Data processing terms
Last updated 18 September 2026
1. Parties, scope and priority
These terms are between the business customer identified in the accepted service agreement (“you”, the controller) and Craig Malloy, sole trader trading as MonaLisaa, at [BUSINESS-ADDRESS] (“we”, the processor). Our contact for instructions, incidents, requests and complaints is [email protected]. Your contact is the authorised business contact recorded for the service; tell us when it changes.
These terms form part of the service agreement and apply whenever we process personal information on your behalf, including during a free draft or preview. They must be agreed before that processing starts. They continue for as long as we or our subprocessors hold that information. They take priority over conflicting service terms about its processing.
“Data protection law” means the UK GDPR and the Data Protection Act 2018, as amended, and other applicable UK data protection requirements. “Personal information”, “controller”, “processor”, “processing” and “personal data breach” have the meanings given by that law. A subprocessor is another provider we use to process this information on your behalf.
We are separately a controller for our own account administration, billing, required business records and independently determined purposes explained in our Privacy policy. That does not authorise us to reuse visitor enquiries for a new purpose. The actual processing determines each party’s role.
2. What you instruct us to do
| Processing detail | Agreed scope |
|---|---|
| Subject matter and purpose | Build, edit, host and support your website; receive, store, display and attempt delivery of enquiries for your business; protect and maintain those services |
| People concerned | Your site visitors and enquirers; your staff, representatives, reviewers and other people whose information you lawfully supply as website content |
| Information | Names, business/contact details, photos and other supplied site content; generation/edit inputs and outputs containing personal information; enquiry name, email, phone and message; site identifiers, timestamps and verification/delivery records; technical information needed for the instructed service |
| Operations | Collection, recording, organisation, storage, retrieval, generation/transformation of website content, public display of approved site content, private display/delivery of enquiries, correction, restriction, return and deletion |
| Duration | For the requested service and its agreed retention periods, followed by return/deletion under section 9. Enquiry rows follow the 30-day rule in section 3 |
| Sensitive information | The ordinary service is not intended for special-category data, criminal-offence records, children’s case records or other sensitive records. Do not instruct their collection or include them deliberately without a separate written assessment and agreement. Unexpected sensitive information is still protected by these terms; tell us so we can limit and address it |
Your documented instructions are these terms, your agreed order, settings and publication/edit instructions, and further instructions we agree in a recordable form, including email. Publication instructions cover personal information in website content; they do not instruct public disclosure of private enquiries.
You determine lawful purposes and bases, provide required information to people, and ensure your instructions and supplied content are lawful. You have the rights of instruction, information, objection to subprocessor changes, assistance, audit and return/deletion set out here. We retain our own legal duties as processor.
We will act only on your documented instructions, including for international transfers, unless UK law requires otherwise. If legally required to process outside those instructions, we will tell you before doing so unless that law prohibits notice on important public-interest grounds. If we believe an instruction infringes data protection law, we will inform you immediately and pause the affected instruction while it is resolved. We will explain if a requested change is outside the agreed service; we will not silently replace it with another purpose.
We will not sell customer-controlled personal information, use private enquiries for our own advertising, or use that information to train our own general-purpose AI models. Any AI provider processing must stay within the authorised service and its binding data protection arrangements; these terms do not assert a provider’s unverified training or retention setting.
3. Current enquiry and content handling
You instruct us to receive and store the standard enquiry fields and attempt to email them using Resend. The recipient is currently the email in your website’s business details, not a separately verified recipient setting. You must supply an authorised destination and notify us of errors; we remain responsible for the security of our processing.
The system may store complete submissions which fail bot verification and may accept unverified submissions where the verification service is unavailable or not configured. It records verification and delivery state. A successful submission response does not guarantee email delivery or receipt. These arrangements do not relieve either party of data minimisation and security obligations. If they do not meet your lawful requirements, do not enable real enquiries; contact us to agree suitable handling.
Enquiry database rows become eligible for automatic deletion once more than 30 days old. The application runs its cleanup at startup and then approximately hourly while running; interruptions can delay deletion. We will investigate cleanup failures and restore the agreed deletion process. The row cleanup does not itself erase mail, backups or provider logs. Provider-held copies remain subject to our obligations and the retention limits disclosed here; copies in your own mailbox are your responsibility.
