The agreement you sign
Data Processing Agreement
DKT Digital, St Peter Port, Guernsey GY1 · [email protected]
DRAFT — pending legal review, not binding. This document has not been reviewed by a solicitor. It is published so you can read our terms before you talk to us, and so we can be held to what it says — but it is a working draft, not a vetted contract, and nothing here is legal advice. A binding version will be issued for signature only once it has been through legal review. If you are relying on any part of it, ask us and we will tell you where it stands.
Where we handle personal data on your behalf, you are the data controller and we are your processor. This agreement is what governs that, and it wins over the engagement letter on any data-protection question. Schedule 1 lists every sub-processor that can touch your data.
This Data Processing Agreement ("DPA") is entered into between:
Data Controller: [CLIENT BUSINESS NAME] ("Client")
[Client address]
[Client registered number if applicable]
Data Processor: DKT Digital, operated by Daniel Thomas
St Peter Port, Guernsey GY1
[email protected]
Date: [DATE]
1. DEFINITIONS
"Personal Data" means any information relating to an identified or identifiable natural person, as defined in the Guernsey Data Protection (Bailiwick of Guernsey) Law 2017.
"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or erasure.
"Sub-processor" means any third party engaged by DKT Digital to process Personal Data on behalf of the Client.
2. PURPOSE AND SCOPE
2.1 DKT Digital processes Personal Data solely to deliver the automation services described in the Service Agreement between the parties.
2.2 The categories of Personal Data processed may include:
- Business contact details (names, email addresses, phone numbers)
- Customer/lead data provided by the Client
- Transaction and operational data from Client platforms
2.3 The data subjects are: Client's customers, leads, and business contacts.
3. DKT DIGITAL'S OBLIGATIONS
3.1 DKT Digital shall:
- a) Process Personal Data only on documented instructions from the Client
- b) Ensure that persons authorised to process Personal Data are bound by confidentiality
- c) Implement appropriate technical and organisational security measures
- d) Engage sub-processors only in accordance with clause 4 (corrected 2026-08-01: this sub-clause previously required "prior written consent from the Client" for every sub-processor, which contradicted the general authorisation granted in clause 4.1 of the same document)
- e) Assist the Client in responding to data subject rights requests
- f) Delete or return all Personal Data upon termination of the Service Agreement
- g) Provide all information necessary to demonstrate compliance with this DPA
3.2 DKT Digital shall notify the Client without undue delay upon becoming aware of a personal data breach.
4. SUB-PROCESSORS
4.1 The Client grants general authorisation to engage the sub-processors listed in Schedule 1. *(Corrected 2026-08-01. This clause previously named three sub-processors — Stripe, Beehiiv and the AI providers — while the platform in fact relied on around fifteen, including the company hosting the database itself. A partial list in a general-authorisation clause is worse than no list, because it reads as complete. Schedule 1 is now the single enumeration and is generated from the live system.)*
4.2 DKT Digital shall give the Client notice of any intended addition or replacement of a sub-processor, and the Client may object on reasonable data-protection grounds.
4.3 DKT Digital shall impose on each sub-processor data-protection obligations equivalent to those in this Agreement, and remains liable to the Client for a sub-processor's performance.
4.4 On personal data and model providers. Where a Service uses an automated language model, the text sent may include Client business data, and may include business contact details where the task requires it (for example drafting a reply to a named enquirer). DKT Digital shall not send special category data, payment card data, health data, or identity documents to any model provider, and shall not send Client Personal Data to a model provider in a jurisdiction described in 7B.4. *(Corrected 2026-08-01: this clause previously read "DKT Digital will not send Client's customers' personal data to AI APIs", which contradicted 7B.3 in the same document and overstated the position. The restriction that is actually operated is the one stated here.)*
5. SECURITY
5.1 DKT Digital implements the following measures. These are stated as measured on 2026-08-01, and each is either true or explicitly marked as not yet in place:
- All data transmitted over HTTPS/TLS.
- The automation engine is not exposed directly to the internet; it is reachable only through a Cloudflare tunnel with TLS, rate-limiting, bot protection and access control in front of it. There is no public port on the host for it.
- The PostgreSQL database is password-protected, bound to the host's internal interface, and not internet-facing.
- Application credentials and API keys are held in a permission-restricted file on the server and injected as environment variables — never in source files or version control, enforced by an automated secret scan.
- Client accounting and banking OAuth tokens are additionally encrypted at the row level (
pgp_sym_encrypt) with a key held only in the server environment, so a database dump does not disclose them. - Nightly backups with integrity checks that abort rather than store a corrupt file, replicated off-site to Cloudflare R2 encrypted with
age; alerting fires on any backup failure. - Not in place: block-level (disk) encryption of the database volume. The host filesystem is not encrypted at rest. This is stated rather than glossed; see Security Overview §2.
6. DATA SUBJECT RIGHTS
6.1 DKT Digital shall assist the Client to fulfil data subject rights requests within the timescales required by applicable law (generally 30 days under the Guernsey DP Law 2017).
