Legal
Data processing agreement
Last updated 27 August 2026.
This agreement is required by Article 28 of the General Data Protection Regulation. It governs personal data that we process on your behalf when we host and publish your website. It forms part of our terms of service and applies for as long as those terms do.
1. Scope
This agreement is between Software Hardware and Application Design Solutions Limited , company number 681226, of Drumaboden, Ramelton, Co. Donegal, F92YF97, Ireland, trading as Findable (“we”, the processor), and the business buying the service (“you”, the controller).
The processing it covers is set out in Annex 1. It applies in addition to our terms of service. Where the two conflict on the handling of personal data, this agreement prevails.
2. Roles
You are the controller of the personal data published on your site and of any personal data your customers send you through it. You decide what is published and why.
We are the processor. We process that data only to provide the service, and we do not determine the purposes for which it is used.
3. Our instructions
We process personal data only on your documented instructions. Your instructions are: the content you enter or approve for publication, the requests you send us by email, and this agreement together with our terms of service.
We will tell you if, in our opinion, an instruction infringes data protection law. If we are required by law to process personal data otherwise than on your instructions, we will tell you before doing so unless the law prohibits it.
4. Confidentiality
Every person we authorise to process personal data under this agreement is bound by an obligation of confidentiality. We limit access to those who need it to provide the service.
5. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32. Those measures are described in Annex 2.
We may change a measure, provided the overall level of security is not reduced.
6. Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 3. We impose data protection obligations on each of them that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may end the agreement under clause 4 of our terms of service without penalty.
7. Your customers’ rights
Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests from individuals exercising their rights under Chapter III of the GDPR.
If a request reaches us directly, we will not respond to it ourselves. We will pass it to you without undue delay.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed.
We will assist you in meeting your own obligations under Articles 33 to 36, including notifying the Data Protection Commission and, where required, affected individuals.
9. Deletion and return
On the ending of the service, we will delete the personal data we process on your behalf within 30 days of your request, and provide you with a copy of your site as static files beforehand.
We may retain personal data where we are required to do so by law, in which case we will retain it only for as long as that law requires and continue to protect it under this agreement.
10. Information and audit
We will make available to you the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
Audits are to be arranged in advance, at reasonable intervals, and carried out in a way that does not disrupt the service to other clients.
11. International transfers
Where a sub-processor listed in Annex 3 processes personal data outside the European Economic Area, that transfer is made under an adequacy decision or under standard contractual clauses adopted by the European Commission, together with any supplementary measures required.
12. Duration
This agreement takes effect when you begin using the service and continues for as long as we process personal data on your behalf. Clauses 4, 5, 9 and 10 survive its ending for as long as we hold any of that data.
Annex 1 — the processing
Subject matter and duration
Hosting and publication of your website, and the delivery of messages sent to you through it, for the duration of your subscription.
Nature and purpose
Storage, publication and transmission, for the purpose of operating a public website for your business and letting you keep its content up to date.
Types of personal data
- Names, photographs, roles and descriptions of people you choose to publish on your site, such as an owner or a member of staff.
- Business contact details published on your site, where these identify an individual — for example a sole trader’s own name, phone number or address.
- Where your site includes an enquiry form, the content of messages sent through it and any contact details the sender provides.
Categories of individuals
- You, and any people you employ or engage whose details you publish.
- Members of the public who contact you through your site.
Annex 2 — security measures
Access to the portal
There are no passwords. Signing in requires a single-use link sent to a known address, which expires after fifteen minutes and cannot be reused. Link requests are rate limited per address and per network address, and the request never reveals whether an address is registered.
Credentials at rest
Sign-in links and session tokens are stored only as SHA-256 hashes, so a copy of the database is not a set of usable credentials. Session cookies are HTTP-only, SameSite=Lax, and marked Secure whenever the portal is served over HTTPS.
Separation between clients
Every request that reads or writes a site compares the site named in the URL against the site belonging to the signed-in account, and refuses where they differ. Staged photographs are stored under a per-client prefix and are addressable only by a hash of their own contents.
Photographs
Uploaded images are re-encoded before publication and all embedded metadata, including any GPS coordinates recorded by a phone, is removed. Files are limited in size and rejected if their decoded dimensions are implausible.
Transport and browser policy
All sites and the portal are served over HTTPS. Each site carries a Content Security Policy restricting scripts, styles, fonts and images to known origins, together with nosniff, a referrer policy, and framing restricted to the portal.
Nothing stored on visitors’ devices
Sites we build set no cookies and write nothing to browser storage. Visit counts are recorded at the server in aggregate and are not linked to an individual or a device.
Payment data
Card and bank details are collected by Stripe and are never transmitted to or stored by us. We receive only the amount and the outcome.
Database
The database runs in the West Europe region. The application connects with an account holding only the privileges it needs, separate from the account used to change the schema.
Change records
Every change to a site is recorded with the account that made it and the time it was made, so an incorrect change can be identified and reversed.
Credentials and deployment
Service credentials are held outside the source repository. Deployments are refused automatically where the artefact is built for a different destination than the one it is being sent to.
Annex 3 — sub-processors
- Cloudflare — Serves the websites and stores their files and photographs.
- Microsoft Azure — Runs the portal application and its database, in the West Europe region.
- Stripe — Takes payments and holds payment details, which do not reach us.
- SMTP2GO — Delivers outbound email, including sign-in links and service notices.
Outbound email is sent through our own email service, which uses SMTP2GO to deliver it. We engage no other sub-processor for personal data processed on your behalf.