Technophobia Logo
Data Processing Addendum (Summary)

Last updated: 14 September 2025

This page summarises our Data Processing Addendum (DPA). It applies when Technophobia Ltd processes personal data for you as a processor. For the full terms download: Technophobia Ltd – Full DPA (PDF).

1. Parties and roles

Controller: You (our client). Processor: Technophobia Ltd (Company No. 14898332), 13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom. VAT: GB 495 7043 58.

2. Subject matter, duration, nature and purpose
  • Subject matter: building and running agreed automation, integration, and related support.
  • Duration: project term and any support period.
  • Nature/Purpose: parsing, routing, syncing, notifying, reporting, and monitoring data as configured.
3. Types of data and data subjects
  • Personal data: names, emails, phone numbers, role, account IDs, order and booking details, message content, logs and metadata.
  • Special categories: not intended. Do not send unless agreed in writing with added controls.
  • Data subjects: your staff, prospects, customers, suppliers and partners.
4. Controller instructions
  • We process only on your documented instructions (the SoW, ticket, or email, plus this DPA).
  • We will inform you if an instruction appears unlawful under UK data law.
5. Security measures
  • MFA on admin accounts and least-privilege access.
  • Encryption in transit, hardened hosts, and network controls.
  • Secrets stored outside code; rotation on change.
  • Environment separation; tests before go-live.
  • Logging and alerting on failures; periodic reviews.
  • Backups for hosted components with restore tests.

Extra measures may apply in the SoW for higher-risk data.

6. Sub-processors (live list)

We use the providers below to deliver the services. We flow down equivalent data terms. We will update this list when providers change.

ProviderPurposeData handledPrimary locationTransfer basis
UK hosting (TBC) Hosting for our websites/self-hosted services (e.g. n8n, StirlingPDF) Operational data and logs United Kingdom UK domestic processing
WordPress Website CMS Contact form submissions (if routed via site) United Kingdom UK domestic processing
Calendly Meeting scheduling Name, email, booking details EU/US UK Addendum/SCCs or adequacy as applicable
Stripe Deposits and payments Name, email, billing details (no full card numbers) EU/US UK Addendum/SCCs or adequacy as applicable
Google (Analytics 4 – optional) Site analytics (consent-based) Usage data and identifiers EU/US UK Addendum/SCCs or adequacy as applicable
OpenAI API (project-specific) Classification/drafting inside automations Text prompts and outputs EU/US UK Addendum/SCCs or adequacy as applicable
Twilio (project-specific) SMS/voice delivery Message content and numbers EU/US UK Addendum/SCCs or adequacy as applicable

If you object to a sub-processor on reasonable grounds, tell us and we will discuss options.

7. International transfers

If data leaves the UK, we use an appropriate safeguard such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. If an adequacy decision applies, we may rely on that.

8. Assistance and requests
  • We help you answer data subject requests that relate to our processing.
  • We provide information you need to meet privacy impact checks where our work is in scope.
9. Incidents and breach notice
  • We notify you without undue delay if we become aware of a personal data breach in systems we control.
  • We share known details, steps taken, and contact points.
10. Deletion or return at end of term

At the end of the services, on your choice we delete or return personal data held in systems we control, unless law requires retention. We may keep minimal records for proofs and accounting.

11. Records and audits
  • We keep records of processing. On reasonable notice, we provide information to show compliance.
  • Where a formal audit is needed, we agree scope, timing, and confidentiality first.
12. Liability and order of precedence
  • Liability is as set out in the main contract. This DPA follows that cap and exclusions.
  • If there is a conflict, the DPA controls for data protection, then the main contract.
13. Contact

Privacy contact: hello@technophobia.uk · +44 1229 774591 · Technophobia Ltd, 13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom.

Technophobia

n8n automation for small teams. UK-based. Fast turnarounds. Clear handovers.

Address
South Cumbria Skills Exchange
Millom
LA18 4JS
United Kingdom

Phone +44 01229 774591
Email hello@technophobia.uk

VAT registered • GDPR-aligned • Typical lead time: 1–2 business days