Skip to main content
Saggar Studio Send an enquiry

Legal · Clients

Data processing.

When we host and run your website, we handle personal data on your behalf. This agreement sets out how, as UK GDPR Article 28 requires.

Last updated
Applies to
Clients on website care or Get found online
Version
1.0

Who is who

1.1This agreement forms part of our terms of business. It applies whenever we process personal data on your behalf in providing the services.

1.2You are the controller. Saggar Studio is the processor. Words such as “personal data”, “processing” and “personal data breach” have the meanings given in UK GDPR.

What we process

ItemDetail
Subject matterBuilding, hosting, maintaining and improving your website, and managing your search presence
DurationFor as long as we provide services to you, plus the deletion period in section 3.8
Nature and purposeHosting, storage, backup, form handling, analytics set-up, support, and reading data in connected accounts to do the work
Types of personal dataDetails people submit through your forms (such as name, email, phone and message), booking details, server logs (IP address, browser, pages visited), analytics identifiers, recordings of how visitors use pages (where Microsoft Clarity is used), and names in reviews and messages on your business profiles
Data subjectsVisitors to your website, your customers and enquirers, and your staff
Special category dataNot expected. Your forms must not collect health or other special category data unless we have agreed in writing how it will be handled.

What we will do

3.1Process personal data only on your documented instructions, which are the contract and anything you tell us in writing, unless the law requires otherwise. We will tell you if we think an instruction breaks data protection law.

3.2Make sure everyone who processes the data is bound by confidentiality.

3.3Keep the data secure with the measures in Annex B.

3.4Use only the sub-processors in Annex A. We will give you at least 30 days’ notice before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may end the affected service without an early-exit charge. Each sub-processor is bound by data protection terms at least as protective as these, and we remain responsible for them.

3.5Help you, as far as we reasonably can, to respond to requests from people exercising their rights, and to meet your duties on security, breach notification, data protection impact assessments and consultation with the ICO. Help that takes more than an hour a month is charged at £45 an hour.

3.6Tell you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to decide whether to report it.

3.7Transfer the data outside the UK only with a safeguard recognised by UK law, such as adequacy regulations or the ICO’s International Data Transfer Agreement or Addendum.

3.8When the services end, return the data on request and delete it within 30 days. Copies in backups are deleted as the backups expire, within six months. None of this applies where the law requires us to keep the data.

3.9Give you the information you reasonably need to show compliance with Article 28. You may audit us, or appoint an auditor bound by confidentiality, once a year on 30 days’ notice, at your cost.

What you will do

4.1Have a lawful basis for all personal data your website collects, and tell people about it in your privacy notice.

4.2Obtain consent for any cookies or similar technologies that need it.

4.3Make sure your instructions to us are lawful.

4.4Tell us before collecting any special category or criminal offence data through your website.

Liability

Each party’s liability under this agreement is subject to the limits in the terms of business, as far as the law allows.

Annex A · Sub-processors

Sub-processorWhat it doesLocation
Cloudflare, Inc.Hosts client websites. Server logs are kept for 90 days.US and global
Make (Celonis)Receives form submissions and forwards themEU
Microsoft Corporation (Excel)Spreadsheets that hold form submissionsEU
Google LLC (Google Workspace)Form notification emails, and backups on Google DriveUS and global
ZohoEmailEU
GitHub, Inc.Website code and backups, in private repositoriesUS
Google LLC (Google Analytics)Visit statistics, where you use itUS and global
Microsoft Corporation (Microsoft Clarity)Heatmaps and session recordings, where you use itUS and global

Google Analytics and Microsoft Clarity only run after a visitor accepts cookies on your website’s cookie banner. Clarity masks what visitors type into form fields, and we do not use it on pages that collect health information or bookings.

Annex B · Security measures

  • Two-factor authentication on every hosting, domain, email and admin account.
  • Unique passwords held in an encrypted Bitwarden vault, protected by two-factor authentication.
  • Access limited to the people doing the work, and removed when it ends.
  • HTTPS on every website we host.
  • Security updates applied within 14 days, and critical updates within 72 hours of release.
  • Encrypted backups, held separately from the live site.
  • Encrypted laptops with automatic screen locks.
  • A written log of security incidents and how each was handled.