Version 1.0. Last updated: 29 September 2026.
These Data Processing Terms form part of the Agreement between SideDish Media Ltd (SDM, we, us or our), company number 10561053, and each of its clients (the Client or you). They set out the terms required by Article 28 of the UK GDPR for personal data that SDM processes on the Client's behalf. Capitalised terms not defined here have the meanings given in our Terms and Conditions.
1. Definitions
1.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and any other data protection law that applies in the United Kingdom, in each case as amended from time to time, including by the Data (Use and Access) Act 2025.
1.2 Client Personal Data means personal data that SDM processes on the Client's behalf in providing the Services.
1.3 The terms controller, processor, personal data, personal data breach, processing, special category data and data subject have the meanings given in the UK GDPR.
2. Roles of the parties
2.1 For Client Personal Data, the Client is the controller and SDM is the processor.
2.2 SDM is a controller of personal data it processes for its own purposes, such as managing its relationship with the Client's staff, billing and its own marketing. SDM's Privacy Policy applies to that processing.
2.3 Where Client Personal Data is used on a Platform, it is also subject to that Platform's own data terms, and the Platform may act as an independent controller. The Client authorises SDM to accept those terms on its behalf where needed to provide the Services.
3. Details of the processing
3.1 Subject matter: the provision of the Services.
3.2 Duration: for the term of the Agreement and until Client Personal Data is deleted or returned under clause 12.
3.3 Nature and purpose: running, tracking and reporting on advertising and marketing campaigns; capturing and passing on enquiries, bookings and leads; building advertising audiences; sending email marketing; and building and managing websites, in each case on the Client's behalf.
3.4 Types of personal data: names, email addresses, phone numbers, booking and enquiry details, messages submitted through forms, call details (phone number, time, duration and campaign source, and call recordings only where enabled under clause 8), online identifiers such as IP addresses, cookie identifiers and ad click identifiers, and customer lists supplied by the Client.
3.5 Data subjects: the Client's customers, prospective customers, website visitors, email subscribers and callers.
3.6 Special category data: SDM does not intend to process special category data. Dietary and allergy information can be health data, which is special category data. The Client must not ask SDM to collect special category data through forms, calls or any other means without SDM's prior written agreement.
4. SDM's obligations
4.1 SDM will:
(a) process Client Personal Data only on the Client's documented instructions, including those set out in the Agreement, unless the law requires otherwise, in which case SDM will tell the Client before processing unless the law prohibits this;
(b) tell the Client promptly if it believes an instruction breaches Data Protection Law;
(c) ensure that everyone authorised to process Client Personal Data is bound by a duty of confidentiality;
(d) put in place appropriate technical and organisational measures to protect Client Personal Data, as required by Article 32 of the UK GDPR, including access controls, multi-factor authentication where available, encryption in transit and access limited to those who need it;
(e) only use sub-processors in line with clause 5;
(f) taking into account the nature of the processing, assist the Client by appropriate technical and organisational measures to respond to requests from data subjects exercising their rights, and pass on any such request it receives directly within five working days;
(g) assist the Client with its obligations on security, personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner's Office (ICO), taking into account the information available to SDM;
(h) delete or return Client Personal Data at the end of the Services under clause 12; and
(i) make available to the Client all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits, including inspections, carried out by the Client or its appointed auditor.
4.2 Audits under clause 4.1(i) must be requested with at least 30 days' written notice, may take place no more than once in any 12-month period (unless required by the ICO or following a personal data breach), and are at the Client's cost.
5. Sub-processors
5.1 The Client gives SDM general authorisation to engage sub-processors. SDM's current sub-processors are: Google (Workspace, Tag Manager and Analytics), WhatConverts (call and form tracking), Brevo (email marketing), Webflow (website hosting and forms), Supabase (database hosting), Vercel (web application hosting), Slack (internal communications) and Zapier (workflow automation).
5.2 SDM will give the Client at least 14 days' notice by email before adding or replacing a sub-processor. The Client may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, either party may terminate the affected Services by written notice.
5.3 SDM will ensure that each sub-processor is bound by a written contract imposing data protection obligations that meet the requirements of Article 28 of the UK GDPR.
