Doxelio Digital Agency

Legal

Data Processing Addendum

Baseline processor terms for client projects where we process personal data on a client's behalf.

Last updated: May 3, 2026

Doxelio Digital Agency is a trading brand operated by MegaDev Ltd, company registration number 208560960. These pages are provided for transparency and general information. They are not a substitute for legal advice tailored to a specific contract, country, or regulated industry.
01

Purpose

This Data Processing Addendum applies when MegaDev Ltd, operating Doxelio Digital Agency, processes personal data for a client as a processor or service provider. It supplements the applicable service agreement.

02

Processing instructions

We process client personal data only to provide the agreed services, follow documented client instructions, maintain security, comply with law, and support the project.

03

Categories of data

  • Website visitor data, contact form submissions, customer records, order details, support requests, account data, analytics data, logs, and technical identifiers.
  • The exact data depends on the client's website, integrations, hosting, CRM, ecommerce platform, and requested services.
04

Subprocessors

We may use hosting, cloud, email, analytics, project management, security, automation, payment, and support providers as subprocessors where needed. We aim to use providers with appropriate confidentiality, security, and data protection commitments.

05

Confidentiality and security

  • People with access to client data are expected to handle it confidentially.
  • We use reasonable technical and organisational measures appropriate to the project scope.
  • Clients remain responsible for account ownership, lawful notices, consent, and the instructions they give us.
06

Assistance

Where reasonably possible and within the agreed service scope, we assist clients with data subject requests, security incidents, audits, deletion, export, and compliance questions related to the services we provide.

07

Deletion or return

After services end, we will delete or return client personal data within a reasonable period unless retention is required by law, backup cycles, dispute protection, accounting, or legitimate security needs.