V1.1 · Updated 23 August 2026
This Data Processing Agreement applies where The Trap House processes personal data on behalf of a Client as a processor under the General Data Protection Regulation (GDPR / AVG).
It forms part of the agreement between the Client and The Trap House together with the Proposal, the applicable General Terms & Conditions and any applicable Service Terms.
The Client is the Controller and The Trap House is the Processor for the processing covered by this Agreement, unless the parties agree otherwise for a specific processing activity.
This Agreement applies only to personal data that we process on your behalf while providing the Services.
It does not apply where we determine the purposes and means of a processing activity independently and therefore act as a separate controller.
The Proposal and applicable Service Terms form part of the documented instructions for the processing.
The subject matter of the processing is the personal data reasonably required for us to provide the Services described in the Proposal.
The processing continues for the duration of the relevant Services and for any limited period afterwards that is reasonably necessary for return, deletion, backups, legal obligations or agreed transition work.
Depending on the Services, the nature of the processing may include collecting, accessing, storing, organising, hosting, transmitting, analysing, modifying, retrieving, backing up, deleting or otherwise handling personal data on your behalf.
The purpose of the processing is to provide the Services and carry out your documented instructions.
Depending on the Services, data subjects may include:
Depending on the Services, personal data may include:
Special-category personal data or criminal-offence data is not intended to be processed unless the Services specifically require it and the parties have agreed appropriate instructions and safeguards.
If the Proposal describes the processing in more detail, that description supplements and, where more specific, takes priority over this section.
We will process personal data only on your documented instructions, including the instructions contained in the Agreement.
We may also process personal data where Union or Member State law requires us to do so. Where legally permitted, we will inform you of that requirement before processing.
If we believe an instruction infringes applicable data-protection law, we will inform you and may pause the affected processing while the issue is resolved.
You are responsible for the lawfulness of the personal data and the instructions you give us.
You are responsible for:
We will ensure that people authorised to process personal data on our behalf are subject to appropriate confidentiality obligations.
Access to personal data will be limited to people who reasonably need that access to provide, support or secure the Services.
We will implement appropriate technical and organisational measures taking into account the nature of the processing, the risks involved, the state of the art and the cost of implementation.
Depending on the Services and risk, measures may include access controls, authentication, encryption where appropriate, system updates, backups, logging, monitoring, secure configuration, confidentiality measures and procedures for restoring availability.
Security measures may differ between Services and may rely partly on third-party infrastructure or platforms identified in the applicable Service Terms.
No technical or organisational measure can remove all security risk.
If we become aware of a personal data breach affecting personal data processed on your behalf, we will notify you without undue delay.
We will provide information reasonably available to us that you need to assess the incident and meet your own notification obligations.
Where all relevant information is not available at once, it may be provided in phases as the investigation develops.
Our notification of an incident does not by itself mean that we accept responsibility or liability for its cause.
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects where the relevant personal data is processed through our Services.
If a data subject contacts us directly about personal data we process only on your behalf, we will refer the request to you unless the law requires us to respond directly.
Additional work required to handle complex or unusual requests may be charged where permitted and where the work is outside the normal scope of the Services.
Taking into account the nature of the processing and information available to us, we will provide reasonable assistance with your obligations relating to:
Assistance beyond the normal scope of the Services may be charged where reasonable and legally permitted.
You give us general written authorisation to use sub-processors where reasonably necessary to provide the Services.
We will ensure that a sub-processor is bound by data-protection obligations that provide an appropriate level of protection for the processing it performs on our behalf.
We remain responsible for our obligations under this Agreement where they are performed by a sub-processor.
We will make information about relevant sub-processors available to you and will inform you of intended material additions or replacements where required, giving you a reasonable opportunity to object on legitimate data-protection grounds.
If an objection cannot reasonably be resolved, either party may end the affected Service in accordance with the Agreement.
We will not knowingly transfer personal data outside the European Economic Area, or allow a relevant sub-processor to do so, unless the transfer is permitted under applicable data-protection law.
Where required, this may include reliance on an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism.
Your documented instructions also apply to international transfers.
We will maintain the records required of us as a processor under applicable data-protection law.
We will make information reasonably necessary to demonstrate compliance with our processor obligations available to you, subject to appropriate confidentiality and security safeguards.
You may request reasonable information or an audit where necessary to demonstrate compliance with this Agreement and Article 28 GDPR.
Audits must be proportionate, protect the confidentiality and security of our systems and other clients, and wherever possible first use available documentation, reports or certifications.
On-site audits require advance agreement and take place during normal business hours without unnecessarily disrupting our operations.
You are responsible for reasonable audit costs where the audit is unusually burdensome or is not triggered by evidence of our material non-compliance.
When the relevant Services end, we will, at your choice and where reasonably possible, return or delete personal data processed on your behalf unless applicable law requires us to retain it.
Data may remain temporarily in routine backups or technical archives until those copies are overwritten or deleted in the normal course of our retention processes, provided they remain protected and are not used for another purpose.
You are responsible for requesting and completing any required export or handover before the applicable deletion period expires.
Liability relating to this Data Processing Agreement is subject to the liability provisions and limits in the General Terms to the extent permitted by applicable law.
Nothing in this Agreement limits a responsibility that cannot legally be limited.
This Data Processing Agreement starts when we begin processing personal data on your behalf and continues for as long as we process that personal data under the Services.
Provisions that by their nature need to continue after the processing ends, including confidentiality, deletion, audit and liability provisions, remain effective for as long as necessary.
The governing-law and dispute provisions in the General Terms apply to this Data Processing Agreement.
If this Agreement conflicts with the General Terms on a matter specifically concerning processing of personal data on your behalf, this Data Processing Agreement takes priority.