Back to Legal

Legal and data protection

Data Processing Addendum

This Addendum explains how Newt Labs handles personal data when we process it on behalf of a customer as part of our WordPress support, maintenance, hosting, security, performance, migration, backup, development, troubleshooting, monitoring, and related website services.

It applies where we access, support, host, maintain, back up, secure, migrate, monitor, develop, troubleshoot, or otherwise work on a website or related system that may contain customer-controlled personal data.

Last updated: 01 September 2026 Part of our service terms Plain English overview

This Addendum is written to make the data processing relationship easier to understand. It should not be treated as legal advice.

Newt Labs illustration showing secure WordPress data processing, website support, server systems, safeguards, and clear responsibility for client data.
1

Applies to client website data

Covers personal data held in or connected to your website, hosting, database, files, backups, forms, users, logs, plugins, or related systems.

2

Supports real WordPress work

Applies to practical work across support, care plans, hosting, security, performance, migrations, and website projects.

3

Explains the data roles

Sets out when you are usually the controller and when Newt Labs acts as processor for the services we provide.

4

Works with our other terms

This Addendum forms part of our Terms of Service where it applies and should be read alongside our Privacy Policy and related legal pages.

How this Addendum applies

This Data Processing Addendum forms part of our Terms of Service where Newt Labs processes personal data on behalf of a customer. It applies automatically where relevant to the services we provide.

This includes when you purchase, use, renew, or continue using our services, or when you instruct Newt Labs to work on your website or related systems.

If you are using our services on behalf of a business, charity, agency, or other organisation, you confirm that you have authority to accept this Addendum on that organisation’s behalf.

Part of our service terms

This Addendum works alongside our Terms of Service and applies where personal data is processed on your behalf.

Applies when relevant

It applies to the services and systems where Newt Labs may handle customer-controlled personal data.

For organisations too

If you act for an organisation, this Addendum applies to that organisation where you have authority to accept it.

The sections below explain the roles, responsibilities, processing details, safeguards, and service context in more detail.

Plain English summary

The simple version

When we work on your website or related systems, we may come across personal data that belongs to your business, customers, users, members, or website visitors.

In most cases, you decide what data your website collects and why. Newt Labs only processes that data where needed to provide the services you have asked us to carry out.

You control your website data

You are usually responsible for the personal data collected through your website, forms, shop, membership area, plugins, integrations, or hosting setup.

We process it to provide the service

Newt Labs may access or handle personal data where needed for support, maintenance, hosting, backups, security, performance, migration, development, troubleshooting, or monitoring.

i

We also handle our own business data

When we process data for our own enquiries, billing, communication, accounting, security, or business records, that is covered separately by our Privacy Policy.

The exact data depends on your setup

A simple brochure site may involve very little personal data. An ecommerce, membership, booking, donation, or learning site may involve more.

The main idea is simple: you control your website data, and we handle it only where needed to provide the agreed service.

Service context

When this Addendum applies

This Addendum applies when Newt Labs provides services that may involve access to customer-controlled personal data.

That can happen when we work on your WordPress website, hosting, database, files, backups, staging site, support tickets, plugins, forms, logs, integrations, or related systems.

Support and troubleshooting

Applies when we investigate issues, fix errors, review support details, or access website systems to complete a support request.

Maintenance and care plans

Applies when we carry out updates, checks, backups, monitoring, reporting, security reviews, or ongoing website support.

Hosting, backups, and staging

Applies when we host, copy, restore, migrate, back up, or create staging versions of a website or database.

Security, performance, and development work

Applies when we review files, logs, plugins, themes, malware findings, performance data, integrations, or other systems needed for the work.

This does not mean we access personal data for every task. It means the Addendum applies where personal data may be involved because of the service, website setup, access provided, or systems we need to work with.

Roles and responsibilities

Who is responsible for what?

For personal data held in or connected to your website, you are usually the Controller. That means you decide what personal data your website collects, why it is collected, how long it is kept, and how it should be used.

Newt Labs acts as Processor when we access or handle that personal data to provide the services you have asked us to carry out.

C

You control your website data

You are responsible for the personal data collected through your website, hosting, forms, shop, membership area, plugins, integrations, user accounts, orders, comments, and related systems.

P

We process data to provide agreed services

Newt Labs may process personal data where needed to provide WordPress support, maintenance, hosting, backups, security, performance, migration, development, troubleshooting, monitoring, or related work.

