Legal
Data Processing Addendum (DPA)
This Addendum applies where Kweedee processes personal data on behalf of a client, as a processor within the meaning of Article 28 of the GDPR. It forms an integral part of the Terms and applies as soon as the Client accepts them.
Last updated: July 20, 2026
1. Roles
The Client is the data controller. Kweedee Ltd (the processor) processes personal data solely on the Client behalf. This Addendum applies specifically to the personal data submitted by visitors of the Client website, for example through contact forms, which Kweedee processes on the Client behalf.
2. Subject-matter, duration, nature and purpose
- Subject-matter and purpose: processing of the data submitted by visitors through the contact forms of websites hosted or operated by Kweedee, in order to deliver each message to the Client and to operate the website technically.
- Nature of the processing: collection, transmission by email, temporary storage and hosting.
- Duration: the term of the service contract between Kweedee and the Client.
- Categories of data subjects: visitors and prospects of the Client website.
- Types of personal data: identity and contact details provided voluntarily (name, email, optional phone) and the content of the message. No special categories of data (Article 9 GDPR) are requested.
3. Obligations of Kweedee as processor
Kweedee undertakes to:
- a) process the data only on the Client documented instructions, the configuration of the service being deemed to constitute such instructions, unless required to do otherwise by law;
- b) ensure that persons authorised to process the data are bound by an obligation of confidentiality;
- c) implement appropriate technical and organisational security measures (Article 32 GDPR): encryption in transit, access control, and regular review;
- d) engage a sub-processor only under the conditions set out in clause 4 below;
- e) assist the Client, as far as possible, in responding to requests from data subjects exercising their rights;
- f) assist the Client in complying with its obligations regarding security, personal data breaches and data protection impact assessments (Articles 32 to 36 GDPR);
- g) notify the Client without undue delay after becoming aware of a personal data breach;
- h) at the Client choice, delete or return the personal data at the end of the services, and delete existing copies unless legally required to retain them;
- i) make available to the Client the information necessary to demonstrate compliance with Article 28 and allow for and contribute to reasonable audits;
- j) immediately inform the Client if, in its opinion, an instruction infringes the GDPR or another data protection provision.
4. Sub-processors
The Client gives Kweedee a general authorisation to engage the sub-processors listed on our Sub-processors page. Kweedee imposes on each of them, by contract, data protection obligations equivalent to those set out in this Addendum. Kweedee informs the Client of any intended addition or replacement of a sub-processor and gives the Client the opportunity to object on legitimate grounds.
5. Transfers outside the EU/EEA
Where a sub-processor processes personal data outside the European Economic Area, Kweedee ensures that an appropriate transfer mechanism is in place, such as the European Commission standard contractual clauses (SCCs) or, where applicable, the EU-US Data Privacy Framework.
6. Liability and precedence
Each party is responsible for its own obligations under the GDPR. In matters of data protection, this Addendum prevails over any conflicting provision of the Terms; all other provisions of the Terms remain in full force. For any question relating to this Addendum, contact contact@kweedee.com.
This document is written in English, which is the authoritative version.