Data processing addendum

Our data processing addendum, in plain English.

Version 1.1 · Last updated 23 September 2026

In short: when we handle personal data on your behalf during an engagement, we act as your processor. This addendum forms part of your engagement letter and sets out what we will and will not do with that data under Article 28 of the UK GDPR.

This Data Processing Addendum forms part of the engagement letter between you (the controller) and Unavoidable Studio Ltd, trading as Unavoidably Secure (the processor). It applies to full audit, standards readiness and ongoing assurance engagements, and to any other work where we process personal data on your behalf. If your engagement could involve health or care records, the extra terms in our healthcare data agreement also apply.

1. Scope of processing

Subject matter
Compliance and web risk auditing, including documentation review, evidence collection, remediation planning and re-testing.
Duration
The term of the engagement, plus the retention period in our privacy notice.
Nature and purpose
Analysing publicly visible technical information and the documents you give us, to find security and compliance gaps against the standards that apply to your organisation.
Types of personal data
Contact details of your staff (name, work email, work phone), and personal data that happens to appear in documents you give us. We do not need special category or health data. If any is shared by mistake, we will redact it or return it on request.
Data subjects
Your staff and contractors, and occasionally people named in documents you share with us.

2. Our obligations as processor

We will:

3. Sub-processors

We will tell you at least 30 days before we add or replace a sub-processor. You may object, and if we cannot resolve your objection reasonably, you may end the engagement.

4. International transfers

Where personal data is transferred outside the UK, we rely on a lawful safeguard, such as the UK-US data bridge for certified organisations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

5. Requests from individuals

We will pass on any request we receive about your data within 5 working days, and help you respond within the time the law allows.

6. Breach notification

If we become aware of a personal data breach affecting your data, we will tell you within 48 hours, including the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose to take.

7. Return or deletion

When the engagement ends, and at your choice, within 30 days we will either return all personal data we hold for you in a common machine-readable format, or delete it securely and confirm the deletion in writing. Where the law requires us to keep audit records or engagement details, for example to defend a claim, we keep the minimum necessary for the shortest necessary time, and it stays protected under this addendum.

8. Audits

With at least 30 days' notice, you may audit our compliance with this addendum. Audits must not disrupt our operations or those of other clients. We will make available our current security documentation and audit log summaries.

Annex A. Security measures

Contact

Questions about this addendum: support@unavoidablysecure.com.