Data Processing Agreement

Last updated: 10 September 2026

This is the contract that governs how CakeIQ processes your customers’ data on your behalf. It’s a legal document, so the full clause text is the part that counts — but each section opens with a plain-English “in short” summary so you can find what you need quickly. For the story behind these commitments, see our Customer Data Protection Commitment.

1. Definitions and scope

In short: This agreement covers only the personal data CakeIQ processes for you as your data processor — not CakeIQ's own account, billing, and security data, which our Privacy Policy covers.

This Data Processing Agreement (“DPA”) forms part of the agreement for use of CakeIQ between TECH LCA LTD, company number 15682096, of 9 Oxford Court, Manchester, M2 3WQ (“CakeIQ”, “Processor”, “we” or “us”), and the subscribing cake shop or other business identified in the applicable order form or CakeIQ account (“Customer” or “Controller”).

By accepting the CakeIQ Terms of Service, opening a paid account, or otherwise using CakeIQ to process personal data, the Customer enters into this DPA. If there is a conflict concerning processing of personal data, this DPA prevails over the general service terms.

“Applicable Data Protection Law” means the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018, Privacy and Electronic Communications Regulations (PECR), and other UK data-protection law applicable to the processing. “Customer Data” means personal data processed by CakeIQ on the Customer’s behalf through the service. “Personal Data Breach”, “process”, “processor”, “controller” and “data subject” have the meanings given by Applicable Data Protection Law.

This DPA applies only where CakeIQ processes Customer Data as processor. CakeIQ remains an independent controller for account administration, billing, security, legal compliance, and its own business communications as explained in the CakeIQ Privacy Policy.

2. Your instructions and responsibilities

In short: You control what data is collected and why. We only act on your documented instructions, and you're responsible for using CakeIQ lawfully.

The Customer appoints CakeIQ to process Customer Data solely to provide, secure, maintain and support the service, carry out the Customer’s settings and authorised communications, and comply with law. The principal service agreement, account configuration, support requests, and other documented directions constitute instructions.

CakeIQ will process Customer Data only on documented instructions unless UK law requires otherwise. Where legally permitted, CakeIQ will inform the Customer before processing required by law.

If CakeIQ reasonably believes an instruction infringes Applicable Data Protection Law, it will inform the Customer and may suspend the affected processing until the instruction is amended or confirmed as lawful. CakeIQ will not be held liable for any service delays arising due to such suspension.

The Customer is the data controller and is responsible for ensuring the lawfulness, fairness, and accuracy of all Customer Data; providing required notices; identifying a lawful basis and any special-category condition; honouring rights; and obtaining any consent or PECR permission required for lifecycle marketing.

The Customer must not use CakeIQ to record unnecessary special-category data, unlawful content, full payment-card details, or information beyond what is reasonably needed to manage orders and authorised communications.

3. Confidentiality

In short: Everyone on our side with access to your data is bound by confidentiality and only sees what their role needs.

CakeIQ will ensure that persons authorised to process Customer Data are bound by confidentiality duties, receive appropriate data-protection and security instructions, and access Customer Data only to the extent necessary for their role.

4. Security

In short: We keep appropriate security measures in place (listed in Annex 2). You're responsible for securing your own staff accounts and devices.

Taking account of the state of the art, implementation cost, processing scope, and risks to individuals, CakeIQ will implement appropriate technical and organisational measures. Current measures are described in Annex 2. CakeIQ may update those measures provided it does not materially reduce the overall protection of Customer Data.

The Customer is responsible for secure configuration and use of the service, including individual user accounts, appropriate permissions, credential security, staff offboarding, and the security of devices and networks under its control. CakeIQ will not be held liable for data breaches caused directly by the customer’s failure to secure their own accounts.

5. Subprocessors

In short: We use a small number of trusted subprocessors to run the service (listed in Annex 3), and we'll give you advance notice before adding a significant new one.

