Effective Date: 21 January 2026
This Data Processing Addendum (the "DPA") forms part of the agreement between Locker and the business customer ("Customer") and applies to the extent Locker processes Customer Personal Data as a processor on Customer's behalf.
1. Definitions
- "Applicable Data Protection Law" means UK GDPR and the Data Protection Act 2018, and where applicable the EU GDPR.
- "Customer Personal Data" means personal data processed by Locker on behalf of Customer in connection with the Services.
- "Processing", "Controller", "Processor", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.
- "Subprocessor" means a third party engaged by Locker to process Customer Personal Data.
2. Roles
Customer is the Controller (or other responsible party) of Customer Personal Data. Locker acts as Processor when processing Customer Personal Data to provide the Services.
3. Scope of Processing; Instructions
Locker shall process Customer Personal Data only on documented instructions from Customer, including as necessary to provide the Services, maintain security, provide support, perform billing operations, and deliver optional AI features when used by Customer Users.
4. Confidentiality
Locker shall ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security
Locker shall implement appropriate technical and organisational measures to protect Customer Personal Data as described in Appendix C.
6. Subprocessing
Customer grants Locker a general authorisation to appoint Subprocessors listed in Appendix B. Locker shall:
- enter into a written agreement with each Subprocessor imposing obligations no less protective than this DPA; and
- remain responsible for Subprocessor performance of its data protection obligations.
6.1 Changes
Locker will provide notice of material changes to Subprocessors. Customer may object on reasonable data protection grounds within fourteen (14) days. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services.
7. International Transfers
Where Customer Personal Data is transferred outside the UK/EEA in a manner requiring safeguards, Locker shall implement appropriate transfer mechanisms (including UK IDTA/UK Addendum and/or EU SCCs, as applicable).
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, Locker shall provide reasonable assistance to enable Customer to respond to data subject requests.
9. DPIAs and Consultation
Locker shall provide reasonable assistance to Customer in relation to DPIAs and prior consultation, where required by Applicable Data Protection Law, to the extent the information is available to Locker.
10. Personal Data Breaches
Locker shall notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data and provide information reasonably necessary to assist Customer with its notification and remediation obligations.
11. Deletion or Return
Upon termination of the Services or written request, Locker shall delete or return Customer Personal Data within a reasonable timeframe, except to the extent retention is required by law or necessary for limited security/compliance purposes.
12. Audits
Locker shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to once per year on at least thirty (30) days' notice, subject to reasonable confidentiality, security, and scope controls. Where reasonable, Locker's security documentation may satisfy audit requests.
Appendix A: Details of Processing
- Subject matter: provision of hosted storage, collaboration, sharing, messaging, and related functionality.
- Duration: for the term of the Customer's agreement and until deletion/return per Section 11.
- Categories of data subjects: Customer Users and collaborators; individuals referenced within Content.
- Categories of personal data: identifiers, communications, metadata, usage/technical logs, support content.
- Special category data: not intended.
Appendix B: Subprocessors
Squarespace; Supabase; Render; Stripe; Sentry; OpenAI (when AI features are used).
See our Subprocessor List for current details.
Appendix C: Security Measures
- Encryption in transit and at rest
- Password hashing
- Access controls designed to prevent cross-user access
- Restricted and logged administrative access
See our Security page for additional details.
© Red Hammer Limited 2026. All rights reserved.