Legal
This agreement governs how Tea Powered Projects Limited processes data on behalf of our platform clients.
This Data Processing Agreement forms part of our Terms of Business, and of any Statement of Work or service agreement signed between Tea Powered Projects Limited (company number 10542712) ("we", "us", "TPP") and the customer ("you").
You are the controller of the personal data processed through the services. We are the processor, and we process that personal data only on your documented instructions.
Where you are yourself a processor for someone else, we act as a sub-processor and your own controller's instructions flow through you.
This agreement is governed by UK GDPR and the Data Protection Act 2018. Where we process personal data of individuals in the EEA, the EU GDPR applies to that processing.
Subject matter - Providing the website, platform and related services described in your agreement.
Duration - The term of your agreement, plus the retention period in clause 8.
Nature and purpose - Hosting, storing, transmitting, backing up and displaying your data so the services work.
Types of personal data - Names, email addresses, postal addresses, phone numbers, IP addresses, enquiry and message content, booking and order records, course enrolments, review content, payment references, website usage data.
Categories of data subject - Your customers, enquirers, website visitors, and your own staff who use the admin.
Special category data - Not required by the services. Do not upload it without agreeing it with us first.
We will:
Process personal data only on your documented instructions, including on international transfers, unless the law requires otherwise. If the law does require otherwise, we will tell you before processing unless we are legally barred from doing so.
Make sure everyone we authorise to process the data is under a duty of confidentiality.
Take the technical and organisational measures required by Article 32 - see Annex 2.
Respect the sub-processor conditions in clause 5.
Help you respond to data subject requests, taking into account the nature of the processing.
Help you with data protection impact assessments and prior consultation, where relevant.
Delete or return the data at the end of the services, as set out in clause 8.
Give you the information you need to demonstrate compliance, and allow audits under clause 9.
Tell you promptly if we think an instruction breaches data protection law.
You give us general authorisation to engage the sub-processors in Annex 1.
We will give you at least 30 days' notice before we add or replace a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you to find a solution. If we cannot, you may terminate the affected service without penalty and without any early termination sum.
Every sub-processor is bound by written terms that impose the same obligations as this agreement. We stay fully liable to you for their performance.
Primary storage is in the United Kingdom. Customer Data is hosted on DigitalOcean's London region, and our error monitoring is self-hosted on TPP infrastructure in the UK. Neither involves a transfer.
Beyond that, transfers fall into two groups:
EEA - Backblaze (backups), Mailgun (email), Microsoft (our own correspondence). Covered by the UK adequacy regulations for the EEA. No further safeguard is required.
United States - Stripe, Twilio, Namecheap, Meta, Google. UK International Data Transfer Agreement, or EU Standard Contractual Clauses with the UK Addendum.
For every transfer outside the UK we carry out a transfer risk assessment and satisfy ourselves that protection for the data is not materially lower than under UK data protection law, which is the test introduced by the Data (Use and Access) Act 2025.
We maintain appropriate technical and organisational measures, set out in Annex 2. We may update them, but not in a way that materially reduces overall security.
Breach notification. If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware. The notification will describe what happened, the categories and approximate number of records and data subjects affected, the likely consequences, and what we are doing about it. If we cannot give you everything at once, we will give you what we have and follow up.
[Note: the live DPA says "without hesitation or delay", which is not a defined standard. 48 hours gives you room to investigate while leaving the controller time to meet their own 72-hour ICO deadline under Article 33.]
When the services end, we will:
Provide your data in a portable format as set out in the CMS Service Terms - a working static export of the website, the media library, business data as CSV or JSON, and a database export.
Retain your data for up to 90 days from termination so you can retrieve anything missing, with read-only access for the first 30 days.
Delete your data at the end of that 90-day period, unless the law requires us to keep it.
Backups are not deleted individually. They are securely isolated and protected from further processing, and they age out on our standard backup retention cycle.
You may ask us in writing to delete earlier, once you have confirmed you have received your export.
We will make available the information you reasonably need to demonstrate compliance with this agreement.
You may request an audit on 30 days' written notice, no more than once in any 12-month period, unless a data protection authority requires otherwise or we have had a breach affecting your data. Audits must not unreasonably disrupt our business or risk other customers' confidentiality. Where an audit goes beyond providing existing documentation, we may charge our standard rate for the time involved.
On any question of data protection, this agreement takes precedence over the CMS Service Terms and over any other term of your agreement.
Current as at [DATE ON PUBLICATION].
DigitalOcean - Hosting, compute, DNS. United Kingdom (London / LON1).
Backblaze - Encrypted offsite backups. European Union.
Namecheap - Domain registration. United States.
Stripe - Card payment processing for bookings and course purchases. Name, email, billing address, payment reference. US / EU.
Mailgun - Sending transactional and notification email. Recipient name, email address, message content. European Union.
Twilio - SMS notifications. Phone number, message content. United States.
Meta (Facebook) - Publishing to a connected Facebook page. Page and account identifiers. United States.
Google - Business Profile posting, Search Console metrics. Account and profile identifiers. United States.
Microsoft - Our own email and document handling. Any personal data in correspondence with us. United Kingdom / EU.
Error monitoring (Sentry) is self-hosted on TPP infrastructure in the United Kingdom. No third party receives error data and no international transfer arises. Do not list it in Annex 1; say so explicitly instead, because clients' security questionnaires ask about Sentry by name and "we host it ourselves" is a strong answer.
Website analytics are first party, served by the TPP platform. There is no Google Analytics and no advertising or social media tracking on any TPP-built site. Confirmed by a clean-browser audit on 2026-07-30 (cookie-audit-2026-07-30.md).
The live DPA says these are "available upon request". That is acceptable but weak. Summarise them here instead - it saves answering the same question in every client security questionnaire.
Draft from what is already documented in company/policies/ and the Cyber Essentials certification:
Access control - named accounts, role-based permissions, least privilege
Encryption - TLS in transit throughout. At rest, encryption is applied wherever the underlying platform supports it, including offsite backups.
Backups - daily, retained per the backup policy, held encrypted offsite with Backblaze in the EU
Hosting - United Kingdom (DigitalOcean, London region)
Monitoring - application error monitoring self-hosted on TPP infrastructure in the UK, plus audit logs on administrative actions
Patching - platform and dependency updates as part of the managed service
Staff - confidentiality obligations, device configuration and password policies
Certification - Cyber Essentials, valid to 22 October 2027
Deletion - documented process, per clause 8