Legal · Attachment 1 to the Managed IT Services Agreement
Data Processing Agreement
Last updated: 23 July 2026
This DPA is made on the same date as the Managed IT Services Agreement (the Linked Agreement), of which it forms Attachment 1, between the following parties:
- Little Big Tech Ltd, a company registered in England and Wales, with company number 13561910 of Hever Castle Golf Club, Hever Road, Edenbridge, Kent, TN8 7NP (we, us or our); and
- The company, partnership or sole trader named as the client in the Proposal, as further particularised in the Proposal, including its registered number and address (you or your),
together the Parties and each a Party. This DPA supplements the Linked Agreement entered into between the Parties and applies to the provision of Services under the Linked Agreement.
Background
- The Parties have entered into the Linked Agreement for the provision of Services.
- In the processing of Company Personal Data in connection with the Linked Agreement, each Party will perform the role/s set out in Annex 1A.
- The Parties would like to implement this DPA to set out each Party's rights and obligations in connection with the Processing of Company Personal Data under the Linked Agreement.
Commencement and Term
- This DPA will commence on the date the Linked Agreement takes effect and will continue for as long as the Linked Agreement remains in effect, or the Processor retains any of the Company Personal Data in its possession or control (whichever is the longer) (Term).
- By entering into this DPA, each Party agrees to be bound by the terms and conditions set out in this DPA, in exchange for the other Party also agreeing to be bound by this DPA.
Processing of Personal Data
- Each Party agrees to comply with Applicable Data Protection Law in the Processing of Company Personal Data.
- The Controller instructs the Processor to process Personal Data in accordance with this DPA (including in accordance with Annex 1).
- The Processor agrees to not process Company Personal Data other than on the Controller's documented instructions, and to the extent applicable, clause 11 of this DPA.
Processor Personnel
- The Processor agrees to take reasonable steps to ensure the reliability of any of the Contracted Processor's Personnel who may have access to the Company Personal Data, ensuring in each case that:
- access is strictly limited to those individuals who need to know / access the relevant Company Personal Data, as strictly necessary for the purposes of the Linked Agreement; and
- the relevant Personnel are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
- The Processor agrees to take reasonable steps to ensure the reliability of any of the Contracted Processor's Personnel who may have access to the Company Personal Data, ensuring in each case that:
Security
- Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor agrees to implement appropriate technical and organisational measures in relation to the Company Personal Data to ensure a level of security appropriate to that risk in accordance with Applicable Data Protection Law, and as further particularised in Annex 2.
- In assessing the appropriate level of security, the Processor agrees to take into account the risks that are presented by Processing, in particular from a Personal Data Breach.
Sub-Processing
- The Controller authorises the Processor's engagement of the Sub-Processors already engaged by the Processor at the date of this DPA, as described in Annex 3.
- Where the Processor wishes to engage a new Sub-Processor, the Processor agrees to provide written notice to the Controller of the details of the engagement of the Sub-Processor at least 14 days' prior to engaging the new Sub-Processor (including details of the processing it will perform). The Controller may object in writing to the Processor's appointment of a new Sub-Processor within 7 days of such notice, provided that such objection is based on reasonable grounds relating to data protection. In such event, the Parties will discuss such concerns in good faith with a view to achieving resolution. If the Parties are not able to achieve resolution, the Processor may, at its election:
- not appoint the proposed Sub-Processor;
- not disclose any Company Personal Data it processes on the Controller's behalf to the proposed Sub-Processor; or
- inform the Controller that it may terminate the Linked Agreement (including this DPA) for convenience, in which case, clause 13.2 will apply.
- The Controller agrees that the remedies described above in clauses 5.2(a)-(c) are the only remedies available to the Controller if it objects to any proposed Sub-Processor by the Processor.
- Where the Processor engages a Sub-Processor to process Company Personal Data, the Processor agrees to enter into a written agreement with the Sub-Processor containing data protection obligations no less protective that those in this DPA with respect to the Company Personal Data (including in relation to Restricted Transfers), and to remain responsible to the Controller for the performance of such Sub-Processor's data protection obligations under such terms.
Data Subject Rights
- Taking into account the nature of the Processing, the Processor agrees to assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligations, as reasonably understood by the Controller, to respond to requests to exercise Data Subject rights under the Applicable Data Protection Law.
