Data Processing Agreement
Last updated: 11 August 2026
1. Definitions
- "Controller" means the business customer who subscribes to BaseCamp OS and who determines the purposes and means of processing personal data relating to their own customers and participants.
- "Processor" means BaseCamp OS (operated by HowMedia UK), who processes personal data on behalf of the Controller.
- "Data Subjects" means the end customers and activity participants whose personal data is stored in BaseCamp OS by the Controller.
- "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.
2. Subject matter and nature of processing
The Processor provides an operations management platform enabling the Controller to manage bookings, session scheduling, waivers, staff certifications, equipment maintenance, and customer records. In doing so, the Processor stores and processes personal data on behalf of the Controller as described below.
Categories of data subjects: The Controller's customers and activity participants.
Categories of personal data:
- Names and contact details (email, phone)
- Date of birth (where collected for age-restricted activities)
- Health declarations (special category data under Art. 9 UK GDPR)
- Signed digital waivers and timestamps
- Booking records and payment status
- Participant details and session attendance
Duration: For the duration of the Controller's subscription to BaseCamp OS, and thereafter as required by applicable law.
3. Processor obligations
The Processor shall, in accordance with Article 28 UK GDPR:
- Process personal data only on documented instructions from the Controller (which includes use of the platform in accordance with these terms), unless required to do so by law.
- Ensure that personnel authorised to process the data are subject to appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures in accordance with Article 32 UK GDPR, including encryption in transit, access controls, and password hashing.
- Not engage sub-processors without prior written authorisation from the Controller, save for the sub-processors listed in clause 5 below, which the Controller accepts by agreeing to this DPA.
- Assist the Controller in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection).
- Assist the Controller in meeting its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, prior consultation).
- Delete or return all personal data to the Controller upon termination of the service, and delete existing copies, unless retention is required by law.
- Make available all information necessary to demonstrate compliance with Article 28 and allow for audits and inspections by the Controller or its mandated auditors.
4. Controller obligations
The Controller warrants that:
- It has a lawful basis for all personal data it instructs the Processor to process.
- It has provided all required privacy notices to Data Subjects, including notice of the health declaration being special category data requiring explicit consent.
- It will not instruct the Processor to process data in a manner that would violate applicable data protection law.
- It is responsible for ensuring that any special category data (such as health declarations) is collected only where a valid Article 9 condition is met.
5. Approved sub-processors
The Controller authorises the Processor to engage the following sub-processors. The Processor will notify the Controller of any intended changes and give the Controller an opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA (SCCs / adequacy) |
| Mailgun Technologies | Transactional email delivery | USA / EU |
| Hostinger | Cloud hosting and infrastructure | EU |
6. Security incident notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting data processed under this DPA. The notification will include, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address it.
7. International transfers
Where personal data is transferred outside the UK or EEA (e.g. to Stripe or Mailgun in the USA), the Processor will ensure that such transfers are subject to appropriate safeguards, including the ICO's International Data Transfer Agreement (IDTA) or reliance on adequacy decisions where applicable.
8. Termination and return of data
Upon termination of the service, the Controller may export their data via the platform's export tools within 30 days of termination. After that period, the Processor will securely delete all Controller data unless retention is required by applicable law (e.g. financial records under the Companies Act 2006).
9. Governing law
This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
10. Acceptance
By accepting this DPA within the BaseCamp OS platform, the Controller confirms that it has read, understood, and agrees to the terms of this Data Processing Agreement. The acceptance is recorded with the accepting user's name, email address, IP address, and timestamp.