Data Processing Agreement
Last updated: 20 June 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Vela Digital Hosting Agreement (the "Agreement") between Vela Digital ("we", "us", the "Processor") and the customer ("you", the "Controller"). It governs our processing of personal data contained in the content we host for you, under Article 28 of the UK GDPR and (where it applies) the EU GDPR. If there is any conflict between this DPA and the rest of the Agreement on the processing of personal data, this DPA prevails.
Roles & scope
Who is controller and who is processor, and over what data.
You are the controller of any personal data within the sites, databases, mailboxes and files we host for you (the "Customer Personal Data"). We act as your processor in respect of that data. You are responsible for having a lawful basis for the data you place on the service and for the accuracy and lawfulness of your instructions. Where we handle data for which we are ourselves the controller (such as your account and billing details), that is covered by our Privacy Notice at /privacy, not this DPA.
Subject matter & details of processing
The Article 28(3) particulars: nature, purpose, duration, data types and data subjects.
| Detail | Description |
|---|---|
| Subject matter | Provision of hosting and related managed services under the Agreement. |
| Nature & purpose | Storing, serving, backing up, transmitting and otherwise hosting the Customer Personal Data so the customer's site, application or mailbox functions. |
| Duration | For the term of the Agreement, plus the export and deletion windows set out below. |
| Types of personal data | Determined by the customer; typically names, contact details, account credentials, message/enquiry content and any data the customer's end users submit to the hosted service. |
| Categories of data subject | The customer's own customers, end users, staff and contacts. |
Our obligations as processor
The mandatory Article 28(3)(a)-(h) commitments.
We will:
- Process on instructions. Process the Customer Personal Data only on your documented instructions (including the Agreement and your use of the service), unless required by law — in which case we will tell you first unless the law forbids it.
- Confidentiality. Ensure that personnel authorised to process the data are bound by appropriate confidentiality obligations.
- Security. Implement appropriate technical and organisational measures under Article 32 (including encryption in transit, access controls on a need-to-know basis, and signed webhooks), proportionate to the risk.
- Sub-processors. Engage sub-processors only under the conditions below, with terms no less protective than this DPA.
- Assist with data-subject rights. Taking account of the nature of the processing, help you respond to requests from data subjects exercising their rights, so far as we reasonably can.
- Assist with compliance. Help you meet your obligations on security, breach notification, data-protection impact assessments and prior consultation, taking account of the information available to us.
- Breach notification. Notify you without undue delay (and in any event within 72 hours of becoming aware) of a personal-data breach affecting the Customer Personal Data, with the information you reasonably need to meet your own notification duties.
- Deletion or return. On the end of the Agreement, delete or return the Customer Personal Data as set out below.
- Audit & information. Make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits on reasonable notice, subject to confidentiality and to protecting other customers' data.
Sub-processors
How we use and change sub-processors, and your right to object.
You give general authorisation for us to engage the sub-processors listed at /legal/sub-processors to help deliver the service. We remain responsible for their performance. We will give you reasonable notice of any intended addition or replacement of a sub-processor (by updating that list and, where you ask, by email), giving you the chance to object on reasonable data-protection grounds; if we cannot resolve a reasonable objection, you may terminate the affected service.
International transfers
What happens when data moves outside the UK/EEA.
Where providing the service involves transferring Customer Personal Data outside the UK or EEA, we will ensure an appropriate safeguard is in place — the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU SCCs as applicable — together with any supplementary measures reasonably required.
Return & deletion
What happens to the data when the Agreement ends.
On termination or expiry of the Agreement you may, for 30 days, ask us to return a copy of the Customer Personal Data in a commonly used format. After that window we will delete the Customer Personal Data within 90 days, and instruct our sub-processors to do the same, except where we are required by law to keep limited records (which remain protected by this DPA for as long as we hold them).
Liability & precedence
How this DPA sits within the wider Agreement.
This DPA is incorporated into, and subject to, the Agreement — including its limitations of liability. Nothing in this DPA limits either party's obligations or liability under data-protection law to data subjects or regulators. For any data-protection matter, this DPA takes precedence over conflicting terms elsewhere in the Agreement. Questions about this DPA: contact info@vela-digital.uk.