Webcoss Logo
Webcoss Logo
  • Home
  • About
    • About WebCOSS
    • WebCOSS UK
    • WebCOSS India
    • Blogs
    • Pricing
    • SEO Meta Tag Analyzer
  • Services
    • Custom Web Development
    • Business Website Design
    • E-commerce Website Development
    • SEO and Digital Growth
    • Mobile-Friendly Website Design
    • On-Page SEO-Off-Page SEO service
  • Projects
  • Contact
Get Started
Follow Us
phone
UK: +44 7361 553886
India: +91 9274778905
Get Started
Home Legal Centre Data Processing Addendum
Controller and Processor Terms

Data Processing Addendum

Controller/processor terms for client personal data and UK–India delivery

Effective 17 July 2026 Updated 17 July 2026 UK and India
Website policy
Client personal data, security and UK–India delivery

Use the contents panel to move between clauses or search this document.

Read the policy
01

Clear data roles

The client normally controls the purpose; WebCOSS processes documented instructions.

02

Security and incidents

Confidentiality, safeguards and breach-notification duties are defined.

03

International transfers

The DPA supports authorised delivery across the UK, India and approved providers.

Document navigation Contents

• Overview 01 Roles and instructions 02 Processing details 03 Confidentiality and personnel 04 Security 05 Sub-processors 06 International transfers 07 Data-subject requests 08 Breach notification 09 Compliance assistance 10 Return and deletion 11 Audits and information 12 Liability and priority
Contact WebCOSS
Before you continue

This Addendum applies where WebCOSS processes client personal data as part of development, hosting, maintenance, support, migration or operation of a client service.

No matching clauses found

Try a different word or clear the search to show the complete policy.

Info

Overview

This Data Processing Addendum ('DPA') forms part of the contract between WebCOSS and the Client where WebCOSS processes personal data on the Client's behalf. It applies to the extent required by applicable data-protection law. Defined terms have the meaning in the Terms or applicable law.

01

Roles and instructions

The Client is the controller or Data Fiduciary and WebCOSS is the processor or Data Processor for Client Personal Data, except where WebCOSS independently determines purposes and means for its own account management, security, billing, legal compliance, or service improvement using appropriately aggregated or de-identified data.

WebCOSS will process Client Personal Data only on the Client's documented instructions, including the contract, configuration, support requests, and authorised user actions, unless law requires otherwise. If lawful, WebCOSS will notify the Client before processing required by law. WebCOSS will promptly inform the Client if an instruction appears to violate applicable data-protection law.

02

Processing details

Subject matterdevelopment, migration, testing, hosting, maintenance, monitoring, support, security, integration, backup, and operation of the Client's website, ecommerce store, portal, database, application, or Subscription Service.
Durationthe service term plus agreed return, deletion, backup, and legal-retention periods.
Naturecollection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, transmission, restriction, deletion, and other operations necessary for the Services.
Purposeproviding and securing the Services and carrying out documented Client instructions.
Data subjectsClient personnel, prospects, customers, users, suppliers, applicants, contractors, and other people whose data the Client submits or makes accessible.
Data typesidentifiers, contact details, Account data, communications, transactions, orders, preferences, device and log data, content, support information, and other categories described in the Order. The Client must not submit special-category, highly sensitive, children's, health, criminal-offence, payment-card, biometric, genetic, or government-identifier data unless expressly agreed.
03

Confidentiality and personnel

WebCOSS will ensure that personnel authorised to process Client Personal Data are subject to confidentiality obligations and receive appropriate privacy and security guidance. Access will be limited to personnel who need it for the Services.

04

Security

WebCOSS will implement reasonable technical and organisational measures appropriate to the risk and the Service, which may include access control, least privilege, authentication, encryption in transit, secure development, logging, malware protection, patching, backups, vulnerability handling, incident response, and supplier controls. Specific measures or certifications apply only if stated in the Order.

The Client remains responsible for its configuration, authorised users, endpoints, lawful data collection, retention settings, and security controls outside WebCOSS's management.

05

Sub-processors

The Client gives general authorisation for WebCOSS to use sub-processors needed to provide the Services, including hosting, cloud, backup, content-delivery, communications, support, monitoring, analytics, development, and security providers and specialist contractors.