The Customer gives CakeIQ general written authorisation to appoint subprocessors needed to provide the service. Current subprocessors are listed in Annex 3. CakeIQ will impose written obligations that provide substantially equivalent protection for Customer Data to the extent applicable to the subprocessor’s services and remains responsible for its obligations under this DPA.

CakeIQ will provide reasonable advance notice of a new subprocessor that materially processes Customer Data. The Customer may object within 10 business days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. The service may or may not continue in the meantime as agreed by both parties. If no reasonable alternative is available, either party may terminate the affected service; this is the Customer’s sole remedy for an unresolved subprocessor objection, without limiting mandatory legal rights.

6. International transfers

In short: If data ever needs to leave the UK, we rely on approved legal safeguards to protect it.

CakeIQ will not make a restricted transfer of Customer Data from the UK unless the transfer is covered by UK adequacy regulations, an approved safeguard or a legally permitted exception. Where required, the parties incorporate the then-current UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as appropriate. CakeIQ will provide reasonable assistance to the customer to undertake any transfer risk assessment required of it and require relevant subprocessors to maintain applicable safeguards.

7. Assistance to you

In short: We'll help you respond to data-subject requests, security incidents, and compliance assessments.

Considering the nature of processing and information available to it, CakeIQ will provide reasonable assistance with:

  • responding to requests to exercise data-subject rights;
  • security obligations and investigation of Personal Data Breaches;
  • data protection impact assessments and prior consultation where required; and
  • demonstrating compliance with the processor obligations in Applicable Data Protection Law.

The Customer remains responsible for deciding whether and how to respond to a request. If CakeIQ receives a request relating to Customer Data, it will not respond substantively except on the Customer’s instruction or where law requires, and will direct the requester to the Customer where reasonably possible. To the extent permitted by law, where the Customer requests assistance that goes beyond standard automated features provided within the service, or requires significant technical or administrative resources from CakeIQ, CakeIQ reserves the right to charge the Customer for such assistance at its then-current professional services rates.

8. Personal data breaches

In short: If a breach happens, we'll tell you promptly and help contain and investigate it. You're responsible for notifying the ICO and affected individuals.

CakeIQ will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe, to the extent then known, the nature of the breach, affected categories and approximate numbers, likely consequences, measures taken or proposed, and a contact point. Initial notice may be provided in phases. Notice is not an admission of fault or liability.

The Customer is responsible for notifications to the ICO and affected individuals unless the parties expressly agree otherwise. CakeIQ will take reasonable steps to contain, investigate and mitigate the breach and preserve relevant evidence. If the Personal Data Breach was caused directly by the Customer’s negligence, breach of contract, or failure to maintain account security, the Customer shall reimburse CakeIQ for all reasonable costs incurred in investigating and mitigating the incident.

9. Return, export and deletion

In short: You can export your data any time. After you leave, you get a 30-day window, then we delete your data — with backups cleared within about 90 days.

During the subscription, the Customer may access or export Customer Data using available service features and may request reasonable assistance. On termination, the account will normally enter a 30-day restricted export/reactivation period, during which lifecycle marketing and routine outbound customer communications will be disabled.

After that period, CakeIQ will delete Customer Data from active systems unless the Customer has lawfully instructed otherwise before termination or Applicable Data Protection Law requires retention. Residual backup copies will be placed beyond ordinary use and deleted through the normal backup cycle, ordinarily within 90 days. CakeIQ may retain securely isolated data to comply with law or preserve legal claims, and will delete it when that need ends.

CakeIQ may delete Customer Data sooner where instructed by the Customer, subject to technical feasibility, legal retention requirements and the need to retain minimal suppression records to respect marketing objections.

10. Audit and information rights

In short: You can ask us to demonstrate compliance, and request an audit once a year (or more, if there's good reason).

On reasonable written request, CakeIQ will provide information reasonably necessary to demonstrate compliance with this DPA. No more than once in any 12-month period, unless a breach, regulator request or credible evidence of material non-compliance justifies more, the Customer may request a remote audit or review of relevant independent assurance materials.

