Legal
Data Processing Agreement
Last updated: 28 September 2026
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the SiteScore Terms of Service between Social Quill LTD ("Social Quill") and the business customer using SiteScore ("Customer").
It applies only where Social Quill processes personal data solely on behalf of the Customer as part of providing SiteScore. For that processing:
Customer = Controller
Social Quill LTD = Processor
Social Quill is not a processor for every piece of data handled by SiteScore. The relationship depends on the particular processing activity. For example, Social Quill acts as a controller for Customer account, billing and security data, as described in our Privacy Policy.
2. Subject matter
Processing of personal data that the Customer submits to, or collects through, SiteScore, such as client records, lead information captured through branded audit pages or widgets, client portal invitations and reports.
3. Duration
For as long as Social Quill provides SiteScore to the Customer, and afterwards until the data is deleted in accordance with section 13.
4. Nature and purpose of processing
Storage, organisation, retrieval, display and transmission of personal data, solely to provide SiteScore features the Customer chooses to use, such as projects, client access, lead management, reporting and monitoring.
5. Categories of personal data
- names;
- email addresses;
- telephone numbers;
- company names;
- website addresses;
- notes entered by the Customer;
- lead status and source information;
- audit information associated with a client or lead.
6. Categories of data subjects
- the Customer's clients and their staff;
- the Customer's leads and prospective clients;
- people invited by the Customer to view a client portal.
7. Instructions from the controller
Social Quill will process personal data only on the Customer's documented instructions, which include these Terms, this DPA and the Customer's use of SiteScore's features, unless required to do otherwise by law. Social Quill will tell the Customer if it believes an instruction breaches applicable data-protection law.
8. Confidentiality
Social Quill will ensure that people authorised to process the personal data are subject to appropriate confidentiality obligations.
9. Security
Social Quill will implement appropriate technical and organisational measures designed to protect the personal data, taking into account the nature of the processing and the risks involved.
10. Subprocessors
The Customer gives general authorisation for Social Quill to use the subprocessors listed on our Subprocessors page. Social Quill will impose data-protection obligations on subprocessors that are appropriate to the processing, and remains responsible for their performance. Where required, Social Quill will communicate material changes to the list in accordance with applicable contractual and legal requirements.
11. International transfers
Personal data may be processed outside the United Kingdom by Social Quill's subprocessors. Where required by applicable data-protection law, appropriate safeguards or transfer mechanisms will be used.
12. Assistance
Taking into account the nature of the processing, Social Quill will provide reasonable assistance to the Customer in:
- responding to requests from data subjects exercising their rights;
- meeting security obligations;
- data protection impact assessments and consultations with supervisory authorities, where required.
If Social Quill receives a data-subject request relating to the Customer's data, it will refer the request to the Customer where reasonably possible.
13. Personal data breaches
Social Quill will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably available to help the Customer meet its own obligations.
14. Deletion and return of data
The Customer can delete client, lead and report data within SiteScore at any time, and can delete its account. On termination, Social Quill will delete the Customer's personal data, subject to legal, security and backup retention requirements. Data remaining in backups will be overwritten in the ordinary course.
15. Audit and assurance
Social Quill will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it appoints, on reasonable notice and subject to confidentiality.
16. Contact
To request a signed copy of this DPA, or for any question about it, contact info.socialquill@gmail.com.
