Data Processing Agreement
under Article 28(3) GDPR
Version 1.0
between
the Controller - the business that holds this Soltyx account, whose legal details are recorded in the dashboard under "Settings -> Legal" -
and
DEVDANI LTD DEVDANI LTD, 124 City Road, London EC1V 2NX, United Kingdom - registered in England and Wales, company number 16744168
- the "Processor" -
This agreement is concluded when a person authorised to represent the Controller accepts the Soltyx Service Terms. The time of acceptance, the person accepting and the version accepted are recorded in the account and can be retrieved there at any time.
In this agreement "GDPR" means Regulation (EU) 2016/679 and, where the Controller is subject to it, the UK GDPR as defined in the Data Protection Act 2018. Where the two differ, each applies to the Controller it governs.
§ 1 Subject matter, duration and place of processing
(1) The Processor operates the Soltyx website and content management service for the Controller. The engagement covers hosting the website, managing content, receiving and administering bookings, contact enquiries, gift cards and payments, and sending confirmation and newsletter email.
(2) This agreement runs for an indefinite period. It begins and ends with the main contract for the use of Soltyx. It cannot be terminated separately from that contract; terminating it terminates the main contract at the same time, and the reverse.
The Controller may terminate both immediately where the Processor has seriously breached data protection law or this agreement, cannot or will not carry out an instruction, or refuses inspection rights in breach of this agreement. Either party's right to terminate for material breach is unaffected.
(3) Place of processing. The Processor is established in the United Kingdom. Processing takes place in the United Kingdom and in member states of the European Union; the places of processing of the subprocessors engaged are set out in § 7.
Where the Controller is established in the EU or EEA, disclosure to the Processor is a restricted transfer. The European Commission found the United Kingdom to provide an adequate level of protection by implementing decision of 19 December 2025, which applies until 27 December 2031. Should that decision be repealed, declared invalid, suspended, restricted in scope or not renewed, the parties hereby already conclude the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), as amended from time to time. They take effect on that event without any further declaration by the parties. The particulars for Annex I follow from §§ 1, 2 and 7 of this agreement and those for Annex II from § 6; the competent supervisory authority for the purposes of Annex I Section C is the authority competent for the Controller. Where the Standard Contractual Clauses conflict with this agreement, they prevail. In that event the Processor will carry out a transfer impact assessment without undue delay and take any supplementary measures required.
Where the Controller is subject to the UK GDPR, disclosure to the Processor is not a restricted transfer, both parties being established in the United Kingdom. Onward transfers to the subprocessors listed in § 7 are covered by the basis stated for each of them, read with the UK Addendum to the Standard Contractual Clauses where the transfer is made under the UK GDPR.
Any further transfer to a third country takes place only on the conditions of Chapter V GDPR.
§ 2 Nature and purpose, types of data, data subjects
(1) Nature of the processing: collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission, restriction, erasure and destruction.
(2) Purpose: operating the Controller's website and the functions connected with it under § 1(1).
(3) Types of data: master and contact data, booking and appointment data, payment data, the contents of forms and messages, newsletter recipient data, and website usage data.
(4) Categories of data subject: visitors to the website, the Controller's customers and prospective customers, and recipients of its newsletter.
(5) Special categories of personal data. The Controller decides what data it collects through the forms provided. Where it collects special categories of personal data within the meaning of Art. 9(1) GDPR - health information in a free-text field, for example - obtaining explicit consent under Art. 9(2)(a) GDPR is the Controller's responsibility.
§ 3 Rights and obligations of the Controller
(1) The Controller is responsible for the lawfulness of the processing under Art. 6(1) GDPR and for upholding data subjects' rights under Arts. 12 to 22 GDPR. The Processor's own statutory responsibility and liability, in particular under Arts. 28(10) and 82 GDPR and for breaches of its own obligations under this agreement, is unaffected. Nothing in this provision shifts the burden of proof to the Controller's disadvantage.
(2) Where a data subject approaches the Processor directly, the Processor forwards the request to the Controller without undue delay and does not answer it itself.
(3) The Controller issues instructions in writing, which includes email and any documented electronic format, in particular the Soltyx dashboard. The Processor carries out and documents oral instructions; the Controller confirms them in writing without undue delay.
(4) The scope of the instructions follows from this agreement, from the main contract, and from the settings and entries the Controller makes in the Soltyx dashboard. The Controller activating or using a function offered in the dashboard constitutes a documented instruction to carry out the processing associated with that function.
(5) The Controller is entitled to satisfy itself of the technical and organisational measures in place before processing begins and at regular intervals thereafter; the procedure is set out in § 11.
