Data Processing Addendum

For business customers processing personal data through Locker.

Effective Date: 21 January 2026

This Data Processing Addendum (the "DPA") forms part of the agreement between Locker and the business customer ("Customer") and applies to the extent Locker processes Customer Personal Data as a processor on Customer's behalf.

1. Definitions

  • "Applicable Data Protection Law" means UK GDPR and the Data Protection Act 2018, and where applicable the EU GDPR.
  • "Customer Personal Data" means personal data processed by Locker on behalf of Customer in connection with the Services.
  • "Processing", "Controller", "Processor", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.
  • "Subprocessor" means a third party engaged by Locker to process Customer Personal Data.

2. Roles

Customer is the Controller (or other responsible party) of Customer Personal Data. Locker acts as Processor when processing Customer Personal Data to provide the Services.

3. Scope of Processing; Instructions

Locker shall process Customer Personal Data only on documented instructions from Customer, including as necessary to provide the Services, maintain security, provide support, perform billing operations, and deliver optional AI features when used by Customer Users.

4. Confidentiality

Locker shall ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.

5. Security

Locker shall implement appropriate technical and organisational measures to protect Customer Personal Data as described in Appendix C.

6. Subprocessing

Customer grants Locker a general authorisation to appoint Subprocessors listed in Appendix B. Locker shall:

  1. enter into a written agreement with each Subprocessor imposing obligations no less protective than this DPA; and
  2. remain responsible for Subprocessor performance of its data protection obligations.

6.1 Changes

Locker will provide notice of material changes to Subprocessors. Customer may object on reasonable data protection grounds within fourteen (14) days. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services.

7. International Transfers

Where Customer Personal Data is transferred outside the UK/EEA in a manner requiring safeguards, Locker shall implement appropriate transfer mechanisms (including UK IDTA/UK Addendum and/or EU SCCs, as applicable).

8. Assistance with Data Subject Rights

Taking into account the nature of the processing, Locker shall provide reasonable assistance to enable Customer to respond to data subject requests.

9. DPIAs and Consultation

Locker shall provide reasonable assistance to Customer in relation to DPIAs and prior consultation, where required by Applicable Data Protection Law, to the extent the information is available to Locker.

10. Personal Data Breaches

Locker shall notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data and provide information reasonably necessary to assist Customer with its notification and remediation obligations.

11. Deletion or Return

Upon termination of the Services or written request, Locker shall delete or return Customer Personal Data within a reasonable timeframe, except to the extent retention is required by law or necessary for limited security/compliance purposes.

12. Audits

Locker shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to once per year on at least thirty (30) days' notice, subject to reasonable confidentiality, security, and scope controls. Where reasonable, Locker's security documentation may satisfy audit requests.


Appendix A: Details of Processing

  • Subject matter: provision of hosted storage, collaboration, sharing, messaging, and related functionality.
  • Duration: for the term of the Customer's agreement and until deletion/return per Section 11.
  • Categories of data subjects: Customer Users and collaborators; individuals referenced within Content.
  • Categories of personal data: identifiers, communications, metadata, usage/technical logs, support content.
  • Special category data: not intended.

Appendix B: Subprocessors

Squarespace; Supabase; Render; Stripe; Sentry; OpenAI (when AI features are used).

See our Subprocessor List for current details.

Appendix C: Security Measures

  • Encryption in transit and at rest
  • Password hashing
  • Access controls designed to prevent cross-user access
  • Restricted and logged administrative access

See our Security page for additional details.


© Red Hammer Limited 2026. All rights reserved.