Data Processing Addendum
Applies to: Business and organisational customers where TerraAqua processes personal data on their behalf
1. Status and purpose
This Data Processing Addendum (“DPA”) forms part of the agreement between TerraAqua and a customer where TerraAqua processes personal data on behalf of that customer as a processor in connection with TerraAqua Cloud or another contracted service.
If TerraAqua determines the purposes and means of processing for its own account, TerraAqua acts as a controller and the Privacy Policy applies instead of, or alongside, this DPA.
2. Definitions
Controller, processor, personal data, processing, personal data breach, data subject and supervisory authority have the meanings given in applicable data-protection law.
Customer means the organisation or person that is controller of Customer Personal Data. Customer Personal Data means personal data processed by TerraAqua on the Customer's behalf.
3. Roles
The Customer is the controller and TerraAqua is the processor for Customer Personal Data described in Annex 1, except where the parties lawfully act in different roles for a specific processing activity.
The Customer is responsible for ensuring that its instructions and use of the services comply with applicable law and that it has a lawful basis for the processing.
4. Documented instructions
TerraAqua will process Customer Personal Data only on the Customer's documented instructions, including instructions in the main agreement, service configuration and written support requests, unless UK law requires otherwise.
If legally permitted, TerraAqua will inform the Customer before processing required by law. TerraAqua will notify the Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law.
5. Confidentiality
TerraAqua will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
6. Security
Taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and the risk to individuals, TerraAqua will maintain appropriate technical and organisational security measures.
Measures may include access control, authentication, encrypted transport, secure development, logging, monitoring, backups, vulnerability management, incident response and staff confidentiality controls, as appropriate to the service.
7. Sub-processors
The Customer gives TerraAqua general authorisation to use sub-processors needed to provide the services. TerraAqua will impose data-protection obligations on each sub-processor that provide an equivalent level of protection for the relevant processing.
TerraAqua remains responsible to the Customer for the performance of its sub-processors' data-protection obligations as required by law.
TerraAqua will make current sub-processor information available on request or through an appropriate online notice. Where required, TerraAqua will give reasonable notice of a material new sub-processor so the Customer may raise a legitimate data-protection objection.
8. International transfers
TerraAqua will not transfer Customer Personal Data outside the United Kingdom except under a lawful transfer mechanism and with appropriate safeguards where required.
Relevant safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful mechanism.
9. Data-subject requests
Taking account of the nature of processing, TerraAqua will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests from data subjects.
If TerraAqua receives a request relating to Customer Personal Data, it will normally refer the requester to the Customer unless legally required to respond directly.
10. Assistance with compliance
Taking account of the nature of processing and information available, TerraAqua will provide reasonable assistance with:
- security obligations;
- personal-data-breach notifications;
- data-protection impact assessments;
- prior consultation with a supervisory authority; and
- demonstrating compliance with processor obligations.
11. Personal data breaches
TerraAqua will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data.
The notification will include available information reasonably needed for the Customer's legal assessment, which may be provided in phases as the investigation continues.
12. Deletion and return
At the end of the relevant service, TerraAqua will delete or return Customer Personal Data at the Customer's choice where technically reasonably available, unless applicable law requires retention.
Data may remain temporarily in protected backups until overwritten under normal retention cycles, provided it remains protected and is not restored except for recovery or legal necessity.
13. Information and audits
TerraAqua will provide information reasonably necessary to demonstrate compliance with this DPA. The Customer may conduct an audit or appoint an independent auditor where required by law, subject to reasonable notice, confidentiality, security restrictions and measures to avoid unnecessary disruption.
TerraAqua may satisfy routine audit requests through current certifications, independent reports, security documentation and written responses where these provide reasonable assurance.
14. Records and regulatory cooperation
TerraAqua will maintain records required of a processor and cooperate with the competent supervisory authority as required by applicable law.
15. Customer obligations
The Customer will:
- provide lawful, fair and transparent instructions;
- limit personal data to what is necessary;
- configure access permissions appropriately;
- protect Customer credentials and systems;
- respond to data-subject requests and regulatory enquiries; and
- avoid submitting special-category or high-risk data unless expressly supported and lawfully agreed.
16. Liability
Liability under this DPA is subject to the liability provisions in the main agreement, except to the extent such limitation is prohibited by applicable data-protection law.
17. Priority
If this DPA conflicts with the main agreement on the processing of Customer Personal Data, this DPA takes priority for that conflict. Mandatory law takes priority over both.
18. Duration
This DPA remains effective while TerraAqua processes Customer Personal Data on the Customer's behalf.
19. Changes in law
The parties will cooperate in good faith to amend this DPA where reasonably necessary to comply with a material change in applicable data-protection law or binding regulatory requirements.
20. Governing law
This DPA is governed by the governing-law clause in the main agreement. If none applies, it is governed by the laws of England and Wales.
Annex 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Provision, security, support and administration of TerraAqua Cloud and contracted connected-aquarium services. |
| Duration | For the term of the service and applicable deletion or backup-retention period. |
| Nature and purpose | Hosting, storage, transmission, organisation, retrieval, support, security, diagnostics, account administration and customer-configured monitoring. |
| Data subjects | Customer personnel, authorised users, account holders, support contacts and other individuals whose information the Customer submits lawfully. |
| Personal data | Names, business contact details, account identifiers, permissions, authentication records, controller identifiers, aquarium names, configuration, operational readings linked to an account, support communications, logs and technical metadata. |
| Special-category data | Not intended or required for ordinary use. The Customer must not submit it unless expressly agreed and lawful. |
| Frequency | Continuous or as initiated by the Customer, controller, application or authorised user. |
| Controller rights | To issue lawful instructions, configure the service, request assistance, receive breach information, obtain compliance information and request deletion or return as provided by this DPA. |
| Controller obligations | To ensure lawful basis, transparency, data accuracy, data minimisation, appropriate access and compliance with data-subject rights. |
21. Contact
Data-processing enquiries may be sent to info@terra-aqua.co.uk.
Version history
| Version | Date | Description |
|---|---|---|
| 1.0 | 21 July 2026 | Initial commercial release |