Your website privacy duties remain yours

You are responsible for your lawful basis, privacy notices, consent choices, data retention decisions, user management, and the tools or integrations you choose to use.

We are controller for our own business data

Newt Labs may act as an independent controller for data we process for our own business purposes, such as enquiries, billing, payment records, legal compliance, accounting, tax records, security, and customer relationship management.

The responsibilities above are separated clearly. They do not make Newt Labs responsible for your own website privacy setup, but they explain how we handle personal data when we process it for the services we provide.

Instructions

Instructions and customer responsibilities

Newt Labs processes customer-controlled personal data based on your documented instructions, unless we are required by law to do otherwise.

Those instructions may come from this Addendum, our Terms of Service, your service order, support tickets, emails, written requests, project briefs, care plan requests, access submissions, or agreed support channels.

If we believe an instruction may breach UK data protection law, we will let you know unless we are legally prevented from doing so.

1
Your instructions guide the work

We use your instructions to understand what you want us to access, fix, review, move, back up, secure, update, monitor, or support.

2
Instructions must be lawful

You are responsible for making sure your instructions to Newt Labs are lawful and that you have the right to ask us to process the personal data involved.

3
Your privacy duties remain yours

You are responsible for your own lawful basis, privacy notices, consent choices, user management, data retention decisions, forms, plugins, integrations, and website data collection.

4
Only send what is needed

You should avoid giving Newt Labs unnecessary personal data. You should not intentionally provide special category data or criminal offence data unless it is necessary for the service and you have confirmed the lawful basis and safeguards that apply.

Practical data handling

What we may need to access or handle

The personal data we may process depends on your website, the services you use, the systems connected to your site, and the access you provide.

For some tasks, we may only need limited technical access. For others, such as hosting, backups, migrations, security work, ecommerce troubleshooting, or membership site support, we may need to access systems where personal data is stored.

Illustration of a WordPress website connected to key data and service layers, including admin access, database, backups, hosting, support messages, security records, user data, logs, and connected systems.

Website systems and content

We may access your WordPress admin area, files, database, plugins, themes, media library, settings, forms, comments, user accounts, and website content where needed for the work.

Hosting, backups, and staging

We may handle website files, databases, backups, server logs, staging copies, migration files, restore points, and related technical records.

Customer, user, and transaction data

Where your website includes ecommerce, bookings, memberships, donations, subscriptions, courses, or user accounts, we may come across names, email addresses, phone numbers, addresses, usernames, order records, booking details, membership data, or similar records.

Support, monitoring, and security records

We may handle support messages, issue details, screenshots, attachments, access notes, uptime data, performance reports, IP addresses, security logs, malware findings, scan results, and other information needed to provide the service.

We aim to access and process only the data needed for the relevant service. Not every service requires access to every type of data.

Access and credentials

How access is handled carefully

To provide support, maintenance, hosting, security, migration, development, or troubleshooting, Newt Labs may need access to your website or related systems.

We treat that access as sensitive. Access is only used where needed for the service, and we use internal processes to help keep credentials, backups, staging sites, support systems, and client information controlled.

Secure WordPress access workflow showing protected credential submission, authorised support access, account security and careful access removal.

You should avoid sending unnecessary personal data or credentials unless they are needed for the work.

Secure access submission

Where possible, access details should be provided through a secure submission method rather than normal email.

Credential management

Passwords and access details may be stored in a secure password management system where needed for service delivery.

Limited access

Access is restricted to authorised Newt Labs team members, contractors, freelancers, suppliers, or service providers who need it to provide the service.

Confidential handling

People authorised to process customer-controlled personal data are expected to keep it confidential and follow internal access and support procedures.

Safer account practices

Where available and appropriate, we may use or encourage strong passwords, individual access, restricted permissions, and two factor authentication.

Careful offboarding

When access is no longer needed, credentials may be removed, restricted, archived, or reduced depending on the service, the client relationship, and the practical systems involved.

Providers and locations

Sub-processors, service providers, and data locations

Newt Labs may use trusted third-party providers to help deliver our services. These may include hosting platforms, infrastructure providers, backup tools, security services, monitoring tools, support systems, payment providers, email providers, password management systems, and other service providers needed to support your website.

Some providers may process personal data on our behalf. Others may act as independent controllers for certain activities, such as payment processing. The role depends on the provider, the service, and the type of data involved.

