Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between ENX Solutions Ltd, a company registered in England and Wales under Company Number 17196500 ("ENX", "Processor"), and the client identified in the applicable proposal or statement of work ("Client", "Controller") for the provision of digital services ("Services"). It applies where, in the course of the Services, ENX processes personal data on behalf of the Client and reflects the parties' obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 ("Data Protection Laws").
Last updated: 4 July 2026
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR. "Sub processor" means any third party engaged by ENX to process personal data on behalf of the Client in connection with the Services.
2. Roles of the parties
The parties acknowledge that, in respect of personal data processed under the Services, the Client is the Controller and ENX is the Processor. Each party will comply with its obligations under Data Protection Laws. Nothing in this DPA relieves the Client of its own obligations as Controller, including providing any required notices and obtaining any required consents from data subjects.
3. Subject matter, nature, purpose and duration
- Subject matter: the personal data processed by ENX to provide the Services described in the applicable proposal or statement of work.
- Nature and purpose of processing: hosting, storage, transmission, configuration, testing, analysis, display, and technical support in connection with websites, automations, AI systems, integrations, advertising and consulting delivered to the Client, and any other processing reasonably necessary to perform the Services.
- Duration: for the term of the engagement and until deletion or return of the personal data in accordance with section 10 of this DPA.
4. Types of personal data and categories of data subjects
Unless the applicable proposal specifies otherwise, the personal data processed by ENX on behalf of the Client may include:
- Contact details (name, email address, phone number, business name, job title, address).
- Account and login information for platforms managed as part of the Services.
- Enquiry, lead and form submission data provided by the Client's website visitors.
- Marketing, analytics and behavioural data (IP address, device identifiers, browser type, pages visited, campaign interactions).
- Transactional data related to the Client's customers where included in files, databases or automations we are asked to work with.
- Any other personal data contained in content, files or systems the Client provides to us.
The categories of data subject may include:
- The Client's employees, contractors and representatives.
- The Client's prospects, leads, customers and end users.
- Visitors to the Client's website or digital properties.
- Any other individuals whose personal data is submitted by or on behalf of the Client during the Services.
The parties do not intend for ENX to routinely process special category or criminal offence data. If any is likely to be processed, the parties will agree additional safeguards in writing beforehand.
5. Processor obligations
ENX will, in respect of personal data processed under this DPA:
- Process the personal data only on the documented instructions of the Client, including as set out in the applicable proposal, statement of work and this DPA, unless required to do otherwise by law, in which case ENX will notify the Client first unless the law prohibits it.
- Ensure that persons authorised to process the personal data are bound by written or statutory duties of confidentiality.
- Implement and maintain the security measures described in section 7.
- Comply with the sub processor requirements in section 6.
- Assist the Client, taking into account the nature of the processing and the information available to ENX, in responding to data subject requests and in complying with the Client's obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), subject to any reasonable fees for such assistance beyond routine support.
- Make available to the Client information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and allow for and contribute to audits as set out in section 11.
- Inform the Client without undue delay if, in ENX's opinion, an instruction infringes Data Protection Laws.
6. Sub processors
The Client provides general authorisation for ENX to engage sub processors for the purposes of providing the Services, including hosting, infrastructure, content delivery, analytics, email delivery, communication tools, project management, file storage, payment processing and AI or automation platforms. On request, ENX will make available a list of the sub processors it uses on the Client's engagement.
ENX will impose data protection obligations on each sub processor that are, in substance, no less protective than those in this DPA, and will remain liable to the Client for the acts and omissions of its sub processors in respect of their processing of the Client's personal data. ENX will inform the Client of any intended addition or replacement of a sub processor that would materially affect the processing of the Client's personal data, giving the Client a reasonable opportunity to object on reasonable data protection grounds. If the parties cannot reasonably resolve such an objection, either party may terminate the relevant Services on written notice.
7. Security measures
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of individuals, ENX will implement appropriate technical and organisational measures to protect personal data. Depending on the Services, these measures include:
- Encryption of personal data in transit using TLS.
- Restricted, role based access to systems and credentials on a need to know basis, with strong passwords and multi factor authentication enabled where available.
- Use of reputable hosting, infrastructure and SaaS providers with recognised security certifications.
- Regular software updates, backups, and separation of production environments from testing.
- Confidentiality obligations for all personnel with access to personal data.
- Deletion or secure return of personal data at the end of an engagement in accordance with section 10.
- Periodic review of processes, risks and provider security posture.
8. International transfers
Where ENX or its sub processors transfer personal data outside the United Kingdom, ENX will ensure that an appropriate transfer mechanism recognised under the UK GDPR is in place, such as an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures required.
9. Personal data breaches
ENX will notify the Client without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting personal data processed under this DPA. That notice will describe, so far as reasonably possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and mitigate its effects, and the contact point for further information. ENX will reasonably cooperate with the Client in investigating and remediating the breach.
10. Return or deletion of personal data
On termination or expiry of the Services, and at the Client's written choice, ENX will delete or return all personal data processed on behalf of the Client and delete any remaining copies, unless retention is required by law. The Client is responsible for exporting any personal data it wishes to retain from third party platforms before those platforms are handed over or decommissioned. Backups containing personal data will be overwritten or expire in accordance with our normal backup retention cycles.
11. Audit rights
ENX will make available to the Client, on reasonable prior written request and no more than once every 12 months (unless required more frequently by a supervisory authority or following a personal data breach), the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR. Where the Client reasonably requires an on site audit, the parties will agree in advance the scope, timing and duration, the auditor (which must be an independent third party subject to appropriate confidentiality obligations and not a competitor of ENX), and any reasonable fees payable by the Client for ENX's time and reasonable costs.
12. Data subject requests
If ENX receives a request from a data subject relating to personal data processed on behalf of the Client, ENX will promptly forward the request to the Client and will not respond directly except on the Client's documented instructions or as required by law.
13. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the main agreement between the parties. Nothing in this DPA excludes or limits liability which cannot lawfully be excluded or limited.
14. Precedence and general
If there is any conflict between this DPA and the main agreement between the parties on any matter of data protection, this DPA takes precedence. All other provisions of the main agreement (including those on governing law and jurisdiction) apply to this DPA. This DPA does not create any rights for any third party.
15. Contact
Questions about this DPA or requests to exercise the Client's rights under it should be sent to stef@enxsolutions.net. See also our Privacy Policy and Terms of Service.