Skip to document
N NativeCMS Service status
Terms of Service Privacy Policy Data Processing Addendum Subprocessor List Support Policy Security Reporting

NativeCMS Data Processing Addendum

Version 1.0 Effective 31 July 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Sam Lewis, a sole trader trading as NativeCMS, at Mortimer Court, Abbey Road, London, NW8 9AD ("NativeCMS" or "Processor"), and Customer ("Controller") where NativeCMS processes Customer Personal Data to provide the service. Capitalised data-protection terms have the meanings in UK GDPR and applicable UK data-protection law.

1. Processing instructions and roles

Customer determines the purposes and means of Customer Personal Data and instructs NativeCMS to process it only to provide, secure, monitor, support, back up, restore and improve the contracted service; to follow Customer's documented dashboard, API and support instructions; and as law requires. NativeCMS informs Customer if an instruction appears unlawful unless prohibited from doing so.

NativeCMS is independently responsible as controller for account, fraud and security, contract and legal records described in the Privacy Policy.

2. Processing details

Item Description
Subject matter Managed Drupal hosting, Native integration, deployment, backups, preview, monitoring and support
Duration Agreement term plus documented export, deletion and protected-backup periods
Nature Collection, storage, organisation, retrieval, transmission, display, backup, restore, deletion and security analysis
Purpose Deliver and protect Customer's configured websites, apps and operational workflows
Data subjects Customer staff and contractors; site or app users; members, subscribers, contacts, form submitters and people represented in Customer content
Data types Identity and contact, account, content, communications, device-capability submissions, technical identifiers, audit data and Customer-configured Drupal fields or files
Special-category or criminal data Not authorised by default; requires a written service-specific assessment and safeguards before upload

Customer ensures its instructions, notices, lawful bases, minimisation and device-capability choices are lawful.

3. Confidentiality and personnel

NativeCMS limits access to people who need it, binds them to confidentiality, provides appropriate security and data-protection training, and removes access promptly when duties end.

4. Security measures

NativeCMS maintains measures appropriate to risk, including:

  • TLS in transit and provider-managed encryption at rest;
  • separate tenants, site and environment identities, PostgreSQL row-level security and relational constraints;
  • least-privilege workload identities and separate privileged worker paths;
  • MFA, session controls, role permissions, audit events and immediate access revocation;
  • secrets in managed secret stores rather than customer code;
  • immutable image and release provenance, dependency, secret and container scanning, and isolated untrusted builds;
  • WAF, bounded rate limiting, network policies and security monitoring;
  • quarantined upload handling, allowlists, quotas and malware-scanning integration where a feature requires it; and
  • documented backups, restore controls and disaster-recovery testing.

Controls may change as threats and technology change, provided the overall level of protection is not materially reduced.

5. Subprocessors

Customer gives general written authorisation for providers listed in Subprocessors. NativeCMS gives at least 30 days' notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds within 14 days. The parties will work in good faith on a reasonable alternative; if none exists, Customer may terminate the affected service without penalty. NativeCMS imposes equivalent data-protection obligations and remains responsible for subprocessors as required by law.

6. International transfers

NativeCMS will not make a restricted transfer without a lawful mechanism. Where needed, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or another valid mechanism. NativeCMS carries out proportionate transfer-risk and supplementary-measure reviews.

7. Assistance

Taking account of the processing and information available, NativeCMS assists Customer with data-subject requests; secure exports, correction and deletion; security and breach notification; data-protection impact assessments and prior consultation; and evidence reasonably needed to demonstrate compliance. Customer remains responsible for responding as controller. Reasonable agreed fees may apply to exceptional assistance not caused by our breach.

8. Personal-data breaches

NativeCMS notifies Customer without undue delay after becoming aware of a breach of Customer Personal Data and supplies available information about its nature, scope, likely consequences, containment and remediation. Information may be provided in phases. Notification is not an admission of fault. Customer decides on regulator or data-subject notification unless law assigns that duty to NativeCMS.

Send suspected personal-data or security incidents to security@nativecms.co.uk with the subject URGENT SECURITY. This mailbox is monitored during published support coverage and by automated escalation; it is not a promise of 24-hour staffed support.

9. Return and deletion

During the agreement Customer may use documented exports. At termination, NativeCMS returns or makes Customer Personal Data available for the 30-day recovery period, then deletes it unless law requires retention. Protected backups are isolated from ordinary use and expire through their documented cycle. Deletion confirmation is available on request.

Customer database and file exports exclude the separately managed NativeCMS platform layer described in product documentation. Platform backups restore both layers without exposing another tenant or protected credentials.

10. Audit

NativeCMS provides current security documentation, independent reports when available and reasonable written answers. No more than annually, or after a material incident, Customer may request a proportionate audit on reasonable notice. An audit must protect other customers, credentials and proprietary systems, use an agreed qualified auditor, avoid disruption and prefer existing evidence. Customer pays unless the audit identifies a material NativeCMS breach.

11. End-of-contract obligations

At the Customer's choice, NativeCMS deletes or returns Customer Personal Data after the service ends and deletes existing copies unless applicable law requires storage. NativeCMS makes information needed to demonstrate compliance with this DPA available to Customer and informs Customer if, in its opinion, an instruction infringes applicable data-protection law.

12. Conflict and legal change

This DPA prevails over conflicting service terms for processing Customer Personal Data. The parties will amend it as reasonably necessary when applicable law or valid transfer mechanisms change.

Sam Lewis, sole trader trading as NativeCMSMortimer Court, Abbey Road, London, NW8 9AD