
Data Processing Agreement
Data Processing Agreement
The Article 28 DPA template for business customers whose data we process.
This template applies where Estia processes personal data on your behalf (for example, when we hold your end-customer records). Where the parties have signed a bespoke DPA, that document takes precedence.
1. Subject matter and duration
The subject matter is the processing of personal data described below, for the duration of the contract between the parties.
2. Nature and purpose of processing
Order fulfilment, delivery logistics, invoicing, accounting, customer support, and platform operation.
3. Type of personal data and categories of data subjects
- Customer account data: name, email, phone, business name, address
- End-customer data (where applicable): name, email, address for delivery
- Order and transaction data
4. Obligations of the Processor (Estia)
- Process personal data only on documented instructions from the Controller
- Ensure persons authorised to process the data are under confidentiality
- Implement appropriate technical and organisational measures (TOMs)
- Assist the Controller in responding to data subject requests
- Assist with DPIAs and prior consultation obligations
- Delete or return personal data at the end of the contract
- Make available the information necessary to demonstrate compliance
5. Obligations of the Controller (customer)
- Ensure a lawful basis exists for the processing instructed
- Provide appropriate privacy notices to its own data subjects
- Respond to data subject requests within statutory deadlines
6. Sub-processors
A current list of sub-processors is maintained in the Privacy Policy → Third Party Recipients section. Estia will give 30 days’ notice of any new sub-processor; the Controller may object in writing within that period.
7. Data breach notification
Estia will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller’s data, including details of the nature of the breach, categories and approximate numbers of data subjects affected, likely consequences, and measures taken.
8. Deletion / return on contract end
On termination of the contract, Estia will delete or return all personal data to the Controller, at the Controller’s choice, unless retention is required by law (e.g. HMRC 7-year retention on invoice records).
9. Audit rights
The Controller may, on reasonable written notice and no more than once per year, audit Estia’s compliance with this DPA. Estia may satisfy the audit obligation by providing a recent independent audit report (e.g. ISO 27001, SOC 2).
Request a signable copy by emailing privacy@estiaco.uk.