Data Processing Agreement
Last updated: 26 August 2026
1. Parties and background
This Data Processing Agreement (DPA) is between Holtbox (“we”, “us”, “our”) — the provider of TheArc — and the organisation that subscribes to TheArc (“you”, “your”).
This DPA is incorporated into the TheArc Terms of Service (ToS) by reference, as set out in clause 6.1 of the ToS. It sets out how we process personal data on your behalf, in line with the UK GDPR (Article 28) and the Data Protection Act 2018, and the EU GDPR where it applies to the processing.
Where this DPA and the ToS conflict, this DPA prevails in respect of data protection matters.
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the UK GDPR (and, where it applies, the EU GDPR).
“Customer personal data” means personal data we process on your behalf in the course of providing TheArc.
“ToS” means the TheArc Terms of Service, as updated from time to time.
3. Details of processing
The subject matter, nature and purpose of the processing, its duration, and the categories of data subjects and personal data involved, are set out in Schedule 1.
4. Our obligations as processor
4.1 We will process Customer personal data only on your documented instructions, unless we are required to process it by law to which we are subject. In that case we will tell you of the legal requirement before processing, unless the law concerned prohibits that information on important grounds of public interest.
4.2 Our processing on your behalf is limited to providing TheArc to you, as described in the ToS (clauses 1 and 5.1). You instruct us to process Customer personal data for that purpose by using TheArc and by accepting these documents.
4.3 We ensure that persons authorised to process Customer personal data on our behalf are subject to appropriate obligations of confidentiality.
4.4 We take the technical and organisational security measures required by Article 32 of the UK GDPR, as described in Schedule 2, and keep them under review.
4.5 We may engage sub-processors only in accordance with clause 7.
4.6 Taking into account the nature of the processing, we will assist you, by appropriate technical and organisational measures so far as possible, to fulfil your obligation to respond to requests from data subjects exercising their rights under Chapter III of the UK GDPR (see clause 5).
4.7 Taking into account the nature of the processing and the information available to us, we will assist you with your obligations under Articles 32 to 36 of the UK GDPR (security, personal data breach notification, data protection impact assessments, and prior consultation with the supervisory authority).
4.8 We will make available to you all information necessary to demonstrate our compliance with Article 28, and allow for and contribute to audits, as set out in clause 10.
5. Data subject rights
5.1 If a data subject contacts us directly with a request relating to Customer personal data, we will direct them to you and tell you about the request, unless we are prevented from doing so by law.
5.2 We will not respond to the data subject ourselves without your instructions, unless we are required to do so by law.
5.3 We will assist you, so far as possible, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction of processing, data portability, and objection).
6. Personal data breaches
6.1 If we become aware of a personal data breach affecting Customer personal data, we will notify you without undue delay after becoming aware of it (as required by Article 33(2) of the UK GDPR). This reflects the promise in clause 8.2 of the ToS that we will tell you promptly.
6.2 The notification will include, so far as is available to us: the nature of the breach; the categories and approximate numbers of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects.
6.3 We will assist you, as needed, in notifying the supervisory authority and affected data subjects, taking into account the nature of the processing and the information available to us.
7. Sub-processors
7.1 You give us general written authorisation to engage sub-processors for the purpose of providing TheArc (Article 28(2) and (4) of the UK GDPR).
7.2 We maintain a list of our sub-processors in Schedule 3. Before engaging a new sub-processor, or changing a listed one, we will give you reasonable notice of the intended change so you have the opportunity to object. If you object on reasonable data-protection grounds and the matter cannot be resolved, you may terminate the affected part of the service on written notice.
7.3 We will impose on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA (Article 28(4)). We remain liable to you for the performance of our sub-processors' obligations, as set out in clause 12.
8. International transfers
8.1 We process Customer personal data within the United Kingdom and/or the European Economic Area. If we transfer Customer personal data outside the UK (or, where the EU GDPR applies, outside the EEA), we will ensure that appropriate safeguards are in place under Chapter V of the UK GDPR, and we will reflect the transfer in Schedule 3 and notify you.
Hosting is with Ionos in the United Kingdom (UK datacenter); backups are stored at Holtbox's own premises in Hanham, South Gloucestershire, UK. No transfers outside the UK/EEA are involved for archive data.
