Last updated: 19 August 2026
Read this first
This page sets out the terms I offer and is provided in good faith. It is not legal advice, and it has not yet been reviewed by a solicitor. Before signing anything with an enterprise or public-sector client, have this reviewed by a qualified lawyer in the relevant jurisdiction — roughly one hour of a solicitor's time. Nobody should represent this as a lawyer-drafted instrument until that has happened.
Why this exists
Under UK GDPR and EU GDPR, when you engage me to work on a system containing personal data, you are the controller and I am a processor. Article 28(3) requires a written contract between us covering specific points. This is that contract.
Separately, I am located in Pakistan, which the UK and EU have not granted an adequacy decision. That makes any transfer of personal data to me a restricted international transfer requiring an appropriate safeguard. I use the UK International Data Transfer Addendum (IDTA) for UK controllers, and EU Standard Contractual Clauses, Module Two (controller to processor) for EEA controllers, as a completed schedule to this agreement.
1. Subject matter and duration
I process personal data only to deliver the development, maintenance or SEO services described in the signed scope document, for the duration of that engagement plus the retention period in clause 8.
2. Nature and purpose of processing
- Building, testing, deploying and maintaining your website or application
- Diagnosing faults, which may require access to production data
- Migrating data between systems where the scope includes migration
- Configuring analytics or search tooling where the scope includes it
3. Types of personal data
Typically: your customers' names, email addresses, postal addresses, phone numbers, order and booking records, and account credentials. I do not knowingly process special category data (health, biometric, religious or political data) and will tell you if a scope appears to require it, so we can agree additional safeguards first.
4. Categories of data subject
Your customers, your enquirers, and your own staff who hold accounts in the system.
5. My obligations as processor
- Process personal data only on your documented instructions
- Ensure anyone with access is bound by confidentiality — in practice this is me alone
- Implement the technical and organisational measures set out on the security page
- Engage no new sub-processor without notifying you and giving you a chance to object
- Assist you in responding to data subject requests
- Assist with your obligations on security, breach notification and impact assessments
- Delete or return all personal data at the end of the engagement, at your choice
- Make available the information needed to demonstrate compliance, and allow audit
6. Breach notification
If I become aware of a personal data breach affecting your data, I will notify you without undue delay and in any case within 24 hours, with what I know about the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the steps taken. You remain responsible for any notification to a supervisory authority or to data subjects.
7. Sub-processors
Current sub-processors are listed on the sub-processors page. I will give you at least 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds. Where you object and no alternative is workable, you may terminate the affected part of the engagement without penalty.
8. Retention and deletion
On termination, I delete all personal data within 30 days, unless you ask for its return first or I am required by law to keep it. This includes local development copies, database dumps and backups under my control. I will confirm deletion in writing if you ask.
9. International transfer
Personal data is accessed and processed in Pakistan. The IDTA (UK) or SCCs Module Two (EEA) are incorporated as a schedule and completed with the specifics of your engagement. Alongside them I have carried out a transfer risk assessment covering the legal context in Pakistan and the supplementary measures in clause 10.
10. Supplementary measures
- Encryption in transit (TLS) for all data access
- Full-disk encryption on every device used for client work
- Access limited to the minimum data needed for the task in hand
- Preference for anonymised or synthetic data in development environments wherever the work allows
- A commitment to notify you of any government access request, unless legally prohibited
11. Liability
Liability is governed by the main services agreement in the signed scope document. Nothing here limits either party's liability under data protection law towards a data subject.
12. Governing law
For UK clients, the laws of England and Wales. For EEA clients, the law of the client's member state. Chosen deliberately — a dispute resolved in your jurisdiction rather than mine removes a genuine risk for you.
How to execute this
Email anasrajpoot766@gmail.com and I will send a countersigned PDF with the IDTA or SCC schedule completed for your engagement, usually the same day. If your organisation has its own DPA template, send it — I will review and sign yours instead where the terms are reasonable.