Letrix Labs LogoLetrix Labs
Legal

Data processing agreement

Last updated: August 2026

When we build, migrate or maintain a system for you, we usually end up handling personal data that belongs to your customers, staff or users. UK GDPR requires that arrangement to be written down. This is that document: it forms part of our Terms of Service and applies automatically whenever we process personal data on your behalf.

If you need a signed copy

This agreement applies without needing to be signed. If your procurement or legal team needs an executed copy, or wants it on your own paper, email hello@letrixlabs.com and we will sort it out.

1. Parties and definitions

This agreement is between you (the Controller) and Dime Corporation Ltd trading as Letrix Labs, company number 13175488, 124 City Road, London, EC1V 2NX, United Kingdom (the Processor).

Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and the EU GDPR where it applies. Personal Data, Processing, Data Subject, Controller, Processor and Personal Data Breach have the meanings given in the UK GDPR. Client Personal Data means personal data we process on your behalf under our engagement.

2. Roles

You are the Controller: it is your data, you decide why and how it is processed, and you are responsible for having a lawful basis for it and for the fairness and accuracy of the data you give us. We are the Processor: we act on your instructions and do not decide the purposes of the processing.

Where we process personal data for our own purposes, such as running our business, invoicing you and keeping our records, we act as a controller in our own right, and our Privacy Policy governs that instead.

3. Our instructions

We process Client Personal Data only on your documented instructions, including in relation to international transfers, unless we are required to do otherwise by law. Where the law requires it, we will tell you before processing unless the law prohibits us from doing so.

Your instructions are the engagement itself: the quote, statement of work or care plan we have agreed, together with anything you subsequently ask us in writing. If we believe an instruction breaches Data Protection Law, we will tell you promptly and may pause that processing until it is resolved.

We do not sell Client Personal Data, use it for our own marketing, or use it to train machine learning models.

4. Confidentiality of personnel

Access to Client Personal Data is limited to people who need it to deliver the work. Everyone with access is bound by a duty of confidentiality that survives the end of their involvement, and is briefed on their obligations before being given access.

5. Security

We implement appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature and risk of the processing. The measures in place are set out in Annex 2.

6. Sub-processors

You give us general authorisation to engage sub-processors. The ones currently authorised are listed in Annex 3.

Before adding or replacing a sub-processor that will handle Client Personal Data, we will give you at least 30 days’ notice. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If we cannot, either of us may terminate the affected part of the engagement without penalty, with fees due for work already done.

Any sub-processor we engage is bound by written terms offering protection equivalent to this agreement, and we remain fully liable to you for their performance.

We do not engage individual contractors who would access Client Personal Data without agreeing it with you first, as set out in our Terms of Service.

7. Assisting you with data subject rights

If we receive a request from one of your data subjects (access, erasure, rectification, portability, objection or restriction), we will not respond to it ourselves. We will forward it to you without undue delay and let them know we have done so.

Taking into account the nature of the processing, we will provide reasonable assistance with the technical measures needed for you to meet your obligations, such as locating, exporting, correcting or deleting records. Straightforward assistance is included in the engagement; if a request requires substantial engineering effort we will agree a fee with you before starting.

8. Assisting you more broadly

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 of the UK GDPR: security of processing, breach notification to the ICO and to data subjects, data protection impact assessments, and prior consultation with the ICO.

9. Personal data breaches

If we become aware of a Personal Data Breach affecting Client Personal Data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it.

Our notification will include, so far as we are able:

  • the nature of the breach, and the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • the measures taken or proposed to address it and mitigate its effects;
  • a point of contact for further information.

Where we cannot provide everything at once, we will provide it in phases as the picture becomes clear rather than delaying the initial notification. We will cooperate with you and take the steps you reasonably request to help investigate and remedy the breach. It is your responsibility as Controller to notify the ICO and affected data subjects where required.

10. International transfers

Client Personal Data is processed in the United Kingdom and the European Economic Area. We will not transfer it outside the UK without ensuring an appropriate safeguard is in place (an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses) and without meeting the requirements of Data Protection Law.

11. Deletion and return

On the ending of the engagement, and at your choice, we will delete or return Client Personal Data. Unless you ask us to do otherwise, we will act on your written request within 30 days.

Two carve-outs, stated plainly: we may retain Client Personal Data where we are legally required to, for as long as that requirement lasts; and copies held in routine encrypted backups are not individually deleted, but are overwritten on their normal cycle and remain protected by this agreement until they are.

We will also return or securely destroy any credentials and access we hold for your systems, and we recommend you revoke them at your end as well.

