Data Processing Agreement
Last updated: October 5, 2026
This Data Processing Agreement ("DPA") applies when Tidypage processes personal data on your behalf, mainly while we host your website during its first year. It forms part of our Terms of Service. By accepting the Terms of Service, you also accept this DPA.
1. Parties and roles
- You (the customer who ordered the website) are the controller of the personal data collected through your website. If you yourself act as a processor for another controller, you confirm that you are authorised to appoint us, and we act as your sub processor.
- We are Hoang Films Limited, operating Tidypage, registered in to be completed: company jurisdiction under number to be completed: company registration number, at to be completed: company address ("we", "us"). For this processing, we are your processor.
- Under the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws, you are the "business" (or "controller") and we are your "service provider" (or "processor").
This DPA does not cover the personal data we process as a controller to run Tidypage (your account, your order, your messages to us). That is described in our Privacy Policy.
2. Definitions
- Data Protection Laws means all laws on the protection of personal data that apply to the processing under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA and other US state privacy laws.
- GDPR means Regulation (EU) 2016/679. UK GDPR means the GDPR as it forms part of the law of the United Kingdom, together with the UK Data Protection Act 2018.
- Customer Personal Data means the personal data we process on your behalf under this DPA, as described in Annex 1.
- Sub processor means any third party we engage to process Customer Personal Data.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- Terms such as "controller", "processor", "data subject", "personal data" and "processing" have the meaning given in the GDPR. Terms such as "business", "service provider", "sell", "share" and "business purpose" have the meaning given in the CCPA.
3. Details of the processing
The subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex 1.
4. Your instructions
- We process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless the law we are subject to requires otherwise. In that case, we inform you of that legal requirement before processing, unless the law prohibits it.
- Your documented instructions are: the Terms of Service, this DPA, the choices you make in your dashboard (for example the email address that receives your contact form messages), and any other written instruction you give us that is consistent with the agreed service.
- We inform you immediately if, in our opinion, an instruction infringes Data Protection Laws.
- You are responsible for the lawfulness of the processing you ask us to carry out. In particular, you are responsible for having a legal basis for collecting personal data through your website, for publishing a privacy notice on your website, for obtaining any consent required (for example for non essential cookies on your website), and for the accuracy of the personal data you publish.
5. Confidentiality
We ensure that every person we authorise to process Customer Personal Data has committed to confidentiality or is under an appropriate legal obligation of confidentiality, and only has access to the data needed for their task.
6. Security
- We implement appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the GDPR and of the UK GDPR. These measures are described in Annex 2.
- We may update these measures over time, provided the overall level of security is not reduced.
7. Sub processors
- General authorisation. You give us a general authorisation to engage sub processors. The sub processors we use at the date of this DPA are listed in Annex 3.
- Notice of changes. We inform you of any intended addition or replacement of a sub processor at least to be completed: subprocessor notice days days in advance, by email or in your dashboard, and we update Annex 3.
- Your right to object. You may object to a new sub processor on reasonable data protection grounds, by writing to hello@tidypage.app within that notice period. We will then work with you in good faith to find a solution. If we cannot, you may end the hosting service, and we will give you a copy of your website files so that you can host it elsewhere.
- Same obligations. We impose on each sub processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA.
- Our responsibility. We remain responsible to you for the performance of our sub processors' obligations.
8. Requests from data subjects
- Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, as far as possible, to respond to requests from data subjects exercising their rights (for example access, correction, deletion, objection).
- If we receive such a request directly about Customer Personal Data, we forward it to you without undue delay and do not answer it ourselves, except to tell the person that we have passed on their request to you.
9. Other assistance
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations regarding:
- the security of processing;
- the notification of Personal Data Breaches to supervisory authorities and to data subjects;
- data protection impact assessments and prior consultation of supervisory authorities, where the processing we carry out is relevant to them.
10. Personal Data Breaches
- We notify you of any Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 48 hours after becoming aware of it.
- Our notice describes, as far as we know at that time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and limit its effects, and a contact point for more information. Where we cannot provide all this information at once, we provide it in stages without further undue delay.
- We take reasonable steps to contain and investigate the breach and to limit its consequences.
- Our notification of a breach is not an acknowledgment of fault or liability.
