DIGIDENT LTD legal centre

Data processing terms

The processor terms incorporated when Customer content contains personal data.

Version 2026-07-23 | Effective 23 July 2026

1. Scope and roles

These terms form part of the business terms. They apply when DIGIDENT processes personal data contained in private Customer notes, job records, entered contacts, preferences or similar Customer content on the Customer's behalf. The Customer is controller and DIGIDENT is processor for that data. Each party remains an independent controller for its own account, security, billing, legal and public-source processing.

2. Processing details

Subject matter: hosting and operating the Customer workspace. Duration: the contract plus a limited deletion or return period. Nature: collection, storage, organisation, retrieval, transmission to authorised users, security, backup and deletion. Purpose: provide and protect the subscribed service. Data subjects may include Customer staff, prospects, business contacts and people connected with saved jobs. Data may include identity, work contact, role, location, notes, status and interaction information. Customers must not intentionally upload special-category or criminal-offence data unless separately agreed in writing with appropriate safeguards.

3. Instructions

DIGIDENT will process Customer personal data only on documented instructions in the agreement and product configuration, including lawful transfers, unless UK law requires otherwise. If legally permitted, we will tell the Customer before required processing. We will inform the Customer if an instruction appears to infringe applicable data-protection law.

4. Confidentiality and security

Personnel authorised to process the data are bound by confidentiality. DIGIDENT will maintain measures appropriate to risk, including access controls, password hashing, secure sessions, transport encryption, secret management, signed webhooks, rate limiting, monitoring, audit records, managed hosting safeguards and recovery procedures.

5. Subprocessors

The Customer gives general authorisation for subprocessors in our current register, including Cloudflare for hosting and Resend where Customer-directed email is sent. GoCardless generally acts as an independent controller for payer and bank data. We will update the register before a material new subprocessor begins processing Customer data and allow a reasonable objection on genuine data-protection grounds.

6. Assistance

Taking account of the processing and information available, DIGIDENT will reasonably assist with data-subject requests, security, breach assessment, impact assessments and regulator consultation. Additional work outside normal service may be charged at a reasonable agreed rate unless caused by our breach.

7. Incidents

We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data and provide available information needed for the Customer's assessment and notices. Notification is not an admission of fault.

8. Return and deletion

On written request or service termination, DIGIDENT will provide a reasonable export where supported and delete or anonymise Customer personal data after the limited recovery period, unless law requires retention. Data may remain in protected backups until normal expiry and will not be restored except for recovery.

9. Audit information

We will provide information reasonably necessary to demonstrate compliance. Audits must first use available documentation, be no more than once annually unless an incident or regulator requires more, avoid other customers' data, and minimise disruption. The Customer bears its audit cost unless a material DIGIDENT breach is found.

10. Transfers and priority

International transfers will use a lawful UK mechanism where required. If these terms conflict with the general terms on processing Customer personal data, these terms prevail.