Legal
Data Processing Addendum
Last updated: 16 September 2026
This Data Processing Addendum (DPA) forms part of the Simply Link Terms of Service and explains how Simply Works LTD processes customer personal data on behalf of merchants using Simply Link.
1. Parties and scope
This DPA is between Simply Works LTD, trading as Simply Link (Simply Works, we, us), and the person or business that has accepted the Simply Link Terms of Service (Merchant, you).
It applies where Simply Works processes personal data on your behalf in connection with the Simply Link service and you are the controller of that personal data. It is intended to satisfy the requirements for controller-processor contracts under Article 28 of the UK GDPR.
This DPA is incorporated into the Terms of Service. If there is a conflict between this DPA and the Terms about processing covered by this DPA, this DPA takes priority to the extent of the conflict.
2. Roles
You determine why and how you use customer information for your business, including which customers you add, what payment requests you create, what information you enter, who you contact, and when you ask Simply Link to send supported communications. For that processing, you are normally the controller and Simply Works acts as your processor.
Simply Works acts as an independent controller where we determine our own purposes and means of processing, including merchant account administration, subscription billing, platform security, fraud and abuse prevention, risk and compliance activity, legal obligations, and service analytics. That processing is described in our Privacy Policy and is not processor activity under this DPA.
Stripe may act as an independent controller or processor for payment and Connected Account processing under Stripe's own terms and privacy documentation. This DPA does not change Stripe's legal role.
3. Details of the processing
- Subject matter
- Providing Simply Link's payment-request, tracking, reminder, recurring-request, receipt, and related account features on your behalf.
- Duration
- For the period you use the Service and for the limited period needed to complete deletion, return, backup rotation, dispute handling, or legal retention obligations after the relationship ends.
- Nature and purpose
- Receiving, storing, retrieving, organising, displaying, transmitting, and deleting Customer Personal Data as necessary to provide the Service according to your settings and instructions.
- Data subjects
- Your customers, prospective customers, payers, and authorised customer contacts whose information you enter into or use through Simply Link.
- Personal data
- Names, email addresses and other customer contact information you provide; service and payment-request information; payment status and transaction metadata; reminder, receipt and communication metadata; and other Customer Personal Data you choose to submit through supported fields.
Simply Link does not ask customers to enter card details into Simply Link. Card details are entered into Stripe's checkout environment and are handled by Stripe.
Simply Link is not designed for special category personal data or criminal offence data in payment-request titles, descriptions, reminder wording, or other public-facing free-text fields. Unless we expressly agree otherwise in writing, you must not use those fields to submit health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or identification biometric data, sex-life or sexual-orientation information, criminal allegations, convictions, or similar sensitive information.
4. Your instructions and responsibilities
The Terms, this DPA, your use of the Service, and the settings and actions you select in Simply Link constitute your documented instructions to us for processor activity. Additional instructions must be agreed in writing where they fall outside the normal operation of the Service.
You are responsible for:
- ensuring that you have a lawful basis and any other required conditions for the Customer Personal Data you provide to us;
- giving individuals any privacy information you are required to provide as controller;
- ensuring your instructions comply with applicable data protection law;
- using only the personal data reasonably necessary for your payment and customer-management purpose; and
- not entering private or sensitive personal information into public-facing payment-request fields.
If we believe an instruction infringes applicable data protection law, we will inform you unless the law prohibits us from doing so. We may pause the affected processing while the issue is resolved.
5. Our processor obligations
For Customer Personal Data covered by this DPA, Simply Works will:
- process it only on your documented instructions, unless UK law requires otherwise;
- ensure people authorised to process it are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures taking account of the nature and risks of the processing;
- assist you, taking account of the nature of the processing and information available to us, with data-subject rights requests and your obligations relating to security, breach notification, data protection impact assessments and prior consultation;
- provide information reasonably necessary to demonstrate compliance with this DPA; and
- not sell Customer Personal Data or use it for unrelated advertising purposes.
6. Security measures
We maintain measures appropriate to the risk and the Service. These include, as applicable:
- HTTPS/TLS for data transmitted between supported clients and the Service;
- authentication and access controls for merchant accounts and administrative access;
- server-side protection of privileged service credentials and secrets;
- database access controls, including row-level access controls where used by the Service;
- managed infrastructure controls for storage, resilience, backups and availability supplied by our hosting and database providers;
- application logging, monitoring, rate limiting and fraud or abuse controls where appropriate; and
- reasonable software, dependency and security maintenance.