- The Processor agrees to:
- promptly notify the Controller if it receives a request from a Data Subject under any Applicable Data Protection Law in respect of Company Personal Data; and
- ensure that it does not respond to that request except on the documented instructions of the Controller or as required by Applicable Data Protection Law to which the Processor is subject, in which case the Processor shall, to the extent permitted by Applicable Data Protection Law, inform the Controller of that legal requirement before the Contracted Processor responds to the request.
Personal Data Breach
- The Processor agrees to notify the Controller without undue delay and in any event, within 24 hours upon the Processor becoming aware of a Personal Data Breach affecting Company Personal Data, providing the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under Applicable Data Protection Law.
- The Processor agrees to co-operate with the Controller and take reasonable commercial steps as are directed by the Controller to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
- If the Controller decides to notify a Supervisory Authority, Data Subjects or the public of a Company Personal Data Breach, the Controller agrees to provide the Processor with advance copies of the proposed notices and, subject to Applicable Data Protection Law (including any mandated deadlines under the UK GDPR), allow the Processor an opportunity to provide any clarifications or corrections to those notices.
Data Protection Impact Assessment and Prior Consultation
- The Processor agrees to provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by article 35 or 36 of the UK GDPR or equivalent provisions of any other Applicable Data Protection Law (to the extent the Controller does not otherwise have access to the relevant information and such information is in the Processor's control).
Deletion or return of Personal Data
- Subject to this clause 9, and subject to any document retention requirements at law, the Processor agrees to promptly and in any event within 30 days of the date of cessation of any Services involving the Processing of Company Personal Data (Cessation Date), delete and procure the deletion of all copies of those Company Personal Data.
- The Processor agrees to provide written certification to the Controller that it has fully complied with this clause 9 within 30 days of the Cessation Date.
- Company Personal Data contained in immutable, archival or backup media may be retained beyond the Cessation Date until it is overwritten or expires in the ordinary course of the Processor's backup retention cycle, provided that such data is isolated from ordinary operational use, is not accessed or Processed for any other purpose, and remains protected in accordance with this DPA until deletion. Any certification given under clause 9.2 may be given on that basis.
Audit Rights
- Subject to this clause 10, where required by law, the Processor shall make available to the Controller on request all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller in relation to the Processing of the Company Personal Data by the Contracted Processors.
- Where clause 10.1 applies, any audit (or inspection):
- must be conducted during the Processor's regular business hours, with reasonable advance notice (which shall not be less than 30 days);
- will be subject to the Processor's reasonable confidentiality procedures;
- must be limited in scope to matters specific to the Controller and agreed in advance with the Processor;
- must not require the Processor to disclose to the Controller any information that could cause the Processor to breach any of its obligations under Applicable Data Protection Law;
- to the extent the Processor needs to expend time to assist the Controller with the audit (or inspection), will be funded by the Controller, in accordance with pre-agreed rates; and
- may only be requested by the Controller a maximum of one time per year, except where required by a competent Supervisory Authority or where there has been a Personal Data Breach in relation to Company Personal Data, caused by the Processor.
- Information and audit rights of the Controller only arise under clause 10.1 to the extent that the Linked Agreement does not otherwise give it information and audit rights meeting the relevant requirements of Applicable Data Protection Law.
Restricted Transfers
- The Parties agree that where the transfer of Company Personal Data between the Parties, or by the Processor to a Sub-Processor, is a Restricted Transfer, it will be subject to the UK Addendum (and documents or legislation referred to within it), which shall be deemed to be incorporated into this DPA, and:
- the Tables in Part 1 of the UK Addendum shall be populated with the relevant information set out in the Annexes to this DPA; and
- the UK Addendum is considered an appropriate safeguard.
- The Parties agree that where the transfer of Company Personal Data between the Parties, or by the Processor to a Sub-Processor, is a Restricted Transfer, it will be subject to the UK Addendum (and documents or legislation referred to within it), which shall be deemed to be incorporated into this DPA, and:
Liability
- Despite anything to the contrary in the Linked Agreement or this DPA, to the maximum extent permitted by law, the Liability of each Party and its affiliates under this DPA is subject to the exclusions and limitations of Liability set out in the Linked Agreement.
