Applies to client website data
Covers personal data held in or connected to your website, hosting, database, files, backups, forms, users, logs, plugins, or related systems.
This Addendum explains how Newt Labs handles personal data when we process it on behalf of a customer as part of our WordPress support, maintenance, hosting, security, performance, migration, backup, development, troubleshooting, monitoring, and related website services.
It applies where we access, support, host, maintain, back up, secure, migrate, monitor, develop, troubleshoot, or otherwise work on a website or related system that may contain customer-controlled personal data.
This Addendum is written to make the data processing relationship easier to understand. It should not be treated as legal advice.
Covers personal data held in or connected to your website, hosting, database, files, backups, forms, users, logs, plugins, or related systems.
Applies to practical work across support, care plans, hosting, security, performance, migrations, and website projects.
Sets out when you are usually the controller and when Newt Labs acts as processor for the services we provide.
This Addendum forms part of our Terms of Service where it applies and should be read alongside our Privacy Policy and related legal pages.
This Data Processing Addendum forms part of our Terms of Service where Newt Labs processes personal data on behalf of a customer. It applies automatically where relevant to the services we provide.
This includes when you purchase, use, renew, or continue using our services, or when you instruct Newt Labs to work on your website or related systems.
If you are using our services on behalf of a business, charity, agency, or other organisation, you confirm that you have authority to accept this Addendum on that organisation’s behalf.
This Addendum works alongside our Terms of Service and applies where personal data is processed on your behalf.
It applies to the services and systems where Newt Labs may handle customer-controlled personal data.
If you act for an organisation, this Addendum applies to that organisation where you have authority to accept it.
The sections below explain the roles, responsibilities, processing details, safeguards, and service context in more detail.
When we work on your website or related systems, we may come across personal data that belongs to your business, customers, users, members, or website visitors.
In most cases, you decide what data your website collects and why. Newt Labs only processes that data where needed to provide the services you have asked us to carry out.
You are usually responsible for the personal data collected through your website, forms, shop, membership area, plugins, integrations, or hosting setup.
Newt Labs may access or handle personal data where needed for support, maintenance, hosting, backups, security, performance, migration, development, troubleshooting, or monitoring.
When we process data for our own enquiries, billing, communication, accounting, security, or business records, that is covered separately by our Privacy Policy.
A simple brochure site may involve very little personal data. An ecommerce, membership, booking, donation, or learning site may involve more.
The main idea is simple: you control your website data, and we handle it only where needed to provide the agreed service.
This Addendum applies when Newt Labs provides services that may involve access to customer-controlled personal data.
That can happen when we work on your WordPress website, hosting, database, files, backups, staging site, support tickets, plugins, forms, logs, integrations, or related systems.
Applies when we investigate issues, fix errors, review support details, or access website systems to complete a support request.
Applies when we carry out updates, checks, backups, monitoring, reporting, security reviews, or ongoing website support.
Applies when we host, copy, restore, migrate, back up, or create staging versions of a website or database.
Applies when we review files, logs, plugins, themes, malware findings, performance data, integrations, or other systems needed for the work.
This does not mean we access personal data for every task. It means the Addendum applies where personal data may be involved because of the service, website setup, access provided, or systems we need to work with.
For personal data held in or connected to your website, you are usually the Controller. That means you decide what personal data your website collects, why it is collected, how long it is kept, and how it should be used.
Newt Labs acts as Processor when we access or handle that personal data to provide the services you have asked us to carry out.
You are responsible for the personal data collected through your website, hosting, forms, shop, membership area, plugins, integrations, user accounts, orders, comments, and related systems.
Newt Labs may process personal data where needed to provide WordPress support, maintenance, hosting, backups, security, performance, migration, development, troubleshooting, monitoring, or related work.
You are responsible for your lawful basis, privacy notices, consent choices, data retention decisions, user management, and the tools or integrations you choose to use.