Security measures may evolve as technology and risks change, provided we do not materially reduce the overall protection of Customer Personal Data without a lawful reason.
7. Sub-processors
You give Simply Works general written authorisation to use sub-processors to help provide the Service. Our current principal sub-processors for Customer Personal Data are:
| Provider | Purpose |
|---|---|
| Supabase | Managed database, authentication and storage infrastructure. |
| Vercel | Application hosting, delivery, infrastructure and technical logging. |
| Resend | Transactional email delivery for supported reminders, receipts and operational customer communications. |
We will put written terms in place with sub-processors that provide the data-protection obligations required by applicable law. We remain responsible for the performance of our sub-processors to the extent required by UK GDPR.
If we intend to add or replace a sub-processor that will process Customer Personal Data, we will give you reasonable advance notice in writing, where reasonably practicable, and a reasonable opportunity to object on genuine data-protection grounds. If we cannot reasonably resolve an objection, either party may end the affected Service in accordance with the Terms.
Stripe's payment and Connected Account processing is governed separately by Stripe's terms and privacy documentation. Stripe is not treated as a sub-processor under this section to the extent it determines its own purposes or acts under a separate legal relationship.
8. International transfers
Some of our providers may process personal data outside the UK. Where Simply Works makes a restricted transfer of Customer Personal Data as processor, we will use a transfer mechanism permitted by UK data protection law, such as applicable UK adequacy regulations or an appropriate safeguard including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard, together with any required transfer assessment.
Where you instruct us to make an international transfer that is not covered by our normal Service arrangements, you are responsible for ensuring your instruction is lawful and for providing any information reasonably required to implement an appropriate safeguard.
9. Data-subject requests
If we receive a request from an individual that relates primarily to Customer Personal Data we process on your behalf, we will normally direct the individual to you or notify you, unless we are legally required to respond ourselves. Taking account of the nature of the processing, we will provide reasonable assistance through available functionality or support so you can respond to valid requests.
Requests relating to processing for which Simply Works is an independent controller are handled under our Privacy Policy.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data that we process on your behalf, we will notify you without undue delay and provide information reasonably available to us to help you meet your legal obligations. We may provide information in stages as our investigation develops.
Our notification of an incident is not an admission of fault or liability. You remain responsible, as controller, for deciding whether notification to the ICO or affected individuals is required, unless applicable law places that responsibility on us for our own controller processing.
11. DPIAs and regulatory assistance
Taking account of the nature of the processing and information available to us, we will provide reasonable assistance if you need information from us for a data protection impact assessment, security assessment, breach assessment, or prior consultation with the ICO relating to our processor activity.
12. Return and deletion
When processor services end, at your choice and subject to available export functionality or a reasonable written request, we will delete or return Customer Personal Data and delete remaining copies, except where UK law requires retention or where limited copies remain temporarily in protected backups pending normal rotation.
This section does not require us to delete information we separately process as an independent controller where we have a lawful reason to retain it, such as records required for accounting, security, fraud prevention, disputes, or legal claims. We will retain only what is necessary for those purposes.
13. Information, audits and inspections
We will make available information reasonably necessary to demonstrate compliance with the processor obligations in this DPA. Where that information is not reasonably sufficient, you may request an audit or inspection relating to processing covered by this DPA.
Audits must, where permitted by law, be on reasonable notice, during normal business hours, proportionate to the risk, and designed to avoid unnecessary disruption or disclosure of another customer's confidential information. We may satisfy an audit request first through relevant policies, security information, provider documentation or a remote review. These restrictions do not prevent a competent regulator from exercising its lawful powers.
14. Liability and legal rights
The liability provisions in the Terms of Service apply to this DPA between you and Simply Works. Nothing in this DPA limits either party's direct statutory duties or the rights of individuals or regulators to the extent those rights or duties cannot lawfully be limited by contract.
15. Contact
Data-protection questions relating to this DPA can be sent to support@simply-link.co.uk.
Simply Works LTD
Company No. 16219998 · Registered in England and Wales
Registered office: 5 The Roundhouse, Fore Street, Bodmin, PL31 2HG