5.4 SDM remains liable to the Client for the performance of its sub-processors' obligations.
6. International transfers
6.1 Some sub-processors and Platforms process data outside the United Kingdom, including in the European Economic Area and the United States.
6.2 SDM will only transfer Client Personal Data outside the United Kingdom where the transfer is permitted by Data Protection Law. This includes transfers to a country covered by UK adequacy regulations, to a US organisation certified under the UK Extension to the EU-US Data Privacy Framework, or under the ICO's International Data Transfer Agreement or International Data Transfer Addendum.
7. Personal data breaches
7.1 SDM will notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data.
7.2 The notification will include, as far as SDM knows at the time: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to deal with it. Where not all of this information is available at once, SDM will provide it in stages without undue delay.
7.3 SDM will take reasonable steps to contain the breach and will co-operate with the Client. The Client is responsible for deciding whether to notify the ICO and affected data subjects.
8. Call tracking and call recording
8.1 SDM may use call tracking, through WhatConverts, to attribute phone calls to campaigns. Call tracking records the caller's phone number, the time and duration of the call and the campaign source.
8.2 Call recording is switched off by default. SDM will only switch it on at the Client's written request.
8.3 Where call recording is switched on:
(a) the Client is responsible for having a lawful basis for recording calls and for explaining call recording in its privacy notice;
(b) SDM will set up an announcement at the start of every recorded call telling callers that the call may be recorded and why;
(c) recordings will be kept for no more than 90 days and then deleted, unless the Client instructs otherwise in writing;
(d) access to recordings will be limited to SDM staff who need it and the Client's nominated contacts;
(e) recordings will only be used for the purposes the Client instructs, such as lead verification, call quality and campaign reporting; and
(f) the Client must ensure that its staff do not take payment card details on a recorded line. If card details are captured on a recording, the Client must tell SDM immediately so the recording can be deleted.
9. Customer lists and advertising audiences
9.1 Where the Client asks SDM to upload a customer list to a Platform, for example for Meta Custom Audiences or Google Customer Match, the Client warrants that it has a lawful basis for doing so, that it has told the people on the list that their data may be used in this way, and that the list only includes people who may lawfully be targeted.
9.2 SDM will upload customer lists only through the Platform's own upload tools, which hash the data before it is matched, and will not keep copies for longer than necessary.
10. Email marketing
10.1 Where SDM sends email marketing on the Client's behalf, the Client warrants that each recipient has given valid consent or falls within the soft opt-in under PECR, and that its consent records are accurate.
10.2 SDM will include an unsubscribe option in every marketing email and will act on unsubscribe requests promptly.
11. The Client's obligations
11.1 The Client warrants that:
(a) it has a lawful basis for all processing it instructs SDM to carry out;
(b) its privacy notice accurately describes that processing, including tracking, advertising, email marketing and any call recording; and
(c) it has obtained any consent required under PECR for cookies and similar technologies on its website.
11.2 The Client will indemnify SDM against all claims, fines, losses and reasonable costs arising from the Client's breach of clause 11.1 or from SDM following the Client's instructions.
12. Deletion and return
12.1 Within 30 days after the Services end, SDM will, at the Client's choice, delete or return Client Personal Data, unless the law requires SDM to keep it. If the Client does not choose within that period, SDM will delete it.
12.2 Client Personal Data held in backups will be deleted in line with normal backup cycles and kept secure until then. Client Personal Data held within Platforms is subject to each Platform's own retention policies.
13. Liability and priority
13.1 Each party's liability under these Data Processing Terms is subject to the limitations in clause 15 of the Terms and Conditions, except where the law does not allow liability to be limited.
13.2 If there is a conflict between these Data Processing Terms and any other part of the Agreement on a data protection matter, these Data Processing Terms take priority.
14. Changes and governing law
14.1 SDM may update these Data Processing Terms in line with clause 19 of the Terms and Conditions, or sooner where needed to comply with a change in Data Protection Law.
14.2 These Data Processing Terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
15. Contact
15.1 Questions about these Data Processing Terms should be sent to hello@sidedishmedia.co.uk.