- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Services where we process personal data on a business customer’s documented instructions
On this page
Data Processing Addendum
This Data Processing Addendum forms part of the Agreement where DM Digital UK Services Ltd processes personal data on the Client’s documented instructions.
1. Definitions and status
Data Protection Laws means the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, PECR and other applicable UK data protection legislation, as amended.
Controller, Processor, Personal Data, Personal Data Breach, Data Subject and Processing have the meanings in Data Protection Laws.
The Client is the Controller and we are the Processor for Client Personal Data, except where the Service description or privacy notice identifies an independent-controller activity.
2. Processing details
| Element | Description |
|---|---|
| Subject matter | Provision, hosting, support, security, communication, backup, integration and administration of the Services |
| Duration | The Agreement plus the applicable return, deletion, backup and legal-retention period |
| Nature and purpose | Collection, recording, organisation, storage, retrieval, consultation, transmission, support, analysis, restriction, deletion and other processing necessary to provide the Services |
| Data subjects | Client staff, authorised users, customers, booking guests, suppliers, contractors, website users, Wi-Fi users and other individuals whose data the Client submits |
| Data types | Identity, contact, booking, communications, account, workforce, usage, device, audit, security, preference, support and payment-reference data |
| Special categories | May include allergy, dietary, health, accessibility or other information submitted by the Client or guest; criminal-offence data is not intended unless expressly agreed |
3. Documented instructions
We will process Client Personal Data only on documented instructions, including the Agreement, platform configuration, authorised support requests and ordinary use of the Service, unless law requires otherwise. If law permits, we will inform the Client before legally required processing.
If we reasonably believe an instruction infringes Data Protection Laws, we may suspend the affected processing and notify the Client. We are not required to provide legal advice or follow an unlawful instruction.
4. Client obligations
The Client warrants that:
- its instructions and processing are lawful, fair and transparent;
- it has identified lawful bases and Article 9 conditions where required;
- it has provided required privacy information and obtained valid consents where relied on;
- Personal Data is adequate, relevant, accurate and limited to what is necessary;
- it will not submit data materially exceeding the agreed scope or risk profile without prior agreement; and
- it will maintain appropriate administrator, user, retention and access settings.
5. Confidentiality and personnel
We will ensure persons authorised to process Client Personal Data are subject to confidentiality obligations and receive appropriate instruction or training for their role.
6. Security
We will implement appropriate technical and organisational measures having regard to the state of the art, implementation cost, nature, scope, context and purposes of processing and risk to individuals. Measures may include access control, authentication, least privilege, logging, encryption in transit, segmentation, patching, backups, supplier due diligence and incident management.
The Client acknowledges that security is shared and must implement measures within its control, including secure endpoints, account governance, lawful configuration and staff training.
7. Subprocessors
The Client gives general written authorisation for the subprocessors listed in the Subprocessor List and for replacements necessary to provide the Services. We will impose data-protection obligations materially equivalent to those required by Article 28.
For a material new subprocessor affecting Client Personal Data, we will provide reasonable notice through the Legal Hub, portal or service communication. The Client may object within 14 days on reasonable documented data-protection grounds. The parties will seek a practical solution; if none is available, either party may terminate the materially affected Service, with prepaid Charges for the unprovided period credited after non-cancellable costs.
8. International transfers
We will not initiate a restricted transfer unless covered by an adequacy regulation, appropriate safeguard or other lawful mechanism. Where appropriate, we may enter into the UK IDTA or UK Addendum and conduct a transfer risk assessment.
9. Data subject requests
Taking into account the nature of processing, we will provide reasonable assistance for the Client to respond to requests. If we receive a request relating to Client-controlled data, we will normally direct the individual to the Client unless authorised or legally required to respond.
Assistance beyond standard platform functionality is chargeable at the Fee Schedule unless caused by our breach.
10. Personal data breaches
We will notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data. Notification will include available information reasonably necessary for the Client’s assessment and will be updated as investigation progresses.
Notification is not an admission of fault. The Client is responsible for regulator and data-subject notification decisions unless law imposes that duty on us in our separate controller capacity.
11. DPIAs and regulatory consultation
Taking into account the processing and information available, we will provide reasonable assistance with data protection impact assessments and prior consultation. Bespoke assistance is chargeable unless required because of our breach.
12. Return and deletion
On termination and on documented request, we will return or delete Client Personal Data in accordance with the Service and Retention Schedule, unless law requires retention. Data may remain in protected backups until overwritten through the normal cycle and will not be restored except for disaster recovery or legal obligation.
13. Audit information
We will make available information reasonably necessary to demonstrate compliance, which may include policies, summaries, questionnaires, certificates or independent reports where available.
On at least 20 Business Days’ notice, the Client may request one audit per year during normal hours, limited to systems relevant to its processing. Audits must protect other customers and security, avoid disruption and be conducted by a bound independent auditor. The Client bears its costs and our reasonable assistance costs unless a material breach is found.
14. Liability
Liability under this Addendum is subject to the liability provisions of the Agreement. Nothing limits liability that cannot lawfully be limited.
15. Precedence
For conflict concerning processing of Client Personal Data, this Addendum prevails over the Master Terms, but the Order prevails where it expressly identifies and varies a specific DPA provision.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