9. Security measures
We apply the technical and organisational security measures set out in Schedule 2, in line with Article 32 of the UK GDPR and clause 8.2 of the ToS.
10. Audit and compliance
10.1 We will make available to you, on request, all information reasonably necessary to demonstrate our compliance with this DPA.
10.2 If you require an audit beyond that, it will be carried out by an independent auditor mandated by you, at your cost, on reasonable notice, no more than once per year, during normal business hours, and subject to our security and confidentiality obligations and to the rights of our other customers. Audits will be conducted in a way that does not compromise the security of our systems or the data of our other customers. We may agree a different frequency where required by your supervisory authority.
11. Return and deletion
11.1 On termination of the ToS, we will provide you with an export of your data on request. You must request the export within 30 days of the termination notice; after that window, we will delete your data from TheArc (subject to any legal retention obligations on us).
11.2 This reflects clause 5.2 of the ToS. Once the export has been delivered and any legal retention period has ended, we will delete all remaining copies of Customer personal data, except where law requires us to keep them (in which case we will keep them confidential and process them only for that legal purpose).
12. Liability
12.1 Nothing in this DPA limits or excludes liability that cannot lawfully be limited or excluded, including any liability arising under data protection law that applies to us as processor.
12.2 Our liability to you under or in connection with this DPA is subject to the liability provisions of the ToS (clause 10), except to the extent that the law does not permit that limitation or exclusion.
13. Term
This DPA starts when processing of Customer personal data starts (which is when you begin a trial, demo or subscription), and continues until the ToS ends and our obligations under clause 11 are complete.
14. Governing law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction (matching clause 13.2 of the ToS).
Schedule 1 — Details of processing
Subject matter: The provision of TheArc, Holtbox's archive management software.
Nature and purpose of the processing: Processing the information you enter into TheArc so that you can record and manage physical folders — where they are stored, when they are recalled, who has them, and when they are destroyed. This includes user accounts and the audit trail of actions taken in TheArc.
Duration: The term of the ToS, plus the period until deletion or return under clause 11.
Categories of data subjects:
- Your employees and other authorised users of TheArc.
- Individuals whose details appear in the archive records you enter into TheArc — for example, people named in folder descriptions, references, or in notes on folder history.
Categories of personal data:
- Account details of your users: name, email address, and actions they take in TheArc.
- Information you choose to enter into archive records, which may include individuals' names and reference details.
- Notes entered on folder history, which may include individuals' names or other details.
- Audit trail information: who took which action, and when.
Note: what is actually processed depends on what you record. We process the data you put in — we do not add to it.
TheArc is designed to hold minimal personal data: client references, names, and dates relating to physical folders, plus short notes on folder history — not case files or documents. This reflects the product as at 25 August 2026; if the data we process changes, this Schedule must be updated.
Schedule 2 — Security measures
- Access to TheArc is by named user accounts. Users are given the least access their role needs (least privilege). The exception is the person who initiates the signup, who becomes the system administrator for the organisation.
- Passwords are stored as salted one-way hashes, and account credentials are protected by multi-factor authentication.
- Data is encrypted in transit (TLS) between your browsers and TheArc, and between our systems.
- Data is encrypted at rest.
- Full backups of your data are taken nightly (ToS clause 7.3), with restore capability.
- Our personnel who have access to Customer personal data are subject to confidentiality obligations.
- Our infrastructure and software are kept patched and under review.
Schedule 3 — Sub-processors
| Sub-processor | Service | Data | Location |
|---|---|---|---|
| Ionos | Hosting provider (VPS) | Customer personal data stored by TheArc | UK (Ionos UK datacenter) |
| Stripe | Payment processing | Payment data only — not archive data; payment details are processed by Stripe under your direct agreement with Stripe | US company; EU data region (Ireland) for UK/EU customers, with transfers to the US under the Data Privacy Framework |
| Holtbox (own infrastructure) | Backup storage | Customer personal data (backups) | Holtbox offices, Hanham, South Gloucestershire, UK |
The backup row is Holtbox's own infrastructure, not a third-party sub-processor — listed so the location of all Customer personal data is visible. The list will be updated if we engage any new sub-processor (clause 7).