Paws Trend
  • Home
  • Services
    IT Services App & Web Development Custom GPTs & AI Agents Film & Content Creation Digital Marketing & Social Media
  • How We Work
  • About
  • Get in Touch

Data Processing Agreement

When we handle personal data on a client's behalf, we are the processor and the client is the controller. This is the agreement that governs that relationship.

On this page

  1. Roles
  2. Scope and instructions
  3. Confidentiality
  4. Security measures
  5. Sub-processors
  6. International transfers
  7. Assistance to the controller
  8. Personal data breaches
  9. Return and deletion
  10. Audits
  11. Liability and term
  12. Annexes
Last updated 9 September 2026 Version 1.0 (template) Form Incorporated into the engagement agreement

This is a published template, not a signed contract. It shows the terms Paws Trend is prepared to agree as a data processor. For a live engagement it is completed with the Annex details, signed by both parties, and — where a client has its own DPA — we are usually happy to sign theirs instead.

We recommend this template is reviewed by a qualified data protection adviser before it is offered to clients. Clause numbering and wording below are indicative, and the Annex fields are completed per engagement.

1. Roles of the parties

Where Paws Trend processes personal data in order to provide services under the engagement agreement, the client is the controller and Paws Trend is the processor, as those terms are used in the GDPR, the UK GDPR and (as “Data Fiduciary” and “Data Processor”) India's DPDP Act, 2023. Each party complies with the data protection law that applies to it. The client is responsible for having a lawful basis for the processing it instructs.

2. Scope and instructions

Paws Trend processes personal data only:

  • for the purposes set out in Annex 1 and as needed to provide the services;
  • on the client's documented instructions, including the engagement agreement and this DPA, and any later written instructions;
  • as required by a law that applies to Paws Trend — in which case, unless that law prohibits it, Paws Trend informs the client first.

Paws Trend tells the client if, in its opinion, an instruction infringes data protection law.

3. Confidentiality

Paws Trend ensures that everyone authorised to process the personal data is under an appropriate duty of confidentiality, is trained on their obligations, and only accesses the data they need for their role.

4. Security measures

Paws Trend implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the nature and risk of the processing. The measures in place are described in Annex 3 and include, as a baseline: encryption in transit, access control on individual accounts with least-privilege and multi-factor authentication, network and endpoint protection, logging, regular backups, patching, and a documented incident-response process.

5. Sub-processors

The client gives general authorisation for Paws Trend to engage the sub-processors listed in Annex 2. Paws Trend:

  • imposes data protection terms on each sub-processor that are no less protective than this DPA;
  • remains fully liable to the client for a sub-processor's performance;
  • gives the client at least 30 days' notice of any intended addition or replacement, during which the client may object on reasonable data protection grounds. If an objection cannot be resolved, either party may terminate the affected services.

6. International transfers

Where providing the services involves transferring personal data outside the country of origin (for example to a US-based host), Paws Trend ensures an appropriate transfer mechanism is in place — the European Commission's Standard Contractual Clauses, the UK Addendum / IDTA, or another lawful mechanism — together with any supplementary measures the transfer requires.

7. Assistance to the controller

Taking into account the nature of the processing, Paws Trend assists the client, by appropriate technical and organisational measures and insofar as possible, to:

  • respond to requests from data subjects exercising their rights;
  • meet its obligations on security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority (GDPR Articles 32–36 and equivalents).

Paws Trend promptly forwards any data subject request it receives directly, and does not respond itself except on the client's instruction.

8. Personal data breaches

Paws Trend notifies the client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the client's data, with the information the client needs to meet its own notification duties, and updates as more becomes known. Paws Trend takes reasonable steps to contain and remediate the breach.

9. Return and deletion

On termination of the services, or earlier at the client's written request, Paws Trend deletes or returns all personal data (at the client's choice) and deletes existing copies, unless a law requires it to keep the data — in which case it protects the data and processes it only as that law requires. Routine backups are overwritten on their normal cycle.

10. Audits

Paws Trend makes available to the client the information reasonably necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the client or an auditor it mandates, on reasonable notice, no more than once in any 12-month period except after a breach or at a regulator's request, and subject to confidentiality.

11. Liability, term and precedence

This DPA takes effect when the engagement agreement does and lasts as long as Paws Trend processes the client's personal data. It forms part of the engagement agreement; the engagement agreement's liability provisions apply to it. If there is a conflict on data protection matters, this DPA prevails over the rest of the engagement agreement, and a client's own executed DPA (where the parties sign one) prevails over this template.

12. Annexes

Annex 1 — Details of processing

Subject matter[the services in the engagement agreement]
DurationThe term of the engagement, plus any retention required by law
Nature and purpose[e.g. website hosting and maintenance, marketing campaign delivery, IT support, AI system development and operation]
Types of personal data[e.g. names, contact details, account identifiers, usage and device data, content submitted by the client's users]
Categories of data subjects[e.g. the client's customers, prospects, website visitors, employees]
Special category data[None expected / specify]

Annex 2 — Authorised sub-processors

Sub-processorFunctionLocation
Namecheap, Inc.Hosting and email infrastructureUnited States
Cloudflare, Inc.TLS, bot protection, cookieless analyticsUnited States / global edge
Cloudflare, Inc.DNS, CDN, TLS, bot protection, analyticsUnited States / global edge
[Email/newsletter platform, if used for a client][e.g. transactional or marketing email][region]
[Cloud / AI provider, if used, e.g. for a client's AI system][model hosting, vector store, compute][region]
[Analytics / ads platforms, if run for a client][campaign delivery and measurement][region]

The current list for a given engagement is the one in that engagement's signed DPA. This page is kept up to date as our standard providers change.

Annex 3 — Technical and organisational measures

  • Encryption — TLS for all data in transit; encryption at rest where the provider supports it.
  • Access control — individual named accounts, least privilege, multi-factor authentication on all administrative access, prompt removal of access when someone leaves a project.
  • Network and endpoint — managed firewalls, endpoint protection, patched systems.
  • Resilience — regular backups, tested restores, documented recovery steps.
  • Logging and monitoring — access and change logging, alerting on anomalies.
  • Organisational — confidentiality undertakings, data protection training, a named contact for data protection, an incident-response process, vendor due diligence before engaging a sub-processor.
  • Data minimisation — we ask clients for only the data an engagement needs, and delete it when the engagement ends.

Nothing on this page is legal advice. Data protection contact: privacy@pawstrend.com. See also our Privacy Policy.

Paws Trend

Trending creativity.

i t

Services

  • IT Services
  • App & Web Dev
  • AI Agents & GPTs
  • Film & Content
  • Digital Marketing

Company

  • About Us
  • How We Work
  • Services
  • Contact

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • Data Processing Agreement
© 2026 Paws Trend. All rights reserved.