Data Processing Agreement
1. Parties and roles
This DPA is between you (the Controller): the Dark Orb account holder who builds a website with the service and collects personal data from its visitors; and us (the Processor): DanTodd Ltd, 1 St. Hilaire Walk, Leeds, England, LS10 4FE, company number 15749189, contact hello@danieltodd.uk. It applies only to personal data that visitors submit through Dark Orb (for example, a contact-form submission). For your own account data we are the controller, and the Privacy Policy governs that. Where this DPA and the Terms of Service conflict on data protection, this DPA prevails.
2. Details of processing (Article 28(3))
- Subject matter: processing of visitor personal data submitted through forms on websites you build and host with Dark Orb, so you can read and act on them.
- Duration: while you hold an account with an active site, or until this DPA is terminated.
- Nature and purpose: receiving, storing, and making available to you the submissions visitors send, so you can read, act on, and reply to them. Submissions that carry an email address are also gathered into a customer record, so you can read everything one person has sent as a single thread. We email each submission to you through our email subprocessor (Resend) to notify you that it has arrived, and when you reply to a customer from your portal your reply is delivered to them the same way. When you ask a question about your customers, or for a summary of a thread, and answering needs interpretation, the relevant enquiry text is sent to our AI subprocessor (Anthropic); this happens only when you ask, never automatically. Beyond that, we do not disclose this data to any third party, and we do not use it for our own purposes.
- Types of personal data: typically a visitor's name, email, and message, plus any custom fields you add.
- Data subjects: visitors to the sites you build.
- Special-category data: not intended; do not configure forms to collect it without your own lawful basis and safeguards.
The most recent 500 submissions per site are retained in the site inbox; customer records last for the life of your account.
3. Our obligations as processor
We will: process only on your documented instructions; keep the data confidential; secure it (clause 4); use subprocessors only under clause 5; help you respond to data-subject requests and meet your security, breach-notification, and impact-assessment obligations; delete or return the data at the end of processing (clause 7); support audits (clause 8); and tell you if an instruction appears to breach the law.
4. Security measures
We apply measures appropriate to the risk: passwordless authentication (passkeys and single-use magic links); a signed, HttpOnly, tamper-evident session cookie; access scoped to your account at the storage layer, not only at the interface; encryption in transit (HTTPS) and at rest on Cloudflare's infrastructure; minimised, tiered audit logging; vendor access isolated behind our own abstraction layer; and data minimisation by design. We may update these measures provided protection is not reduced.
5. Subprocessors
You give general authorisation for us to engage subprocessors, published in our Subprocessors list, each bound by obligations no less protective than this DPA. For visitor form-submission data specifically, the relevant subprocessors are Cloudflare (hosting and storage), Resend (delivering each submission to you by email notification, and delivering the replies you send to your customers), and Anthropic (interpreting the questions you ask about your customers and summarising threads: the relevant enquiry text is sent only when you ask, never automatically). We do not send your form-submission data to OpenAI, Pexels, or any other subprocessor. We will give reasonable prior notice of any change. If you reasonably object to a new subprocessor on data-protection grounds and we cannot resolve it, you may stop using the affected part of the service.
6. Data-subject rights
When a visitor exercises a right over data they submitted to your site, you are the controller and the request is yours to answer. You can access, export, correct, and delete your site's submissions through your portal, and we will assist with anything that needs us. If a visitor contacts us directly, we will direct them to you and let you know.
7. End of processing
On termination, on closure of your account, or on your instruction, we will delete the visitor personal data we process for you unless the law requires us to keep it. Deleting your account removes your sites, their versions, their form submissions, and your customer records. Backup copies age out within 30 days. On request, before deletion, we will return the submissions to you in a portable format.
8. Audit and information
We will make available the information reasonably necessary to demonstrate compliance with Article 28, including this DPA, the Subprocessors list, the Privacy Policy, and the Substrate Audit Log Policy. Where you reasonably need more to satisfy a regulator, we will cooperate in good faith, on reasonable notice, during business hours, without compromising other customers' security or confidentiality.
9. Breach notification
If we become aware of a personal-data breach affecting the visitor data we process for you, we will notify you without undue delay and provide the information you reasonably need to meet your own obligations. Reporting a reportable breach to the ICO within 72 hours remains your obligation as the controller.
10. International transfers
Visitor form-submission data is hosted on Cloudflare's infrastructure. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. The specific mechanism per subprocessor is being confirmed with our solicitor and recorded in the Subprocessors list as it is settled.
11. Liability and term
This DPA takes effect when you accept the Terms of Service and continues while you use the service. Liability is subject to the limitations in the Terms of Service (clause 9), which remain under solicitor review. Obligations that by their nature should survive termination (confidentiality, end-of-processing handling, and audit cooperation for data already processed) continue to apply.
12. Governing law
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over it.
← Back