WebsitePal Back to WebsitePal

Data Policy

Last updated: 26 July 2026

This Data Policy (“Policy”) forms part of the WebsitePal Terms of Service between DM-Me trading as WebsitePal Pro (“WebsitePal”, “Processor”) and the business client (“Client”, “Controller”) where WebsitePal processes Client Personal Data on the Client’s behalf.

1. Scope And Definitions

This Policy applies to personal data processed by WebsitePal solely to host, maintain or support the Client website or to operate features such as website contact forms on the Client’s documented instructions (“Client Personal Data”).

“Applicable Data Protection Law” means the EU General Data Protection Regulation, Spanish data-protection law, the UK GDPR, the Data Protection Act 2018 and other data-protection law applicable to the processing. “Controller”, “Processor”, “Personal Data”, “Data Subject”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given by applicable law.

This Policy does not apply where WebsitePal acts as an independent controller for account administration, billing, security, legal compliance or its own business operations, which are covered by the WebsitePal Privacy Policy.

2. Processing Details

  • Subject matter: hosting, displaying, transmitting, storing, maintaining and supporting the Client website and its agreed features.
  • Duration: the period WebsitePal provides the relevant service, plus the limited return, deletion and backup period described below.
  • Nature and purpose: receiving website enquiries; delivering them to the Client; hosting Client content; maintaining website functionality; troubleshooting; security; backup and restoration; and other processing documented by the Client within the agreed service.
  • Data subjects: Client personnel, team members, customers, prospective customers, reviewers, suppliers, project contacts and visitors who communicate through the Client website.
  • Data types: names, business contact details, email addresses, telephone numbers, enquiry content, photographs, testimonials, job roles, technical logs, IP addresses and other personal data the Client chooses to include in or collect through the website.
  • Sensitive data: the service is not intended for special-category or highly sensitive personal data. The Client must not submit it without prior written agreement and appropriate safeguards.

3. Client Instructions

WebsitePal will process Client Personal Data only on documented instructions from the Client, including the Terms, this Policy, the Client’s configured website fields and support requests, unless law requires otherwise. If legally permitted, WebsitePal will inform the Client before processing required by law.

WebsitePal will promptly tell the Client if it believes an instruction infringes Applicable Data Protection Law. WebsitePal is not required to follow an instruction that would be unlawful or outside the agreed service.

4. Client Responsibilities

The Client determines the purposes and lawful basis for Client Personal Data and is responsible for:

  • providing an accurate privacy notice on the Client website;
  • having a lawful basis for collecting and supplying personal data;
  • responding to Data Subject requests and regulatory enquiries as Controller;
  • configuring the website to collect only information that is necessary;
  • ensuring its instructions and supplied content comply with law; and
  • notifying WebsitePal of any unusual regulatory or security requirements before processing begins.

5. Confidentiality And Access

WebsitePal will limit access to Client Personal Data to personnel and contractors who need it to provide, secure or support the service. Those people will be subject to appropriate confidentiality obligations and receive relevant instructions about secure handling.

6. Security

WebsitePal will maintain measures appropriate to the processing risk, including authenticated access, role-based administrative controls, encrypted network connections, restricted database and storage permissions, rate limiting, logging, backup arrangements, supplier security measures and processes for managing vulnerabilities and incidents.

The Client acknowledges that no online system can be guaranteed completely secure and that appropriate measures may change as technology, threats and the service develop.

7. Sub-processors

The Client gives WebsitePal general written authorisation to use sub-processors needed to deliver the service. Current categories and principal providers may include Vercel for hosting and delivery, Supabase for database/authentication/storage, Resend for email delivery, OpenAI for agreed AI-assisted generation, and infrastructure, domain, email or WordPress providers required for a separately requested service.

WebsitePal will require a sub-processor to protect Client Personal Data under written terms appropriate to the processing. WebsitePal remains responsible for its sub-processors to the extent required by Applicable Data Protection Law.

WebsitePal will give reasonable notice of a material new sub-processor where the change affects Client Personal Data. The Client may raise a reasonable data-protection objection. The parties will work in good faith on a practical solution; if none is reasonably available, either party may end the affected processing service.

8. International Transfers

Where Client Personal Data is transferred outside the country or recognised area in which it is protected, WebsitePal will ensure an applicable adequacy decision or recognised transfer safeguard is used. This may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and supplementary technical or organisational measures where appropriate.

9. Data Subject Requests

Taking account of the nature of the processing, WebsitePal will provide reasonable assistance to help the Client respond to requests to access, correct, delete, restrict, object to or export Client Personal Data. If WebsitePal receives a request relating to Client Personal Data, it will normally refer the requester to the Client and notify the Client unless prohibited by law.

Assistance within the normal capabilities of the service is included. Substantial bespoke work may be charged at a rate agreed in advance where permitted by law.

10. Personal Data Breaches

WebsitePal will notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data. As information becomes available, the notice will describe the nature of the incident, likely consequences, affected information, mitigation taken and a contact point.

The Client remains responsible for deciding whether notice to a Supervisory Authority or affected person is required. WebsitePal will provide reasonable assistance with that assessment and response.

11. Compliance Assistance

Taking account of the service and information available to it, WebsitePal will provide reasonable assistance with security obligations, Data Protection Impact Assessments and prior consultation with a Supervisory Authority where the Client reasonably requires it for the processing covered by this Policy.

12. Return And Deletion

At the Client’s written request made before or within 30 days after the affected processing service ends, WebsitePal will provide a reasonable export of Client Personal Data then available through its systems, subject to the Terms and supported formats.

After that period, WebsitePal will delete or anonymise Client Personal Data from live systems within a reasonable operational period, unless retention is required by law. Residual backup copies may remain until overwritten through the applicable backup cycle and will remain protected and unavailable for ordinary use.

13. Information And Audits

WebsitePal will make available information reasonably necessary to demonstrate compliance with this Policy. The Client must first use documentation, certifications and written responses made available by WebsitePal. If those are insufficient, the Client may request an audit no more than once each year, on reasonable written notice, during normal business hours and without accessing another client’s information or creating material security risk.

The Client will bear reasonable costs of an audit unless it identifies a material breach by WebsitePal. Nothing in this section restricts the powers of a competent Supervisory Authority.

14. Liability And Priority

Liability arising under this Policy is subject to the liability provisions in the Terms of Service, except to the extent Applicable Data Protection Law does not allow a liability to be limited. If this Policy conflicts with the Terms on the protection of Client Personal Data, this Policy takes priority.

15. Contact

Data-processing questions and notices can be sent to info@websitepal.pro or DM-Me trading as WebsitePal Pro, 24 Santa Ana de Bolueta, 48004 Bilbao, Vizcaya, Spain.