Data Processing Agreement
Tamar Ari Ltd (Company Number: 17350294), trading as Growth Market. This DPA forms part of the Agreement between Growth Market (Processor) and the Customer (Controller), and applies whenever we process Personal Data on the Customer's behalf in connection with the Services.
Last updated: 27 July 2026
1. Purpose
The purpose of this DPA is to ensure that Personal Data is processed in accordance with:
- UK General Data Protection Regulation (UK GDPR);
- Data Protection Act 2018;
- where applicable, the EU GDPR;
- any other applicable data protection legislation.
2. Definitions
Unless otherwise defined in the Agreement, the following definitions apply.
- Controller means the entity determining the purposes and means of processing Personal Data.
- Processor means Growth Market when processing Personal Data on behalf of the Customer.
- Personal Data has the meaning given under Applicable Data Protection Law.
- Processing includes collection, recording, storage, consultation, transmission, deletion and any other operation performed on Personal Data.
- Data Subject means an identified or identifiable natural person.
- Subprocessor means any third party engaged by Growth Market to process Personal Data.
3. Scope of processing
Growth Market shall process Personal Data solely for the purpose of providing the Services described in the Agreement.
Processing activities may include:
- website development;
- software development;
- CRM implementation;
- AI services;
- workflow automation;
- SEO;
- reputation management;
- hosting support;
- technical maintenance;
- customer support;
- consulting.
4. Processing instructions
Growth Market shall process Personal Data only:
- in accordance with documented instructions from the Customer;
- as necessary to perform the Agreement;
- where required by Applicable Law.
Where Growth Market believes that an instruction violates Applicable Law, it shall inform the Customer unless prohibited by law.
5. Confidentiality
Growth Market shall ensure that all employees, contractors and authorised persons who process Personal Data:
- are bound by confidentiality obligations;
- receive appropriate privacy awareness;
- access Personal Data only where necessary.
Confidentiality obligations shall survive termination of employment or contractual relationships.
6. Security measures
Growth Market shall implement appropriate technical and organisational measures including, where appropriate:
- encryption in transit;
- encryption at rest where appropriate;
- role-based access controls;
- multi-factor authentication;
- secure authentication procedures;
- audit logging;
- network monitoring;
- firewall protection;
- vulnerability management;
- regular software updates;
- malware protection;
- secure cloud infrastructure;
- access reviews;
- backup procedures;
- disaster recovery measures.
These measures shall be reviewed periodically according to the Company’s risk profile.
7. Subprocessors
The Customer authorises Growth Market to engage Subprocessors where reasonably necessary.
Growth Market shall ensure that every Subprocessor is contractually required to implement data protection obligations substantially equivalent to those contained in this DPA.
Growth Market remains responsible for the performance of its Subprocessors to the extent required by Applicable Law.
8. International transfers
Where Personal Data is transferred outside the United Kingdom or another jurisdiction requiring transfer safeguards, Growth Market shall implement appropriate legal mechanisms, including where applicable:
- UK International Data Transfer Agreement (IDTA);
- UK Addendum to the EU Standard Contractual Clauses;
- adequacy decisions;
- other recognised safeguards.
9. Data subject rights
Taking into account the nature of the Processing, Growth Market shall provide reasonable assistance to enable the Customer to respond to requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection;
- automated decision-making.
Growth Market shall not respond directly to Data Subject requests unless authorised or legally required.
10. Security incidents
Growth Market maintains procedures designed to detect, investigate and respond to Security Incidents.
Where Growth Market becomes aware of a Personal Data Breach affecting Customer Data, it shall notify the Customer without undue delay after becoming aware of the breach.
Such notification shall include, where reasonably available:
- nature of the incident;
- categories of affected data;
- likely consequences;
- mitigation measures taken;
- recommended actions.
11. Assistance
Growth Market shall provide reasonable assistance regarding:
- DPIAs;
- regulatory enquiries;
- breach investigations;
- security assessments;
- compliance documentation;
- lawful requests from supervisory authorities.
Such assistance may be subject to reasonable fees where the request falls outside the agreed Services.
12. Records
Growth Market shall maintain records relating to Processing activities where required by Applicable Law.
13. Audits
Where reasonably necessary, and subject to appropriate confidentiality obligations, the Customer may request information demonstrating compliance with this DPA.
Audits shall:
- be conducted during normal business hours;
- avoid disruption to Growth Market’s operations;
- be subject to reasonable advance notice;
- not compromise confidential information belonging to other customers.
Growth Market may provide independent audit reports or security certifications instead of permitting on-site inspections where appropriate.
14. Return or deletion of data
Upon termination of the Agreement, Growth Market shall, at the Customer’s written request and unless retention is required by Applicable Law:
- return Personal Data;
- securely delete Personal Data; or
- anonymise Personal Data.
Backup copies retained solely for disaster recovery purposes may remain until overwritten in accordance with normal retention procedures.
15. Liability
Nothing in this DPA shall increase the liability of either party beyond the liability limitations contained in the Agreement unless Applicable Law provides otherwise.
16. Order of precedence
Where this DPA conflicts with the Agreement concerning Personal Data processing, this DPA shall prevail.
17. Changes
Growth Market may update this DPA to reflect:
- legislative changes;
- regulatory guidance;
- technological developments;
- business operations.
Material changes shall become effective upon publication or notification where required.
18. Governing law
This DPA shall be governed by the laws of England and Wales.
Any dispute arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales, subject to any mandatory rights under Applicable Data Protection Law.
This page is maintained by TAMAR ARI LTD and is provided for information. It is not legal advice and is not an independent certification.