Introduction
The UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 govern how organisations process personal data in the United Kingdom. These regulations ensure that personal data is processed lawfully, fairly, and transparently while protecting the rights and freedoms of data subjects.
We are committed to maintaining the highest standards of data protection and privacy, ensuring compliance with both UK GDPR and the Data Protection Act 2018, as well as the Privacy and Electronic Communications Regulations (PECR) where applicable.
Definitions
Personal data: any information relating to an identified or identifiable real person. An identifiable real person is defined as any real person who can be directly or indirectly identified.
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collecting, recording, transmission, storage, conservation, extracting, consultation, use, disclosure by transmission and so on.
Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Your GDPR Responsibilities
When you use our services to store or process personal data (including customer or user data), you are the Data Controller and WebProject acts as a Data Processor. This applies to all personal data you place on our servers either directly, via hosted websites, or through any of our other services.
Under UK GDPR, as a Data Controller, you must ensure that any Data Processor services you use are compliant with data protection regulations. This includes conducting due diligence on our services and ensuring appropriate contractual terms are in place, including Data Processing Agreements (DPAs) that meet UK GDPR requirements.
Our GDPR Commitment
WebProject is committed to maintaining full compliance with UK GDPR, Data Protection Act 2018, and PECR.
Our ongoing compliance measures include:
- Annual data protection training for all staff with regular refresher sessions
- Comprehensive data protection impact assessments (DPIAs) for new services and significant changes
- Regular audits of all systems, processes, and third-party services for GDPR compliance
- Continuous monitoring and improvement of data protection measures
- Updated Data Processing Agreements (DPAs) that meet current UK GDPR requirements
- Clear data retention and deletion policies aligned with UK GDPR principles
- Established procedures for handling data subject requests (access, rectification, erasure, etc.)
- Incident response procedures for potential data breaches
Our Role as a Data Processor
You retain full ownership and control of all data you submit to our services, whether hosted on your premises or our servers. WebProject acts solely as a Data Processor under UK GDPR, processing personal data only on your documented instructions as the Data Controller.
Our processing activities are limited to providing hosting, storage, and technical support services as specified in our Data Processing Agreement. We do not access, analyse, or otherwise process your data for our own purposes beyond what is strictly necessary to provide our services.
- We do not share your data with third parties except as explicitly authorised by you or required by law
- All requests from law enforcement or regulatory authorities are handled through our established legal request procedures
- We require proper legal documentation before responding to any data access requests
- We will notify you of any legal requests for your data unless legally prohibited from doing so
Data Location and International Transfers
Your data is stored on our infrastructure located in the following UK and approved jurisdictions:
- UK Data Centers: iomart Maidenhead (Tier 4 facility), OVH Erith (London)
- EU Data Centers: OVH RBX1-RBX5 (France, Roubaix)
All data transfers outside the UK comply with UK GDPR international transfer requirements. Transfers to EU countries rely on the UK-EU adequacy decision.
Backup and Redundancy: Microsoft Azure backup services in UK data centers (Durham, London, Cardiff). All backup data remains within UK jurisdiction.
Security
All our employees keep up to date with all technical aspects of security and ensure the ongoing security of our servers and systems. Security patches are applied to our systems as a matter of priority.
Remote admin access to our servers is strictly restricted to key personnel within our Technical Support team. Data centre staff have physical access to the servers only when requested by our technical support team.
All WebProject employees are trained and made aware of their responsibilities under GDPR, including their responsibilities with regards to access, security and processing of any personal data stored on our servers.
Sub-Processors
We use the following sub-processors to provide our hosting and related services:
- ProEmails.UK - ProEmails for transactional emails, UK/EU regions
- Microsoft 365 - Business email services, UK data centers
- MaxMind - Fraud prevention/spam detection via IP address checking
- OVHcloud - Primary hosting infrastructure, UK and France, ISO 27001 and PCI-DSS certified
- iomart - UK Tier 4 data center, ISO 9001, 27001, 22301, and PCI DSS certified
We will notify you of any intended changes to sub-processors and provide you with the opportunity to object.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Data is retained in accordance with our Data Processing Agreement and your documented instructions
- Upon termination of services, we will return or securely delete all personal data within 30 days
- Backup data is automatically purged in accordance with our backup retention schedule
Data Breaches
In the unlikely event of a personal data breach occurring, we have established procedures to respond in accordance with UK GDPR requirements.
- Detection and Assessment: We have monitoring systems in place to detect potential data breaches
- Notification to Controller: We will notify you without undue delay upon becoming aware of a breach
- ICO Reporting: If the breach is likely to result in a risk to the rights and freedoms of individuals, we will assist you in reporting to the ICO within 72 hours
- Data Subject Notification: Where the breach is likely to result in a high risk, we will assist you in communicating with affected data subjects
- Documentation: We maintain records of all personal data breaches regardless of whether they require notification
Data Subject Rights
UK GDPR provides data subjects with several important rights:
- Right to Access: Data subjects have the right to obtain confirmation as to whether personal data concerning them is being processed
- Right to Rectification: Data subjects can request correction of inaccurate personal data
- Right to Erasure: Also known as the "right to be forgotten"
- Right to Restriction of Processing: Data subjects can request restriction of processing in specific situations
- Right to Data Portability: Data subjects can request their personal data in a structured, commonly used, and machine-readable format
- Right to Object: Data subjects can object to processing based on legitimate interests or direct marketing
- Rights related to Automated Decision-Making: Protection against decisions based solely on automated processing
We will respond to data subject requests within one month of receipt, in accordance with UK GDPR timeframes.
ICO Registration
WebProject is registered with the Information Commissioner's Office (ICO) as a data controller. Our registration details are available on the ICO website.
We Help You to Comply with UK GDPR
Upon request, we can provide:
- Data Processing Agreement (DPA) meeting UK GDPR requirements
- Technical and organisational measures (TOMs) documentation
- Sub-processor information and lists
- Evidence of our ICO registration
- Security and compliance certifications
- Assistance with data subject request handling where relevant
Your Right to Complain
If you believe that our processing of your personal data does not comply with UK GDPR, you have the right to complain to the Information Commissioner's Office (ICO).
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: https://ico.org.uk/
Helpline: 0303 123 1113
Data Protection Contact
Any questions, queries or requests for further information regarding our UK GDPR compliance should be sent to:
WebProject, 9 Orchard Road, Stevenage, Hertfordshire SG1 3HD
Email: [email protected]
Phone: +44 (0) 2034 328891
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. Organisations should consult with qualified legal professionals to ensure full compliance with UK GDPR, Data Protection Act 2018, and any other applicable regulations. This statement was last updated in March 2026.