Version: September 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Livetech Ltd, company number 09335110 (“Livetech”), and the Client receiving hosting, website management or related Services from Livetech (“Client”).
It applies where Livetech processes Personal Data on behalf of the Client.
1. Definitions
For this DPA:
Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and, where applicable to the relevant processing, the EU GDPR, together with other applicable data protection legislation as amended from time to time.
Controller, Processor, Personal Data, Data Subject, Personal Data Breach and processing have the meanings given by Applicable Data Protection Law.
Where Livetech processes Personal Data on behalf of the Client:
- the Client is the Controller; and
- Livetech is the Processor.
This DPA does not apply to Personal Data for which Livetech acts as Controller in its own right, such as information used for Livetech’s own customer administration, invoicing, legal compliance and business operations.
2. Subject Matter
Livetech processes Personal Data as necessary to provide hosting, website management, technical support, maintenance, backup, security and related Services purchased by the Client.
3. Duration
Processing continues for the duration of the relevant Services and for any limited period afterwards during which Personal Data remains within backups, logs or systems in accordance with applicable retention, security and deletion procedures or legal obligations.
4. Nature and Purpose of Processing
Depending upon the Services, processing may include:
- hosting and storing website files and databases;
- receiving and transmitting website requests;
- processing IP addresses and technical information;
- maintaining server, access and security logs;
- maintaining website databases;
- operating backup systems;
- monitoring availability and security;
- detecting malicious or unauthorised activity;
- restoring websites or data;
- troubleshooting;
- providing technical support;
- migrating data; and
- returning or deleting data when Services end.
Livetech processes Personal Data only for purposes reasonably necessary to provide the agreed Services.
5. Types of Personal Data
Depending on the Client’s website and Services, Personal Data may include:
- IP addresses;
- server and access-log data;
- browser, device and connection information;
- website-user identifiers;
- names;
- contact details;
- enquiry information;
- information submitted through website forms;
- login and account information;
- transaction information where applicable;
- Personal Data contained in Client website files or databases; and
- other Personal Data which the Client chooses to process using the Services.
The Client determines what information its website or systems collect.
6. Categories of Data Subject
Data Subjects may include:
- visitors to the Client’s website;
- customers and prospective customers;
- employees;
- contractors;
- suppliers;
- business contacts; and
- other individuals whose Personal Data is processed through the Services.
7. Documented Instructions
Livetech will process Personal Data only on documented instructions from the Client unless required otherwise by applicable law.
Documented instructions include:
- the Terms of Business;
- this DPA;
- the relevant SOW;
- the Client’s configuration and use of the Services; and
- subsequent written instructions, including instructions recorded by email.
Where Livetech believes an instruction infringes Applicable Data Protection Law, Livetech will inform the Client unless prohibited from doing so.
Where applicable law requires Livetech to process Personal Data other than on the Client’s instructions, Livetech will inform the Client before processing unless prohibited by law.
8. Confidentiality
Livetech will ensure that personnel authorised to process Personal Data:
- are subject to appropriate confidentiality obligations;
- access Personal Data only where reasonably necessary for their role;
- are informed of relevant confidentiality and security responsibilities; and
- process Personal Data only as necessary for the Services.
Administrative and infrastructure access is restricted to authorised personnel.
9. Technical and Organisational Measures
Livetech will maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures are proportionate to the nature of the Services and risks involved.
They include, where appropriate:
Infrastructure and network protection
- firewalls and network security controls;
- appropriate server configuration;
- restricted administrative access;
- security monitoring and logging;
- controls designed to identify malicious or unauthorised activity;
- appropriate security updates and software maintenance; and
- protection of administrative interfaces.
Access control
- access limited according to operational need;
- authentication and credential controls;
- management of privileged access; and
- removal or adjustment of access when no longer required.
Transmission security
Where appropriate and supported by the Service, technologies such as HTTPS/TLS are used to protect information transmitted between systems.
Backup and resilience
Livetech operates backup and restoration arrangements appropriate to the hosting Services being supplied.
Backup arrangements support recovery but do not remove any separate legal or business requirement on the Client to retain independent records.
Organisational measures
Measures include:
- staff confidentiality obligations;
- controlled infrastructure access;
- management of administrative privileges;
- security incident procedures;
- oversight of material infrastructure suppliers and sub-processors; and
- procedures for responding to significant security incidents.
Livetech may update its security measures as technology, Services and threats change, provided that the overall protection of Personal Data is not materially reduced.
10. Sub-processors
The Client gives Livetech general written authorisation to engage sub-processors reasonably necessary to provide the Services.
Livetech maintains its principal sub-processor information at: https://www.livetech.co.uk/sub-processors-list
Livetech will:
- undertake reasonable due diligence when selecting material sub-processors;
- require relevant sub-processors to protect Personal Data under appropriate contractual obligations;
- impose data protection obligations providing an equivalent level of protection required by Article 28 where applicable; and
- remain responsible to the Client for the performance of its sub-processors’ applicable data protection obligations as required by law.
