Legal

Data Processing Addendum

Data protection terms that apply when Peak Platform processes personal data on behalf of a customer.

Last updated: 27 August 2026

Introduction

This Data Processing Addendum ("DPA") forms part of the agreement between PEAK PLATFORM WEBSITES LTD trading as Peak Platform ("Peak Platform", "we", "us", "our") and the customer receiving Peak Platform services ("Customer") where Peak Platform processes personal data on behalf of the Customer.

This DPA supplements the Peak Platform Terms and Conditions, applicable proposal, quotation, order, scope of work and/or other service agreement between Peak Platform and the Customer (together, the "Agreement").

Where Peak Platform processes personal data as a processor on behalf of the Customer, this DPA automatically applies to that processing.

1. Definitions

  • Applicable Data Protection Law — all applicable UK laws relating to privacy and the processing of personal data, including the UK GDPR, the Data Protection Act 2018 and other applicable legislation as amended or replaced from time to time.
  • Controller — the person or organisation determining the purposes and means of processing personal data.
  • Processor — a person or organisation processing personal data on behalf of a Controller.
  • Customer Personal Data — personal data processed by Peak Platform on behalf of the Customer in connection with the services.
  • Data Subject — an identified or identifiable individual to whom personal data relates.
  • Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Sub-processor — a third party engaged by Peak Platform to process Customer Personal Data in connection with providing the services.

2. Roles of the parties

Where Peak Platform processes Customer Personal Data solely on behalf of the Customer, the Customer is the Controller and Peak Platform is the Processor. The Customer determines the purposes for which Customer Personal Data is processed, and Peak Platform processes that data only as necessary to provide the contracted services and in accordance with the Customer's documented instructions.

Peak Platform may separately act as an independent Controller for personal data it processes for its own legitimate business purposes, including:

  • customer account administration;
  • invoicing;
  • payment records;
  • business communications;
  • fraud prevention;
  • legal compliance;
  • service administration;
  • and Peak Platform's own business records.

Such independent Controller processing is governed by our Privacy Policy rather than this DPA.

3. Customer instructions

Peak Platform will process Customer Personal Data only:

  • in accordance with the Agreement;
  • in accordance with this DPA;
  • according to documented instructions provided by the Customer;
  • as reasonably necessary to provide and maintain the contracted services;
  • or where processing is required by applicable law.

Written instructions may include instructions contained within the Agreement, a proposal, quotation or scope of work, email, support request, platform configuration, or another recorded written instruction.

If applicable law requires Peak Platform to process personal data contrary to the Customer's instructions, Peak Platform will inform the Customer before processing unless prohibited from doing so by law.

If Peak Platform reasonably believes an instruction infringes Applicable Data Protection Law, Peak Platform may inform the Customer and suspend the affected processing while the matter is resolved.

4. Details of the processing

Subject matter. Processing of personal data necessary to design, develop, host, maintain, support, automate, integrate and otherwise provide the digital services purchased from Peak Platform.

Duration. For the duration of the applicable Peak Platform service and for any reasonable period afterwards required to securely return, export, back up or delete data, subject to legal retention requirements.

Nature and purpose. Processing may include collection, recording, organisation, storage, hosting, retrieval, consultation, transmission, integration, modification, structuring, backup, support access, deletion, and other processing reasonably required to provide the contracted service.

Categories of Data Subjects. Depending on the Customer's service, this may include the Customer's customers, prospective customers, leads and enquiries, website visitors, employees, workers, contractors, applicants and candidates, suppliers, business contacts, platform users, members, and other individuals whose personal data the Customer chooses to process through the services.

Types of personal data. Depending on the service, this may include names, email addresses, telephone numbers, business details, postal addresses, enquiry information, contact-form submissions, account information, usernames, IP addresses, technical and device information, employment information, application information, uploaded documents, communications, CRM records, and other information entered, uploaded or transmitted through the Customer's service.

Customers must notify Peak Platform before intentionally using a service to process significant volumes of special-category personal data, criminal-offence data or other unusually sensitive information, so that appropriate safeguards and service suitability can be considered.