12. Audit and information

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits and inspections conducted by you or an auditor you appoint.

In practice, we ask that audits happen no more than once a year unless there has been a breach or a regulator requires it, that you give at least 30 days’ notice, that they occur during business hours without unreasonably disrupting our work, and that the auditor is bound by confidentiality. We may charge a reasonable fee for time spent on audits beyond the first each year.

13. Liability

Our liability under this agreement is subject to the limitations and exclusions in our Terms of Service. Nothing in this agreement limits either party’s liability to a data subject or a regulator, or excludes liability that cannot lawfully be excluded.

14. Duration and precedence

This agreement applies for as long as we process Client Personal Data on your behalf, and the obligations that by their nature should continue, such as confidentiality, deletion and liability, survive its end.

Where this agreement conflicts with our Terms of Service on the subject of personal data processing, this agreement takes precedence. Where it conflicts with a signed data processing agreement specific to your engagement, that document takes precedence.

Annex 1: Details of the processing

Subject matterProvision of design, development, migration, maintenance and support services as set out in the engagement.
DurationFor the term of the engagement, plus any retention period described in clause 11.
Nature of processingStorage, access, retrieval, organisation, structuring, alteration, transmission, backup, testing, migration and deletion, as necessary to deliver the services.
PurposeBuilding, migrating, fixing and maintaining the systems you have engaged us to work on, and providing support in relation to them.
Types of personal dataDetermined by the contents of your systems. Typically: names, email addresses, postal addresses, phone numbers, account credentials, order and transaction records, user-generated content, IP addresses and log data.
Categories of data subjectDetermined by the contents of your systems. Typically: your customers, prospects, website visitors, subscribers, staff and contractors.
Special category dataNot processed unless you tell us in advance that your systems contain it, so that we can agree any additional measures needed.

Annex 2: Technical and organisational measures

Access control

  • Access to client systems is limited to the people who need it for the work in hand.
  • Credentials for client systems are stored in a dedicated, access-controlled 1Password vault, never in plain text, never in email or chat, and never in source control.
  • Multi-factor authentication is used on our accounts and on client systems wherever the system supports it.
  • Access is revoked when it is no longer needed, and at the end of the engagement.

Infrastructure and data handling

  • Our core systems (support, analytics and error monitoring) are self-hosted and run by us in the UK and EU.
  • Data in transit is encrypted using TLS. Data at rest is encrypted where the platform supports it.
  • Working copies of client data are kept only as long as the task requires and are removed afterwards.
  • Production data is not used in development or testing environments where a synthetic or anonymised alternative will do.
  • We minimise what we collect and access: we do not take copies of data we do not need.

Resilience and continuity

  • Where a care plan includes backups, they are taken weekly, daily or hourly according to the plan, held off-site in the United Kingdom or the European Union, and retained for 31 days as standard.
  • Backups are encrypted and access-controlled.
  • Restoration is tested on a reasonable-endeavours basis; see our Terms of Service on the limits of any restoration guarantee.

Organisational measures

  • Everyone with access is bound by confidentiality obligations that survive the engagement.
  • Sub-processors are subject to written terms equivalent to this agreement.
  • We maintain a breach response process and the 48-hour notification commitment in clause 9.
  • Software and dependencies on systems under our care are kept up to date as part of the relevant service.

Annex 3: Authorised sub-processors

These are the sub-processors that may handle Client Personal Data in the course of our work. Providers we use purely for our own business, which never touch your data, are not listed here: they appear in our Privacy Policy.

Sub-processorPurposeLocation
FreeScout (self-hosted by Letrix Labs)Support ticketing, where your correspondence may include personal dataUnited Kingdom / EU
CrispLive chat, where a conversation may include personal dataEuropean Union (France)
CloudflareDNS routing, DDoS protection and Content Delivery Network (CDN)Global / UK / EU
VercelWebsite hosting and serverless/edge functions (EU region)European Union / Global
GlitchTip (self-hosted by Letrix Labs)Error diagnostics for systems under our careUnited Kingdom / EU
1PasswordEncrypted storage of credentials for systems we are authorised to accessEU / United States

Where a project requires a sub-processor not listed here, such as a hosting provider, a third-party API or an email delivery service, it is normally engaged under your own account and your own contract with that provider, in which case it is not our sub-processor. Where that is not possible, we will agree it with you before proceeding.

Contact

For anything relating to this agreement, including audit requests, breach queries and signed copies, email hello@letrixlabs.com.

Dime Corporation Ltd trading as Letrix Labs, company number 13175488, 124 City Road, London, EC1V 2NX, United Kingdom. ICO registration ZC094825.