Technophobia Logo
Data Processing Addendum (Full)

Last updated: 14 September 2025

This Data Processing Addendum (DPA) forms part of any agreement between Technophobia Ltd and the Customer. It applies when we process personal data for you as a processor under UK data protection law.

1. Parties and roles

Processor: Technophobia Ltd (Company No. 14898332, VAT GB 495 7043 58), 13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom. hello@technophobia.uk · +44 1229 774591

Controller: The Customer named in the main agreement or SoW.

Terms used here have the meanings in UK GDPR and the Data Protection Act 2018.

2. Subject matter and duration
  • Subject matter: automation, integration, monitoring, support, and related services described in the SoW.
  • Duration: the term of the services plus any exit period.
3. Nature and purpose

Processing may include collecting, receiving, storing, organising, adapting, transmitting, restricting, deleting, or otherwise handling data to run agreed workflows, integrations, notifications, reports, and tests.

4. Types of data and data subjects
  • Personal data: names, emails, phone numbers, role, account IDs, order/booking details, message content, workflow logs and metadata.
  • Special categories: not intended. Do not include unless we both agree controls in writing.
  • Data subjects: your staff, prospects, customers, suppliers, and partners.
5. Controller instructions
  • We process personal data only on your documented instructions: the agreement, SoW, tickets, and your written requests.
  • If an instruction appears unlawful, we will tell you.
6. Confidentiality and staff
  • We keep personal data confidential.
  • Staff and contractors are bound by confidentiality and receive appropriate training.
  • Access is on a least-privilege basis.
7. Security

We will implement the technical and organisational measures in Schedule B and any extra measures in the SoW, taking account of risk, state of the art, and costs.

8. Sub-processors
  • We may use sub-processors listed at /sub-processors and any project-specific ones named in the SoW.
  • We put written terms in place with sub-processors that protect personal data to a similar level.
  • You authorise our use of sub-processors for the services. You may object on reasonable grounds; we will discuss options.
9. International transfers

If personal data leaves the UK, we will use a valid transfer tool (e.g., UK IDTA, UK Addendum to EU SCCs, or adequacy). We will apply supplementary measures where needed.

10. Assistance
  • We help you respond to data subject requests that relate to our processing.
  • We assist with security, breach notices, impact assessments, and consultations to the extent relevant to our services.
11. Personal data breaches
  • If we become aware of a personal data breach in systems we control, we will notify you without undue delay.
  • We will share known details, mitigation steps, and a contact point. Notifications are not admissions of fault.
12. Records and audit
  • We keep records of processing we carry out for you.
  • On reasonable notice, we will provide information needed to show compliance. Where a formal audit is required, we agree scope, timing, and confidentiality first.
13. Return and deletion
  • On end of services, at your choice we delete or return personal data held in systems we control, unless law requires retention.
  • We may keep minimal logs and billing records as required by law.
14. Controller duties
  • You have a lawful basis for personal data you ask us to process.
  • You do not send special category data unless agreed in writing with controls.
  • You keep your own systems and consents in order.
15. Liability and precedence
  • Liability follows the caps and exclusions in the main agreement.
  • If there is a conflict, this DPA controls for data topics, then the main agreement.
16. Law and jurisdiction

English law governs this DPA. The courts of England and Wales have exclusive jurisdiction.

17. Signatures
CustomerProcessor: Technophobia Ltd
Name: ____________________________
Title: ____________________________
Date: ____ / ____ / ______
Signature: _______________________
Name: ____________________________
Title: ____________________________
Date: ____ / ____ / ______
Signature: _______________________
Schedule A — Details of processing
Subject matterAutomation, integration, monitoring, and support as in the SoW.
DurationProject term and any support period; plus exit steps.
Nature and purposeParsing, routing, syncing, notifications, reporting, monitoring, and testing.
Categories of data subjectsCustomer staff, prospects, customers, suppliers, partners.
Categories of personal dataNames, emails, phone numbers, role, account IDs, order/booking details, message content, logs and metadata.
Special categoriesNot intended. If needed, add an annex with controls and limit flows.
RetentionOperational logs 30–90 days by default; project data per SoW or your instruction; billing records 7 years.
LocationsUK by default; EU/US for some providers as listed on /sub-processors or the SoW.
Schedule B — Technical and organisational measures
  • Access control: MFA on admin accounts; least-privilege roles; access reviews; separate client workspaces.
  • Secrets: stored outside code; restricted access; rotation on change.
  • Network and host security: hardened hosts; firewalls; patched OS; restricted inbound access; TLS for data in transit.
  • Application security: code review for risky changes; environment separation; rollback steps; change logs.
  • Monitoring and logging: health checks; alerting on failures; log retention 30–90 days unless agreed otherwise.
  • Backups and DR: backups for hosted components; periodic restore tests; documented RTO/RPO where relevant.
  • Supplier due diligence: contract terms with sub-processors; review of locations and controls; short data retention where practical.
  • Personnel: confidentiality commitments; training; joiner/mover/leaver checks.
  • Data minimisation: restrict fields; mask test data; avoid special category data unless agreed.
  • Incident response: internal playbooks; rapid containment; client notice without undue delay.
Schedule C — Sub-processors

Current providers are listed at /sub-processors. Project-specific providers appear in the SoW.

Schedule D — International transfer tools
  • UK IDTA or UK Addendum to EU SCCs as applicable.
  • Adequacy decisions where available.
  • Supplementary measures based on risk (e.g., encryption in transit, limited retention, regional processing).
Contact

Privacy contact: hello@technophobia.uk · +44 1229 774591
Technophobia Ltd, 13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom.

Technophobia

n8n automation for small teams. UK-based. Fast turnarounds. Clear handovers.

Address
South Cumbria Skills Exchange
Millom
LA18 4JS
United Kingdom

Phone +44 01229 774591
Email hello@technophobia.uk

VAT registered • GDPR-aligned • Typical lead time: 1–2 business days