Service providers help us deliver the work

We may use providers for hosting, backups, server management, monitoring, support communication, password management, billing, payments, email, security, and related service delivery.

Authorised people may support your website

Newt Labs may use authorised employees, contractors, freelancers, suppliers, and support team members to provide services. Access is limited to what is needed for the relevant task.

Some processing may happen outside the UK

Some providers, contractors, or support team members may process personal data outside the United Kingdom. Where required, appropriate safeguards will be used under UK data protection law.

Provider details may change over time

The providers used can depend on the service, your website setup, and the tools required. We may update our sub-processors and service providers from time to time.

Current service provider examples

Current service providers may include hosting, backup, security, support, communication, password management, monitoring, and payment systems such as DigitalOcean, SpinupWP, ManageWP, Sucuri, Cloudflare, Help Scout, 1Password, Google Workspace, Stripe, GoCardless, PayPal, and related infrastructure providers where used.

We aim to use reputable providers and restrict access to what is reasonably needed to provide the relevant service.

Requests and incidents

Data requests, incidents, and compliance questions

If a question, request, or security issue relates to personal data we process on your behalf, Newt Labs will provide reasonable assistance based on the service, the systems involved, the access available, and the information we reasonably hold.

This may include helping you locate, export, correct, restrict, or delete personal data in supported website systems, or giving relevant technical information if a personal data breach or compliance question arises.

Client request being reviewed across supported website systems with clear technical assistance for data, security and compliance issues.

Data subject requests

If you receive a request from someone exercising their data protection rights, we may provide reasonable technical help where the request relates to website systems we support.

Security incidents

If we become aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay and provide reasonable information where available.

Compliance assistance

Where relevant, we may provide reasonable assistance with security questions, breach assessment, data protection impact assessments, or ICO-related enquiries linked to the services we provide.

Reasonable boundaries

Any wider audit, inspection, or information request should be reasonable, proportionate, pre-agreed, confidential, and handled in a way that does not disrupt our business, weaken security, or expose other clients’ information.

You remain responsible for deciding whether you need to notify regulators, customers, users, or other people, unless the law says otherwise.

Data lifecycle

Return, deletion, and retention

When our services end, you may ask Newt Labs to return or delete personal data we have processed on your behalf, unless we are required or permitted to keep it by law.

We will take reasonable steps to return or delete relevant personal data within a reasonable period, taking account of the service, systems involved, technical limits, backup processes, and any legal or business record requirements.

We aim to avoid keeping customer-controlled personal data for longer than needed, but some records may need to remain for practical, legal, accounting, security, or backup-related reasons.

Returning data

Where reasonable and appropriate, we may help return website data, files, databases, backups, or related records connected to the services we provided.

×
Deleting data

Where reasonable and appropriate, we may delete or remove personal data processed on your behalf after the service ends or after receiving a written request.

Backups and logs

Some data may remain in backups, logs, archives, staging copies, support records, or technical systems until it is overwritten, expires, or is deleted through normal retention processes.

§
Records we may need to keep

Newt Labs may retain some records where needed for legal, accounting, tax, security, fraud prevention, dispute resolution, service history, or legitimate business record purposes.

🔑
Credentials and access

Access details may be removed, restricted, archived, or reduced when they are no longer needed, depending on the service and client relationship.

Formal schedule

Formal processing details

The formal schedule below sets out the processing details for this Addendum. The exact personal data involved will depend on your website, the services you use, the systems connected to your site, and the access you provide to Newt Labs.

These details apply where Newt Labs processes personal data on your behalf as part of the services we provide.

Subject matter of processing

The provision of WordPress support, maintenance, hosting, backups, development, troubleshooting, migration, security, performance, monitoring, and related website services by Newt Labs.

Duration of processing

For the duration of your agreement with Newt Labs, plus any additional period where data is retained in backups, support records, logs, archives, legal records, accounting records, or other systems in line with our retention practices or legal obligations.

Nature and purpose of processing

We may process personal data to access, support, maintain, back up, restore, migrate, secure, troubleshoot, monitor, test, update, improve, or otherwise work on your website and related systems.

Types of personal data

This may include names, email addresses, phone numbers, postal addresses, usernames, account details, IP addresses, form submissions, comments, order records, booking records, membership records, support messages, website content, database records, logs, backups, and credentials where provided for support purposes.

Categories of people

The data may relate to your staff, website users, administrators, customers, members, subscribers, donors, students, parents, service users, suppliers, partners, contacts, website visitors, or people who submit forms, orders, bookings, donations, or enquiries through your website.