7. RETURN AND DELETION
7.1 Upon termination, DKT Digital shall, within 10 working days — the same window the Offboarding document and the Letter of Engagement both state, and the Offboarding document governs the process:
- a) Return to the Client a copy of all Personal Data in a portable format
- b) Delete all copies of Personal Data from its systems, subject to 7.2
- c) Certify in writing what was deleted and when
7.2 Retention required by law. Sub-clause 7.1(b) does not require deletion of records DKT Digital is required by law to retain — principally financial and tax records such as invoices and payment records. Those are retained for the period required and then deleted; they are not used for any other purpose in the meantime. Backups already taken age out under the normal backup-retention window rather than being individually edited.
*(7.1 window aligned and 7.2 added 2026-08-01. §7.1 previously said "within 14 days" while the Offboarding document and the Letter of Engagement both say "within 10 working days" — three documents, two units, and no statement of which governed. They are now one figure rather than an assertion that 14 calendar days and 10 working days are equivalent, which is only true when the span happens to contain exactly two weekends and no public holidays. §7.1 also previously promised deletion of all copies with no carve-out, which was a promise this business cannot lawfully keep and which contradicted three other documents that all say the opposite — the Offboarding document, the Security Overview §6 retention table, and the published Privacy Policy. A deletion promise that has to be broken is worse than a narrower one that holds.)*
[SOLICITOR] — the retention period itself is deliberately not stated here. The Privacy Policy says 7 years (citing Guernsey financial record-keeping) and the Security Overview's proposed retention column says 6 years (tax). Those are two different numbers for the same records and only a solicitor should settle which is correct for a Guernsey sole trader serving UK clients. Tracked as
LEGAL-RETENTION-6-VS-7-YEARS.
7A. AUDITS AND INSPECTIONS
*Added 2026-07-30. UK GDPR Article 28(3)(h) requires the processor to make available all information necessary to demonstrate compliance and to allow for and contribute to audits and inspections. This was the one mandatory head of Article 28(3) the template did not cover — measured against the ICO's own checklist, not assumed.*
7A.1 DKT Digital shall make available to the Client all information reasonably necessary to demonstrate compliance with its obligations under this Agreement and Article 28 UK GDPR.
7A.2 DKT Digital shall allow for and contribute to audits and inspections of its processing activities by the Client or an auditor mandated by the Client, on not less than 14 days' written notice, no more than once in any 12-month period unless a Personal Data Breach has occurred.
7A.3 An audit shall be conducted during normal business hours, shall not unreasonably disrupt DKT Digital's operations, and shall not require disclosure of information relating to other clients.
7A.4 Where DKT Digital holds a current independent certification or report covering the relevant controls, provision of that report shall satisfy 7A.2 unless the Client has reasonable grounds to require a direct audit. *(DKT Digital holds no such certification at the date of this template — see the register entry LEGAL-DPA-AUDIT-CLAUSE.)*
7B. INTERNATIONAL TRANSFERS
*Added 2026-07-30. Not one of the Article 28(3) heads, but load-bearing here as a matter of fact: the platform sends prompt text to model providers outside the UK. Naming them is what makes the transparency clause in the Letter of Engagement true rather than decorative.*
7B.1 **Personal Data is stored in the European Union — specifically on infrastructure operated by Hetzner Online GmbH in Falkenstein, Germany** — and is served through Cloudflare's network. DKT Digital is established in the Bailiwick of Guernsey. Processing that involves a transfer outside the UK/EEA is limited to the sub-processors listed in Schedule 1 and to the purpose stated there. *(Corrected 2026-08-01. This clause previously stated that Personal Data is stored in the United Kingdom. That was wrong: the platform was migrated to a German host on 2026-07-24 and the clause was not updated. It was verified against the live server before this correction was written.)*
7B.2 Where Personal Data is transferred outside the UK/EEA, DKT Digital shall ensure the transfer relies on a valid transfer mechanism (adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses).
7B.3 Model providers. Where a Service uses an automated language model, the text sent to the provider may include Client business data. DKT Digital shall not send special category data, payment card data, or health data to any model provider. Model providers used are named in Schedule 1 and do not train their models on API-submitted content.
7B.4 DKT Digital shall not send Client Personal Data to a model provider established in a jurisdiction whose national security law permits compelled disclosure without judicial oversight. *(This reflects a rule that is already enforced inside the platform, prohibiting the sending of client names, emails, financial account details, health data or identity documents to certain providers. It is stated here so the contractual promise and the engineering rule are the same sentence rather than two things that can drift apart.)*
8. GOVERNING LAW
This DPA is governed by the laws of the Bailiwick of Guernsey.
