Data Processing Addendum (DPA)
Digily Link · Data processing agreement
Data Processing Addendum (DPA)
This addendum governs how Digily Link processes, on the customer's behalf, the personal data a Digily Link user collects from visitors to their own profile.
Role split: the profile owner is the controller of the visitor data collected through their own forms, appointment blocks and subscription components; Dijital Mekan Ltd is a processor only to the extent it hosts or transmits that data on the profile owner's documented instructions. Processing that Dijital Mekan Ltd carries out for accounts, security, invoicing and its own legal obligations is covered by the UK GDPR & Data Protection Notice, not by this addendum.
1. Parties and acceptance
Controller / Customer: the natural or legal person who uses a Digily Link account for their professional, commercial, organizational or content activity and decides which data is collected from profile visitors and for what purpose.
Processor: Dijital Mekan Ltd, registered in England and Wales, company number 14955219, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom; support@digily.link ("Digily Link").
This addendum forms part of the agreement for Customers who accept the Terms and Conditions during registration through an unticked acceptance box, and for Customers who otherwise expressly accept it. If the Customer has a separately signed data processing agreement with Dijital Mekan Ltd, that specific agreement prevails where the two conflict.
2. Subject matter, duration and purpose
| Element | Scope |
|---|---|
| Subject matter | Receiving, hosting, displaying and delivering to the Customer the records created through in-profile contact, appointment, email or phone collection and similar form components; keeping them secure; and deleting them on the Customer's instruction. |
| Duration | The period during which the Customer uses the relevant feature and account, plus the time needed to complete deletion or return. Separate platform records subject to statutory retention are out of scope. |
| Data subjects | People who visit the Customer's Digily Link profile and submit information through a form, appointment or subscription component; where relevant, the Customer's staff or authorized contacts. |
| Data types | Depending on the fields the Customer chose: name, email, phone, message, appointment date and time, form answers; plus IP address, timestamp, browser and device, and security records. |
| Processing operations | Collection, storage, organization, display, delivery to the Customer, security checks, access in the course of support, export, and erasure or destruction. |
3. Instructions and lawfulness
- Digily Link processes the data only within this addendum, the platform settings, support requests and the Customer's lawful written or electronic instructions. If Digily Link considers an instruction to breach applicable law, it informs the Customer unless prohibited from doing so and may suspend the instruction.
- The Customer is responsible for the controller obligations, including privacy information, lawful basis or consent, data minimization, retention periods, data subject requests, and the rules on children's and special category data.
- The Customer only adds form fields that are necessary for the stated purpose. The Customer does not collect health, biometric, political, religious, criminal conviction or other special category data without an appropriate Article 9 condition and additional safeguards, and never asks visitors for payment card details, passwords or access keys.
- If the Customer wants to use visitor data for advertising, bulk messaging or any purpose different from the one it was collected for, the Customer sets up the required information and consent processes separately.
4. Digily Link's obligations
- ensure that only people who need the data for their role, and who are bound by confidentiality, can access it;
- apply access control, password security, transport security, logging, abuse prevention and incident response measures proportionate to the risk;
- give the Customer reasonable assistance with data subject requests, personal data breach assessments, data protection impact assessments and requests from competent authorities;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, including the available details and the measures taken or proposed;
- not use the Customer's data for its own independent advertising or profiling purposes, unless disclosure is directly required by law;
- answer the Customer's reasonable compliance questions with the necessary information and documents, within the limits of confidentiality and security.
5. Sub-processors and integrations
The Customer gives general authorization for the following categories of sub-processors to be used in delivering the service. Digily Link imposes data protection obligations consistent with this addendum on each sub-processor and remains responsible, to the extent required by law, for the sub-processor's performance.
- Hosting and infrastructure providers: the servers, storage and backups on which the platform runs;
- Cloudflare: traffic and device records within the scope of CDN, WAF and DDoS protection and Turnstile security;
- Email delivery providers: where the Customer enables email notifications, the message, form content and delivery data needed to send form and appointment records to the Customer's email address;
- Integrations chosen by the Customer: where the Customer expressly links or redirects to Google Forms, Typeform, Calendly, PayPal or another external service, the relevant data may go directly to that provider. Assessing the necessary agreements and lawful basis for that provider is the Customer's responsibility.
Platform analytics and advertising technologies are not used to process the Customer's form records in the ordinary course. Non-essential measurement or campaign scripts on profile and form pages must remain blocked until the visitor has given the relevant preference and must be configured so that they do not read form field values. If the Customer chooses to enter or send form data into an external tool, evaluating the recipient, transfer, transparency and lawful basis for that new processing is the Customer's responsibility.
If Digily Link adds a new sub-processor that will process Customer data, or materially changes a sub-processor's role, it gives reasonable advance notice. The Customer may raise a specific, justified data protection objection, and the parties will look for a reasonable solution. If none is found, the affected feature may be discontinued.
6. International transfers
Where Cloudflare, an email delivery provider or an integration chosen by the Customer processes data outside the United Kingdom, the transfer relies on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or another safeguard permitted under the UK GDPR. The Customer explains to their own visitors the recipient, country, purpose and scope of any foreign integration the Customer adds on their own instruction. The safeguards used for the standard platform infrastructure are described in the Privacy Notice.
7. Data subject requests
A visitor to the Customer's profile applies to the Customer first. If a request reaches Digily Link directly, it is forwarded to the Customer unless the law requires a direct answer. The Customer can view records in the dashboard, delete them individually or in bulk, and export them as Excel or CSV. For reasonable access or rectification operations beyond that, Digily Link provides support proportionate to the request. The legal assessment of the request and answering it in time remain the Customer's responsibility.
8. Return, deletion and account closure
The Customer can delete the relevant records from the dashboard at any time; records are kept until the Customer deletes them or the account is closed. When account deletion completes, the form and appointment records linked to the account, profiles and content are removed from the active systems. Copies held in short-term rolling backups are kept apart from ordinary use, exist only for disaster recovery for a limited period, and are then overwritten or deleted in rotation; if a backup is restored, earlier deletions are applied again. Records that the law imposes directly on Digily Link for security, evidence or official requests may be kept separately, limited to the mandatory scope and period.
When the service ends, the Customer is responsible for exporting their own records before closure and accepts that records may be unrecoverable after deletion.
9. Information and audits
Digily Link provides the information and available audit or security summaries reasonably necessary to demonstrate compliance with this addendum. On-site audits are carried out on these conditions: a document review takes place first, at least 30 days' notice is given, audits are limited to once per year, and the confidentiality of other customers and the security of the systems are preserved; binding requests from authorities and verified serious breaches remain reserved. Extraordinary costs specific to the Customer's audit may be passed on to the Customer by prior agreement.
10. Liability, term and precedence
This addendum applies for the life of the account or feature; the confidentiality, security, deletion and audit provisions survive the end of processing by their nature. The parties' liability is subject to mandatory law and the limits in the Terms and Conditions. If this addendum and the general terms conflict on the processing of personal data on the Customer's behalf, this addendum prevails.
Contact: support@digily.link · Dijital Mekan Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.