Data processing agreement (DPA)

Data processing agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions or any other agreement between Adjustable (“Processor”, “we”, “us”, “our”) and the Client (“Controller”, “you”, “your”) relating to the use of the Adjustable accessibility toolbar and related services (“Service”).


This DPA governs our processing of personal data on your behalf in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions or any other agreement between Adjustable (“Processor”, “we”, “us”, “our”) and the Client (“Controller”, “you”, “your”) relating to the use of the Adjustable accessibility toolbar and related services (“Service”).


This DPA governs our processing of personal data on your behalf in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

  1. Definitions

“Controller” means the organisation that determines the purposes and means of processing personal data.

“Processor” means the organisation that processes personal data on behalf of the Controller.

“Personal Data” means any information relating to an identified or identifiable natural person.

“UK GDPR” refers to the UK General Data Protection Regulation.

“Sub-processor” means a third party engaged by the Processor to process personal data on behalf of the Controller.


Terms not defined in this DPA shall have the meanings given in the UK GDPR.

“Controller” means the organisation that determines the purposes and means of processing personal data.

“Processor” means the organisation that processes personal data on behalf of the Controller.

“Personal Data” means any information relating to an identified or identifiable natural person.

“UK GDPR” refers to the UK General Data Protection Regulation.

“Sub-processor” means a third party engaged by the Processor to process personal data on behalf of the Controller.


Terms not defined in this DPA shall have the meanings given in the UK GDPR.

  1. Scope of processing

2.1 The Processor will process Personal Data only as necessary to provide the Service and only on documented instructions from the Controller, unless required to do so by law.


2.2 The processing carried out by Adjustable is limited and primarily relates to:

  • Administrator account data (e.g., name, email, login credentials) for the client dashboard

  • Optional login cookies when “remember me” is chosen

  • IP addresses captured temporarily for page-view logs

  • Support communications initiated by the Controller.


2.3 Personal Data relating to end users of the website using the toolbar is not processed by Adjustable, because:

  • the toolbar uses local storage, not cookies

  • user preferences are stored only in the visitor’s own browser

  • no user-identifiable data is transmitted to Adjustable servers.

2.1 The Processor will process Personal Data only as necessary to provide the Service and only on documented instructions from the Controller, unless required to do so by law.


2.2 The processing carried out by Adjustable is limited and primarily relates to:

  • Administrator account data (e.g., name, email, login credentials) for the client dashboard

  • Optional login cookies when “remember me” is chosen

  • IP addresses captured temporarily for page-view logs

  • Support communications initiated by the Controller.


2.3 Personal Data relating to end users of the website using the toolbar is not processed by Adjustable, because:

  • the toolbar uses local storage, not cookies

  • user preferences are stored only in the visitor’s own browser

  • no user-identifiable data is transmitted to Adjustable servers.

  1. Nature and purpose of processing

Processing is carried out solely for:

  • Delivering the Service

  • Providing account access and security

  • Supporting, maintaining and improving the Service

  • Communicating with the Controller about the Service.


The Processor will never use Personal Data for marketing unless expressly authorised by the Controller.

Processing is carried out solely for:

  • Delivering the Service

  • Providing account access and security

  • Supporting, maintaining and improving the Service

  • Communicating with the Controller about the Service.


The Processor will never use Personal Data for marketing unless expressly authorised by the Controller.

  1. Duration of processing

The Processor will process Personal Data for the duration of the Agreement and will delete or return the data upon termination, unless retention is required by law.

The Processor will process Personal Data for the duration of the Agreement and will delete or return the data upon termination, unless retention is required by law.

  1. Controller responsibilities

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.

  1. Processor obligations

We shall:

  • Process data only on documented instructions

  • Ensure staff with access to Personal Data are bound by confidentiality obligations

  • Implement appropriate technical and organisational security measures

  • Notify the Controller of any data breach without undue delay

  • Assist the Controller with fulfilling data subject rights where applicable

  • Maintain records of processing activities as required by law.

  1. Sub-processors

7.1 The Controller authorises the Processor to use Sub-processors for hosting, infrastructure and operational purposes.


7.2 The Processor will:

  • Use only Sub-processors that implement appropriate data protection measures

  • Enter into written agreements with Sub-processors imposing obligations equivalent to this DPA

  • Remain liable for the actions of Sub-processors.


