Gardenroom StudioBack to the site

Data Processing Agreement

How Gardenroom Studio handles personal information on behalf of the businesses that use it, as UK GDPR requires.

Last updated 10 October 2026

This agreement forms part of the Terms of Service between Gardenroom Studio (the “Processor”) and the business that has the workspace (the “Controller”). It applies to the personal information the Processor handles for the Controller when the Controller uses the service, mainly the people who send enquiries through the Controller’s website, widget and forms (“Customer Data”). It is intended to meet Article 28 of the UK GDPR and the Data Protection Act 2018. Where the EU GDPR also applies, it applies in the same way.

What we process and why

ItemDetail
Subject matterProviding the Gardenroom Studio service to the Controller
DurationFor as long as the Controller’s workspace exists, plus the short period needed to delete the data afterwards
Nature and purposeStoring, organising, displaying, emailing, exporting and deleting enquiries and website content; sending notifications; protecting the service from abuse
Types of personal dataName, email address, phone number, message, garden-room design and preferences, record of consent, hashed IP address; also the names and email addresses of the Controller’s team
People concernedThe Controller’s customers and prospects, and the Controller’s team members
Special categoriesNone are requested. The Controller must not ask people to submit them through the service

What we promise

  • We process Customer Data only on the Controller’s documented instructions, which are these terms and the Controller’s use of the service, unless the law requires otherwise. If we think an instruction breaks data protection law, we will say so.
  • Everyone with access to Customer Data at our end is bound by confidentiality.
  • We keep Customer Data secure using the measures in the next section.
  • We use only the subprocessors listed below, and follow the process in “Changing subprocessors”.
  • We help the Controller respond to requests from people exercising their rights, for example by letting the Controller search, export and delete a person’s enquiries. If someone contacts us directly we will pass it on and not answer it ourselves, unless the law requires.
  • We help the Controller with security, breach notification, impact assessments and consulting the regulator, taking into account what we know.
  • We tell the Controller without undue delay, and in any case within 48 hours, after we become aware of a personal data breach affecting Customer Data.
  • When the Controller deletes a workspace, or the agreement ends, we delete Customer Data, apart from copies we must keep by law, and from backups as they are overwritten. Before then, the Controller can export its enquiries.
  • We give the Controller the information it reasonably needs to check we are following this agreement, and allow reasonable audits, no more than once a year unless there has been a breach, on reasonable notice and with the Controller paying its own costs. We may meet this by sharing our up-to-date security documentation.

Security measures

  • Each workspace’s data is isolated at the database level using row-level security, so one business cannot read another’s.
  • Encryption in transit between visitors, the web application and our servers.
  • Passwords and API keys are stored hashed. Sessions are stored securely and can be revoked.
  • Access to Customer Data is limited by role, and changes are recorded in an activity log.
  • Our application and database are not exposed directly to the internet; traffic reaches them through an encrypted tunnel.
  • Sign-up and enquiry forms are protected by bot checks and rate limits.
  • Uploaded and imported pictures are checked, and unsafe addresses are refused when we fetch content from a website.
  • Automated tests and reviews of the code that enforces the points above.

Subprocessors

The Controller agrees we may use the following to provide the service.

SubprocessorWhat it doesWhere
Cloudflare, Inc.Hosts the web application, DNS, the secure tunnel to our server and Turnstile bot checks; connects customers’ own domainsGlobal network, including the UK, EEA and US
ResendSends emails such as enquiry notifications and confirmationsIreland (EU), with processing in the US
Our server providerRuns our database and application serversAs set out in our records, available on request
Anthropic, OpenAI, GoogleProcess assistant messages, only for workspaces that use the assistant and only with the provider the workspace picksUnited States and other locations
StripeTakes payment for paid plans, only if the Controller buys oneEEA and US

Changing subprocessors

We will tell the Controller (by email to the workspace owner, or a notice in the app) at least 30 days before adding or replacing a subprocessor that handles Customer Data. The Controller may object in writing on reasonable data-protection grounds within that time. If we cannot reasonably address the objection, the Controller may end its paid plan and delete its workspace without penalty. We stay responsible for our subprocessors and they are bound by terms no less protective than these.

Transfers outside the UK

Where Customer Data is sent outside the UK or EEA, we make sure one of these applies: an adequacy decision, such as the UK–US data bridge; the UK International Data Transfer Agreement or Addendum to the EU standard contractual clauses; or another lawful safeguard.

The Controller’s responsibilities

The Controller must have a lawful basis for collecting and using Customer Data, give people a clear privacy notice and the consent wording shown on its forms, respond to requests from people, and not use the service to collect data it has no right to collect. The wording a person agrees to on a form is recorded with their enquiry.

Liability and law

Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by the law of England and Wales. If it conflicts with the Terms about the handling of Customer Data, this agreement wins.

Questions about this agreement, or a signed copy, can be requested at hello@3dgardenroomstudio.com.