§ 4 Persons authorised to give and receive instructions
(1) On the Controller's side, the persons recorded in the Soltyx dashboard as owner or administrator are authorised to give instructions.
(2) On the Processor's side, instructions are received by: DEVDANI LTD, DEVDANI LTD, 124 City Road, London EC1V 2NX, United Kingdom - registered in England and Wales, company number 16744168, email: hello@soltyx.app. The Processor will notify any change in writing.
(3) Both parties retain instructions for as long as they apply and for three full calendar years thereafter.
§ 5 Obligations of the Processor
(1) The Processor processes personal data only within the scope of this agreement and on the Controller's instructions, unless required to process otherwise by law to which it is subject. In such a case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
(2) The Processor uses the personal data entrusted to it for no purposes of its own. In particular it does not analyse that data for its own product or market research, does not use it for its own advertising, and does not use it to train or improve artificial intelligence models.
Where the Controller uses the AI features of the service, the Processor transmits to the provider named in § 7 only the content the Controller has itself entered and the information about the Controller's business needed to perform the function; no master, booking or payment data of the Controller's customers is transmitted. If the Controller itself enters such data into an AI feature, that data is transmitted too, and the Controller is responsible for it. The provider does not use the transmitted content to train its models.
(3) The Processor separates the data it processes for the Controller from the data of other controllers and from its own data by logical, multi-tenant data storage. It takes appropriate technical measures to ensure that no access to the Controller's data is possible from another controller's context.
(4) The Processor requires the persons authorised to process the data to keep it confidential; that obligation continues after their engagement ends (Arts. 28(3)(b) and 29 GDPR).
(5) Taking into account the nature of the processing and the information available to it, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling data subjects' rights under Arts. 12 to 22 GDPR and in complying with the obligations in Arts. 32 to 36 GDPR, in particular the security of processing, notifications under Arts. 33 and 34, and data protection impact assessments (Arts. 28(3)(e) and (f) GDPR). It also assists the Controller in maintaining its record of processing activities.
The functions provided in the service for access, rectification, erasure and data portability, and the provision of the evidence referred to in § 11(2), are supplied at no separate charge. Where the assistance the Controller requests goes beyond those functions, the Processor may charge for the necessary effort at its rates in force, notified to the Controller in writing in advance; this does not apply where the effort arises from a circumstance for which the Processor is responsible.
(6) The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes data protection law (Art. 28(3), final sentence, GDPR), giving its reasons. It is entitled to suspend performance of the instruction until the Controller confirms or amends it, to the extent that performing it would expose the Processor to liability or a fine. If the Controller confirms the instruction, the Processor carries it out, unless doing so would manifestly infringe the law.
(7) The Processor has not appointed a data protection officer, the statutory conditions for doing so not being met. It will inform the Controller without undue delay if that changes.
(8) [LAWYER] The Processor has not at present designated a representative in the Union under Art. 27 GDPR. It keeps the conditions of Art. 27 under review and will designate a representative without undue delay once they are met, notifying the Controller of the designation and its contact details in writing. Until then the Processor is reachable by the Controller and by supervisory authorities at the details in § 4(2).
§ 6 Technical and organisational measures
(1) The Processor takes the measures required by Art. 32 GDPR. Those in place at the time this agreement is concluded are:
- encryption of all data in transit (TLS) and encrypted database connections,
- encryption of stored data and of backups at rest,
- separation of the data of different controllers (multi-tenancy),
- access and authorisation control on a least-privilege basis, including multi-factor authentication for administrative access,
- regular, encrypted backups and a documented, regularly tested restore procedure (Art. 32(1)(c) GDPR),
- measures to ensure the resilience of systems and services (Art. 32(1)(b) GDPR),
- logging of security-relevant events and administrative access,
- a documented procedure for detecting, assessing and handling personal data breaches,
- a procedure for regularly testing, assessing and evaluating the effectiveness of the measures (Art. 32(1)(d) GDPR),
- confidentiality undertakings from the persons authorised to process the data, and their regular training,
- a deletion concept, including deletion from backups at the end of the applicable backup cycle.
Physical and entry security at the data centres is provided by the subprocessors named in § 7.
(2) Changes to the measures. The Processor may adapt the technical and organisational measures during the term where there is good reason to do so. Good reason exists in particular where the state of the art develops, where new security risks or vulnerabilities are identified, where the systems used or the subprocessors engaged under § 7 change, or where legal, regulatory or normative requirements change.
An adaptation must not fall below the level of protection agreed in paragraph (1). This is assessed objectively against the criteria in Art. 32(1) GDPR, and the burden of showing that the level of protection is maintained rests with the Processor. An adaptation that endangers the purpose of the agreement or alters the character of the service is not permitted.