Newt Labs may act as an independent controller for data we process for our own business purposes, such as enquiries, billing, payment records, legal compliance, accounting, tax records, security, and customer relationship management.
The responsibilities above are separated clearly. They do not make Newt Labs responsible for your own website privacy setup, but they explain how we handle personal data when we process it for the services we provide.
Newt Labs processes customer-controlled personal data based on your documented instructions, unless we are required by law to do otherwise.
Those instructions may come from this Addendum, our Terms of Service, your service order, support tickets, emails, written requests, project briefs, care plan requests, access submissions, or agreed support channels.
If we believe an instruction may breach UK data protection law, we will let you know unless we are legally prevented from doing so.
We use your instructions to understand what you want us to access, fix, review, move, back up, secure, update, monitor, or support.
You are responsible for making sure your instructions to Newt Labs are lawful and that you have the right to ask us to process the personal data involved.
You are responsible for your own lawful basis, privacy notices, consent choices, user management, data retention decisions, forms, plugins, integrations, and website data collection.
You should avoid giving Newt Labs unnecessary personal data. You should not intentionally provide special category data or criminal offence data unless it is necessary for the service and you have confirmed the lawful basis and safeguards that apply.
The personal data we may process depends on your website, the services you use, the systems connected to your site, and the access you provide.
For some tasks, we may only need limited technical access. For others, such as hosting, backups, migrations, security work, ecommerce troubleshooting, or membership site support, we may need to access systems where personal data is stored.
We may access your WordPress admin area, files, database, plugins, themes, media library, settings, forms, comments, user accounts, and website content where needed for the work.
We may handle website files, databases, backups, server logs, staging copies, migration files, restore points, and related technical records.
Where your website includes ecommerce, bookings, memberships, donations, subscriptions, courses, or user accounts, we may come across names, email addresses, phone numbers, addresses, usernames, order records, booking details, membership data, or similar records.
We may handle support messages, issue details, screenshots, attachments, access notes, uptime data, performance reports, IP addresses, security logs, malware findings, scan results, and other information needed to provide the service.
We aim to access and process only the data needed for the relevant service. Not every service requires access to every type of data.
To provide support, maintenance, hosting, security, migration, development, or troubleshooting, Newt Labs may need access to your website or related systems.
We treat that access as sensitive. Access is only used where needed for the service, and we use internal processes to help keep credentials, backups, staging sites, support systems, and client information controlled.
You should avoid sending unnecessary personal data or credentials unless they are needed for the work.
Where possible, access details should be provided through a secure submission method rather than normal email.
Passwords and access details may be stored in a secure password management system where needed for service delivery.
Access is restricted to authorised Newt Labs team members, contractors, freelancers, suppliers, or service providers who need it to provide the service.
People authorised to process customer-controlled personal data are expected to keep it confidential and follow internal access and support procedures.
Where available and appropriate, we may use or encourage strong passwords, individual access, restricted permissions, and two factor authentication.
When access is no longer needed, credentials may be removed, restricted, archived, or reduced depending on the service, the client relationship, and the practical systems involved.
Newt Labs may use trusted third-party providers to help deliver our services. These may include hosting platforms, infrastructure providers, backup tools, security services, monitoring tools, support systems, payment providers, email providers, password management systems, and other service providers needed to support your website.
Some providers may process personal data on our behalf. Others may act as independent controllers for certain activities, such as payment processing. The role depends on the provider, the service, and the type of data involved.
We may use providers for hosting, backups, server management, monitoring, support communication, password management, billing, payments, email, security, and related service delivery.
Newt Labs may use authorised employees, contractors, freelancers, suppliers, and support team members to provide services. Access is limited to what is needed for the relevant task.
Some providers, contractors, or support team members may process personal data outside the United Kingdom. Where required, appropriate safeguards will be used under UK data protection law.
The providers used can depend on the service, your website setup, and the tools required. We may update our sub-processors and service providers from time to time.
