← Legal & Policies

Data Processing Agreement

BulFront’s Art. 28 GDPR terms as processor of your website visitors’ data.

Template pending legal review — complete the highlighted [placeholders] before relying on this document.

Effective date: [EFFECTIVE DATE]. This Data Processing Agreement ("DPA") forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor", "we") and the customer ("Controller", "you"). It applies where we process personal data on your behalf — for example, the leads, bookings, orders and analytics your published website collects from its visitors.

1. Roles You are the Controller of your end-users’ personal data; we are your Processor. For our own account/billing data we are an independent Controller (see the Privacy Policy).

2. Scope and instructions We process personal data only to provide the Service and on your documented instructions, including as configured through the platform, unless legally required otherwise.

3. Confidentiality Personnel authorised to process personal data are bound by confidentiality.

4. Security We implement appropriate technical and organisational measures, including access controls, encryption in transit, hashed credentials and regular backups.

5. Subprocessors You authorise the subprocessors listed on our Subprocessor page. We will inform you of intended changes and give you the opportunity to object.

6. Data-subject requests We will assist you, taking into account the nature of processing, to respond to data-subject requests, and forward to you any request we receive directly.

7. Personal-data breaches We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need.

8. International transfers Where applicable, transfers outside the EEA are covered by appropriate safeguards such as Standard Contractual Clauses.

9. Deletion and return On termination we will delete or return your end-users’ personal data within a reasonable period, except where retention is legally required.

10. Audits We will make available information necessary to demonstrate compliance with Art. 28 GDPR and allow for reasonable audits, subject to confidentiality and security.

11. Contact Data protection contact: [PRIVACY EMAIL], [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

This document is a template pending review by a qualified lawyer.

Data Processing Agreement — BulFront · BulFront