Product
Solutions
Compare
Resources
Get early access Talk to us
Legal

Data Processing Agreement

Last updated 25 August 2026. Written to be read rather than skimmed past.

Need a signed copy? Email legal@wpcentrify.com and we will return a signed counterpart, usually within one business day. Standard Contractual Clauses are available for international transfers.

Placeholder notice for the site owner: the named subprocessor list in section 6, plus entity and jurisdiction details, must be completed before publishing. Have this reviewed by a qualified data protection lawyer.

1. Parties and scope

This Data Processing Agreement forms part of the agreement between CentriQor ("Processor"), incorporated in [JURISDICTION PLACEHOLDER] (placeholder), and the customer ("Controller") for the provision of WPCentrify.

It applies where the Processor processes personal data on behalf of the Controller in the course of providing the service. A signed counterpart is available on request for any paid plan by emailing legal@wpcentrify.com.

2. Subject matter and nature of processing

Subject matter: provision of WordPress management, backup, monitoring, security scanning and reporting services.

Duration: for the term of the agreement, plus the retention periods set out in section 8.

Nature and purpose: storage, transmission, backup, restoration, analysis of site operational metadata, and generation of reports, solely to provide the service.

Categories of data subject: the Controller's personnel and end users, and where backups are enabled, individuals whose personal data appears within the Controller's WordPress sites.

Categories of personal data: contact and authentication data for Controller personnel; and, within backups, whatever personal data the Controller's sites contain, which the Processor does not inspect, index or analyse.

3. Processor obligations

  • Process personal data only on documented instructions from the Controller, including regarding international transfers, unless required otherwise by law, in which case the Processor informs the Controller unless legally prohibited.
  • Ensure personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement and maintain the technical and organisational measures described in section 5.
  • Respect the conditions in section 6 for engaging subprocessors.
  • Assist the Controller in responding to data subject requests, taking into account the nature of the processing.
  • Assist the Controller with breach notification, data protection impact assessments and prior consultation.
  • Delete or return personal data at the end of the agreement in accordance with section 8.
  • Make available all information necessary to demonstrate compliance and allow for audits as set out in section 9.

4. Controller obligations

The Controller warrants that it has a lawful basis for the processing it instructs, has provided any required notices to data subjects, and is authorised to connect each WordPress site it adds to the service. The Controller is responsible for configuring retention, access and automation policies appropriate to its own obligations.

5. Security measures

The Processor implements appropriate technical and organisational measures including:

  • Encryption in transit using TLS 1.3 and at rest using AES-256, with key management separated from data storage.
  • Scoped, rotating connection credentials rather than shared administrative passwords.
  • Role-based access control with least privilege, and enforced multi-factor authentication for personnel.
  • Logical isolation of customer data across storage, processing and job execution.
  • Append-only audit logging of actions taken on customer systems.
  • Continuous infrastructure and application monitoring with alerting on anomalous access.
  • Documented incident response, business continuity and disaster recovery procedures, tested periodically.
  • Background-checked personnel with role-appropriate security training.

6. Subprocessors

The Controller grants general authorisation for the Processor to engage subprocessors, subject to the Processor imposing data protection obligations no less protective than those in this DPA, and remaining fully liable for their performance.

Current subprocessors are limited to providers of cloud infrastructure and object storage, payment processing, transactional email delivery, customer support tooling, and error and performance monitoring. Placeholder: list each named subprocessor, its function, and its processing location before publishing.

The Processor gives at least 30 days' notice before adding or replacing a subprocessor. The Controller may object on reasonable data protection grounds, and if the objection cannot be resolved, may terminate the affected service with a prorated refund.

7. International transfers

Where personal data is transferred outside its region of origin, the Processor relies on an adequacy decision where one applies, and otherwise on Standard Contractual Clauses, which are incorporated by reference and available on request. The Controller may select regional data residency, where enabled on the account, to limit transfers.

8. Retention, return and deletion

On termination, the Controller may export all personal data for 30 days. Thereafter the Processor deletes personal data from active systems within 30 days and from backup systems within 90 days, except where retention is required by law, in which case the data remains subject to this DPA for as long as it is retained.

9. Audit and assurance

The Processor makes available documentation demonstrating compliance, including its security overview, architecture description and subprocessor list. Where the Controller reasonably requires further assurance, the Processor will complete a security questionnaire and, no more than once in any twelve month period and on reasonable notice, permit an audit conducted at the Controller's expense under confidentiality and without disrupting the service or compromising other customers.

10. Personal data breach

The Processor notifies the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the Controller's data. Notification includes the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken and proposed, and a contact point. The Processor cooperates with the Controller in investigating and remediating the breach.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service in relation to the processing of personal data, this DPA prevails.

12. Contact

Data protection enquiries: privacy@wpcentrify.com
Contract and signature requests: legal@wpcentrify.com
CentriQor, [REGISTERED ADDRESS PLACEHOLDER] (placeholder)