11. End of the processing: deletion or return
- When the hosting service ends, or earlier if you ask us in writing, you choose whether we return Customer Personal Data to you (together with your website files) or delete it.
- We carry out your choice within to be completed: deletion period days days. If you have not made a choice by the end of the hosting service, we ask you, and if you still have not answered within that period, we delete the data.
- Copies held in backups are deleted in the normal backup cycle, within to be completed: backup retention period at most, and remain protected by this DPA until then.
- We may keep Customer Personal Data only where the law we are subject to requires it, and only for as long as required. This DPA continues to apply to that data.
- On request, we confirm the deletion in writing.
12. Information and audits
- We make available to you all information reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR and of the UK GDPR, including answers to reasonable written security questionnaires.
- We allow for and contribute to audits, including inspections, carried out by you or by an independent auditor you appoint who is bound by confidentiality, under the following conditions:
- you give us at least 30 days' written notice, unless a shorter period is required by a supervisory authority or follows a Personal Data Breach;
- audits take place no more than once in any 12 month period, unless required by a supervisory authority or following a Personal Data Breach;
- audits take place during normal business hours, and do not disrupt our service or give access to other customers' data;
- each party bears its own costs, unless the audit reveals a material breach of this DPA by us, in which case we bear the reasonable costs of the audit.
- Where relevant, we may meet these requests by providing the certifications or audit reports of our sub processors.
13. International transfers
- We and our sub processors may process Customer Personal Data outside the country where it was collected, including in to be completed: team locations, in to be completed: hosting location and in the other locations listed in Annex 3.
- Transfers from the European Economic Area. Where processing under this DPA involves a transfer of Customer Personal Data from the European Economic Area to a country that the European Commission has not recognised as providing an adequate level of protection, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor;
- you are the data exporter and we are the data importer;
- in Clause 7, the optional docking clause does not apply;
- in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in section 7 of this DPA;
- in Clause 11, the optional language does not apply;
- in Clause 13, the competent supervisory authority is determined in accordance with that Clause;
- in Clause 17, the SCCs are governed by the law of to be completed: scc governing law;
- in Clause 18, disputes are resolved by the courts of to be completed: scc governing law;
- Annexes I and II of the SCCs are completed with the information in Annexes 1, 2 and 3 of this DPA.
- Transfers from the United Kingdom. Where the UK GDPR applies to such a transfer, the UK Addendum is incorporated into this DPA by reference. Table 1 is completed with the parties' details in section 1 of this DPA, Table 2 refers to the SCCs as set out above, Table 3 is completed with Annexes 1, 2 and 3 of this DPA, and in Table 4 either party may end the UK Addendum as allowed by its Section 19.
- Transfers from Switzerland. Where Swiss law applies to such a transfer, the SCCs apply as set out above, with the following adaptations: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the term "member state" does not exclude data subjects in Switzerland from bringing claims in their place of habitual residence.
- Onward transfers. Where we transfer Customer Personal Data to a sub processor in a country without an adequate level of protection, we put in place an appropriate safeguard, such as the SCCs (Module Three) or the sub processor's certification under the EU US Data Privacy Framework and its UK and Swiss extensions.
- If a court or authority invalidates a transfer mechanism we rely on, we work with you to put in place an alternative mechanism without undue delay.
14. United States privacy laws
Where the CCPA or another US state privacy law applies to Customer Personal Data, we act as your service provider or processor, and we:
- do not sell or share Customer Personal Data;
- do not retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Terms of Service (hosting your website, delivering your contact form messages, making the edits you ask for, and keeping the service secure), or as otherwise permitted by the CCPA and its regulations;
- do not retain, use or disclose Customer Personal Data outside the direct business relationship between you and us;
- do not combine Customer Personal Data with personal information we receive from or on behalf of anyone else, or collect from our own interactions with consumers, except as permitted by the CCPA and its regulations;
- comply with the obligations that apply to us under the CCPA and provide the same level of privacy protection as the CCPA requires of you;
- notify you if we determine that we can no longer meet our obligations under the CCPA;
- allow you to take reasonable and appropriate steps to ensure that we use Customer Personal Data in a manner consistent with your obligations under the CCPA, and, upon notice, to stop and remediate any unauthorised use;
- require our sub processors, by written contract, to meet the same obligations.