WebCOSS will impose data-protection obligations appropriate to the processing. On request, WebCOSS will provide available information about material sub-processors. For a Subscription Service where ongoing processor access is material, WebCOSS will provide reasonable notice of a new sub-processor and consider a substantiated objection based on data-protection risk. If the parties cannot resolve the objection, the Client may terminate the affected Service as its exclusive remedy.

06

International transfers

The Client authorises processing in the UK, India, and other locations used by approved sub-processors. Each party will comply with transfer restrictions applicable to it. Where WebCOSS initiates a restricted transfer of UK personal data and no adequacy regulation applies, the parties will use an appropriate UK transfer mechanism, which may include the International Data Transfer Agreement or the UK Addendum, together with a transfer risk assessment and supplementary measures where required.

The parties will cooperate with requirements applicable to transfers of Indian personal data as relevant provisions and government directions take effect.

07

Data-subject requests

Taking account of the nature of processing, WebCOSS will provide reasonable assistance through appropriate technical and organisational measures for the Client to respond to requests to access, correct, erase, restrict, port, object, withdraw consent, or exercise other applicable rights. WebCOSS may refer a requester to the Client unless instructed otherwise. Assistance beyond standard functionality may be charged where lawful.

08

Breach notification

WebCOSS will notify the Client without undue delay after becoming aware of a personal-data breach affecting Client Personal Data. As information becomes available, the notice will describe the nature of the incident, likely consequences, affected data and individuals where known, mitigation taken or proposed, and a contact for follow-up.

WebCOSS's notification is not an admission of fault. The Client is responsible for determining and making notices to regulators, affected individuals, and others, unless the parties agree otherwise or law directly requires WebCOSS to notify.

09

Compliance assistance

Taking account of the nature of processing and information available, WebCOSS will provide reasonable assistance with security, breach response, data-protection impact assessments, prior consultations, records, and regulatory enquiries relating to the Services. Additional or unusual assistance may be charged at agreed rates where permitted.

10

Return and deletion

At the end of the Service, WebCOSS will, at the Client's choice and subject to payment, return or delete Client Personal Data within a reasonable period, except data retained in backups until normal overwrite or data that law requires WebCOSS to keep. During retention, the DPA continues to apply and processing is limited to storage, security, legal compliance, and deletion.

11

Audits and information

WebCOSS will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once each year, unless a breach or regulator reasonably requires more, the Client may request a remote audit based on questionnaires, policies, reports, and evidence. An on-site audit requires at least 30 days' notice, must avoid disruption and exposure of other clients' data, and is at the Client's cost unless a material breach by WebCOSS is found.

Audit rights do not require WebCOSS to disclose trade secrets, vulnerability details that would create security risk, privileged information, or another client's confidential data.

12

Liability and priority

The contract's liability limits apply to this DPA to the maximum extent permitted by law. If this DPA conflicts with the Terms about processing Client Personal Data, this DPA prevails. A signed DPA or mandatory transfer clause prevails over this standard DPA.

WebCOSS Legal Centre

Related policies

Terms and Conditions Website access, project delivery, fees, ownership and liability. Privacy Policy How WebCOSS collects, uses, shares and protects personal data. Cookie Notice Cookies, analytics, embedded services and consent choices.
Webcoss

Smart Web Solutions for Smart Businesses

Quick Links

  • Home
  • About Us
  • Services
  • Projects
  • Blogs
  • Contact
  • FAQs
  • SEO Meta Tag Analyzer

Our Services

  • Custom Web Development
  • Business Website Design
  • E-commerce Website Development
  • SEO and Digital Growth

Get in Touch

UK Address:
Kingsbury Trading Estate, Unit 7, Barningham Way, United Kingdom

India Address:
Himalaya hight, F-10, Anand - Vidyanagar Rd, Nanikhodiyar, Anand, Gujarat 388301

webcoss.anand@gmail.com

UK: +44 7361 553886

India: +91 9274778905

Building Digital Success Together
Terms & Conditions Privacy Policy Cookie Notice Data Processing Addendum