audit:
- normally no more than once in any 12-month period;
- on at least 30 days' written notice;
- during normal business hours;
- subject to confidentiality and reasonable security restrictions; and
- without unnecessary disruption or access to another customer's information.
The frequency and notice limits do not apply where:
- a confirmed breach affects Covered Data;
- the Customer has reasonable documented grounds to suspect material non-compliance;
- a regulator requires the audit; or
- Applicable Data Protection Law requires more immediate access.
The Customer bears its own audit costs. WebPolisher may charge reasonable additional costs for bespoke assistance beyond its ordinary compliance obligations, except where the audit identifies WebPolisher's material breach of this DPA.
14. Return and deletion
At the end of the affected service, the Customer may choose return or deletion of Covered Data.
WebPolisher will complete the requested return or deletion within 30 days, unless UK law requires retention.
Covered Data in protected backups will be placed beyond ordinary business use and expire within 35 days under the normal backup cycle.
Contract, billing, fraud, security and legal evidence retained by PeckUK Limited as controller is not Covered Data and will remain restricted to the relevant lawful purpose.
15. Liability and priority
The liability provisions in the Service Terms apply to this DPA, subject to rights and liabilities that cannot lawfully be limited.
This DPA controls over conflicting service-contract wording only for Covered Data processing.
Nothing in the contract relieves either party of its direct obligations under Applicable Data Protection Law.
16. Term and law
This DPA begins when the service contract is formed and continues for as long as WebPolisher processes Covered Data.
It is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to mandatory powers and rights of a regulator or data subject.
Annex 1 - Processing details
Subject matter and purpose
Hosting, securing, maintaining, supporting, backing up and making available the Customer's website and instructed service features.
Duration
The service term plus the period reasonably required for return, deletion, backup expiry, security, dispute and legal obligations.
Nature of processing
Collection, receipt, hosting, organisation, storage, access, retrieval, transmission, display, support, backup, export, restriction and deletion as required to provide the instructed service.
Categories of data subject
- Customer staff and authorised users.
- Customer contractors.
- Customer website visitors.
- Customer prospects and customers.
- People who submit a hosted website form.
Types of personal data
- Names, business roles and business contact details.
- Website-form submissions and correspondence.
- Customer Content containing personal data.
- Account and user identifiers.
- IP addresses and technical identifiers.
- Support, audit and security records connected with the hosted service.
Sensitive data
Special-category and criminal-offence data is not authorised unless separately agreed and safeguarded in writing.
Customer rights and obligations
The Customer may issue lawful instructions, configure approved service features, request assistance, receive compliance information, object to Subprocessors, request return or deletion, and exercise audit rights under this DPA.
The Customer obligations are set out in section 5.
Annex 2 - Technical and organisational measures
WebPolisher's minimum measures include:
- role-based access and least-privilege permissions;
- multi-factor authentication for privileged, provider and billing access;
- unique user access rather than shared privileged credentials;
- tenant and resource scoping, including database row-level security where applicable;
- encryption in transit using current supported TLS;
- provider-managed encryption at rest;
- controlled secrets and bounded provider credentials;
- logging of material account, acceptance, billing, security and administrative events;
- append-only or tamper-evident contract and payment evidence where applicable;
- protected backups and tested recovery procedures proportionate to the service;
- deletion and backup-expiry controls;
- dependency, vulnerability and security-update maintenance;
- change review and testing for material access-control and recovery changes;
- error-data minimisation and scrubbing;
- incident response, containment, investigation and notification procedures;
- provider due diligence, contract and transfer records;
- confidentiality obligations and appropriate staff guidance; and
- annual and material-change review of the measures.
Supplier details
WebPolisher is a trading name of PeckUK Limited.
PeckUK Limited is registered in England and Wales under company number 08756155.
Registered office: 90 Stowmarket Road, Needham Market, Ipswich, Suffolk, IP6 8DX, United Kingdom.
VAT number: 173 8752 74.
Contact: updates@webpolisher.co.uk.