Termination
- A material failure or inability to comply with the terms of this DPA and/or Applicable Data Protection Law constitutes a material breach of the Linked Agreement. In such event, the Controller may, without penalty:
- require the Processor to suspend the relevant Processing of Company Personal Data until such compliance is restored, such suspension to take effect immediately where it is necessary in order for the Controller to comply with Applicable Data Protection Law or with the requirement of a Supervisory Authority; and/or
- terminate the Linked Agreement (including this DPA) on written notice to the Processor. Such termination will take effect immediately only where the breach is incapable of remedy or where the breach has not been remedied within the cure period set out in clause 17.4(a) of the Linked Agreement; otherwise it will take effect on expiry of that cure period.
- In the case of such termination, the Processor shall provide a prompt pro-rata refund of all sums paid in advance under the Linked Agreement which relate to the period after the date of termination. A suspension under clause 13.1(a) does not of itself give rise to a right to a refund.
- Notwithstanding the expiry or termination of this DPA, this DPA will remain in effect until, and will terminate automatically upon, deletion by the Processor of all Company Personal Data covered by this DPA, in accordance with this DPA.
- A material failure or inability to comply with the terms of this DPA and/or Applicable Data Protection Law constitutes a material breach of the Linked Agreement. In such event, the Controller may, without penalty:
General
- Amendment: Other than as expressly permitted under this DPA and to the extent permitted by law, this DPA may only be amended by written instrument executed by the Parties.
- Assignment: A Party must not assign or deal with the whole or any part of its rights or obligations under this DPA without the prior written consent of the other Party (such consent not to be unreasonably withheld).
- Confidentiality: Each Party agrees to keep this DPA and any information it receives about the other Party and its business in connection with this DPA (Confidential Information) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
- disclosure is required by law; or
- the relevant information is already in the public domain.
- Contracts (Rights of Third Parties) Act 1999: Notwithstanding any other provision of this DPA, nothing in this DPA confers or is intended to confer any right to enforce any of its terms on any person who is not a party to it.
- Acceptance: This DPA forms Attachment 1 to the Linked Agreement and is accepted by you at the same time, and in the same manner, as the Linked Agreement.
- Order of Precedence: In the event of any conflict or inconsistency between the agreements entered into between the Parties, the UK Addendum shall prevail, then the Annexes, followed by this DPA and then the Linked Agreement.
- Governing law and disputes: This DPA is governed by the laws of England and Wales. Each Party irrevocably and unconditionally submits to the exclusive jurisdiction of the courts operating in England and Wales and any courts entitled to hear appeals from those courts and waives any right to object to proceedings being brought in those courts.
- Notices: Any notice given under this DPA must be in writing addressed to the addresses set out in Annex 1A, or the relevant address last notified by the recipient to the Parties in accordance with this clause. Any notice may be sent by standard post or email, and will be deemed to have been served on the expiry of 48 hours in the case of post, or at the time of transmission in the case of transmission by email.
- Severance: If a provision of this DPA is held to be void, invalid, illegal or unenforceable, that provision is to be read down as narrowly as necessary to allow it to be valid or enforceable, failing which, that provision (or that part of that provision) will be severed from this DPA without affecting the validity or enforceability of the remainder of that provision or the other provisions in this DPA.
Definitions and Interpretation
- In this DPA, unless the context otherwise requires, all terms have the meanings given to them in the Annexes, and:
Applicable Data Protection Law means the laws and regulations applicable to the processing of Personal Data by the Parties in connection with the Linked Agreement, including the Data Protection Act 2018 (including the UK GDPR), and where applicable, the EU GDPR.
Company Personal Data means any Personal Data Processed by a Contracted Processor on behalf of a Controller in connection with the Linked Agreement (and where the Processor is also acting as a Controller, any Personal Data it processes in connection with the Linked Agreement).
Contracted Processor means the Processor or a Sub-Processor.
Controller means the Party specified in Annex 1A as the Controller that performs the role of a Controller as that term is defined under the UK GDPR.
Data Subject means any individual person that is identified or identifiable by way of Personal Data.
DPA means this Data Processing Agreement and all Annexes attached to it.
EU GDPR means Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation).
