Data Processing Agreement
How Gardenroom Studio handles personal information on behalf of the businesses that use it, as UK GDPR requires.
Last updated 10 October 2026
This agreement forms part of the Terms of Service between Gardenroom Studio (the “Processor”) and the business that has the workspace (the “Controller”). It applies to the personal information the Processor handles for the Controller when the Controller uses the service, mainly the people who send enquiries through the Controller’s website, widget and forms (“Customer Data”). It is intended to meet Article 28 of the UK GDPR and the Data Protection Act 2018. Where the EU GDPR also applies, it applies in the same way.
What we process and why
| Item | Detail |
|---|---|
| Subject matter | Providing the Gardenroom Studio service to the Controller |
| Duration | For as long as the Controller’s workspace exists, plus the short period needed to delete the data afterwards |
| Nature and purpose | Storing, organising, displaying, emailing, exporting and deleting enquiries and website content; sending notifications; protecting the service from abuse |
| Types of personal data | Name, email address, phone number, message, garden-room design and preferences, record of consent, hashed IP address; also the names and email addresses of the Controller’s team |
| People concerned | The Controller’s customers and prospects, and the Controller’s team members |
| Special categories | None are requested. The Controller must not ask people to submit them through the service |
What we promise
- We process Customer Data only on the Controller’s documented instructions, which are these terms and the Controller’s use of the service, unless the law requires otherwise. If we think an instruction breaks data protection law, we will say so.
- Everyone with access to Customer Data at our end is bound by confidentiality.
- We keep Customer Data secure using the measures in the next section.
- We use only the subprocessors listed below, and follow the process in “Changing subprocessors”.
- We help the Controller respond to requests from people exercising their rights, for example by letting the Controller search, export and delete a person’s enquiries. If someone contacts us directly we will pass it on and not answer it ourselves, unless the law requires.
- We help the Controller with security, breach notification, impact assessments and consulting the regulator, taking into account what we know.
- We tell the Controller without undue delay, and in any case within 48 hours, after we become aware of a personal data breach affecting Customer Data.
- When the Controller deletes a workspace, or the agreement ends, we delete Customer Data, apart from copies we must keep by law, and from backups as they are overwritten. Before then, the Controller can export its enquiries.
- We give the Controller the information it reasonably needs to check we are following this agreement, and allow reasonable audits, no more than once a year unless there has been a breach, on reasonable notice and with the Controller paying its own costs. We may meet this by sharing our up-to-date security documentation.
Security measures
- Each workspace’s data is isolated at the database level using row-level security, so one business cannot read another’s.
- Encryption in transit between visitors, the web application and our servers.
- Passwords and API keys are stored hashed. Sessions are stored securely and can be revoked.
- Access to Customer Data is limited by role, and changes are recorded in an activity log.
- Our application and database are not exposed directly to the internet; traffic reaches them through an encrypted tunnel.
- Sign-up and enquiry forms are protected by bot checks and rate limits.
- Uploaded and imported pictures are checked, and unsafe addresses are refused when we fetch content from a website.
- Automated tests and reviews of the code that enforces the points above.
Subprocessors
The Controller agrees we may use the following to provide the service.
| Subprocessor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Hosts the web application, DNS, the secure tunnel to our server and Turnstile bot checks; connects customers’ own domains | Global network, including the UK, EEA and US |
| Resend | Sends emails such as enquiry notifications and confirmations | Ireland (EU), with processing in the US |
| Our server provider | Runs our database and application servers | As set out in our records, available on request |
| Anthropic, OpenAI, Google | Process assistant messages, only for workspaces that use the assistant and only with the provider the workspace picks | United States and other locations |
| Stripe | Takes payment for paid plans, only if the Controller buys one | EEA and US |
Changing subprocessors
We will tell the Controller (by email to the workspace owner, or a notice in the app) at least 30 days before adding or replacing a subprocessor that handles Customer Data. The Controller may object in writing on reasonable data-protection grounds within that time. If we cannot reasonably address the objection, the Controller may end its paid plan and delete its workspace without penalty. We stay responsible for our subprocessors and they are bound by terms no less protective than these.
Transfers outside the UK
Where Customer Data is sent outside the UK or EEA, we make sure one of these applies: an adequacy decision, such as the UK–US data bridge; the UK International Data Transfer Agreement or Addendum to the EU standard contractual clauses; or another lawful safeguard.
The Controller’s responsibilities
The Controller must have a lawful basis for collecting and using Customer Data, give people a clear privacy notice and the consent wording shown on its forms, respond to requests from people, and not use the service to collect data it has no right to collect. The wording a person agrees to on a form is recorded with their enquiry.
Liability and law
Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by the law of England and Wales. If it conflicts with the Terms about the handling of Customer Data, this agreement wins.
Questions about this agreement, or a signed copy, can be requested at hello@3dgardenroomstudio.com.