DashHarbor Legal

Data Processing Addendum

This addendum applies where DashHarbor processes personal data on your behalf through your managed website. It supplements the Terms of Service. “Data-protection law” means applicable UK data-protection law, including the UK GDPR and Data Protection Act 2018. Neither party is relieved of its own legal obligations.

Roles and scope

Where you decide why and how personal data is used through your website, you are the controller and DashHarbor acts as processor for the service operations carried out on your behalf. If you act for another controller, you must have authority to give the instructions covered here and meet your own obligations to that controller.

DashHarbor's own account administration, billing, security and necessary operational records are separate controller-side activities described in the Privacy Policy. This addendum does not turn all information held by DashHarbor into processor data or make FastSpring a subprocessor for website visitor data.

Processing description

The subject matter is operating your managed EmDash website. Processing lasts for the service relationship and the time needed to complete lawful return or deletion. Its nature and purpose include hosting, storing, retrieving, displaying, transmitting and deleting website data, and maintaining secure access and technical operation. Backup or recovery processing is included only to the extent those measures are actually provided.

Data subjects may include website visitors, customers, business contacts, staff and people mentioned in published material. Data may include names, contact information, images, correspondence, published content and associated technical information, depending on what your website collects or contains. These are broad examples, not an assumption that every website collects every category.

You determine and document the actual categories, lawful purposes and relevant retention needs. Tell us about requirements that materially affect processing before relying on the service for them. This description is not approval to upload sensitive or unlawful material without appropriate safeguards.

Your instructions and responsibilities

We will process website personal data only on your documented instructions, including instructions about international transfers, unless UK law requires otherwise. Where legally permitted, we will tell you of that requirement before processing. The agreement, your use of available service controls and additional written instructions form the documented instructions.

You are responsible for a lawful basis, accurate notices, necessary permissions and lawful instructions. We will tell you if we believe an instruction infringes applicable data-protection law. Additional instructions that require unavailable functionality must be discussed; they do not automatically create a new service capability.

Confidentiality and security

People authorised to process website personal data must be subject to confidentiality obligations. Access should be limited to what is necessary for the service and support or security work.

We will apply technical and organisational measures appropriate to the processing risks and Article 32 requirements. The current service uses HTTPS, protected editor access, authentication and customer-scoped resource controls. These measures do not promise absolute security, a particular certification or a recovery SLA. We must consider security as the service and risks change.

Subprocessors and transfers

By agreeing to this addendum, you give general written authorisation for infrastructure subprocessors used to provide the agreed service. Cloudflare is the relevant current infrastructure provider for website hosting and related service operations where it processes website data. FastSpring is used for account billing, not identified here as a subprocessor of website visitor data.

We will inform you of intended additions or replacements before they process website data and give you a reasonable opportunity to object on data-protection grounds. We will discuss a reasonable solution to a justified objection. Equivalent applicable data-protection obligations must be imposed on subprocessors, and DashHarbor remains responsible for their performance of those obligations.

Processing may involve infrastructure outside the UK. Restricted transfers require applicable safeguards and lawful instructions. We will make information about relevant providers and transfer arrangements available for your data-protection assessment; this addendum does not assert UK-only storage.

Rights requests and compliance assistance

Taking account of the nature of processing and information available, we will assist you with data-subject requests, security obligations, breach assessment and notification, required data-protection impact assessments and consultation with the regulator. We will forward requests about your website's personal data to you rather than decide them independently, unless law requires otherwise.

Ask through your service support correspondence and identify what assistance is needed without sending unnecessary personal data. We can discuss practical arrangements, but these do not remove either party's statutory duties or deadlines.

Personal data incidents

We will notify you without undue delay after becoming aware of a personal data breach affecting website data processed on your behalf. We will provide available information needed to understand the incident and meet your obligations, with further information as it becomes available, and cooperate with reasonable containment and remediation.

You remain responsible for decisions and notifications required of you as controller. Notification of an incident is not a promise that all facts can be established immediately or that service will recover within a fixed time.

Return and deletion

When processing ends, we will, at your choice, return or delete personal data processed on your behalf and delete remaining copies unless UK law requires storage. Arrange any required return before authorising self-service website deletion. This obligation does not promise a complete automated site-export facility; return arrangements must be agreed for the relevant data.

Self-service deletion removes customer-specific website data and infrastructure as the workflow completes. Where immediate removal of a residual technical copy is not possible, it must be kept protected, put beyond ordinary use and removed as soon as practicable, subject to lawful retention requirements.

Limited controller-side operational, security, billing and audit records may remain for purposes described in the Privacy Policy. This is not permission to keep the website's processor data indefinitely for general operational convenience.

Information and audits

We will make available information needed to demonstrate compliance with applicable Article 28 obligations and allow and contribute to audits or inspections by you or an auditor you appoint. Reasonable arrangements for timing, confidentiality and protection of other customers' data may be agreed without removing these rights.

Raise questions or additional processing requirements through your service correspondence. If this addendum conflicts with other service terms about website personal data, its data-protection provisions take priority. Updates must preserve the protections required by applicable law.