Data processing agreement (DPA)
Data processing agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions or any other agreement between Adjustable (“Processor”, “we”, “us”, “our”) and the Client (“Controller”, “you”, “your”) relating to the use of the Adjustable accessibility toolbar and related services (“Service”).
This DPA governs our processing of personal data on your behalf in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions or any other agreement between Adjustable (“Processor”, “we”, “us”, “our”) and the Client (“Controller”, “you”, “your”) relating to the use of the Adjustable accessibility toolbar and related services (“Service”).
This DPA governs our processing of personal data on your behalf in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
Definitions
“Controller” means the organization that determines the purposes and means of processing personal data.
“Processor” means the organization that processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable natural person.
“UK GDPR” refers to the UK General Data Protection Regulation.
“Sub-processor” means a third party engaged by the Processor to process personal data on behalf of the Controller.
Terms not defined in this DPA shall have the meanings given in the UK GDPR.
“Controller” means the organization that determines the purposes and means of processing personal data.
“Processor” means the organization that processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable natural person.
“UK GDPR” refers to the UK General Data Protection Regulation.
“Sub-processor” means a third party engaged by the Processor to process personal data on behalf of the Controller.
Terms not defined in this DPA shall have the meanings given in the UK GDPR.
Scope of processing
2.1 The Processor will process Personal Data only as necessary to provide the Service and only on documented instructions from the Controller, unless required to do so by law.
2.2 The processing carried out by Adjustable is limited and primarily relates to:
Administrator account data (e.g., name, email, login credentials) for the client dashboard
Optional login cookies when “remember me” is chosen
IP addresses captured temporarily for page-view logs
Support communications initiated by the Controller.
2.3 Personal Data relating to end users of the website using the toolbar is not processed by Adjustable, because:
the toolbar uses local storage, not cookies
user preferences are stored only in the visitor’s own browser
no user-identifiable data is transmitted to Adjustable servers.
2.1 The Processor will process Personal Data only as necessary to provide the Service and only on documented instructions from the Controller, unless required to do so by law.
2.2 The processing carried out by Adjustable is limited and primarily relates to:
Administrator account data (e.g., name, email, login credentials) for the client dashboard
Optional login cookies when “remember me” is chosen
IP addresses captured temporarily for page-view logs
Support communications initiated by the Controller.
2.3 Personal Data relating to end users of the website using the toolbar is not processed by Adjustable, because:
the toolbar uses local storage, not cookies
user preferences are stored only in the visitor’s own browser
no user-identifiable data is transmitted to Adjustable servers.
Nature and purpose of processing
Processing is carried out solely for:
Delivering the Service
Providing account access and security
Supporting, maintaining and improving the Service
Communicating with the Controller about the Service.
The Processor will never use Personal Data for marketing unless expressly authorized by the Controller.
Processing is carried out solely for:
Delivering the Service
Providing account access and security
Supporting, maintaining and improving the Service
Communicating with the Controller about the Service.
The Processor will never use Personal Data for marketing unless expressly authorized by the Controller.
Duration of processing
The Processor will process Personal Data for the duration of the Agreement and will delete or return the data upon termination, unless retention is required by law.
The Processor will process Personal Data for the duration of the Agreement and will delete or return the data upon termination, unless retention is required by law.
Controller responsibilities
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
Processor obligations
We shall:
Process data only on documented instructions
Ensure staff with access to Personal Data are bound by confidentiality obligations
Implement appropriate technical and organizational security measures
Notify the Controller of any data breach without undue delay
Assist the Controller with fulfilling data subject rights where applicable
Maintain records of processing activities as required by law.
Sub-processors
7.1 The Controller authorizes the Processor to use Sub-processors for hosting, infrastructure and operational purposes.
7.2 The Processor will:
Use only Sub-processors that implement appropriate data protection measures
Enter into written agreements with Sub-processors imposing obligations equivalent to this DPA
Remain liable for the actions of Sub-processors.