We certify that we understand and will comply with these restrictions. Sections 5, 6, 7, 10, 11 and 12 of this DPA also apply to processing governed by US state privacy laws, which include the duties of confidentiality, deletion or return, information, assessment and subcontracting those laws require.
15. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in section 12 of the Terms of Service, as if they were set out here. Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws, including the rights of data subjects under Article 82 of the GDPR or of the UK GDPR, or the rights of data subjects as third party beneficiaries under the SCCs.
16. Duration, precedence and changes
- Duration. This DPA applies for as long as we process Customer Personal Data on your behalf, and its obligations continue until that data has been returned or deleted.
- Precedence. If there is a conflict, the SCCs (and the UK Addendum) prevail over this DPA, and this DPA prevails over the Terms of Service on matters of data protection.
- Changes. We may update this DPA to reflect changes in Data Protection Laws or in our sub processors (following section 7). We will tell you before any change that reduces the protection of Customer Personal Data takes effect.
- Governing law. Except for the SCCs and the UK Addendum, which are governed by the law they specify, this DPA is governed by the same law as the Terms of Service.
- Contact. For any question about this DPA, write to hello@tidypage.app.
Annex 1: Details of the processing
- Subject matter. Hosting your website and making the edits you request, as described in the Terms of Service.
- Duration. The hosting period (12 months from the day your website goes live, plus any renewal you agree with us), followed by the return or deletion period in section 11.
- Nature of the processing. Storage, hosting and serving of your website; collection and transmission of contact form submissions; recording of server and security logs; backup; editing of your website content at your request; deletion.
- Purpose. To make your website available online, to deliver the messages your visitors send through your contact form to the email address you choose, to keep your website secure and available, and to make the edits you ask for.
- Categories of data subjects.
- Visitors to your website.
- People who send a message through your website's contact form.
- People whose personal data appears in your website content (for example your team members).
- Categories of personal data.
- Contact form submissions: the fields your form contains (for example name, email address, phone number) and the content of the message, which may include any information the visitor chooses to write.
- Server and security logs: IP address, browser and device information, date and time of requests, pages requested, referring page.
- Personal data contained in your website content (for example names, job titles and photos of your team members).
- Special categories of data. None are intended. Your website is not designed to collect special categories of personal data (such as health data), and you agree not to ask visitors for them without telling us first, so that we can agree on appropriate additional safeguards.
- Frequency of transfers. Continuous, for as long as we host your website.
- Retention. Server logs: to be completed: client site log retention. Contact form submissions: to be completed: contact form storage policy. Website content: for the hosting period. In all cases, followed by return or deletion under section 11.
Annex 2: Technical and organisational security measures
- Encryption in transit. Every website we host is served over HTTPS only.
- Access control. Access to hosting accounts and to Customer Personal Data is limited to the team members who need it for their task, through individual accounts protected by multi factor authentication. Access is removed when it is no longer needed.
- Least privilege and traceability. Administrative actions on our systems are recorded in audit logs.
- Data minimisation. Contact forms only collect the fields needed for their purpose. Logs are kept for a limited time (Annex 1).
- Protection against abuse. Contact forms are protected against spam and automated abuse with rate limiting.
- Maintenance. Software, dependencies and hosting configurations are kept up to date, and security patches are applied promptly.
- Infrastructure. Our hosting providers are selected for their security commitments. Encryption at rest and physical security of data centres are provided by them, as described in their own documentation.
- Availability and backups. Your website and its data are backed up to be completed: backup frequency, and backups are kept for to be completed: backup retention period.
- Confidentiality. Everyone with access to Customer Personal Data is bound by confidentiality.
- Incident response. We follow a documented process to detect, assess, contain, notify and learn from security incidents, including the 48 hour notice in section 10.
- Deletion. Data is deleted securely at the end of the processing, as described in section 11.
- Review. We review these measures at least once a year and after any significant incident.
Annex 3: Sub processors
| Sub processor | Service | Location |
|---|---|---|
| to be completed: hosting provider | Hosting of your website, storage of server logs and backups | to be completed: hosting location |
| to be completed: email provider | Delivery of contact form messages to your email address | to be completed: email provider location |
We inform you of any change to this list as described in section 7.