7.3 A list of current Sub-processors (e.g., hosting providers) will be made available upon request.

7.1 The Controller authorises the Processor to use Sub-processors for hosting, infrastructure and operational purposes.


7.2 The Processor will:

  • Use only Sub-processors that implement appropriate data protection measures

  • Enter into written agreements with Sub-processors imposing obligations equivalent to this DPA

  • Remain liable for the actions of Sub-processors.


7.3 A list of current Sub-processors (e.g., hosting providers) will be made available upon request.

  1. International data transfers

8.1 If Personal Data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses or an adequacy decision.


8.2 Transfers will only occur where necessary for delivering the Service.

8.1 If Personal Data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses or an adequacy decision.


8.2 Transfers will only occur where necessary for delivering the Service.

  1. Data subject rights

Where possible, the Processor will assist the Controller in responding to:

  • Access requests

  • Correction or erasure requests

  • Objections or restrictions

  • Data portability requests.


The Controller remains responsible for verifying the identity of the data subject and determining whether the request is valid.

Where possible, the Processor will assist the Controller in responding to:

  • Access requests

  • Correction or erasure requests

  • Objections or restrictions

  • Data portability requests.


The Controller remains responsible for verifying the identity of the data subject and determining whether the request is valid.

  1. Security measures

We implement reasonable and proportionate technical and organisational security measures, including:

  • Secure hosting environments

  • Encryption in transit

  • Access controls and authentication

  • Monitoring and logging

  • Secure development practices.

A full list of security measures is available upon request.

We implement reasonable and proportionate technical and organisational security measures, including:

  • Secure hosting environments

  • Encryption in transit

  • Access controls and authentication

  • Monitoring and logging

  • Secure development practices.

A full list of security measures is available upon request.

  1. Data breaches

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.

  1. Return or deletion of data

Upon termination of the Service, we will:

  • Delete Personal Data processed on your behalf

  • Retain only what is legally required (e.g., financial records)

  • Provide confirmation of deletion upon request.

  1. Audit rights

The Controller may request:

  • Information necessary to demonstrate compliance with this DPA

  • Confirmation of our security and data protection measures.

The Controller may request:

  • Information necessary to demonstrate compliance with this DPA

  • Confirmation of our security and data protection measures.

  1. Controller responsibilities

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.


Any audits must be:

  • Conducted with reasonable notice

  • Not disruptive to our operations

  • Limited to once per year unless legally required.

The Controller is responsible for:

  • Ensuring it has a lawful basis for processing Personal Data

  • Providing accurate and lawful instructions to the Processor

  • Ensuring its use of the Service complies with the UK GDPR and other relevant laws

  • Ensuring its own website’s privacy policy accurately describes the use of Adjustable.


Any audits must be:

  • Conducted with reasonable notice

  • Not disruptive to our operations

  • Limited to once per year unless legally required.

  1. Liability

Liability under this DPA follows the limitation terms set out in the main Terms & Conditions.

Liability under this DPA follows the limitation terms set out in the main Terms & Conditions.

  1. Governing law

This DPA is governed by the laws of England and Wales. Any disputes shall be resolved in the courts of England and Wales.

This DPA is governed by the laws of England and Wales. Any disputes shall be resolved in the courts of England and Wales.

Company information

Adjustable is a software product provided by webfire Ltd, trading as Adjustable.

Registered company name: webfire Ltd
Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company number: 04923193
VAT number: GB 839 3686 77
Trading name: Adjustable

For billing and contractual purposes, payments will appear as webfire Ltd t/a Adjustable.

Adjustable is a software product provided by webfire Ltd, trading as Adjustable.

Registered company name: webfire Ltd
Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company number: 04923193
VAT number: GB 839 3686 77
Trading name: Adjustable

For billing and contractual purposes, payments will appear as webfire Ltd t/a Adjustable.

Contact us

If you have any questions or concerns about our Data Processing Agreement, please contact us:


Email: info [at] getadjustable [dot] com
Contact us: Contact Adjustable
Address: Adjustable, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

If you have any questions or concerns about our Data Processing Agreement, please contact us:


Email: info [at] getadjustable [dot] com
Contact us: Contact Adjustable
Address: Adjustable, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Effective date

This Statement was last updated on 20th June 2025.

This Statement was last updated on 20th June 2025.

Adjustable logo

© 2026 Adjustable, all rights reserved

Navigate

Platform

Resources

Compare

Terms