Livetech will provide reasonable notice of intended material additions or replacements to sub-processors and provide the Client with a reasonable opportunity to raise a legitimate data protection objection.
If the parties cannot reasonably resolve an objection, either party may terminate the affected Service in accordance with the contractual arrangements.
11. International Transfers
Livetech will not knowingly make a restricted international transfer of Personal Data in breach of Applicable Data Protection Law.
Where an international transfer requires safeguards, Livetech will ensure that an appropriate transfer mechanism or other lawful safeguard is used.
The location of particular processing may depend on the Service purchased and the infrastructure or technology provider used.
12. Personal Data Breaches
If Livetech becomes aware of a Personal Data Breach affecting Personal Data processed by Livetech on behalf of the Client, Livetech will notify the Client without undue delay.
Where reasonably available, Livetech will provide information to assist the Client in understanding:
- the nature of the incident;
- affected Personal Data or systems;
- likely consequences;
- containment or remediation actions; and
- other information reasonably required by the Client to meet its own obligations.
Information may be provided in stages where all facts are not immediately available.
Livetech will take reasonable steps within its control to investigate, contain and remediate a breach relating to the Services.
The Client remains responsible for deciding whether it must notify the ICO, another supervisory authority or affected Data Subjects in its capacity as Controller.
13. Data Subject Rights
Taking account of the nature of the processing, Livetech will provide reasonable assistance to enable the Client to respond to requests from Data Subjects exercising applicable rights.
This may include requests concerning:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability; and
- other rights provided by Applicable Data Protection Law.
Where Livetech receives a request directly concerning Personal Data it processes solely on behalf of the Client, Livetech will normally refer the requester to the Client or notify the Client rather than determine the request itself.
14. Assistance With Compliance
Taking into account the nature of the processing and information available to Livetech, Livetech will provide reasonable assistance concerning:
- security of processing;
- Personal Data Breach investigation;
- regulatory breach notifications;
- communications to affected Data Subjects;
- Data Protection Impact Assessments;
- prior consultation with a supervisory authority where required; and
- reasonable information required to demonstrate compliance with Article 28.
The Client remains responsible for determining whether such actions are legally required.
15. Return and Deletion
When relevant Services end, Livetech will, at the Client’s choice and subject to technical capability:
- return or make Personal Data available for export; or
- delete Personal Data,
unless applicable law requires continued retention.
The Client should obtain any required copy of its website or data before termination where practicable.
Personal Data contained within backups may not be capable of immediate individual deletion.
Where that occurs, the data will remain protected and beyond normal operational use and will subsequently be overwritten or deleted in accordance with the relevant backup-retention cycle.
16. Information, Audit and Inspection
Livetech will make available information reasonably necessary to demonstrate compliance with its obligations under Article 28.
Where reasonably necessary, Livetech will allow for and contribute to appropriate audits or inspections relating to Personal Data processed on the Client’s behalf.
Where possible, compliance should first be demonstrated through:
- policies;
- technical information;
- security documentation;
- supplier information;
- questionnaires;
- certifications where held; or
- other appropriate evidence.
Where further audit activity is reasonably required:
- reasonable prior written notice should be given;
- audits should normally occur during business hours;
- they must not unreasonably disrupt Livetech’s operations;
- the confidentiality and security of other customers must be protected;
- auditors must be appropriately qualified and subject to confidentiality obligations; and
- the Client will bear its own costs and Livetech’s reasonable additional costs unless the audit identifies a material breach by Livetech.
These restrictions do not prevent appropriate urgent investigation following a serious security incident or where required by a competent supervisory authority.
17. Client Responsibilities
The Client is responsible for:
- deciding the purposes for which Personal Data is processed;
- ensuring an appropriate lawful basis exists;
- providing required privacy information;
- deciding what Personal Data its website collects;
- ensuring its instructions are lawful;
- controlling its employees’ and users’ access;
- managing appropriate retention requirements; and
- meeting its obligations as Controller.
Where the Client intends to process particularly sensitive, high-risk or unusual categories of information through the Services, it should tell Livetech where that information materially affects the security or processing arrangements required.
18. Relationship With the Terms
This DPA forms part of Livetech’s Terms of Business whenever Livetech processes Personal Data on behalf of the Client.
Where this DPA conflicts with another provision of the agreement specifically concerning such processing, this DPA takes precedence.
Other commercial provisions, including agreed liability provisions, continue to apply so far as legally permissible.
Nothing in the agreement restricts statutory rights of individuals or powers of a supervisory authority.
19. Updates
Livetech may update this DPA where reasonably necessary because of changes in law, regulatory guidance, Services, suppliers, security requirements or technology.
Material changes will be notified in accordance with the variation provisions contained in Livetech’s Terms of Business.
20. Contact
Questions relating to this DPA may be sent to:
Livetech Ltd
16 Trinity Square
Llandudno
Wales
LL30 2RB
Email: [email protected]
Telephone: 01492 233 606