7.3 A list of current Sub-processors (e.g., hosting providers) will be made available upon request.
7.1 The Controller authorizes the Processor to use Sub-processors for hosting, infrastructure and operational purposes.
7.2 The Processor will:
Use only Sub-processors that implement appropriate data protection measures
Enter into written agreements with Sub-processors imposing obligations equivalent to this DPA
Remain liable for the actions of Sub-processors.
7.3 A list of current Sub-processors (e.g., hosting providers) will be made available upon request.
International data transfers
8.1 If Personal Data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses or an adequacy decision.
8.2 Transfers will only occur where necessary for delivering the Service.
8.1 If Personal Data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses or an adequacy decision.
8.2 Transfers will only occur where necessary for delivering the Service.
Data subject rights
Where possible, the Processor will assist the Controller in responding to:
Access requests
Correction or erasure requests
Objections or restrictions
Data portability requests.
The Controller remains responsible for verifying the identity of the data subject and determining whether the request is valid.
Where possible, the Processor will assist the Controller in responding to:
Access requests
Correction or erasure requests
Objections or restrictions
Data portability requests.
The Controller remains responsible for verifying the identity of the data subject and determining whether the request is valid.
Security measures
We implement reasonable and proportionate technical and organizational security measures, including:
Secure hosting environments
Encryption in transit
Access controls and authentication
Monitoring and logging
Secure development practices.
A full list of security measures is available upon request.
We implement reasonable and proportionate technical and organizational security measures, including:
Secure hosting environments
Encryption in transit
Access controls and authentication
Monitoring and logging
Secure development practices.
A full list of security measures is available upon request.
Data breaches
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
Return or deletion of data
Upon termination of the Service, we will:
Delete Personal Data processed on your behalf
Retain only what is legally required (e.g., financial records)
Provide confirmation of deletion upon request.
Audit rights
The Controller may request:
Information necessary to demonstrate compliance with this DPA
Confirmation of our security and data protection measures.
The Controller may request:
Information necessary to demonstrate compliance with this DPA
Confirmation of our security and data protection measures.
Controller responsibilities
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
Any audits must be:
Conducted with reasonable notice
Not disruptive to our operations
Limited to once per year unless legally required.
The Controller is responsible for:
Ensuring it has a lawful basis for processing Personal Data
Providing accurate and lawful instructions to the Processor
Ensuring its use of the Service complies with the UK GDPR and other relevant laws
Ensuring its own website’s privacy policy accurately describes the use of Adjustable.
Any audits must be:
Conducted with reasonable notice
Not disruptive to our operations
Limited to once per year unless legally required.
Liability
Liability under this DPA follows the limitation terms set out in the main Terms & Conditions.
Liability under this DPA follows the limitation terms set out in the main Terms & Conditions.
Governing law
This DPA is governed by the laws of England and Wales. Any disputes shall be resolved in the courts of England and Wales.
This DPA is governed by the laws of England and Wales. Any disputes shall be resolved in the courts of England and Wales.
Company information
Adjustable is a software product provided by webfire Ltd, trading as Adjustable.
Registered company name: webfire Ltd
Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company number: 04923193
VAT number: GB 839 3686 77
Trading name: Adjustable
For billing and contractual purposes, payments will appear as webfire Ltd t/a Adjustable.
Adjustable is a software product provided by webfire Ltd, trading as Adjustable.
Registered company name: webfire Ltd
Registered office address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company number: 04923193
VAT number: GB 839 3686 77
Trading name: Adjustable
For billing and contractual purposes, payments will appear as webfire Ltd t/a Adjustable.
Contact us
If you have any questions or concerns about our Data Processing Agreement, please contact us:
Email: info [at] getadjustable [dot] com
Contact us: Contact Adjustable
Address: Adjustable, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
If you have any questions or concerns about our Data Processing Agreement, please contact us:
Email: info [at] getadjustable [dot] com
Contact us: Contact Adjustable
Address: Adjustable, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Effective date
This Statement was last updated on 20th June 2025.
This Statement was last updated on 20th June 2025.