Legal

Data processing agreement

The Article 28 terms on which Noddable processes personal data on your behalf — your clients' details, their notes, and the photographs of them. It applies automatically; you do not have to ask for it.

Version 2026-09-16 · In effect from 16 September 2026 · Last updated 16 September 2026
Published by [REGISTERED COMPANY NAME] Limited, company number [COMPANY NUMBER], registered in England and Wales. Questions: legal@noddable.com

Draft — not yet reviewed by a solicitor. This document was prepared as a starting point and has not been checked by a qualified legal adviser. It should not be relied on, held out as binding, or published to customers in this state. Details shown in square brackets are placeholders that must be completed.

This agreement is between you, the customer named on the account (the controller), and [REGISTERED COMPANY NAME] Limited (the processor). It is incorporated into the terms of service and takes effect when you create an account. No signature is required, but we will sign a counterpart on request — see clause 12.

It is written to satisfy Article 28(3) of the UK GDPR, and of the EU GDPR where that applies to you. Terms such as personal data, processing, controller, processor, data subject and personal data breach have the meanings given in that legislation.

1. Scope and precedence

This agreement applies to all personal data we process on your behalf in providing the service. Where it conflicts with the terms of service or any other document between us, this agreement prevails on matters of personal data. It does not apply to personal data for which we are ourselves the controller — your own account and billing data — which is covered by the privacy policy.

2. Roles of the parties

You are the controller. You decide what personal data enters the service, for what purpose, and for how long. You are responsible for having a lawful basis for it, for providing the privacy information your own data subjects are entitled to, and for the accuracy and lawfulness of what you upload — including any consent, model release or other permission that photographing and distributing a person's image requires.

We are the processor. We act only on your instructions and have no independent purpose of our own for this data.

3. Processing on instructions

  1. We will process personal data only on your documented instructions, including as to transfers to a third country, unless required otherwise by law — in which case we will tell you before processing, unless the law prohibits us from telling you on important grounds of public interest.
  2. Your instructions are: this agreement, the terms of service, the settings you choose in the product, and any further written instruction we agree to. Using the service is itself an instruction to do the things the service does.
  3. We will tell you if, in our opinion, an instruction infringes data protection law. We may decline to act on an instruction that would.
  4. We will not use your clients' personal data for our own purposes, will not sell or share it, and will not use it to train machine learning models.

4. Confidentiality of personnel

Everyone we authorise to process personal data is bound by a written duty of confidentiality that survives the end of their engagement, is given access only where their role requires it, and receives data protection training appropriate to what they do.

5. Security

We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation and the risk to data subjects. Those measures are described in Annex 2. We may change them, but not in a way that materially reduces the overall level of protection.

6. Sub-processors

  1. You give general authorisation for us to appoint sub-processors. Those engaged at the date of this agreement are listed in Annex 3 and, in current form, on the sub-processors page.
  2. We will give you at least 30 days' notice before adding or replacing a sub-processor. You may subscribe to those notices on that page.
  3. You may object on reasonable data protection grounds within those 30 days. We will work with you to find a solution; if none is available, you may terminate the affected part of the service and we will refund any fees covering the period after termination.
  4. Each sub-processor is engaged under a written contract imposing obligations no less protective than these, and we remain fully liable to you for their performance.

7. Assisting with data subject rights

The service is built so that you can answer most requests yourself: you can search, export, correct and delete the content of your sites and galleries directly, and a gallery's selections and notes export as a file.

Where you cannot, we will assist by appropriate technical and organisational measures, so far as is possible, and taking into account the nature of the processing. If a data subject contacts us directly about data you control, we will not respond substantively; we will tell them to contact you and forward the request to you without undue delay.

8. Breaches, assessments and consultation

  1. Breach notification. We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once we will provide it in phases without further undue delay. Notifying your supervisory authority and your data subjects remains your decision, as controller, and we will give you what you need to make it.
  2. Impact assessments. We will provide reasonable assistance with data protection impact assessments and with any prior consultation with a supervisory authority, limited to the processing we perform and the information available to us.
  3. Security assistance. We will assist you in ensuring compliance with the obligations in Articles 32 to 36, taking into account the nature of processing and the information available to us.