Current service providers may include hosting, backup, security, support, communication, password management, monitoring, and payment systems such as DigitalOcean, SpinupWP, ManageWP, Sucuri, Cloudflare, Help Scout, 1Password, Google Workspace, Stripe, GoCardless, PayPal, and related infrastructure providers where used.
We aim to use reputable providers and restrict access to what is reasonably needed to provide the relevant service.
If a question, request, or security issue relates to personal data we process on your behalf, Newt Labs will provide reasonable assistance based on the service, the systems involved, the access available, and the information we reasonably hold.
This may include helping you locate, export, correct, restrict, or delete personal data in supported website systems, or giving relevant technical information if a personal data breach or compliance question arises.
If you receive a request from someone exercising their data protection rights, we may provide reasonable technical help where the request relates to website systems we support.
If we become aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay and provide reasonable information where available.
Where relevant, we may provide reasonable assistance with security questions, breach assessment, data protection impact assessments, or ICO-related enquiries linked to the services we provide.
Any wider audit, inspection, or information request should be reasonable, proportionate, pre-agreed, confidential, and handled in a way that does not disrupt our business, weaken security, or expose other clients’ information.
You remain responsible for deciding whether you need to notify regulators, customers, users, or other people, unless the law says otherwise.
When our services end, you may ask Newt Labs to return or delete personal data we have processed on your behalf, unless we are required or permitted to keep it by law.
We will take reasonable steps to return or delete relevant personal data within a reasonable period, taking account of the service, systems involved, technical limits, backup processes, and any legal or business record requirements.
We aim to avoid keeping customer-controlled personal data for longer than needed, but some records may need to remain for practical, legal, accounting, security, or backup-related reasons.
Where reasonable and appropriate, we may help return website data, files, databases, backups, or related records connected to the services we provided.
Where reasonable and appropriate, we may delete or remove personal data processed on your behalf after the service ends or after receiving a written request.
Some data may remain in backups, logs, archives, staging copies, support records, or technical systems until it is overwritten, expires, or is deleted through normal retention processes.
Newt Labs may retain some records where needed for legal, accounting, tax, security, fraud prevention, dispute resolution, service history, or legitimate business record purposes.
Access details may be removed, restricted, archived, or reduced when they are no longer needed, depending on the service and client relationship.
The formal schedule below sets out the processing details for this Addendum. The exact personal data involved will depend on your website, the services you use, the systems connected to your site, and the access you provide to Newt Labs.
These details apply where Newt Labs processes personal data on your behalf as part of the services we provide.
The provision of WordPress support, maintenance, hosting, backups, development, troubleshooting, migration, security, performance, monitoring, and related website services by Newt Labs.
For the duration of your agreement with Newt Labs, plus any additional period where data is retained in backups, support records, logs, archives, legal records, accounting records, or other systems in line with our retention practices or legal obligations.
We may process personal data to access, support, maintain, back up, restore, migrate, secure, troubleshoot, monitor, test, update, improve, or otherwise work on your website and related systems.
This may include names, email addresses, phone numbers, postal addresses, usernames, account details, IP addresses, form submissions, comments, order records, booking records, membership records, support messages, website content, database records, logs, backups, and credentials where provided for support purposes.
The data may relate to your staff, website users, administrators, customers, members, subscribers, donors, students, parents, service users, suppliers, partners, contacts, website visitors, or people who submit forms, orders, bookings, donations, or enquiries through your website.
Our services are not intended to require special category data or criminal offence data. However, we may incidentally access such data if you store it on your website, in your database, backups, forms, user accounts, support messages, or related systems.
You are responsible for making sure any personal data stored in your website or provided to Newt Labs is collected, used, and shared lawfully.
Newt Labs uses practical technical and organisational measures to help protect customer-controlled personal data where we process it as part of our services.
The measures used may vary depending on the service, the website setup, the systems involved, the tools available, and the access provided to Newt Labs.
Access to customer systems is restricted to authorised people who need it to provide the relevant service. Where possible, access is managed on a least privilege basis.