Personal information you instruct us to publish in a site is publicly accessible. Upload URLs may be accessible without signing in before publication, and preview links can be shared. Do not supply confidential files for these paths. This is not permission for us to make private enquiry content public.
We follow your documented retention instructions for customer-controlled information, subject to applicable law and the limits disclosed here. The enquiry-row cleanup described above is implemented. There is no automatic 90-day cleanup of drafts/uploads or account/site deletion 90 days after closure. Provider email and log retention is not established by that enquiry rule. Agree necessary handling with us before supplying information that requires a deletion schedule the service cannot currently enforce; this disclosure does not permit indefinite retention or displace our legal duties.
4. Confidentiality and security
We will ensure that everyone we authorise to handle your personal information is bound by confidentiality obligations or an appropriate statutory duty, and only has access necessary for their work.
We will implement appropriate technical and organisational measures required by Article 32 of the UK GDPR, taking account of the nature of the information, risks, available technology and implementation costs. These include measures appropriate to protect confidentiality, integrity, availability and resilience, recover access after an incident and test whether the safeguards work.
The source implements these controls:
- SHA-256 hashes of sign-in and session secrets in database records; single-use sign-in links; expiry checks; Secure, HttpOnly and SameSite=Lax session cookies.
- Account ownership checks when listing or deleting private enquiry rows.
- Input validation and Turnstile checks when enabled and configured. Failed or unavailable verification is handled as disclosed in section 3; Turnstile is not a universal fail-closed guarantee.
- HTTPS endpoints for external API calls and published Workers URLs. The app sends HSTS, content-type, referrer, framing and permissions headers. These headers do not establish encryption at rest or a complete content security policy.
- A database site-storage activation gate seeded off. This is separate from the existing enquiry and account database. Custom enquiry fields are not implemented in this checkout; the current form uses the fixed fields in section 2.
Uploads and shareable previews have the public-access limits in section 3. Non-local database connections request TLS but the current client disables certificate verification; this is not verified end-to-end database server authentication. Provider encryption at rest, privileged access procedures and deployment settings are not established by these source controls.
We do not currently operate an independent backup, and there is no tested restore. Primary file storage on the Railway volume is not an independent backup. We cannot promise recovery of lost database records, content or uploads from a tested backup. This is a current availability and recovery risk, not a security certification. The duties above still apply; this disclosure does not establish that the present measures meet every processing risk.
5. Other providers and transfers
You give general written authorisation to use the subprocessors identified in the completed Schedule A for the stated work. This does not authorise an unidentified supplier or unrelated processing. Before appointment we will assess the provider’s ability to protect the information and put a binding agreement in place imposing the relevant data protection obligations. We remain responsible to you for a subprocessor’s performance of those obligations.
We will give you at least 30 days’ written notice of an intended addition or replacement, explaining its identity, work, locations and safeguards. You may object on reasonable data protection grounds before it starts processing. We will discuss a suitable alternative or safeguard. If we cannot resolve the objection, you may end the affected service before the new processing starts, with a refund of prepaid fees for the affected service we will not supply. An emergency does not remove the need for lawful authorisation; if necessary, we will suspend the affected processing while arranging an authorised solution.
We will not make a restricted international transfer without your documented instructions and an applicable UK transfer basis. Schedule A must identify locations and the actual adequacy basis or other safeguards, together with any required transfer assessment and supplementary protections. We will provide information or copies of safeguards on request, subject to proportionate protection of confidential details. These terms are not themselves an international transfer agreement.
6. Helping with rights and compliance
Taking account of the processing, we will use appropriate technical and organisational measures to help you respond to people exercising their rights, including access, correction, erasure, restriction, objection and portability. We will forward a request concerning your information to your authorised contact without undue delay and will not decide it for you unless instructed or legally required. We may give the person your contact details and acknowledge receipt.
We will provide relevant information and practical assistance in time for applicable deadlines, taking account of the nature of the processing and information available to us. This includes assistance with security, breach assessments and notifications, data protection impact assessments and prior consultation with the ICO where required under Articles 32–36. Tell us promptly about your deadline and the information needed. We may verify an instruction’s authority before disclosing private records.
Routine assistance under these terms is included in the service. Any charge for exceptional additional work must be reasonable and agreed beforehand; a fee dispute must not prevent assistance required by law or delay urgent incident handling.