5. Customer responsibilities

The Customer is responsible for:

  • ensuring it has a lawful basis for processing Customer Personal Data;
  • providing appropriate privacy information to Data Subjects;
  • obtaining consent where consent is required;
  • ensuring instructions given to Peak Platform comply with Applicable Data Protection Law;
  • ensuring Customer Personal Data supplied to Peak Platform has been collected lawfully;
  • determining appropriate retention periods;
  • responding to Data Subjects as Controller;
  • ensuring the service is appropriate for the sensitivity of the information the Customer chooses to process;
  • maintaining appropriate account and access security under the Customer's control.

Peak Platform is not responsible for determining the Customer's lawful basis or deciding whether the Customer is legally permitted to collect particular information.

6. Confidentiality

Peak Platform will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, are given access only where reasonably necessary, and are informed of relevant data-protection responsibilities. Access to Customer Personal Data is limited to authorised personnel and contractors who require access to provide or support the services.

7. Security

Peak Platform will implement appropriate technical and organisational measures taking account of the nature of the processing, available technology, implementation costs, and the risks presented by the processing. Measures may include, where appropriate:

  • access controls and authentication;
  • encryption in transit, and encryption at rest where supported and appropriate;
  • secure hosting and role-based permissions;
  • password and access management;
  • software and dependency updates;
  • backups where applicable;
  • vulnerability remediation;
  • logging and monitoring where appropriate;
  • protection against unauthorised access;
  • procedures for responding to security incidents;
  • limiting access to personnel who reasonably require it.

No online service can be guaranteed completely secure, and we do not claim that a security incident can never occur. We take reasonable steps to protect Customer Personal Data and to review our measures over time.

8. Personal Data Breaches

Where Peak Platform becomes aware of a Personal Data Breach affecting Customer Personal Data, Peak Platform will notify the Customer without undue delay. Where reasonably available, notification will include information about the nature of the breach, the affected data, the affected Data Subjects, the likely consequences, measures taken or proposed, and relevant contact information.

Peak Platform will provide reasonable assistance to enable the Customer to meet applicable breach notification obligations. The Customer, acting as Controller, remains responsible for determining whether notification to the Information Commissioner's Office or affected Data Subjects is legally required.

9. Data Subject rights

Peak Platform will provide reasonable assistance, taking account of the nature of the processing, to help the Customer respond to Data Subject requests including, where applicable, access, rectification, erasure, restriction, portability, objection and other applicable rights.

Where Peak Platform receives a request directly relating to Customer Personal Data for which the Customer is Controller, Peak Platform will ordinarily direct or forward the request to the Customer rather than responding independently, unless legally required to do otherwise.

10. Compliance assistance

Taking account of the nature of processing and the information reasonably available to us, Peak Platform will provide reasonable assistance to the Customer regarding applicable obligations relating to:

  • security of processing;
  • Personal Data Breaches;
  • Data Protection Impact Assessments;
  • prior consultation with the ICO where legally required;
  • and other applicable Article 32–36 UK GDPR obligations.

Peak Platform may charge reasonable fees for substantial assistance outside the ordinary scope of the purchased service, provided any charge is communicated in advance.

11. Sub-processors

The Customer gives Peak Platform general written authorisation to engage Sub-processors where reasonably necessary to provide the services. Peak Platform may use Sub-processors for functions including website hosting, cloud infrastructure, databases, content delivery, email, communications, analytics, automation, APIs, AI-assisted functionality where applicable, payment processing, domain infrastructure, backups, monitoring, development infrastructure, and other supporting technology.

Peak Platform will ensure that Sub-processors processing Customer Personal Data are subject to written data-protection obligations providing an appropriate and legally required level of protection, and remains responsible for the performance of its Sub-processors' applicable data-processing obligations to the extent required by Applicable Data Protection Law.

Customers will be informed of material changes to Sub-processors, and may raise a reasonable data-protection objection to a new Sub-processor. This does not create a general right to veto technology suppliers for commercial reasons. Where a legitimate objection cannot reasonably be resolved, Peak Platform may offer an alternative solution where commercially reasonable, or allow termination of the affected service.