Passwords and access details may be stored in a secure password management system where needed. Secure submission methods may be used to collect access details.
Where available and appropriate, strong passwords, individual accounts, restricted permissions, and two factor authentication may be used or encouraged.
Backups may be created, stored, restored, or managed for support, hosting, migration, troubleshooting, security, continuity, or recovery purposes.
Security measures may include WordPress updates, malware scans, security checks, firewall configuration, login protection, hardening steps, and reporting relevant security issues to the customer.
Hosting environments are managed using reputable hosting, infrastructure, storage, and server management providers. Access to hosting systems is restricted where possible.
Support requests are handled through approved support channels. Team members and contractors are expected to follow internal procedures for website access, support work, credential handling, and client confidentiality.
Newt Labs aims to access and process only the data needed for the relevant service. Suspected security incidents are reviewed where appropriate, and customers are notified without undue delay where Newt Labs becomes aware of a personal data breach affecting personal data processed on their behalf.
Security measures are applied in a practical way based on the service, the risk, the systems involved, and what is technically available in the customer’s setup.
Newt Labs may use authorised sub-processors and service providers to help deliver our services. These providers support areas such as hosting, backups, server management, website monitoring, security, support communication, password management, billing, payments, email, and related service delivery.
The providers used may depend on the service, your website setup, the tools required, and the systems involved.
Providers such as DigitalOcean, SpinupWP, DigitalOcean Spaces, ManageWP, and Amazon Web Services or Amazon S3 via ManageWP may be used for hosting, server management, backups, storage, updates, monitoring, and related website administration where relevant.
Providers such as Sucuri and Cloudflare may be used for security scanning, malware detection, firewall services, DNS, CDN, caching, performance, traffic handling, and related security or performance services where enabled.
Providers such as Help Scout, 1Password, and Google Workspace may be used for support tickets, client communication, internal administration, password management, documents, email, calendar, and related business records.
Providers such as Stripe, GoCardless, and PayPal may be used for payment processing, billing, invoices, mandates, transaction records, and related payment information. Some payment providers may act as independent controllers for certain activities.
Newt Labs may also use authorised employees, contractors, freelancers, suppliers, and support team members to provide services. These people may be based in the UK or internationally and are expected to follow confidentiality, access control, and internal support procedures.
Newt Labs may update its sub-processors and service providers from time to time. Where required by UK data protection law, we will provide reasonable notice of material changes and give customers a reasonable opportunity to object on reasonable data protection grounds.
Where a provider is used to process personal data on behalf of Newt Labs, we aim to make sure appropriate data protection terms and safeguards are in place.
This Addendum works alongside the main agreement between you and Newt Labs. It applies only where the issue relates to Newt Labs processing personal data on your behalf.
If there is a conflict between this Addendum and the main agreement, this Addendum takes priority only to the extent the conflict relates to the processing of customer-controlled personal data.
Each party’s liability under this Addendum is subject to the exclusions and limits set out in the main agreement, unless the law requires otherwise.
If this Addendum conflicts with the main agreement on a personal data processing issue, this Addendum applies to that issue. All other terms remain unchanged.
This Addendum is governed by the laws of England and Wales.
The courts of England and Wales have exclusive jurisdiction over disputes relating to this Addendum.
These terms help make the relationship between this Addendum and our wider service terms clear.
If you are a customer, agency partner, website manager, or compliance contact and need more clarity about this Addendum, please contact Newt Labs.
We can help you understand which legal page applies, what information may be relevant to your service, and where to find the right next step.
Ask us if you are unsure how this Addendum applies to your website, hosting, support, care plan, migration, security work, or project.
Contact us if you need reasonable information about processing, sub-processors, data locations, security measures, or service-related data handling.
Use the related legal pages if your question is about our Privacy Policy, Terms of Service, Scope of Service, or Cookies Policy.
We will point you to the most relevant information based on your question and the service involved.