Legal
Data Processing Agreement
When we host a site for you, the personal data inside it stays yours — you are the controller and we are your processor. This agreement sets out how we handle that data on your behalf under the UK and EU GDPR.
About this agreement
Last updated: 22 July 2026.
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you (the "customer") and Zinn Digital® Ltd (Company No. 16385785), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Zinn Digital", "we", "us"). It applies where, in providing the hosting and related services, we process personal data on your behalf — principally the personal data contained inside the websites and applications you host with us.
It reflects Article 28 of the UK GDPR and the EU GDPR. For personal data where we are the controller — your account, billing and our own website-visitor data — our Privacy Policy applies instead of this DPA. If your organisation needs this DPA signed as a standalone document, contact us and we will arrange it.
1. Definitions and roles
Terms such as personal data, processing, controller, processor, sub-processor, data subject, personal data breach and supervisory authority have the meanings given in applicable data protection law (the UK GDPR, the EU GDPR, and the UK Data Protection Act 2018).
- For the personal data inside your hosted sites and applications ("customer personal data"), you are the controller and Zinn Digital® is the processor.
- Where your own end users' data is itself controlled by a third party for whom you act, you confirm you have the authority to instruct us on their behalf.
- Zinn Digital® remains the controller for account, billing and our own website-analytics data, governed by our Privacy Policy.
2. Scope, duration and our instructions
We process customer personal data only to provide, secure, support and maintain the hosting and related services you have bought, and only on your documented instructions — which include your configuration of the service and your use of its features. Using the service is itself an instruction to process the data it contains for those purposes.
The subject matter is the operation of your hosting; the duration is the term of your agreement plus any wind-down period in section 9. The nature and purpose of processing is hosting, storage, transmission, backup, security and support. The types of data and categories of data subject are whatever you choose to place on the service, which you control. We will tell you if, in our opinion, an instruction infringes data protection law, and we do not use customer personal data for our own purposes or to train models.
3. Confidentiality
We ensure that the people authorised to process customer personal data are bound by an appropriate duty of confidentiality, and we limit access to those who need it to deliver or support the service. Access to production systems is least-privilege and logged.
4. Security measures
We implement appropriate technical and organisational measures to protect customer personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access, appropriate to the risk. These include:
- Encryption of data in transit with TLS across our services.
- Per-tenant isolation so one customer's environment cannot reach another's, enforced down to the database with row-level security.
- Least-privilege access controls, with secrets held in a dedicated secrets manager rather than in code or configuration files.
- An auditable trail of privileged and administrative actions.
- Continuous monitoring, malware scanning, and a defined process for detecting, handling and reporting security incidents.
- Regular backups, with restoration testing, according to the retention window of your plan.
5. Sub-processors
You give general authorisation for us to engage sub-processors to help deliver the service. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible to you for their performance. We currently use sub-processors in the following categories:
- Infrastructure and cloud providers that host the platform and its data.
- Payment providers, to take payment and prevent fraud (they receive billing data, not the contents of your sites).
- A transactional email provider, to send account and service messages.
- A product-analytics provider (PostHog), used on our own websites only and only with the visitor's consent.
- Domain registries and DNS, CDN and security providers, where your plan uses them.
6. Changes to sub-processors
We keep the categories above current and will make a list of specific sub-processors available on request. Where we intend to add or replace a sub-processor that processes customer personal data, we will give you a way to be informed and a reasonable opportunity to object on legitimate data protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.
7. Assisting you with data subject rights
Taking into account the nature of the processing, we help you respond to requests from data subjects to exercise their rights — access, rectification, erasure, restriction, portability and objection — by providing the appropriate technical and organisational measures, and the tools in the service, insofar as this is possible.
If we receive a request directly from one of your data subjects, we will not respond to it ourselves except on your instruction or as legally required, and we will pass it to you where we can identify that it relates to your data.
8. Personal data breaches
We maintain a defined incident process. On becoming aware of a personal data breach affecting customer personal data, we notify you without undue delay and provide the information you reasonably need to meet your own notification duties to a supervisory authority and to data subjects — including the nature of the breach, the likely consequences, and the measures taken or proposed. We also assist you, taking into account the information available to us, with your obligations to keep processing secure, to carry out data protection impact assessments, and to consult supervisory authorities where required.
9. International transfers
We are based in the United Kingdom and prefer to keep data in the UK and the European Economic Area. Where customer personal data is transferred outside the UK or EEA — whether by us or a sub-processor — we rely on a lawful transfer mechanism such as an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, together with additional safeguards where needed, so the data keeps an essentially equivalent level of protection.
10. Return and deletion on termination
On the end of the service, and at your choice, we make customer personal data available for you to export for a reasonable period, and then delete or return it and delete existing copies, unless the law requires us to keep it. Data held in backups is deleted on the ordinary backup-expiry cycle. Where retention is legally required, we keep only what the law requires and continue to protect it under this DPA.
11. Audits and demonstrating compliance
We make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To protect the security and confidentiality of the shared platform and other customers, audits are on reasonable prior notice, at reasonable frequency, subject to confidentiality, and we may satisfy an audit request by providing our documentation, security descriptions and any third-party reports we hold.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service on the processing of customer personal data, this DPA prevails; if there is a conflict between this DPA and the Standard Contractual Clauses (where they apply), the clauses prevail.
13. How to contact us
The processor under this DPA is Zinn Digital® Ltd (Company No. 16385785), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For any data protection question, to exercise your rights, or to request this DPA as a signed standalone document, reach us through the contact page at zinndigital.com/contact, or email office@zinndigital.com. We route data protection requests to the person responsible for them.
Frequently asked questions
When does this DPA apply, and when does the Privacy Policy apply?
This DPA applies to the personal data inside the sites and applications you host with us, where you are the controller and we are your processor. Our Privacy Policy applies to the data we control in our own right — your account, your billing, and our own website-visitor analytics.
Do I need to sign anything?
This DPA already forms part of your Terms of Service, so it is in force without a separate signature. If your organisation's procurement needs it executed as a standalone document, contact us and we will arrange it.
Who are your sub-processors?
We use sub-processors in defined categories — infrastructure and cloud, payments, transactional email, product analytics (on our own sites only), and domain/DNS/CDN/security providers where your plan uses them. We will provide the specific list on request and give you a way to be informed of changes and to object.
Do you use my hosted data to train AI models?
No. We process the personal data inside your sites only to run the hosting on your documented instructions. We do not use it for our own purposes, and we do not use it to train models.
What happens to my data if I leave?
We make it available for export for a reasonable period, then delete or return it and delete our copies, except anything the law requires us to keep. Backups are deleted on their ordinary expiry cycle.