Data Processing Agreement
These are our Article 28 terms for client work. They apply whenever we process personal data on your behalf — building, hosting or maintaining your website, app or notification system — and they form part of our engagement terms, incorporated by reference. Where they conflict with anything else we have agreed on data protection, these terms prevail.
If you only visit charnette.io or send us an enquiry, this page is not the one you want: see our Privacy Policy.
1. Roles
You are the controller. Charnette Ltd, trading as Charnette Labs, is the processor. You decide why and how personal data in your site or app is processed; we act only on your documented instructions.
Where you are yourself a processor for someone else — a representation company holding data on behalf of the properties it represents, for instance — we act as sub-processor, and these terms apply as if you were the controller.
One thing is not covered by this agreement: personal data you give us about yourself as our client, such as your contact details and our correspondence. For that we are a controller in our own right, and our Privacy Policy applies.
2. Subject matter, duration, nature and purpose
We process personal data only to provide the services you have engaged us for. In practice that means designing and building your website or application, hosting and serving it, maintaining and updating it, operating any forms, enquiry routing, booking flow or notification system within it, and providing support when something breaks.
Processing lasts for the term of our engagement, and then for the wind-down period in section 8.
3. Types of personal data
What we process depends entirely on what your site does. Typically it is some of:
- Enquiry and contact data — names, email addresses, phone numbers, and the content of messages sent through your forms
- Booking or reservation data — travel dates, party details, preferences and special requirements, where your site takes them
- Subscriber data — email addresses and notification tokens for your mailing list or push notifications
- Account data — login credentials and profile details for your staff or trade partners
- Technical data — IP addresses and device information recorded in server logs
Special category data. A booking form that asks about dietary requirements, accessibility needs or medical conditions is collecting Article 9 health data, even where nobody thinks of it that way. If your site does that, tell us, so the safeguards match. We do not seek special category data and our systems are not designed around it.
4. Categories of data subject
- Your guests, customers and prospective customers
- Trade partners — agents, operators and representatives who use your site
- Your own staff, where they hold accounts in a system we built
- Anyone else who submits their details through a service we operate for you
5. Our obligations
We will:
- Process personal data only on your documented instructions, including on international transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids us from doing so
- Ensure everyone we authorise to process your data is bound by confidentiality
- Take the security measures in section 6
- Respect the conditions in section 7 before engaging another processor
- Help you respond to requests from data subjects, taking into account the nature of the processing — in practice, by retrieving, correcting or deleting records in your systems when you ask
- Help you meet your own obligations on security, breach notification, data protection impact assessments and prior consultation under Articles 32 to 36, taking into account what we know and what is available to us
- Delete or return your data at the end of the engagement, as you choose (section 8)
- Make available the information you need to demonstrate compliance, and allow audits (section 9)
We will tell you if an instruction you give us appears to breach data protection law. We are not your legal adviser and cannot verify your lawful basis for collecting anything — that is yours to determine — but we will not carry out an instruction quietly if it looks wrong to us.
6. Security
Appropriate to the risk, and stated as what we actually do rather than as an aspiration:
- Data encrypted in transit over TLS, and at rest where our hosting and database providers offer it
- Access on a least-privilege basis, per person rather than by shared password, so it can be revoked individually
- Administrative access limited by allowlist, failing closed when the list is empty or unreadable
- Secrets held in the hosting platform's encrypted environment store, never in source control
- Backups operated by our hosting and database providers under their own retention terms
- Review of what is held, with removal of what is no longer needed
We are a small studio. Our security rests substantially on the platforms in section 7 and on keeping the number of people with access very low. We would rather say that than imply a security function we do not have.
7. Sub-processors
You give general authorisation for the sub-processors below. Before we add or replace one we will give you at least 30 days’ written notice, by email and by updating this page. You may object within those 30 days on reasonable data protection grounds; if we cannot resolve your objection you may terminate the affected service.
Vercel Inc. — United States, with UK/EU regions available. Hosting, content delivery, server logs, and cookieless performance measurement.
Supabase Inc. — United States, with a choice of region per project. Database, authentication and file storage where your project uses them.
Postmark (ActiveCampaign LLC) — United States. Transactional email only: form notifications, sign-in codes and system messages. Not marketing.
Cloudflare, Inc. — United States, global edge. DNS and, where configured, protection in front of your site.
Not every project uses every one. If your engagement needs a provider not on this list — a specific booking engine, payment provider or notification service you have asked for — we will name it in your project documentation before we connect it.
We engage each sub-processor under a written contract imposing the same obligations as this agreement so far as they apply to that provider’s service, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures. In practice this is the provider’s own data processing agreement, which we enter into on your behalf. Where a sub-processor fails, we remain fully liable to you for its performance.
8. Return and deletion
At the end of our engagement we will, at your choice, return your data in a commonly used machine-readable format or delete it. Tell us which. If you tell us nothing, we will keep it for 90 days and then delete it — long enough for a handover to a new supplier to go wrong and be retried, short enough that we are not holding your guests’ data indefinitely by default.
We may keep a copy where UK or EU law requires it, and only for as long as that law requires. Backups held by our providers expire on their own cycles rather than being individually purged; until they do, they remain protected by this agreement.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and allow and contribute to audits conducted by you or an auditor you appoint.
In the first instance we will answer a written questionnaire and provide our sub-processors’ own certifications and reports, which will satisfy most requests. Where that is genuinely insufficient we will accommodate an on-site or remote audit on reasonable notice, no more than once a year unless a breach or a regulator’s instruction makes another necessary, and subject to confidentiality.
10. Personal data breach
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you. That leaves you the balance of your own 72-hour window under Article 33 to notify the ICO.
We will tell you what we know: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and what we are doing about it. Where we do not have all of it at once, we will send what we have rather than wait for a complete picture.
We will help you meet your own obligations to notify the regulator and, where required, affected individuals. We will not notify a regulator or an individual about a breach of your data on your behalf unless you ask us to — that is the controller’s decision to make.
11. International transfers
Our sub-processors in section 7 are established in the United States. Where personal data is transferred outside the UK, we rely on the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it.
We will not transfer your data outside the UK other than through the providers named here, or ones notified to you under section 7, without your instruction. On request we will provide a copy of the relevant clauses or tell you where the provider publishes them.
12. Liability and governing law
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Any limitation of liability in our engagement terms applies to this agreement too, taken together rather than separately, except where UK GDPR does not permit it to be limited.
13. The processor
Charnette Ltd, trading as Charnette Labs
Registered in England and Wales No. 17167712
20 Wenlock Road, London, England, N1 7GU
ICO registration ZC206607 — ico.org.uk/register
Data protection contact: hello@charnette.io
We have not appointed a Data Protection Officer; neither Article 37 trigger applies. Enquiries reach Graeme Watson at the address above.



