Data Processing Addendum

Last updated: 3 September 2026.

This Addendum is part of the Terms of Service between Digidom Studios Limited (trading as Hubdash) and the Customer (a company registered in the United Kingdom).

It applies when we process Customer Data (personal data the Customer or its Authorised Users submit to the Service) as processor. The Customer is the controller. UK GDPR and the Data Protection Act 2018 apply.

Authorised User account data (login, billing) is covered by our Privacy Policy, not this Addendum.

1. Subject matter

We process Customer Data to provide the Service: CRM and contact records, messages, form responses, calendar bookings, files, tracking events, and Authorised User identity needed to operate the account.

We process it only for that purpose, for the life of the account, and then as set out in section 11.

2. Instructions

The Customer's use of the Service is our documented instruction. We will not use Customer Data for our own purposes, sell it, or use it to train models.

We will tell the Customer if we think an instruction breaks UK GDPR, unless the law forbids us from saying so.

If UK law requires us to process Customer Data other than on the Customer's instructions, we will tell the Customer unless the law prohibits that.

3. Customer responsibilities

The Customer must have a lawful basis to collect and use Customer Data, and must publish its own UK privacy notice. The Customer is responsible for PECR compliance for marketing it sends through the Service.

4. Confidentiality

We ensure people who process Customer Data for us are bound by confidentiality.

5. Security

We will take appropriate technical and organisational measures, including encryption in transit, access control, logging, and hosting in AWS eu-west-2 (UK), including Amazon DocumentDB.

6. Subprocessors

The Customer authorises us to use the providers listed on our Subprocessors page.

We will post material additions there. The Customer has 30 days from the post to object on reasonable data-protection grounds. If we cannot accommodate the objection, either party may terminate the affected Service.

Each subprocessor is bound to data-protection terms no less protective than this Addendum.

Customer-connected integrations (for example the Customer's own SendGrid, Mailgun, Twilio, or WhatsApp credentials) are the Customer's processors, not ours. This Addendum does not apply to those providers.

We send Hubdash transactional and platform email through Mailgun and Postmark on our own accounts. Those providers are our subprocessors and appear on the Subprocessors page.

7. Assistance

We will help the Customer meet its UK GDPR duties for Customer Data, including data-subject requests, security, breach notification, and data-protection impact assessments, taking into account the nature of the processing.

We will not respond to requests from the Customer's contacts ourselves, other than to direct them to the Customer, unless the law requires us to.

8. Breaches

We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information the Customer reasonably needs to notify the ICO or affected people.

9. Audits

On written request we will provide information reasonably necessary to show we meet this Addendum.

10. Restricted transfers

The Service is hosted in the United Kingdom (AWS eu-west-2).

Where we transfer Customer Data out of the UK, or a subprocessor does, we will use the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. We do not rely on EU standard contractual clauses alone as the transfer tool.

11. End of the contract

Within 10 days after the account ends, we will delete Customer Data or return it in a reasonable format, at the Customer's written choice, then delete remaining copies unless UK law requires us to keep them.

12. Order

If this Addendum and the Terms conflict on Customer Data, this Addendum prevails.