TerraAqua Legal Centre

Data Processing Addendum

Document IDTA-LC-015
Version1.0
Effective date21 July 2026
Last reviewed21 July 2026
OwnerTerraAqua
ClassificationPublic

Applies to: Business and organisational customers where TerraAqua processes personal data on their behalf

1. Status and purpose

This Data Processing Addendum (“DPA”) forms part of the agreement between TerraAqua and a customer where TerraAqua processes personal data on behalf of that customer as a processor in connection with TerraAqua Cloud or another contracted service.

If TerraAqua determines the purposes and means of processing for its own account, TerraAqua acts as a controller and the Privacy Policy applies instead of, or alongside, this DPA.

2. Definitions

Controller, processor, personal data, processing, personal data breach, data subject and supervisory authority have the meanings given in applicable data-protection law.

Customer means the organisation or person that is controller of Customer Personal Data. Customer Personal Data means personal data processed by TerraAqua on the Customer's behalf.

3. Roles

The Customer is the controller and TerraAqua is the processor for Customer Personal Data described in Annex 1, except where the parties lawfully act in different roles for a specific processing activity.

The Customer is responsible for ensuring that its instructions and use of the services comply with applicable law and that it has a lawful basis for the processing.

4. Documented instructions

TerraAqua will process Customer Personal Data only on the Customer's documented instructions, including instructions in the main agreement, service configuration and written support requests, unless UK law requires otherwise.

If legally permitted, TerraAqua will inform the Customer before processing required by law. TerraAqua will notify the Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law.

5. Confidentiality

TerraAqua will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.

6. Security

Taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and the risk to individuals, TerraAqua will maintain appropriate technical and organisational security measures.

Measures may include access control, authentication, encrypted transport, secure development, logging, monitoring, backups, vulnerability management, incident response and staff confidentiality controls, as appropriate to the service.

7. Sub-processors

The Customer gives TerraAqua general authorisation to use sub-processors needed to provide the services. TerraAqua will impose data-protection obligations on each sub-processor that provide an equivalent level of protection for the relevant processing.

TerraAqua remains responsible to the Customer for the performance of its sub-processors' data-protection obligations as required by law.

TerraAqua will make current sub-processor information available on request or through an appropriate online notice. Where required, TerraAqua will give reasonable notice of a material new sub-processor so the Customer may raise a legitimate data-protection objection.

8. International transfers

TerraAqua will not transfer Customer Personal Data outside the United Kingdom except under a lawful transfer mechanism and with appropriate safeguards where required.

Relevant safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful mechanism.

9. Data-subject requests

Taking account of the nature of processing, TerraAqua will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests from data subjects.

If TerraAqua receives a request relating to Customer Personal Data, it will normally refer the requester to the Customer unless legally required to respond directly.

10. Assistance with compliance

Taking account of the nature of processing and information available, TerraAqua will provide reasonable assistance with:

11. Personal data breaches

TerraAqua will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data.

The notification will include available information reasonably needed for the Customer's legal assessment, which may be provided in phases as the investigation continues.

12. Deletion and return

At the end of the relevant service, TerraAqua will delete or return Customer Personal Data at the Customer's choice where technically reasonably available, unless applicable law requires retention.

Data may remain temporarily in protected backups until overwritten under normal retention cycles, provided it remains protected and is not restored except for recovery or legal necessity.

13. Information and audits

TerraAqua will provide information reasonably necessary to demonstrate compliance with this DPA. The Customer may conduct an audit or appoint an independent auditor where required by law, subject to reasonable notice, confidentiality, security restrictions and measures to avoid unnecessary disruption.

TerraAqua may satisfy routine audit requests through current certifications, independent reports, security documentation and written responses where these provide reasonable assurance.

14. Records and regulatory cooperation

TerraAqua will maintain records required of a processor and cooperate with the competent supervisory authority as required by applicable law.

15. Customer obligations

The Customer will:

16. Liability

Liability under this DPA is subject to the liability provisions in the main agreement, except to the extent such limitation is prohibited by applicable data-protection law.

17. Priority

If this DPA conflicts with the main agreement on the processing of Customer Personal Data, this DPA takes priority for that conflict. Mandatory law takes priority over both.

18. Duration

This DPA remains effective while TerraAqua processes Customer Personal Data on the Customer's behalf.

19. Changes in law

The parties will cooperate in good faith to amend this DPA where reasonably necessary to comply with a material change in applicable data-protection law or binding regulatory requirements.

20. Governing law

This DPA is governed by the governing-law clause in the main agreement. If none applies, it is governed by the laws of England and Wales.

Annex 1 — Processing details

ItemDescription
Subject matterProvision, security, support and administration of TerraAqua Cloud and contracted connected-aquarium services.
DurationFor the term of the service and applicable deletion or backup-retention period.
Nature and purposeHosting, storage, transmission, organisation, retrieval, support, security, diagnostics, account administration and customer-configured monitoring.
Data subjectsCustomer personnel, authorised users, account holders, support contacts and other individuals whose information the Customer submits lawfully.
Personal dataNames, business contact details, account identifiers, permissions, authentication records, controller identifiers, aquarium names, configuration, operational readings linked to an account, support communications, logs and technical metadata.
Special-category dataNot intended or required for ordinary use. The Customer must not submit it unless expressly agreed and lawful.
FrequencyContinuous or as initiated by the Customer, controller, application or authorised user.
Controller rightsTo issue lawful instructions, configure the service, request assistance, receive breach information, obtain compliance information and request deletion or return as provided by this DPA.
Controller obligationsTo ensure lawful basis, transparency, data accuracy, data minimisation, appropriate access and compliance with data-subject rights.

21. Contact

Data-processing enquiries may be sent to info@terra-aqua.co.uk.

Version history

VersionDateDescription
1.021 July 2026Initial commercial release