Skip to Content (Press Enter)

Updated: 29th September, 2026

Data Processing Annex

This annex forms part of the Statamic Maintenance Terms and Conditions (the "Terms"). It applies whenever the Service Provider processes personal data on the Client's behalf while providing the Services. Words defined in the Terms have the same meaning here. If this annex and the Terms disagree on how personal data is handled, this annex takes precedence. A plain-English summary is on the Security and Data Handling page.

  1. ROLES

    1. The Client is the controller of the personal data processed by or through the Website. The Service Provider is the Client's processor when it processes that data to provide the Services.

    2. Each party will comply with the UK GDPR and the Data Protection Act 2018 in its own role.

  2. WHAT IS PROCESSED

    1. Purpose: maintaining, updating, monitoring and supporting the Website, as described in the Terms.

    2. Nature: reading server logs and application monitoring data, and accessing the Website's CMS, files and database, and the third-party services it connects to (such as a CRM or email platform), where needed to diagnose or fix an issue or to apply and test an update.

    3. Types of personal data: IP addresses, request details such as the pages requested, browser and time of request, and error and performance data. Where access is needed to carry out the Services, also personal data held in the Website, such as form submissions and CMS user accounts, or in a third-party service the Website sends it to, such as contacts in a CRM or email platform.

    4. Whose data: visitors to the Website, people who submit forms on it or whose details are passed to a connected third-party service, and the Client's CMS users.

    5. The Services do not require access to special category data, such as health information. If the Website holds any, the Client will tell the Service Provider before the Services start.

    6. Duration: for as long as the agreement lasts, and until the data is deleted under section 7.

  3. INSTRUCTIONS AND CONFIDENTIALITY

    1. The Service Provider will process personal data only on the Client's documented instructions. The Terms, this annex and any instructions the Client gives by email are those instructions. The only exception is where the law requires otherwise, in which case the Service Provider will tell the Client first, unless the law prevents it.

    2. The Service Provider will tell the Client if it believes an instruction breaks data protection law.

    3. Anyone the Service Provider allows to process the Client's personal data is bound by a duty of confidentiality.

  4. SECURITY

    1. The Service Provider keeps appropriate technical and organisational measures in place to protect personal data, including:

      1. accessing the Client's systems and connected third-party services only with credentials or access the Client provides, and keeping them secure

      2. using two-factor authentication on accounts used to access the Website and its server, where the service offers it

      3. connecting to the Client's systems only over encrypted connections, such as SSH for server access and HTTPS for the CMS and web-based services

      4. keeping the devices used to provide the Services encrypted, password protected and up to date

      5. keeping any local copy of the Website needed for testing to what the work requires, and deleting it when it is no longer needed

  5. SUB-PROCESSORS

    1. The Client authorises the Service Provider to use the sub-processors listed in section 9.

    2. The Service Provider will tell the Client before adding or replacing a sub-processor that will process the Client's personal data. If the Client objects on reasonable data protection grounds, the parties will look for an alternative in good faith.

    3. Each sub-processor is bound by data protection terms that give at least the same protection as this annex, and the Service Provider remains responsible to the Client for its sub-processors.

    4. Personal data is not transferred outside the UK or the European Economic Area except as described in clause 15.5.2 of the Terms, and then only with appropriate safeguards in place.

    5. Third-party services the Client contracts with directly, such as its hosting provider, CRM or email platform, are the Client's own processors, not the Service Provider's sub-processors. The Service Provider accesses them only with access the Client provides, and only as far as needed to provide the Services.

  6. HELPING THE CLIENT

    1. The Service Provider will help the Client respond to people exercising their data protection rights, such as asking for a copy of their data or for it to be deleted, by finding or removing that data in the Website or in a connected third-party service.

    2. Server logs and monitoring data record the IP address and request details of every visit automatically. Individual entries can't practically be removed or reliably linked to a person, so they are not searched or edited in response to a request. Instead they are deleted automatically after 90 days, the monitoring provider's standard retention, so that problems and security incidents found some time after they happen can still be traced.

    3. The Service Provider will help the Client meet its security, breach notification and data protection impact assessment obligations, as far as they relate to the Services.

    4. The Service Provider will notify the Client of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it, with the information available at the time.

    5. Time spent helping under this section is charged at the rates in clause 4.3 of the Terms, unless the need for help was caused by the Service Provider.

  7. WHEN THE AGREEMENT ENDS

    1. The Website, its data and the third-party services it connects to stay on the Client's own systems and accounts throughout, so there is nothing to return.

    2. When the agreement ends, the Service Provider will delete any copies of the Client's personal data it holds, such as local copies of the Website, unless the law requires it to keep them.

  8. CHECKING COMPLIANCE

    1. The Service Provider will give the Client the information needed to show it is meeting this annex.

    2. The Client, or an auditor it appoints, may carry out a reasonable audit on at least 30 days' notice, no more than once a year unless there has been a personal data breach. The Client pays its own costs, and any time the Service Provider spends is charged at the rates in clause 4.3 of the Terms.

  9. SUB-PROCESSOR LIST

    1. Laravel Holdings Inc. (Laravel Nightwatch): application monitoring. Data: IP addresses, request details, errors and performance data. Location: EU data centres by default, or the US if the Client requests it under clause 15.5.2 of the Terms. Retention: 90 days.