Get your free preview site made for your business free today
    We Catch It Logo

    Data Processing Agreement

    Last Updated: 2026

    This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between We Catch It ("Processor", "We", "Us", "Our") and the Client ("Controller", "You", "Your").

    This Agreement applies where We Catch It processes personal data on behalf of a client in connection with the services we provide.

    1. Business Information

    Business Name: We Catch It

    Business Structure: Sole Trader

    Address:

    83 Edinburgh Road
    Harthill
    Shotts
    ML7 5PT

    Email: wecatchit@outlook.com

    Telephone: 07996 532477

    Website: https://wecatchit.uk

    2. Purpose

    This Agreement explains how personal data is processed when providing services including:

    • Smart Websites
    • Website Hosting
    • Website Maintenance
    • Smart Receptionist
    • Smart Chatbots
    • Missed Call Text Back
    • CRM Integration
    • Business Automation
    • SEO
    • Digital Marketing
    • Appointment Booking
    • Lead Management

    3. Definitions

    For the purposes of this Agreement:

    Controller means the organisation determining the purposes and means of processing personal data.

    Processor means We Catch It acting on behalf of the Controller.

    Personal Data means any information relating to an identified or identifiable individual.

    Processing includes collecting, storing, transmitting, analysing, deleting or otherwise using personal data.

    UK GDPR means the United Kingdom General Data Protection Regulation together with the Data Protection Act 2018.

    4. Roles

    In most circumstances:

    • The Client is the Data Controller.
    • We Catch It acts as the Data Processor.

    Where We Catch It collects personal information for its own business purposes, We Catch It acts as an independent Data Controller.

    5. Categories of Personal Data

    Depending upon the services provided, we may process:

    • Names
    • Business names
    • Email addresses
    • Telephone numbers
    • Mobile numbers
    • Missed call information
    • Appointment details
    • Chatbot conversations
    • Contact form submissions
    • Website enquiry information
    • CRM records
    • Marketing preferences
    • IP addresses
    • Browser information
    • Device information
    • Website analytics
    • Cookie identifiers

    6. Categories of Data Subjects

    Personal data may relate to:

    • Customers
    • Prospective customers
    • Employees
    • Website visitors
    • Business contacts
    • Suppliers
    • Contractors

    7. Purpose of Processing

    Personal data may be processed for purposes including:

    • Website functionality
    • Customer support
    • Appointment scheduling
    • Lead management
    • CRM integration
    • AI chatbot responses
    • Missed call text messaging
    • Smart Receptionist services
    • Business automation
    • Marketing campaigns
    • Website analytics
    • Service improvements
    • Fraud prevention
    • Security monitoring

    8. Lawful Processing

    We Catch It shall only process personal data:

    • in accordance with documented instructions from the Client;
    • where required by law; or
    • where necessary to provide the contracted services.

    9. Confidentiality

    Anyone authorised to process personal data on behalf of We Catch It is subject to appropriate confidentiality obligations.

    10. Security Measures

    We implement reasonable technical and organisational measures designed to protect personal data, including where appropriate:

    • Secure passwords
    • Encryption in transit
    • Secure hosting
    • Access controls
    • Authentication measures
    • Firewalls
    • Anti-malware protection
    • Software updates
    • Regular monitoring
    • Secure cloud services

    No internet-connected system can be guaranteed to be completely secure.

    11. Sub-processors

    To provide our services, we may engage trusted third-party processors, including:

    • Stripe
    • GoCardless
    • Twilio
    • OpenAI
    • Zapier
    • Calendly
    • Google Analytics
    • Google Ads
    • Google Maps
    • Microsoft Clarity
    • Meta (Facebook)
    • WhatsApp
    • Website hosting providers
    • Domain registrars
    • Cloud infrastructure providers

    These providers process personal data only as necessary to deliver the requested services and remain subject to their own privacy and security obligations.

    12. International Transfers

    Some third-party providers may process personal data outside the United Kingdom.

    Where international transfers occur, appropriate safeguards will be used where required under UK GDPR.

    13. Data Subject Rights

    Where We Catch It receives a request relating to:

    • Access
    • Rectification
    • Erasure
    • Restriction
    • Portability
    • Objection

    we will notify the Client where appropriate unless prohibited by law.

    The Client remains responsible for responding to requests where acting as Data Controller.

    14. Data Breaches

    If We Catch It becomes aware of a personal data breach affecting client data, we will notify the Client without undue delay after becoming aware of the incident where legally required.

    Notifications will include available information necessary to assist the Client in meeting their own legal obligations.

    15. Retention

    Personal data is retained only for as long as necessary to:

    • provide services;
    • comply with legal obligations;
    • resolve disputes;
    • enforce contractual rights;
    • maintain appropriate business records.

    Retention periods vary depending upon the type of service provided.

    16. Deletion of Data

    Upon termination of services, We Catch It may:

    • delete personal data;
    • return personal data where technically feasible;
    • retain limited records where required by law or for legitimate business purposes.

    Backup systems may retain encrypted copies for a limited period before automatic deletion.

    17. Client Responsibilities

    The Client agrees to:

    • obtain all necessary consents;
    • provide lawful instructions;
    • comply with UK GDPR;
    • ensure personal data supplied is accurate;
    • respond to data subject requests where acting as Controller.

    18. Audits

    Where reasonably necessary and proportionate, the Client may request information demonstrating compliance with this Agreement.

    Requests must be made in writing and may be subject to reasonable administrative charges where excessive or repetitive.

    19. Liability

    Each party remains responsible for its own compliance with applicable data protection legislation.

    Nothing within this Agreement limits liability where such limitation would be unlawful.

    20. Changes to this Agreement

    We Catch It may update this Data Processing Agreement from time to time to reflect changes in legislation, technology, or our services.

    The latest version will always be published on our website.

    21. Governing Law

    This Agreement shall be governed by the laws of Scotland.

    Any disputes shall be subject to the exclusive jurisdiction of the Scottish courts.

    22. Contact

    We Catch It

    83 Edinburgh Road
    Harthill
    Shotts
    ML7 5PT

    Email: wecatchit@outlook.com

    Telephone: 07996 532477

    Website: https://wecatchit.uk

    Google
    5.0
    Based on Google Reviews
    Avatar
    Hi there! Have a question? Talk with us here.
    Avatar
    Hi there! Have a question? Chat with us here.