Stay Safe Online

Data Processing Agreement

This Data Processing Agreement forms part of the terms of service between Compos UK Ltd and the customer. It applies where Compos processes personal data on the customer's behalf in providing the service.

Last updated: July 1, 2026
  1. Definitions

    Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Data Protection Law, meaning the UK GDPR, the EU GDPR (Regulation (EU) 2016/679), the Data Protection Act 2018, and any other applicable data protection laws, as amended.

    Customer Personal Data means personal data processed by Compos on the customer's behalf under the service.

  2. Roles And Scope

    2.1 As between the parties, the customer is the controller (or processor acting for a third party controller) and Compos is the processor of customer personal data.

    2.2 This DPA covers personal data of the customer's own website visitors, enquirers, and customers that is processed through the service for example, form submissions delivered to the inbox, content the customer puts into the knowledge base, and data handled through Cleo and the hub.

    2.3 The details of the processing are set out in Annex 1.

  3. Compos' Obligations As Processor

    Compos shall:

    3.1 Process Only On Instructions -ย Process customer personal data only on the customer's documented instructions (including those given through the service's settings, such as Cleo's autonomy levels), and as set out in this DPA and the terms, unless required by law (in which case Compos will tell the customer first, unless the law prohibits it).

    3.2 Confidentiality -ย Ensure that personnel authorised to process customer personal data are bound by appropriate confidentiality obligations.

    3.3 Security -ย Implement appropriate technical and organisational measures to protect customer personal data, as described in Annex 2 (Article 32).

    3.4 Sub Processors -ย Engage sub processors only as permitted by clause 5.

    3.5 Data Subject Requests -ย Taking into account the nature of the processing, assist the customer by appropriate measures, so far as possible, in responding to requests from data subjects exercising their rights. If Compos receives such a request directly, it will not respond except on the customer's instruction (unless legally required), and will inform the customer.

    3.6 Assistance -ย Assist the customer in ensuring compliance with its obligations on security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities (Articles 32โ€“36), taking into account the information available to Compos.

    3.7 Breach Notification -ย Notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, and provide information reasonably available to help the customer meet its own notification duties (see clause 7).

    3.8 Deletion Or Return -ย On termination of the service, delete or return customer personal data as set out in clause 10.

    3.9 Information And Audits -ย Make available information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in clause 8.

  4. Customers' Obligations

    4.1 The customer shall comply with data protection law in its capacity as controller, including having a valid lawful basis and providing required notices to data subjects.

    4.2 The customer is responsible for the accuracy and lawfulness of customer personal data and of its instructions, and warrants it has the right to provide that data to Compos for processing.

    4.3 The customer must not provide special category or other sensitive data through the service unless it has confirmed Compos can lawfully process it.

  5. Sub Processors

    5.1 The customer gives general authorisation for Compos to engage sub processors to provide the service.

    5.2 Compos will impose data protection obligations on each sub processor that are no less protective than those in this DPA, and remains responsible for its sub processors' performance.

    5.3 Compos will give the customer reasonable notice of any intended addition or replacement of a sub processor (at least 14 days), so the customer can object on reasonable data protection grounds. If an objection cannot be resolved, the customer may terminate the affected part of the service.

  6. International Transfers

    6.1 Compos and its sub processors may transfer customer personal data outside the UK / EEA only where an adequacy decision applies, or with appropriate safeguards in
    place, such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with any additional measures required.

  7. Personal Data Breach

    7.1 Compos will notify the customer without undue delay on becoming aware of a personal data breach affecting customer personal data, using the account contact details, and will provide the information reasonably available, including (as it becomes known) the nature of the breach, likely consequences, and measures taken or proposed.

    7.2 Compos will cooperate with the customer and take reasonable steps to mitigate and remediate the breach.

  8. Audits

    8.1 Compos will make available information necessary to demonstrate compliance with Article 28 and this DPA.

    8.2 Where the customer reasonably requires further assurance, the customer (or an independent auditor it appoints) may audit Compos' relevant processing, on reasonable prior notice (30 days), no more than once per year except following a personal data breach or at a supervisory authority's request, during business hours, and without unreasonable disruption. The parties will bear their own costs unless otherwise agreed.

  9. Liability

    The liability of each party under this DPA is subject to the limitations and exclusions of liability in the terms of service, except to the extent data protection law requires otherwise.

  10. Term, Deletion And Return

    10.1 This DPA lasts as long as Compos processes customer personal data under the service.

    10.2 On termination or expiry, Compos will, at the customer's choice, delete or return customer personal data, and delete existing copies, unless the law requires it to keep the data. The customer should export any data it wishes to keep before terminating. Standard deletion period: Within 90 days.

  11. Governing Law

    This DPA is governed by the law stated in the terms of service (England and Wales), without prejudice to mandatory provisions of data protection law.

  12. Annex 1 - Details Of Processing

    Subject Matter - Provision of the Compos service (website building, AI content, SEO, integrations, and form handling).

    Duration - For the term of the service, plus any deletion / return period.

    Nature And Purpose: Hosting, storing, organising, generating, analysing, and transmitting customer personal data as needed to provide the service and the features the customer uses.

    Types Of Personal Data - Names, email addresses, phone numbers, postal addresses, message content, and other data submitted through the customer's website forms, knowledge base, or content, as determined by the customer.

    Categories Of Data Subjects - The customer's website visitors, enquirers, leads, and customers.

    Special Categories - None, unless separately agreed in writing.

  13. Annex 2 - Technical and organisational measures (Article 32)

    Encryption of data in transit (TLS), and at rest where applicable.

    Access controls and least privilege access for personnel.

    Authentication controls and secure credential storage.

    Network and application security controls; regular patching.

    Logging and monitoring of access and activity.

    Backups and tested restoration procedures.

    Staff confidentiality undertakings and data protection awareness.

    Secure software development and change management practices.

    Incident response and breach handling procedures.

    Sub processor due diligence and contractual safeguards.

  14. Annex 3 - Sub Processors

    Hostinger Service Hosting / Storage
    Stripe Subscription and payment processing
    Anthropic,ย Fal.ai AI text and image generation via The Hub
    Hostinger Transactional and form notification email
    Google Product / Usage Analytics
    Google Maps / Places, Search Console, Analytics, Read Only Business Profile
    Google Google Reviews