Skip to content

This Data Processing Agreement (“DPA”) forms part of the Master Terms and Conditions between Step3 Digital Ltd (“Step3” / “Processor”) and the client purchasing services (“Client” / “Controller”).

1. Definitions

In this DPA, the terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the meanings given to them in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (collectively, “Data Protection Laws”).

2. Scope and Nature of Processing

In this DPA, the terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the meanings given to them in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (collectively, “Data Protection Laws”).

  • Subject matter: The provision of WordPress web hosting, maintenance, and technical support services by Step3 to the Client.
  • Duration: For the duration of Step3’s commercial services to the Client and any subsequent backup retention period.
  • Nature and purpose: Storage, transmission, automated backup, troubleshooting, monitoring, applying security updates, and technical support.
  • Types of data: Site user accounts, contact form entries, limited analytics identifiers, access logs, and website database backups.
  • Categories of Data Subjects: The Client’s website visitors, customers, donors, staff, or users whose data passes through the Client’s website infrastructure.

Step3 shall process Personal Data only on documented instructions from the Client, unless required to do so by UK law.

3. Client (Controller) Responsibilities

The Client warrants that it has all necessary rights and lawful bases to provide the Personal Data to Step3 for processing. The Client is solely responsible for managing its own public-facing privacy notices, cookie banners, and ensuring its website configuration minimizes data collection where appropriate. Step3 shall inform the Client if it believes an instruction infringes Data Protection Laws.

4. Confidentiality & Security

  • Personnel: Step3 ensures that all personnel authorised to process Personal Data are bound by strict obligations of confidentiality.
  • Security Measures: Step3 implements appropriate technical and organisational measures proportionate to risk. This includes enterprise web application firewalls (WAF), encryption in transit and at rest (where supported by the platform), vulnerability management, and routine backup integrity checks.

5. Sub-processors

The Client provides general authorisation for Step3 to engage third-party sub-processors to deliver the services.

  • Current Sub-processors: Include, but are not limited to, Rocket.net (hosting infrastructure), Cloudflare (CDN and edge security), and Google Workspace (internal communications).
  • Changes: Step3 shall notify the Client of any intended changes concerning the addition or replacement of sub-processors. The Client may object on reasonable data protection grounds within 14 days. If Step3 cannot accommodate the objection, Step3 reserves the right to terminate the affected services without penalty.

6. International Transfers

If Personal Data is transferred outside the UK by Step3 or its sub-processors, Step3 will ensure a valid transfer mechanism is in place, such as the UK Addendum to the EU Standard Contractual Clauses (SCCs) or the International Data Transfer Agreement (IDTA), to ensure the data remains protected to UK standards.

7. Assistance to the Controller & Data Subject Rights

Step3 will assist the Client, using appropriate technical measures, in fulfilling the Client’s obligations to respond to Data Subject requests (e.g., Right to be Forgotten, Right of Access). To the extent that such assistance requires Step3 to expend material time or resources beyond the standard provision of the services, Step3 reserves the right to charge the Client for this assistance at its standard Pay-As-You-Go (PAYG) hourly rate.

8. Personal Data Breaches

Step3 shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting the Client’s data. Step3 will provide the Client with sufficient information to allow the Client to meet any obligations to report to the Information Commissioner’s Office (ICO) or notify Data Subjects.

9. Records and Audits

Step3 shall make available to the Client all information necessary to demonstrate compliance with Article 28 of the UK GDPR.

  • The Client may exercise its right of audit (at a maximum frequency of once per calendar year).
    Audits must be conducted during normal business hours with at least 30 days’ reasonable written notice.
  • The Client shall bear all costs associated with such audits, including reimbursing Step3 for its time spent facilitating the audit at its standard hourly rate, unless the audit reveals a material breach by Step3.

10. Data Return and Deletion

Upon termination of the main services, Step3 will, at the Client’s choice, delete or return all live Personal Data. Step3 will safely allow existing immutable, automated server backups to expire and be securely purged according to their standard retention lifecycle (typically 14 to 30 days).

11. Limitation of Liability

Any claims brought under or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the main Step3 Master Terms and Conditions. Step3’s total aggregate liability regarding data protection breaches shall not exceed the financial cap established in the main commercial agreement.