7. Personal data breaches
We will notify your authorised contact without undue delay after becoming aware of a personal data breach affecting information processed for you. We will not wait until every fact is known or treat 72 hours as an allowance to delay notifying you.
As information becomes available, we will explain what happened, the categories and approximate numbers of affected people and records where possible, likely consequences, action taken or proposed, and a contact for follow-up. We will provide updates, preserve relevant evidence, help contain and remedy the breach and assist your assessment and notifications. You remain responsible for your controller decisions about reporting to the ICO and notifying affected people; we retain any separate duties that apply to us.
8. Evidence and audits
We will make available the information you reasonably need to demonstrate compliance with these terms and Article 28. We will allow and contribute to audits and inspections by you or an auditor you appoint.
We may agree proportionate arrangements on notice, confidentiality, security and timing, protecting other customers’ information and avoiding unnecessary disruption. Those arrangements must not prevent an effective audit, urgent investigation or regulator access. Existing reports may answer some questions but are not an absolute substitute for your audit rights. We will address established shortcomings without undue delay.
9. Return and deletion
At the end of the processing service, you may choose return or deletion of the personal information we still hold for you. You may give that instruction before the service ends. Return will use a commonly usable electronic format through a secure, authorised route. Routine deletion under the agreed schedule continues during the service; information already lawfully deleted cannot be returned.
The intended subscription arrangement is for the site to remain hosted to the end of the paid period and then come down; automatic hosting cessation is not implemented. That commercial end date is not a personal-data return or deletion deadline. Send your choice to [email protected]; we must agree a secure return route and completion schedule before relying on this exit process. No automated full-service export/deletion process or default deletion deadline after silence is currently implemented. Normal enquiry expiry continues in the meantime.
After return, or on your choice of deletion, we will securely delete existing copies, including by instructing our subprocessors, unless UK law requires storage. If retention is legally required, we will identify the requirement where permitted, restrict access and use to that requirement and delete when it ends.
We do not currently operate an independent backup, and there is no tested restore. Provider-held copies may persist for a period set by the provider. Deletion from our database does not guarantee removal from provider copies. We cannot state a verified expiry or final deletion deadline for those copies. We must establish the available provider deletion/restriction arrangements before representing this exit process as complete. We will take the steps required by law concerning public copies and confirm the scope and limits of completed return/deletion on request.
Schedule A — authorised providers
The following is the source-derived service inventory. The actual contracting entities, processing/support countries, executed processing terms, retention and UK transfer safeguards remain unverified. This schedule is not complete for use as a processing agreement until those facts are recorded; integration with a brand does not prove contractual authorisation.
| Service to verify | Information/work | Role boundary to record |
|---|---|---|
| Railway — application, PostgreSQL and primary filesystem volume | Site content, uploads, enquiry rows and operational records | Repository deployment records identify Railway and the /data volume; no independent backup, object bucket or UK-only region is established |
| Resend | Full enquiry alert, visitor reply-to address, recipient and delivery information | Subprocessor for instructed enquiry delivery; separate controller-side sign-in email is outside this customer schedule |
| Cloudflare | Workers and Workers Static Assets for published content and HTTPS delivery, relevant Turnstile processing, and analytics only if a site token is configured | Record the role for each service and any separate provider purposes |
| OpenAI | Customer-controlled personal information in generation prompts, copy and editing/site-summary inputs or outputs | Subprocessor to the extent it processes for this instructed service; verify contract, retention and settings. No routine visitor-enquiry feed to the AI is authorised |
| Google Gmail — the [email protected] support mailbox, if used for customer-controlled information | Instructions and necessary incident/support material | Check that the actual Gmail/account arrangement supplies required processor protection; do not casually forward raw enquiries to it |
| Other services | No additional processor integration was identified in the inspected application/generator source | This does not verify provider onward subprocessors or tools used outside the repo; these must be reconciled with the actual accounts before processing |
Stripe’s work for our own billing and a registrar’s independent registration duties are not automatically processing on your behalf under this schedule. Their actual roles and disclosures must be assessed separately. Likewise, direct browser requests to Google Fonts require transparent information and a role assessment; adding a name to a subprocessor table cannot change its legal role.