LoginStart free trial
Legal

Data Processing Terms

Last updated: 8 October 2026

These Data Processing Terms (“DPT”) apply when Linkwards processes personal information on behalf of a customer through the Service. They form part of the Terms of Service and apply automatically to every customer account. They are written to meet the requirements for operator agreements under POPIA (South Africa) and processor agreements under the GDPR and UK GDPR, and similar laws, where those laws apply.

1. Definitions

  • “Customer Personal Information” means personal information that is submitted to or collected through a customer’s Page or account and processed by Linkwards on the customer’s behalf, such as visitors’ booking requests, newsletter sign-ups and Page analytics.
  • “Customer” means the person or organisation that holds the Linkwards account. For this purpose, the Customer is the “responsible party” (under POPIA) or “controller” (under GDPR).
  • “Linkwards” is the “operator” (under POPIA) or “processor” (under GDPR).
  • “Data Protection Law” means the data protection and privacy laws that apply to the processing, including POPIA, the GDPR, the UK GDPR and equivalents.
  • Other terms such as “personal information”, “process” and “data subject” have the meanings given in Data Protection Law.

2. Roles

  • For Customer Personal Information, the Customer decides the purposes and means of processing and Linkwards processes it on the Customer’s behalf.
  • For information about the Customer themselves (such as account, billing and support details) and for operating, securing and improving the Service, Linkwards acts as an independent responsible party / controller, as explained in our Privacy Policy. This DPT does not apply to that information.

3. Details of the processing

  • Subject matter and purpose: providing the Linkwards Service to the Customer: hosting and displaying the Customer’s Page; receiving and storing booking requests and newsletter sign-ups; recording Page analytics; notifying the Customer; and supporting the Customer.
  • Duration: for as long as the Customer has an account, and until deletion under our Data Retention and Deletion terms.
  • Categories of data subjects: the Customer’s visitors, prospective and existing clients, enquirers and newsletter subscribers.
  • Types of personal information: names; email addresses; phone numbers; booking details (requested service, date and time, status, source); marketing consent choices; and Page analytics (random session identifiers, referring website, device type, browser, campaign tags, approximate country, interactions and scroll depth).
  • Special categories: the Service is not designed to process special or sensitive personal information (such as health, biometric or criminal data, or information about children). The Customer must not use free-text fields, booking requests or other features to collect it unless the law allows it and the Customer has taken the extra steps required.

4. Customer’s responsibilities

The Customer:

  • has and will keep a lawful basis for processing Customer Personal Information and for giving it to Linkwards to process;
  • will provide visitors with the notices, and obtain any consents, that Data Protection Law requires, including for marketing messages, cookies and tracking tools such as Google Analytics and the Meta Pixel that the Customer adds to a Page;
  • is responsible for handling requests from data subjects, and for how long it keeps data it has exported or copied out of Linkwards;
  • will configure the Service, including booking retention settings, in line with its own legal obligations; and
  • will make sure its instructions to Linkwards comply with law.

5. Linkwards’ obligations

Linkwards will:

  • Follow instructions. Process Customer Personal Information only on the Customer’s documented instructions, which are the Terms, this DPT, and the Customer’s use of the Service’s features and settings, unless the law requires otherwise (in which case we will tell the Customer where the law allows). We will tell the Customer if we believe an instruction breaches Data Protection Law.
  • Keep it confidential. Make sure that people authorised to process Customer Personal Information are bound by confidentiality, and that staff access is limited by role, secured with multi-factor authentication and recorded in an audit log.
  • Secure it. Apply appropriate technical and organisational security measures, including encrypted connections, row-level access controls that restrict each Customer to their own data, separation of server-side credentials, bot protection, and monitoring appropriate to the risks.
  • Use sub-processors responsibly. Engage sub-processors only under written terms with data protection obligations that are no less protective than these, and remain responsible for them. The Customer gives a general authorisation for the sub-processors listed on our Sub-processors page. We will give notice of new or replacement sub-processors by updating that page and, where practical, by email or in the app, so the Customer can object on reasonable grounds. If the Customer objects and we cannot reasonably resolve it, the Customer may stop using the Service and cancel.
  • Help with data subject requests. Taking into account the nature of the processing, give the Customer the tools (such as the ability to view, export and delete bookings and subscribers) to respond to requests from data subjects, and tell the Customer if we receive a request directly relating to Customer Personal Information, instead of responding ourselves unless required.
  • Notify of security compromises. Tell the Customer without undue delay after becoming aware of a security compromise affecting Customer Personal Information, with the information we have to help the Customer meet its own notification duties.
  • Assist with compliance. Provide reasonable help with data protection impact assessments and consultations with regulators, where needed and relating to the Service.
  • Return or delete. When the Customer’s account is closed, delete Customer Personal Information as described on our Data Retention and Deletion page, unless the law requires us to keep it. Before deletion, the Customer can export certain data from the app.
  • Demonstrate compliance. Make available information reasonably necessary to show we meet this DPT, and allow reasonable audits (no more than once a year, with reasonable notice, at the Customer’s cost, during business hours, subject to confidentiality and without disrupting other customers) where the Customer cannot be satisfied through the information we provide or where Data Protection Law requires.

6. International transfers

Customer Personal Information is stored primarily in the United Kingdom (London), and our sub-processors may process it in other countries. Where required, we will make sure transfers are covered by an appropriate lawful mechanism, such as an adequacy decision, binding agreements with sub-processors, or standard contractual clauses (including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply). The parties agree that those clauses, if needed, are incorporated into this DPT by reference with the Customer as exporter and Linkwards as importer, and that their details are completed by this DPT and our Sub-processors page.

7. Liability and precedence

Each party’s liability under this DPT is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPT and the Terms about the processing of Customer Personal Information, this DPT prevails. If there is a conflict between this DPT and any standard contractual clauses that apply, the clauses prevail.

8. Changes

We may update this DPT to reflect changes in law or the Service, in line with the way we change our Terms. If you need a signed copy of this DPT or have questions, email support@linkwards.com.

Our other legal documents