Legal

Data Processing Agreement

If you are a UK or EU business, your procurement process will ask for this. Most offshore suppliers cannot produce one. Here it is before you have to ask.

Last updated: 19 August 2026

Read this first

This page sets out the terms I offer and is provided in good faith. It is not legal advice, and it has not yet been reviewed by a solicitor. Before signing anything with an enterprise or public-sector client, have this reviewed by a qualified lawyer in the relevant jurisdiction — roughly one hour of a solicitor's time. Nobody should represent this as a lawyer-drafted instrument until that has happened.

Why this exists

Under UK GDPR and EU GDPR, when you engage me to work on a system containing personal data, you are the controller and I am a processor. Article 28(3) requires a written contract between us covering specific points. This is that contract.

Separately, I am located in Pakistan, which the UK and EU have not granted an adequacy decision. That makes any transfer of personal data to me a restricted international transfer requiring an appropriate safeguard. I use the UK International Data Transfer Addendum (IDTA) for UK controllers, and EU Standard Contractual Clauses, Module Two (controller to processor) for EEA controllers, as a completed schedule to this agreement.

1. Subject matter and duration

I process personal data only to deliver the development, maintenance or SEO services described in the signed scope document, for the duration of that engagement plus the retention period in clause 8.

2. Nature and purpose of processing

3. Types of personal data

Typically: your customers' names, email addresses, postal addresses, phone numbers, order and booking records, and account credentials. I do not knowingly process special category data (health, biometric, religious or political data) and will tell you if a scope appears to require it, so we can agree additional safeguards first.

4. Categories of data subject

Your customers, your enquirers, and your own staff who hold accounts in the system.

5. My obligations as processor

6. Breach notification

If I become aware of a personal data breach affecting your data, I will notify you without undue delay and in any case within 24 hours, with what I know about the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the steps taken. You remain responsible for any notification to a supervisory authority or to data subjects.

7. Sub-processors

Current sub-processors are listed on the sub-processors page. I will give you at least 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds. Where you object and no alternative is workable, you may terminate the affected part of the engagement without penalty.

8. Retention and deletion

On termination, I delete all personal data within 30 days, unless you ask for its return first or I am required by law to keep it. This includes local development copies, database dumps and backups under my control. I will confirm deletion in writing if you ask.

9. International transfer

Personal data is accessed and processed in Pakistan. The IDTA (UK) or SCCs Module Two (EEA) are incorporated as a schedule and completed with the specifics of your engagement. Alongside them I have carried out a transfer risk assessment covering the legal context in Pakistan and the supplementary measures in clause 10.

10. Supplementary measures

11. Liability

Liability is governed by the main services agreement in the signed scope document. Nothing here limits either party's liability under data protection law towards a data subject.

12. Governing law

For UK clients, the laws of England and Wales. For EEA clients, the law of the client's member state. Chosen deliberately — a dispute resolved in your jurisdiction rather than mine removes a genuine risk for you.

How to execute this

Email anasrajpoot766@gmail.com and I will send a countersigned PDF with the IDTA or SCC schedule completed for your engagement, usually the same day. If your organisation has its own DPA template, send it — I will review and sign yours instead where the terms are reasonable.

Need the signed PDF?

Ask and it comes back the same day, with the IDTA or SCC schedule completed for your engagement.

Response
Replies within 1 business day
Hours
Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
Booking
Booking projects from October 2026
WhatsApp — opens a chat with +92 346 5348466 in a new tab