Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between Middle East Software Solutions Limited ("we", the "Processor") and Business-plan customers ("you", the "Controller") under which htmldrop processes Personal Data on your behalf.
It incorporates Article 28 of the UK GDPR and (where applicable) the EU GDPR, plus the UK International Data Transfer Addendum and EU Standard Contractual Clauses for transfers outside the UK/EEA. If you're not on the Business plan, you don't need a separate DPA — our Privacy Policy covers the relationship.
1. How this DPA gets signed
You don't need a wet signature. By subscribing to the Business plan through your htmldrop account, you accept this DPA as written. If your procurement process requires a countersigned copy, email [email protected] with your company name + account holder; we'll return a PDF within two business days. We can sign your DPA template instead if it's substantively similar — material changes are negotiated separately.
2. Roles and subject-matter
You are the Controller of the Personal Data you upload, generate, or cause to flow through htmldrop. We are the Processor and act only on your documented instructions, which are: operating the Service for you as described in the Terms and this DPA.
Subject matter: hosting, serving, and storing
Controller-supplied content via htmldrop; processing access logs and
account metadata.
Duration: for the term of your subscription plus the
retention windows in §6 below.
Nature and purpose: providing the Service.
Types of Personal Data: end-user identifiers (email,
account ID), billing data (limited per §4 of
the sub-processors page), uploaded content (which may contain
Personal Data the Controller is responsible for), request metadata (IP,
user-agent, URL paths).
Categories of data subjects: your authorised
end-users; visitors to drops you publish.
3. Our obligations
We will:
- Process Personal Data only on your documented instructions and only to provide the Service. If a request from law enforcement, a court, or a regulator obliges us to process otherwise, we'll tell you first unless the law forbids it.
- Ensure people authorised to access Personal Data are bound by written confidentiality obligations.
- Maintain the security measures listed in our Security policy, including encryption in transit and at rest, principle-of-least-privilege access, audit logging, and incident response.
- Assist you with data-subject requests by exposing the
/api/v1/account/export+/api/v1/account/deleteendpoints in the dashboard. For requests we can't answer through that API alone, we'll help within a reasonable time. - Assist you with DPIAs, breach notifications, and consultations with supervisory authorities where the law requires it.
- Notify you in writing within 72 hours of becoming aware of a Personal Data Breach affecting your data.
- At the end of the subscription, delete or return all Personal Data within 30 days, subject to legal-hold obligations.
4. Sub-processors
You give us general authorisation to engage sub-processors. The current list is on /sub-processors and is kept up to date. We'll notify you by email at least 30 days before a new sub-processor goes live. You can object on reasonable data-protection grounds within that window; if we can't resolve the objection, you can terminate the Business plan and we'll refund any unused portion of the term.
We hold a back-to-back DPA with each sub-processor that imposes equivalent obligations to those in this DPA.
5. International transfers
Personal Data is processed primarily in the UK and the EEA. Where a transfer to a third country is necessary (e.g. via a US-based sub-processor), we rely on either: (a) an adequacy decision, (b) the EU Standard Contractual Clauses 2021/914 with the UK Addendum, or (c) Binding Corporate Rules where the sub-processor has them. The sub-processors page notes which legal basis applies for each.
6. Retention
The categories below apply unless your written instruction overrides them (and to the extent the law lets us follow that instruction):
- Drop content + metadata: for the lifetime of the drop. Deleted drops are removed from object storage within 7 days; the database row is retained for 30 more days for audit then hard-deleted.
- Account data: for the lifetime of the account. Soft-deleted accounts are hard-deleted after 30 days.
- Request logs (IP + user-agent): 30 days, then deleted.
- Billing records: 7 years where UK tax law requires it.
7. Audits
Once per calendar year, with at least 30 days' written notice, you can audit our compliance with this DPA — at your cost — using a mutually acceptable third-party auditor under a confidentiality agreement. We'll respond to questionnaires (SIG-Lite, CAIQ, your own) within a reasonable time as an alternative. We may decline access to anything that would breach a confidentiality obligation to another customer.
8. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service. Nothing in this DPA limits liability for: gross negligence, wilful misconduct, breach of confidentiality, or anything the law doesn't allow us to limit (e.g. liability for death or personal injury caused by negligence under UK law).
9. Order of precedence
If this DPA and the Terms of Service conflict on a data-protection matter, this DPA wins. On every other matter, the Terms win.
10. Changes
Material changes get an effective-date bump and an email notice to the Business-plan account contact at least 30 days before they take effect. You can terminate the Business plan within that window if you disagree.
11. Contact
Middle East Software Solutions Limited
Companies House registration: 15913819, England and Wales
Legal & DPA: [email protected]
Privacy / DSAR: [email protected]