Data Processing Agreement
Effective 10 September 2026 · Updated 11 September 2026
- Company
- Tarlara Digital Ltd
- Company number
- 17390332
- Registered office
- 52 Stancliffe Avenue, Marford, Wrexham, LL12 8LW
- Privacy enquiries
- privacy@tarlaradigital.com
This Data Processing Agreement forms part of the agreement between the Customer and Tarlara Digital Ltd governing the Service. It applies where Tarlara processes Personal Data on the Customer’s behalf.
1. Roles
The Customer is normally the Controller and Tarlara is normally the Processor for Customer Personal Data. If the Customer acts as a Processor for another Controller, Tarlara acts as its Subprocessor to the applicable extent.
Tarlara acts separately as Controller for its own account administration, billing, security and business communications, as described in its Privacy Policy.
2. Definitions
Applicable Data Protection Law means applicable UK data-protection law, including the UK GDPR and Data Protection Act 2018. Customer Personal Data means Personal Data processed by Tarlara on the Customer’s behalf through the Service. Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing have the meanings given by Applicable Data Protection Law. Subprocessor means another Processor engaged by Tarlara to process Customer Personal Data.
3. Documented instructions
Tarlara will process Customer Personal Data only on the Customer’s documented instructions, including instructions concerning international transfers, unless UK law requires otherwise. The agreement, this DPA, and the Customer’s use and configuration of the Service constitute documented instructions to process Customer Personal Data as necessary to provide, secure, maintain and support the Service.
If law requires other processing, Tarlara will inform the Customer before processing unless that law prohibits notice on important grounds of public interest. Tarlara will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the issue is resolved.
4. Customer obligations and rights
The Customer determines the purposes and lawful basis of its processing and is responsible for lawful instructions, required notices, responding to Data Subjects, and having the rights needed to provide Customer Personal Data. The Customer may give documented instructions and exercise the rights provided by this DPA and Applicable Data Protection Law.
5. Confidentiality
Tarlara will ensure that people authorised to process Customer Personal Data are subject to confidentiality obligations and access the data only where reasonably required for the Service or legal obligations.
6. Security
Tarlara will maintain technical and organisational measures appropriate to the nature, scope, context and purposes of processing and the risks to individuals. These measures are summarised in Annex 2 and may evolve provided the overall level of protection is not materially reduced.
7. Subprocessors
The Customer gives Tarlara general written authorisation to engage Subprocessors. Current relevant Subprocessors and their purposes are listed in the Supplier and Subprocessor Schedule.
Tarlara will impose equivalent Article 28 data-protection obligations on each Subprocessor and remains liable to the Customer for the Subprocessor’s compliance with those obligations.
Tarlara will give at least 30 days’ notice by email or in-Service notification before adding or replacing a Subprocessor. Where a shorter period is reasonably necessary for security, legal compliance or service continuity, Tarlara will give notice as soon as reasonably practicable.
The Customer may make a reasonable data-protection objection during the notice period. The parties will try to resolve it. If no reasonable resolution is available, the Customer may discontinue the affected Service in accordance with the applicable agreement.
8. International transfers
Tarlara will not make a restricted international transfer of Customer Personal Data unless an appropriate lawful mechanism is in place. Relevant transfer information is summarised in the Supplier and Subprocessor Schedule.
9. Data Subject requests
Taking account of the nature of processing, Tarlara will provide appropriate technical and organisational assistance, insofar as reasonably possible, to help the Customer respond to Data Subject requests. Tarlara may direct a requester to the Customer where the Customer is Controller, unless law requires Tarlara to respond directly.
10. Assistance
Taking account of the nature of processing and information available, Tarlara will assist the Customer with obligations concerning processing security, Personal Data Breach assessment and notification, data-protection impact assessments, and prior consultation with the Information Commissioner where required.
11. Personal Data Breaches
Tarlara will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. It will provide available information reasonably required to help the Customer meet applicable notification duties and may provide information in phases. The Customer remains responsible for deciding whether regulator or Data Subject notification is required where it is Controller.
12. Return and deletion
At the end of the Service, Tarlara will, at the Customer’s choice, return or delete Customer Personal Data and delete existing copies unless UK law requires continued storage. Tarlara will provide a reasonable opportunity to export Customer Data where supported by the Service.
Data remaining temporarily in protected backups will be put beyond ordinary use and deleted through the normal backup cycle. Legally retained data will remain protected and processing will be limited to the permitted purpose.
13. Information and audits
Tarlara will provide information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and will allow and contribute to reasonable audits or inspections by the Customer or its appointed auditor.
Audits should normally use existing information first, provide reasonable notice, avoid unnecessary disruption, protect other customers and confidential systems, and occur no more than once in 12 months unless a material incident, reasonable compliance concern or Supervisory Authority requires otherwise. The Customer bears its reasonable audit costs unless law requires otherwise or the audit identifies a material breach by Tarlara.
14. Legal requests
If Tarlara receives a binding legal request for Customer Personal Data, it may disclose the information legally required. Where permitted, Tarlara will notify the Customer before disclosure and seek to limit disclosure to what the request requires.
15. Liability and priority
Liability arising from this DPA is subject to the applicable agreement’s liability provisions except where limitation is prohibited by law. If this DPA conflicts with the Terms concerning Customer Personal Data, this DPA prevails to that extent.
16. Duration and law
This DPA continues while Tarlara processes Customer Personal Data on the Customer’s behalf. Obligations concerning confidentiality, deletion and retained data continue for as long as necessary. The DPA is governed by the laws of England and Wales unless Applicable Data Protection Law requires otherwise.
ANNEX 1 DETAILS OF PROCESSING
- Subject matter and duration
- Provision, operation, security, support and maintenance of the Service for the subscription period and applicable return, deletion and retention period.
- Nature and purpose
- Hosting, storage, retrieval, organisation, transmission, backup, support, security and other processing necessary to provide the Service under the Customer’s instructions.
- Data Subjects
- Customer users and administrators; employees; contractors; suppliers; professional advisers; property or building contacts; and other individuals whose data the Customer lawfully places in the Service.
- Personal Data
- Names, business contact details, organisation and role information, account identifiers, activity and audit information, contractor or supplier information, information in Customer documents, and other Personal Data the Customer chooses to enter.
- Special-category data
- The Service is not intended primarily for special-category data. The Customer should not enter it unless necessary, lawful and appropriate for the enabled functionality.
- Frequency
- Continuous or as initiated by Customer use.
ANNEX 2 TECHNICAL AND ORGANISATIONAL MEASURES
- organisation and tenant isolation;
- authentication, role and access controls;
- multi-factor authentication for appropriate privileged access;
- encryption in transit and protected storage controls;
- audit and security logging;
- backup and recovery procedures;
- vulnerability and dependency management;
- secure secrets and change management;
- incident-response and access-revocation procedures; and
- Subprocessor due diligence and contractual controls.
ANNEX 3 SUBPROCESSORS
The Tarlara Supplier and Subprocessor Schedule forms part of this DPA. It identifies current relevant providers, their purposes and available transfer information. Changes are managed under clause 7.