Any audit must be proportionate, during normal business hours, on at least 30 days’ notice, avoid access to other customers’ data or CakeIQ confidential information, and comply with reasonable security requirements. If the Customer appoints a third-party auditor to conduct the review, that auditor must be mutually agreed upon and must execute a strict, direct confidentiality agreement with CakeIQ prior to the audit. The Customer bears its audit costs; CakeIQ may charge reasonable costs for assistance beyond standard compliance information, unless the audit identifies a material breach by CakeIQ. Nothing limits a regulator’s lawful powers.

11. Liability and duration

In short: This agreement runs for as long as we're processing your data, and liability follows the caps in our Terms of Service.

This DPA begins when CakeIQ first processes Customer Data and continues until that processing ends. Liability under this DPA is subject to the exclusions and caps in the CakeIQ Terms of Service to the maximum extent permitted by law. Nothing excludes or limits liability that cannot lawfully be excluded or limited, or changes either party’s direct statutory responsibilities under Applicable Data Protection Law.

12. General

In short: UK law governs this agreement, and we'll update it if data protection law requires changes.

This DPA is governed by the law and jurisdiction specified in the CakeIQ Terms of Service. Changes required by Applicable Data Protection Law may be made on reasonable notice. If any provision is invalid, the remainder continues in force.

Annex 1 — Processing details

In short: The nature and purpose of processing, categories of data, and data subjects covered by this DPA.

  • Subject matter: CakeIQ’s provision of order-management software to the Customer.
  • Duration: For the length of the Customer’s subscription, plus the retention periods in clause 9.
  • Nature and purpose: Storage, retrieval, and processing of order and customer records so the Customer can manage its bakery orders and communications.
  • Categories of data subjects: The Customer’s own customers, and the Customer’s staff who use the service.
  • Categories of Customer Data: Names, contact details, delivery addresses, order details, reference photos and signatures, and communication preferences, as entered by the Customer.
Annex 2 — Technical and organisational measures

In short: The concrete security controls CakeIQ has in place today.

  • Access control: authenticated accounts, role-based permissions, restricted administrative access and staff offboarding controls.
  • Authentication: httpOnly session cookies using signed JWTs and password hashing using bcrypt; secret values kept outside source code.
  • Transmission security: encrypted HTTPS/TLS connections for service access and provider communications where supported.
  • Infrastructure: managed deployment through Vercel and PostgreSQL/application infrastructure through Railway, with provider security controls and logical tenant separation within the application.
  • Availability and recovery: backups and restoration procedures appropriate to the service, with deletion through scheduled backup cycles.
  • Operational security: logging, error monitoring, dependency and vulnerability management, change controls, restricted support access and incident-response procedures.
  • Data minimisation and lifecycle: configured fields, documented deletion requests, account export/closure process and suppression records limited to what is needed to honour objections.
  • Personnel and suppliers: confidentiality commitments, need-to-know access, supplier due diligence and contractual data-protection terms.
Annex 3 — Authorised subprocessors

In short: The specific companies we currently use to run CakeIQ, and what each one does.

  • Vercel Inc. — hosts the CakeIQ web application.
  • Railway Corp. — hosts our application servers and PostgreSQL database.
  • Stripe, Inc. — processes CakeIQ subscription payments.
  • Resend — delivers transactional and lifecycle emails on our behalf.
  • Google LLC (Places API) — powers delivery-address autocomplete when staff enter an order.

Subprocessor details and locations may change as providers update their infrastructure. CakeIQ will maintain accurate operational records and give notice of material additions or replacements as described in clause 5.

Acceptance

In short: This DPA is accepted electronically along with the CakeIQ Terms of Service.

This DPA may be accepted electronically with the CakeIQ Terms of Service. A separately signed copy may be used where required by the Customer.

Processor: TECH LCA LTD, Company No. 15682096, 9 Oxford Court, Manchester, M2 3WQ. Privacy contact: info@techlca.com.