Liability means any expense, cost, liability, loss, damage, claim, notice, entitlement, investigation, demand, proceeding or judgment (whether under statute, contract, equity, tort (including negligence), misrepresentation, restitution, indemnity or otherwise), howsoever arising, whether direct or indirect and/or whether present, unascertained, future or contingent and whether involving a third party or a Party to this DPA or otherwise.
Linked Agreement means the Managed IT Services Agreement entered into between the Parties.
Personnel means in respect of a Contracted Processor, any of its employees, consultants, and subcontractors.
Processor means the Party specified in Annex 1A as a Processor that performs the role of a Processor as that term is defined under the UK GDPR.
Restricted Transfer means a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018.
Services means the services the subject of the Linked Agreement.
Sub-Processor means any person appointed by or on behalf of the Processor to process Company Personal Data on behalf of the Controller in connection with the Linked Agreement.
UK GDPR means the EU GDPR as incorporated into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018.
UK Addendum means the international data transfer addendum to the European Commission's standard contractual clauses for international data transfers approved by the Information Commissioner's Office under section 119A of the Data Protection Act 2018 on 21 March 2022 (version B.1.0), and as updated from time to time.
- The terms, “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” shall have the same meaning as in the EU GDPR or UK GDPR, as applicable.
- The word include shall be construed to mean include without limitation.
- In this DPA, unless the context otherwise requires, all terms have the meanings given to them in the Annexes, and:
Annex 1
Annex 1A – List of Parties
| we, us or our | LITTLE BIG TECH LTD, a company established in England and Wales, with company number 13561910. Registered office: Hever Castle Golf Club, Hever Road, Edenbridge, Kent, TN8 7NP Address for notices: Runway East London Bridge, 18 Crucifix Lane, London SE1 3JW Phone: 03333 055 331 Email: info@littlebigtech.co.uk Key contact person's contact details and role: Nick Haley, Chief Executive Officer, nick@littlebigtech.co.uk, Runway East London Bridge, 18 Crucifix Lane, London SE1 3JW Role: We are the data processor. We process personal data on your behalf solely for the purpose of delivering the Managed IT Services as set out in the Linked Agreement. Exporter/Importer: Importer. Where we make an onward transfer of Company Personal Data to a Sub-Processor located outside the UK, we act as exporter and that Sub-Processor acts as importer, in accordance with clause 5.4 and clause 11. |
| you or your | The company, partnership or sole trader named as the client in the Proposal, as further particularised in the Proposal, including its registered number, address, phone and email. Role: You are the data controller. You determine the purposes and means of processing personal data that you provide to us in connection with the Linked Agreement. Exporter/Importer: Exporter. |
Annex 1B: Description of Transfer
| Personal Data Transferred |
|
| Special Categories of Personal Data and criminal convictions and offences | The Services are not intended to involve, and the Processor does not require, the Processing of special categories of personal data or personal data relating to criminal convictions and offences. Such data may nevertheless be incidentally Processed where it is present in the Controller's systems, mailboxes, files or support material. The Processor does not seek out, extract or otherwise Process such data for any purpose beyond delivery of the Services, and applies the technical and organisational measures set out in Annex 2 to all Company Personal Data without distinction. |
| Relevant Data Subjects |
|
| Frequency of the transfer | Continuous |
| Nature of the transfer | As specified in the Linked Agreement, this DPA, including without limitation the collection, storage, retrieval, use and transmission of Company Personal Data by us as necessary to provide, maintain and improve the Services. |
| Purpose of processing | The purpose of the transfer and processing are as specified in the Linked Agreement and this DPA. |
| Duration of the Processing | The term of the Linked Agreement and for a period of 30 days after termination or expiry of the Linked Agreement after which all Company Personal Data will be deleted in accordance with clause 9 of this DPA. |
Annex 1C: Information required for the UK Addendum
Information required for Table 2 of the UK Addendum
| Module | Module in operation | Clause 7 (Docking Clause) | Clause 11 (Option) | Clause 9a (Prior/General Authorisation) | Clause 9a (Time period) | Importer data combined with Exporter data? |
|---|---|---|---|---|---|---|
| 1 | No | n/a | n/a | — | — | — |
| 2 | No | n/a | n/a | n/a | — | — |
| 3 | Yes | n/a | n/a | General Authorisation | 14 days | No |
| 4 | No | n/a | n/a | — | — | n/a |
Information required for Table 4 of the UK Addendum
Ending this Addendum when the Approved UK Addendum changes — which Parties may end this Addendum as set out in Section 19 of Part 2 of the UK Addendum: Neither Party (neither the Importer nor the Exporter may end this Addendum under Section 19).