The Processor documents every adaptation and keeps the current version of the measures available in the Soltyx dashboard. It notifies the Controller in writing at least 30 days before a material adaptation takes effect. Where a material adaptation is unreasonable for the Controller, the Controller may terminate this agreement and the main contract within 30 days of receiving the notice, with effect from the date the adaptation takes effect; fees paid in advance are refunded pro rata.
Adaptations necessary to avert an immediate and specific threat to the security of the processing may be made at once; the Processor informs the Controller without undue delay afterwards, in writing.
§ 7 Subprocessors
(1) The Controller grants general authorisation for the engagement of the following subprocessors:
| Company | Service | Place of processing | Basis for third-country transfer |
|---|---|---|---|
| Hetzner Online GmbH, Germany | Database and storage of course videos | Germany | Not applicable (processed in the EU) |
| Vercel Inc., USA | Running the website and application, and storage of uploaded files (Vercel Blob) | Frankfurt region (EU); access from the USA possible | Adequacy decision (EU) 2023/1795 (EU-US Data Privacy Framework), certification verified; additionally, and if it lapses: Standard Contractual Clauses (EU) 2021/914, Module Three, with the UK Addendum where the UK GDPR applies |
| Resend Inc., USA | Sending transactional and newsletter email | USA | Adequacy decision (EU) 2023/1795 (EU-US Data Privacy Framework), certification verified; additionally, and if it lapses: Standard Contractual Clauses (EU) 2021/914, Module Three, with the UK Addendum where the UK GDPR applies |
| Microsoft Corporation, USA (Clarity) | Audience measurement, only where the Controller switches it on and only after the visitor consents | USA | Adequacy decision (EU) 2023/1795 (EU-US Data Privacy Framework); additionally, and if it lapses: Standard Contractual Clauses (EU) 2021/914, Module Three, with the UK Addendum where the UK GDPR applies |
| Anthropic PBC, USA (engaged through Vercel Inc.) | AI features, on the Controller's request only; the Controller's own content only | USA | Standard Contractual Clauses (EU) 2021/914, Module Three, through the data processing agreement with Vercel Inc. |
(1a) The Processor has agreed the transfer basis stated with each subprocessor named in paragraph (1) and monitors that it remains in place. If an adequacy decision ceases to apply, the Standard Contractual Clauses (EU) 2021/914 in the applicable module apply to that subprocessor without further declaration, read with the UK Addendum where the UK GDPR applies. A current list of the subprocessors engaged, including their seat, place of processing and transfer basis, is kept available at https://www.soltyx.app/subprocessors.
(2) The Processor informs the Controller of the intended engagement or replacement of a subprocessor in writing, to the email address the Controller has recorded in the dashboard, at least 30 days before the intended change. The notice names the company, its seat, the service to be provided, the place of processing and the basis for any third-country transfer. The Processor does not use that subprocessor for the Controller's data before the objection period in paragraph (3) has expired.
(3) The Controller may object to the change in writing within 30 days of receiving the notice, on reasonable data protection grounds. The Processor then considers without undue delay whether it can provide the service without that subprocessor or using a reasonable alternative, and informs the Controller of the outcome in writing; until then it does not use the subprocessor for the Controller's data. If neither is possible with reasonable effort, either party may terminate this agreement and the main contract on 30 days' notice. Fees paid in advance are refunded pro rata; the Controller has no further claim arising from the termination.
(4) The Processor may replace a subprocessor without observing the period in paragraph (2) where this is necessary to avert a specific threat to the security of the processing or because the existing subprocessor has failed. It informs the Controller without undue delay; the rights in paragraph (3) are unaffected.
(5) The Processor selects subprocessors with care and imposes on them by contract the same data protection obligations it owes under this agreement. It remains fully responsible to the Controller for their performance (Art. 28(4) GDPR).
§ 8 Independent third-party providers
(1) Where the Controller activates a connection to one of the following providers in the Soltyx dashboard, that provider acts as an independent controller for the processing described, and not as a subprocessor of the Processor:
| Provider | Processing concerned | Role |
|---|---|---|
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Processing payments through the Stripe account held in the Controller's own name | Independent controller for payment processing and for its own regulatory and anti-money-laundering obligations |
| Google Ireland Limited | Retrieving Google reviews, connecting Google Calendar and signing in with a Google account, each through an account held in the Controller's own name | Independent controller for the purposes described in its own privacy terms |
(2) The provider's own data protection terms apply to that processing. The Controller concludes any agreements required with the provider directly; the Processor draws this to the Controller's attention before the relevant function is activated in the dashboard and identifies the provider's applicable terms.