9. Deletion or return

  1. You can export your content at any time during the subscription, at no charge.
  2. At the end of the subscription we retain your content for 30 days so that you can still retrieve it, then delete it from live systems within 90 days of the end of the subscription. Copies in backups are overwritten within a further 35 days. If you ask us to delete it sooner, we will do so within 30 days of the request.
  3. We may retain personal data where law requires it — for example within accounting records — and where we do, this agreement continues to apply to it.

10. Information and audits

  1. We will make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
  2. In practice, we will first offer our current security documentation and answer a written assessment. That will usually be enough. Where it is not, or where a supervisory authority requires more, you may audit on 30 days' written notice, no more than once a year unless a breach or an authority's requirement makes it necessary, during business hours, without unreasonable disruption, and subject to confidentiality.
  3. You bear the cost of an audit, except where it reveals material non-compliance on our part, in which case we do.

11. International transfers

Personal data is held in the United Kingdom and the European Economic Area by default. Where a transfer outside those areas is necessary, we will make it only under a lawful transfer mechanism — an adequacy decision where one applies, or the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, which are incorporated into this agreement by reference and take precedence over it where they conflict. We will carry out a transfer risk assessment and apply supplementary measures where they are needed, and will give you a copy on request.

12. Liability, signature and changes

Each party's liability under this agreement is subject to the limits in the terms of service, except where the law does not permit those limits to apply. Nothing here limits a data subject's rights or a supervisory authority's powers.

If you need a countersigned copy — for your own compliance file, or because a client of yours requires it — email legal@noddable.com and we will return one. We will update this agreement where the law changes, and will notify you before a material change takes effect.

Annex 1 — Details of processing

Subject matterProvision of the Noddable website publishing and client gallery delivery service.
DurationThe term of the subscription, plus the retention periods in clause 9.
Nature and purposeHosting, storing, resizing, watermarking, transmitting and displaying content you upload; operating share links; recording selections, notes and download activity; generating exports; and providing support.
Types of personal dataPhotographs and video that may depict identifiable people; names, email addresses and other details you choose to put on a site or into a gallery; free-text notes written by your clients; a gallery reviewer's anonymous identifier; a one-way hash of a reviewer's IP address, used to count devices and never stored in its original form; and the contents of support correspondence.
Special category dataNot requested and not required. Photographs can reveal special category data by implication — for example a religious ceremony or a person's health. If your use involves it, the Article 9 condition for it is yours to identify as controller.
Categories of data subjectYour clients and their guests; people appearing in your photographs and video; visitors who contact you through your site; and your own staff and collaborators with access to the account.
FrequencyContinuous, for the duration of the subscription.

Annex 2 — Technical and organisational security measures

  • Encryption. TLS for all traffic in transit. Encryption at rest for the database and for stored objects.
  • Access control. Tenant isolation is enforced in one place, and the identifier used to scope every query is derived from the authenticated session or the request hostname — never from anything the browser supplies. Staff access to production is limited to those who need it for support and operations.
  • Authentication. Passwordless one-time codes, rate limited per address and per caller. Session tokens are stored only as a SHA-256 hash, so a database copy cannot be replayed as a live session.
  • Segregation of client media. Client galleries and page snapshots are stored in a separate bucket from public website media, reachable only through a handler that has first checked a share token or a session.
  • Withheld work. Original files in an unreleased gallery are refused by the server, not merely hidden by the interface.
  • Upload validation. Files are identified by their actual signature rather than by the declared content type, and uploaded folder paths are re-sanitised server-side.
  • Content isolation. A content security policy restricts what a published page may load or execute; customer content is rendered as text, never as markup.
  • Resilience. Data is stored on replicated infrastructure. Backups are taken and their restoration is tested.
  • Data minimisation. Visitor statistics store no identifier of any kind. Device counts are derived from a one-way hash. Records with no further purpose are deleted on a schedule rather than left to accumulate.
  • Change management. Changes are reviewed before release; dependencies are kept current; vulnerability reports are accepted at security@noddable.com under a published disclosure policy.

Annex 3 — Sub-processors

The current list, with each provider's role, location and transfer safeguard, is maintained on the sub-processors page and forms part of this annex. Changes are notified under clause 6.

← All legal documents