Annex 2
Technical and Organisational Measures Including Technical and Organisational Measures to Ensure the Security of the Data
| Designated data protection officer (if required) or privacy manager | Nick Haley, Chief Executive Officer, acts as privacy lead. There is no dedicated internal privacy team; Little Big Tech Ltd is not required to appoint a formal Data Protection Officer under Article 37 UK GDPR. |
| Security certifications | Little Big Tech Ltd is Cyber Essentials certified and applies Cyber Essentials standard configuration to all managed environments. Little Big Tech Ltd also holds the Assurix Trusted MSP Mark, an independently audited certification of its security posture and operational standards, reassessed on a continuous basis against the Assurix framework. |
| Internal policies e.g. security policy, data retention and deletion policies | Security policy, data retention and deletion policy, and acceptable use policy in place. Data is retained in line with a documented retention schedule (for example: client tickets and support logs, 3 years; security and audit logs, minimum 12 months; system backups, 30 days daily / 12 months monthly; HR records, 6 years post-employment), with secure destruction on expiry. The Acceptable Use Policy is reissued to all staff for mandatory re-acknowledgement annually, or sooner following any material update. |
| Pseudonymisation and encryption of personal data | Encryption of data at rest and in transit across all managed environments. Data at rest is encrypted using AES-256 (including BitLocker/FileVault full-disk encryption); data in transit is encrypted using TLS 1.2 or higher. Personal Data is not currently pseudonymised or anonymised as part of the Services. |
| Product security features | Multi-factor authentication, Conditional Access policies, Microsoft Defender or equivalent EDR solution, 24/7 SOC monitoring. |
| Network security | Managed Microsoft Intune or Addigy device management platform, vulnerability management, patch management, and email filtering. Little Big Tech operates a cloud-native architecture with no internally hosted production servers; all managed environments are cloud/SaaS-based (principally Microsoft 365 and Google Workspace). Endpoint firewalls are centrally managed via Microsoft Defender for Endpoint and Microsoft Intune, with no exposed RDP and no legacy insecure protocols in use, and all activity is monitored by a 24/7 Security Operations Centre (SOC). Vulnerability scans are run monthly across all systems (weekly for internet-facing and high-risk assets), and remediation prioritised by severity. |
| Physical security and disaster recovery | All Personnel subject to confidentiality obligations. Access limited to what is necessary to perform the Services. The London office (Runway East, London Bridge) is a coworking space — physical access and building security is managed by Runway East as the building operator. The Harwich (Technical Support Office) and Kent (Projects Office) sites are operated directly by Little Big Tech, with lock-and-key access restricted to Little Big Tech staff. Backups are held via Axcient x360 Cloud (SOC 2 certified, immutable AirGap storage) following the 3-2-1 backup principle, with recovery testing performed at least quarterly and a full disaster recovery simulation at least annually. |
| Human resources security | DBS (Disclosure and Barring Service) checks are conducted on all new starters, with a rollout to annual checks across all existing staff currently underway. Personnel with access to Company Personal Data are direct employees only — no contractors are engaged in technical roles — and are bound by confidentiality obligations under their employment contract, covering non-disclosure, non-use, and return or deletion of confidential information on termination. Access is revoked immediately upon departure, with accounts disabled and privileged access removed the same day. The password policy requires a 12-character minimum, prohibits sharing, and mandates multi-factor authentication on all accounts; passwords are reset on detection of compromise or a high-risk sign-in rather than on a fixed rotation schedule. All staff complete mandatory data protection and security awareness training annually. |
Annex 3
List of Subprocessors
The Controller authorises the Processor to engage third-party sub-processors as reasonably required to deliver the Services, including cloud platform providers, security vendors, backup service providers, and device management platform providers. The Processor maintains a current list of Sub-Processors, which is available to the Controller upon written request. The Processor will notify the Controller of any new Sub-Processor in accordance with clause 5.2 of this DPA.
Questions about this agreement?
Get in touch and our team will be happy to talk you through it.
Get in Touch