Last updated: July 2026
Data Processing Agreement
This agreement governs how Served Online handles personal data on your behalf when we host your website. It forms part of our Terms of Service and takes effect when you become a customer.
Roles
When your website collects personal data from your own visitors — for example, someone submitting your contact form — you are the data controller and Served Online is your data processor, acting on your instructions. This agreement covers only that processing. (Data we handle for our own purposes — billing you, contacting you — is covered by our Privacy Policy, where we are the controller.)
What we process, and why
- Purpose: to host your website and pass enquiries submitted through it to you.
- Nature of processing: receiving a contact-form submission, transmitting it to you by email, and recording that a submission occurred.
- Duration: for as long as we host your site under an active Care Plan.
- Categories of data subject: your website visitors who choose to contact you.
- Categories of personal data: the details an enquirer enters into your contact form — typically their name, email address, phone number (if provided) and the content of their message.
Important: we deliver each enquiry to you by email and do not store its contents. Our systems retain only a non-identifying record that a submission occurred (a reference to your site and a timestamp) — no enquirer names, contact details or messages are kept in our database.
Our obligations
We will:
- Process this personal data only on your documented instructions, including for any transfer outside the UK, unless we're required to do otherwise by law (in which case we'll tell you, unless the law prevents it).
- Ensure anyone authorised to process the data is bound by confidentiality.
- Apply appropriate technical and organisational security measures (see below).
- Engage sub-processors only as set out below, and place equivalent data-protection obligations on them.
- Assist you, as far as we reasonably can, in responding to requests from individuals exercising their rights (access, erasure, and so on).
- Assist you with your obligations around security, breach notification and impact assessments, taking into account the information available to us.
- On termination, delete the submission records we hold. As we don't store enquiry contents, there is nothing further to return.
- Make available the information you reasonably need to demonstrate our compliance with this agreement.
Security
We host on Cloudflare's infrastructure, serve all sites over encrypted connections (HTTPS), transmit enquiries over encrypted email connections, and restrict access to our systems to authorised persons only. Because enquiry contents aren't stored on our systems, the volume of personal data at rest is minimal by design.
Sub-processors
We use the following sub-processors for this processing:
- Cloudflare — hosts your website and serves the contact form.
- SendGrid (Twilio) — delivers enquiry emails to you.
- Supabase — stores the non-identifying submission record (EU-hosted, Frankfurt).
We'll give you reasonable notice of any intended change to these sub-processors, so you can object.
International transfers
Where a sub-processor processes data outside the UK (Cloudflare and SendGrid/Twilio), that transfer is protected by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or an equivalent approved safeguard.
Personal data breaches
If we become aware of a personal data breach affecting data we process for you, we'll notify you without undue delay and give you the information you reasonably need to meet your own notification obligations.
Liability
Each party's liability under this agreement is subject to the limitations of liability set out in our Terms of Service.
Governing law
England and Wales.