Data processing addendum
Last updated: 2026-06-29
This addendum forms part of the agreement between wausernames Ltd (“wausernames”) and any business customer (“Customer”) whose use of the service involves us processing personal data on the Customer's behalf. It supplements our privacy policy and terms of service.
1. Roles
For personal data wausernames processes to run its own marketplace (accounts, payments, KYC), wausernames is the controller — see the privacy policy. For personal data we process solely on a Customer's documented instructions, wausernames acts as processor and the Customer as controller.
2. Scope and instructions
We process personal data only to provide the service and on the Customer's documented instructions, unless required otherwise by law. The subject matter is the operation of the marketplace; the duration is the term of the agreement plus mandated retention.
3. Confidentiality and security
Personnel with access to personal data are bound by confidentiality. We apply appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, access controls, and audit logging.
4. Sub-processors
We use the sub-processors listed in our privacy policy (including Stripe, PostHog, our email, hosting, and database providers, and our AML screening provider), each under a data-processing agreement. We will give notice of changes to sub-processors.
5. International transfers
Where personal data is transferred outside the UK / EEA, we rely on adequacy decisions or Standard Contractual Clauses with the UK Addendum.
6. Data subject requests and breach
We assist the Customer in responding to data-subject requests and notify the Customer without undue delay after becoming aware of a personal-data breach affecting their data.
7. Deletion
On termination we delete or return personal data processed on the Customer's behalf, except where retention is required by law (for example, MLR 2017 transaction records).