Special category data

Our services are not intended to require special category data or criminal offence data. However, we may incidentally access such data if you store it on your website, in your database, backups, forms, user accounts, support messages, or related systems.

You are responsible for making sure any personal data stored in your website or provided to Newt Labs is collected, used, and shared lawfully.

Safeguards

Technical and organisational measures

Newt Labs uses practical technical and organisational measures to help protect customer-controlled personal data where we process it as part of our services.

The measures used may vary depending on the service, the website setup, the systems involved, the tools available, and the access provided to Newt Labs.

Access control

Access to customer systems is restricted to authorised people who need it to provide the relevant service. Where possible, access is managed on a least privilege basis.

Credential management

Passwords and access details may be stored in a secure password management system where needed. Secure submission methods may be used to collect access details.

Authentication

Where available and appropriate, strong passwords, individual accounts, restricted permissions, and two factor authentication may be used or encouraged.

Backups and restoration

Backups may be created, stored, restored, or managed for support, hosting, migration, troubleshooting, security, continuity, or recovery purposes.

Website security

Security measures may include WordPress updates, malware scans, security checks, firewall configuration, login protection, hardening steps, and reporting relevant security issues to the customer.

Hosting and infrastructure

Hosting environments are managed using reputable hosting, infrastructure, storage, and server management providers. Access to hosting systems is restricted where possible.

Support systems and internal procedures

Support requests are handled through approved support channels. Team members and contractors are expected to follow internal procedures for website access, support work, credential handling, and client confidentiality.

Data minimisation and incident handling

Newt Labs aims to access and process only the data needed for the relevant service. Suspected security incidents are reviewed where appropriate, and customers are notified without undue delay where Newt Labs becomes aware of a personal data breach affecting personal data processed on their behalf.

Security measures are applied in a practical way based on the service, the risk, the systems involved, and what is technically available in the customer’s setup.

Provider schedule

Authorised sub-processors and service providers

Newt Labs may use authorised sub-processors and service providers to help deliver our services. These providers support areas such as hosting, backups, server management, website monitoring, security, support communication, password management, billing, payments, email, and related service delivery.

The providers used may depend on the service, your website setup, the tools required, and the systems involved.

Hosting, infrastructure, and backups

Providers such as DigitalOcean, SpinupWP, DigitalOcean Spaces, ManageWP, and Amazon Web Services or Amazon S3 via ManageWP may be used for hosting, server management, backups, storage, updates, monitoring, and related website administration where relevant.

Security, performance, and traffic services

Providers such as Sucuri and Cloudflare may be used for security scanning, malware detection, firewall services, DNS, CDN, caching, performance, traffic handling, and related security or performance services where enabled.

Support, communication, and internal systems

Providers such as Help Scout, 1Password, and Google Workspace may be used for support tickets, client communication, internal administration, password management, documents, email, calendar, and related business records.

Payments and billing

Providers such as Stripe, GoCardless, and PayPal may be used for payment processing, billing, invoices, mandates, transaction records, and related payment information. Some payment providers may act as independent controllers for certain activities.

Authorised people

Newt Labs may also use authorised employees, contractors, freelancers, suppliers, and support team members to provide services. These people may be based in the UK or internationally and are expected to follow confidentiality, access control, and internal support procedures.

Changes to providers

Newt Labs may update its sub-processors and service providers from time to time. Where required by UK data protection law, we will provide reasonable notice of material changes and give customers a reasonable opportunity to object on reasonable data protection grounds.

Where a provider is used to process personal data on behalf of Newt Labs, we aim to make sure appropriate data protection terms and safeguards are in place.

Questions about data processing?

Questions about data processing?

If you are a customer, agency partner, website manager, or compliance contact and need more clarity about this Addendum, please contact Newt Labs.

We can help you understand which legal page applies, what information may be relevant to your service, and where to find the right next step.

Client discussing data processing and compliance questions with a support specialist, with clear routes to service, security and policy information.

For service questions

Ask us if you are unsure how this Addendum applies to your website, hosting, support, care plan, migration, security work, or project.

For compliance questions

Contact us if you need reasonable information about processing, sub-processors, data locations, security measures, or service-related data handling.

For policy questions

Use the related legal pages if your question is about our Privacy Policy, Terms of Service, Scope of Service, or Cookies Policy.

We will point you to the most relevant information based on your question and the service involved.