12. Sub-processor list

Peak Platform maintains information about material Sub-processors used in delivering its services. Customers may request the current Sub-processor list by contacting Adam@peakplatform.co.uk.

13. International data transfers

Where Customer Personal Data is transferred outside the United Kingdom in circumstances constituting a restricted transfer under Applicable Data Protection Law, Peak Platform will ensure an appropriate lawful transfer mechanism is used where required. This may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to approved EU Standard Contractual Clauses, or another legally recognised transfer mechanism. Where required, appropriate transfer assessments and supplementary safeguards will be considered.

14. Deletion and return of data

At the end of the applicable service, and subject to the Customer's instructions, Peak Platform will delete or return Customer Personal Data where required by Applicable Data Protection Law. Data may remain temporarily in backups, and backup copies may be retained until overwritten or deleted according to normal backup cycles. Retained backup data remains protected and is not actively processed except where necessary for restoration, security or legal requirements. Peak Platform may retain information where required by applicable law.

The Customer's rights to receive or request deletion of Customer Personal Data do not create any right to receive Peak Platform source code, software, website designs, frameworks, databases and database structures, reusable components, templates, systems or other Peak Platform intellectual property. Ownership and licensing of websites, software and domains are governed by the Terms and Conditions, which are unaffected by this DPA.

15. Audits and compliance information

Peak Platform will make available information reasonably necessary to demonstrate compliance with its applicable Article 28 obligations, and the Customer may request reasonable compliance information. Where an audit is genuinely required, it will:

  • be subject to reasonable prior written notice;
  • occur during normal business hours;
  • avoid unreasonable disruption;
  • protect Peak Platform's confidential information;
  • not expose information belonging to other customers;
  • use existing reports or documentation where those reasonably satisfy the requirement;
  • be conducted no more frequently than reasonably necessary, unless required following a security incident or by a regulator.

Peak Platform may charge reasonable costs for extensive audits or assistance beyond normal compliance obligations where legally permitted and communicated in advance. Nothing in this section restricts the lawful powers of the ICO or another competent regulator.

16. Records and regulatory cooperation

Peak Platform will maintain the records required of it under Applicable Data Protection Law and will reasonably cooperate with the ICO or another competent supervisory authority where legally required.

17. Liability

Liability arising under this DPA is subject to the applicable liability provisions and limitations in the Peak Platform Terms and Conditions or applicable Agreement, except to the extent such liability cannot lawfully be excluded or limited. Nothing in this DPA excludes regulatory responsibilities that apply directly to Peak Platform under Applicable Data Protection Law.

18. Order of precedence

If there is a conflict concerning the processing of personal data, the following apply in this order to the extent of the conflict:

  • mandatory Applicable Data Protection Law;
  • any legally required international transfer mechanism;
  • this DPA;
  • the applicable service Agreement / Terms and Conditions.

For commercial matters unrelated to personal-data processing, the normal Peak Platform Terms and the applicable proposal or scope of work continue to apply.

19. Duration

This DPA begins when Peak Platform begins processing Customer Personal Data as a Processor and continues for as long as Peak Platform processes Customer Personal Data on behalf of the Customer. Relevant confidentiality, deletion, security and data-protection obligations survive termination where necessary.

20. Changes to this DPA

Peak Platform may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, technology, Sub-processors, security practices or Peak Platform services. Material changes affecting existing processing arrangements will be communicated appropriately. Changes will not materially reduce the legally required protection for Customer Personal Data.

21. Governing law

This DPA is governed by the laws of England and Wales and follows the jurisdiction provisions contained in the Peak Platform Terms and Conditions, subject to mandatory Applicable Data Protection Law.

22. Contact

Questions relating to this DPA should be directed to:
PEAK PLATFORM WEBSITES LTD
Trading as Peak Platform
4th Floor, 14 Museum Place, City Centre, Cardiff, CF10 3BH, United Kingdom

Email: Adam@peakplatform.co.uk

This page is maintained by Peak Platform and is provided for information. It is not legal advice.