(3) In so far as the Processor transmits data to those providers for the Controller, receives data from them, or stores such data in the service, it acts as processor under this agreement.
§ 9 Personal data breaches
(1) The Processor notifies the Controller of any personal data breach without undue delay, as a rule within 24 hours of becoming aware of it (Art. 33(2) GDPR).
(2) The notification contains the information the Controller needs for its own notification under Art. 33(1) GDPR, in particular the nature of the breach, the categories of data and of data subjects affected, the likely consequences and the measures taken.
(3) The Processor does not itself notify the supervisory authority or data subjects; those notifications are the Controller's responsibility.
§ 10 Deletion and return
(1) After this agreement ends, the Processor makes the personal data available for retrieval in a common, structured, machine-readable format for a period of 30 days. At the Controller's choice, the Processor instead returns the data by other means or deletes it immediately.
(2) After the period in paragraph (1), the Processor deletes the personal data from its production systems within 30 days. Data in backups is deleted at the end of the applicable backup cycle, and in any event within 90 days; until deleted, data in backups is processed only for the purpose of restoration.
(3) Data subject to a statutory retention obligation is excepted from deletion, as is data that has been completely and irreversibly anonymised. Data retained under a statutory obligation is blocked and processed only to meet that obligation; on request the Processor identifies the data concerned and the legal basis for retaining it.
(4) The Processor provides evidence of deletion in writing on request.
§ 11 Evidence and inspection
(1) The Processor makes available to the Controller all information necessary to demonstrate compliance with this agreement and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by it (Art. 28(3)(h) GDPR). This extends to compliance by the subprocessors engaged under § 7; the Processor may discharge that obligation by producing their evidence under paragraph (2).
(2) Evidence may first be given by producing the current version of the measures under § 6, by answering a questionnaire from the Controller, and by appropriate certifications, attestations or audit reports from independent third parties, in so far as these cover the processing relevant to the Controller.
(3) Where the evidence under paragraph (2) is not sufficient to assess compliance, the Controller may require an inspection on site or by remote access. It gives at least ten working days' notice in writing; the inspection takes place during the Processor's normal business hours and in a manner that avoids avoidable disruption to its operations. The parties agree the date. If no agreement is reached within two weeks of the notice, the Controller determines the date acting reasonably, choosing a date no earlier than four weeks after the notice. In the event of a personal data breach, a specific suspicion of a breach of this agreement, or at the request of a supervisory authority, an inspection may be carried out without observing those periods.
(4) The Processor may require an auditor mandated by the Controller to give an appropriate confidentiality undertaking and not to be in direct competition with the Processor. It may refuse a named auditor only for good reason, notifying the reasons without undue delay; the Controller then names another.
(5) Each party bears its own costs. The evidence under paragraph (2) and one inspection under paragraph (3) per calendar year are provided at no separate charge. The Processor may charge a reasonable fee at its rates in force, notified in writing in advance, for inspections beyond that; this does not apply where the inspection is occasioned by a circumstance for which the Processor is responsible, or is required by a supervisory authority.
§ 12 Liability
(1) Nothing in this agreement excludes or limits either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded or limited.
(2) Subject to paragraph (1), neither party is liable for loss of profit, loss of revenue, loss of anticipated savings, loss of business opportunity, or any indirect or consequential loss.
(3) Subject to paragraph (1), the Processor's total liability arising out of or in connection with this agreement in any contract year is limited to the greater of twelve times the monthly fee applying when the liability arose and 5.000 EUR. Several claims arising from the same underlying set of facts count as one claim.
(4) Liability to data subjects under Art. 82 GDPR is unaffected by the preceding paragraphs. Paragraphs (1) to (3) apply to any apportionment between the parties under Art. 82(5) GDPR.
(5) These limitations also operate in favour of the Processor's officers, employees and subcontractors.
(6) The Controller is responsible for keeping its own copies of content that matters to it. The Processor's liability for loss of data is limited to the effort that would have been required to restore it had the Controller kept reasonable backups.
§ 13 Final provisions
(1) This agreement supplements the Soltyx Service Terms agreed between the parties. Where the two conflict, this agreement prevails on questions of data protection and the Service Terms prevail on everything else, including liability.
(2) Amendments must be made in writing. Neither party may amend this agreement by its own declaration alone, and the Controller's agreement will not be deemed from silence. A new version takes effect only if the Controller expressly accepts it; until then the version last accepted continues to apply.
(3) This agreement is governed by the law of England and Wales.
(4) The courts of London have exclusive jurisdiction over any dispute arising out of or in connection with this agreement. The Processor may also bring proceedings in the courts of the Controller's own domicile.
(5) If any provision is or becomes invalid, the validity of the remainder is unaffected.