[SOLICITOR] — WHICH REGIME ACTUALLY GOVERNS, AND WHERE DISPUTES GO. NOT SETTLED HERE. This document deliberately states the facts and stops. The facts, each verified rather than assumed:
- The processor is established in Guernsey. DKT Digital is the trading name of Daniel Thomas, a sole trader in the Bailiwick of Guernsey, whose data-protection law is the Data Protection (Bailiwick of Guernsey) Law 2017 — the law §1 uses to define "Personal Data", and the law this clause names as governing.
- The data is processed in Germany. Per §7B.1, the platform and the database run on infrastructure operated by Hetzner Online GmbH in Falkenstein — inside the EU/EEA, so EU GDPR is the law of the place of processing.
- The clients are expected to be in the UK. §7A cites UK GDPR Article 28 and the audit obligations are drafted to the ICO's Article 28 checklist.
So three regimes touch this one agreement, and this document currently names Guernsey law as governing while importing UK GDPR obligations. That may well be right — a UK client will reasonably expect UK GDPR terms, and a processor can contract to standards higher than its own jurisdiction requires. But whether Guernsey governing law plus a Guernsey jurisdiction clause is the correct and enforceable choice for a UK controller, and whether the Article 28 wording should cite UK GDPR, EU GDPR, the Guernsey Law or all three, is a legal judgement. **It has not been made here, and no number, period or forum has been invented to paper over it.** Tracked as
LEGAL-GOVERNING-LAW-VS-UK-GDPR.
SCHEDULE 1 — SUB-PROCESSORS
*Added 2026-08-01. Clauses 4.1, 7B.2 and 7B.3 each referred to "Schedule 1" and no Schedule 1 existed — three cross-references pointing at nothing. This schedule is the enumeration taken from the live system (the same list as Security Overview §3), so the contract and the engineering reality are one list rather than two.*
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the automation engine and the database — all Personal Data at rest | Germany |
| Cloudflare, Inc. | Website and portal delivery, tunnel, access control, bot protection, encrypted off-site backup storage (R2) | Global edge |
| Resend | Transactional email delivery to the Client's contacts | US |
| Brevo | Transactional email delivery (secondary path) | France (EU) |
| Google (Workspace / Cloud, via service account) | Calendar bookings; optional spreadsheet sync | US / EU |
| GoCardless Ltd | Direct Debit mandates and retainer collection | UK |
| Stripe, Inc. | Card payment processing | US / Ireland (EU) |
| TrueLayer Ltd | Open-banking verification, only where the Client authorises a bank feed | UK |
| Xero Ltd | The Client's own accounting data, under the Client's own authorisation | New Zealand / global |
| Calendly LLC | Meeting booking (name, email) | US |
| Crisp IM SAS | Website live chat (visitor messages, email) | France (EU) |
| Hunter.io | Email-address verification for outbound marketing only — never transactional Client sends | EU / US |
| Apollo.io | Prospect sourcing for outbound marketing — not existing-Client data | US |
| Telegram FZ-LLC | Operational alerts to DKT Digital, which may contain names or email addresses | Global |
| Twilio Inc. | SMS notifications. Not currently live — becomes a sub-processor only if SMS is enabled for the Client | US |
| Groq, Inc. · Cerebras Systems · Google (Gemini) · OpenRouter | Automated language-model processing, subject to clauses 4.4 and 7B.3–7B.4 | US |
Model providers in this schedule are used through their APIs and do not train their models on API-submitted content.
SIGNATURES
For and on behalf of [CLIENT BUSINESS NAME]:
Name: ________________________
Title: ________________________
Date: ________________________
Signature: ________________________
For and on behalf of DKT Digital:
Name: Daniel Thomas
Title: Sole trader (DKT Digital is the trading name of Daniel Thomas)
Date: ________________________
Signature: ________________________
NOT LEGAL ADVICE
This template was drafted by an automated system against the ICO's published Article 28 guidance and has not been reviewed by a solicitor. It is a starting point for that review, not a substitute for it. Clauses 7A and 7B in particular were added on 2026-07-30 to close measured gaps and have had no professional review at all. Tracked in our internal legal-document register.
Corrections made on 2026-08-01, before this template was published on the website. Each was a factual defect verified against the live system, not a drafting preference — and each is flagged in place so the solicitor can see what changed and why:
- 7B.1 said Personal Data is stored in the United Kingdom. It is stored in Germany. The platform moved to a German host on 2026-07-24 and the clause was never updated. This was the most serious of the four: a data-location statement in a data-processing agreement that a client would rely on.
- 4.1 named three sub-processors where the live system relies on about fifteen — including the company hosting the database. Replaced by Schedule 1.
- Schedule 1 did not exist, though three separate clauses referred to it. Now written.
- 4.2 and 7B.3 contradicted each other on whether personal data reaches model providers. Now one statement (4.4), matching what the system actually enforces.
- 3.1(d) required written consent for every sub-processor, contradicting the general authorisation in clause 4.1 of the same document.
- §5 described the pre-migration setup and claimed only "regular backups of all configurations". Rewritten from measurement, including an explicit statement of the control that is not in place.