Skip to content

Data Processing Addendum

Effective Date: September 13, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Calico Design LLC (“Calico Design,” “we,” “us,” or “our”) and the customer or entity using Calico Design hosting, website management, development, maintenance, or related services (“Customer,” “you,” or “your”).

This DPA applies when Calico Design processes Personal Data on behalf of Customer in connection with the services.

This DPA supplements the Calico Design Terms of Service, Privacy Policy, Acceptable Use Policy, applicable order forms, proposals, statements of work, and other agreements governing the services (collectively, the “Agreement”).

If there is a direct conflict between this DPA and the Agreement concerning the processing of Customer Personal Data, this DPA will control with respect to that conflict.

1. Definitions

For purposes of this DPA:

  • “Applicable Data Protection Law” means any privacy, data protection, or information security law applicable to the processing of Customer Personal Data under the Agreement.
  • “Controller” includes a “business” or similar entity that determines the purposes and means of processing Personal Data.
  • “Processor” includes a “service provider,” “contractor,” or similar entity that processes Personal Data on behalf of a Controller.
  • “Customer Personal Data” means Personal Data processed by Calico Design on behalf of Customer in connection with Customer’s websites, applications, databases, forms, hosting environment, backups, or services.
  • “Data Subject” includes an individual, consumer, website visitor, customer, employee, subscriber, user, or other person whose Personal Data is processed.
  • “Personal Data” includes “personal information,” “personally identifiable information,” and similar terms defined by Applicable Data Protection Law.
  • “Personal Data Breach” means a confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
  • “Processing” means any operation performed on Personal Data, including collecting, recording, storing, organizing, accessing, transmitting, modifying, retrieving, backing up, restoring, deleting, or otherwise using Personal Data.
  • “Subprocessor” means a third party engaged by Calico Design to process Customer Personal Data in connection with providing the services.

2. Roles of the Parties

With respect to Customer Personal Data:

  • Customer acts as the Controller, Business, or equivalent responsible party; and
  • Calico Design acts as the Processor, Service Provider, Contractor, or equivalent processing party.

Customer determines the purposes for which Customer Personal Data is collected and processed through Customer’s website, applications, forms, ecommerce systems, analytics, plugins, integrations, and other services.

Calico Design processes Customer Personal Data only as reasonably necessary to provide, maintain, secure, troubleshoot, support, back up, restore, migrate, or otherwise perform the services requested by Customer.

3. Customer Instructions

Customer instructs Calico Design to process Customer Personal Data as necessary to provide the services described in the Agreement.

Customer’s instructions include:

  • The Agreement;
  • Hosting and service configuration selected by Customer;
  • Support requests;
  • Website maintenance requests;
  • Migration requests;
  • Backup and restoration requests;
  • Development or troubleshooting instructions; and
  • Other documented instructions provided by Customer.

Calico Design will process Customer Personal Data only according to Customer’s documented instructions unless otherwise required by applicable law.

If Calico Design reasonably believes an instruction violates Applicable Data Protection Law, we may inform Customer and suspend the affected processing until the matter can be clarified.

4. Customer Responsibilities

Customer is responsible for determining whether its collection and use of Personal Data complies with Applicable Data Protection Law.

Customer represents that it has a lawful basis and all necessary rights, notices, permissions, and consents required for Calico Design to process Customer Personal Data as contemplated by the Agreement.

Customer is responsible for:

  • Maintaining an appropriate privacy policy;
  • Providing legally required privacy notices;
  • Obtaining legally required consent;
  • Configuring cookies and tracking technologies appropriately;
  • Responding to requests from Data Subjects;
  • Determining appropriate retention periods;
  • Determining what information its website collects;
  • Selecting and configuring third-party plugins and integrations;
  • Ensuring Customer Personal Data is lawfully provided to Calico Design; and
  • Complying with privacy laws applicable to Customer’s business.

5. Details of Processing

The general subject matter, nature, purpose, duration, and categories of processing are described below and in the Agreement.

Subject Matter

Processing of Customer Personal Data in connection with website hosting, WordPress management, web development, website maintenance, backups, migrations, technical support, security, monitoring, and related services.

Nature and Purpose of Processing

Processing may include:

  • Hosting websites and databases;
  • Storing files and media;
  • Serving website content;
  • Maintaining backups;
  • Restoring websites;
  • Website migration;
  • Security monitoring;
  • Malware detection and remediation;
  • Troubleshooting;
  • Technical support;
  • Website maintenance;
  • Performance monitoring;
  • Logging and diagnostics; and
  • Other processing necessary to provide the services.

Duration

Customer Personal Data may be processed for the duration of the Customer’s use of the applicable services and for a limited period afterward as reasonably necessary for backups, security, legal obligations, dispute resolution, or normal system deletion cycles.

6. Categories of Data Subjects

Depending on Customer’s website and business, Customer Personal Data may relate to:

  • Website visitors;
  • Customers and prospective customers;
  • Employees;
  • Contractors;
  • Vendors;
  • Subscribers;
  • Members;
  • Users;
  • Job applicants;
  • Form submitters;
  • Ecommerce customers;
  • Event registrants;
  • Reservation or appointment customers; and
  • Other individuals interacting with Customer.

7. Categories of Personal Data

Depending on Customer’s website and configuration, Customer Personal Data may include:

  • Name;
  • Email address;
  • Telephone number;
  • Postal address;
  • IP address;
  • Device and browser information;
  • Account information;
  • Website activity;
  • Form submissions;
  • Order information;
  • Reservation or appointment information;
  • Customer communications;
  • User-generated content;
  • Analytics information;
  • Technical logs;
  • Authentication information;
  • Identifiers;
  • Purchase or transaction information; and
  • Other information Customer chooses to collect through its website or applications.

8. Sensitive or Regulated Personal Data

Unless Calico Design expressly agrees otherwise in writing, the services are not intended for workloads requiring specialized handling of highly regulated or sensitive Personal Data.

Customer should not knowingly use the services to process information subject to specialized regulatory requirements without first confirming with Calico Design that the applicable service is appropriate.

Such information may include:

  • Protected health information subject to HIPAA;
  • Complete payment card data;
  • Government identification numbers;
  • Biometric information;
  • Highly sensitive financial information;
  • Authentication secrets;
  • Genetic information; or
  • Other specially regulated categories of Personal Data.

Customer remains responsible for determining whether the services are appropriate for the Personal Data Customer chooses to process.

9. Confidentiality

Calico Design will limit access to Customer Personal Data to personnel, contractors, and service providers who reasonably require access to perform the services.

Persons authorized by Calico Design to access Customer Personal Data will be subject to appropriate confidentiality obligations.

Calico Design will not disclose Customer Personal Data except:

  • As necessary to provide the services;
  • As instructed by Customer;
  • To authorized Subprocessors;
  • As required by applicable law; or
  • As otherwise permitted under the Agreement.

10. Security Measures

Calico Design will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the services and the risks associated with processing Customer Personal Data.

Depending on the service and hosting environment, such measures may include:

  • Access controls;
  • Authentication controls;
  • Password protections;
  • Encrypted communications;
  • Firewalls;
  • Malware detection;
  • Security monitoring;
  • Software updates;
  • Backup systems;
  • Logging;
  • Network security;
  • Infrastructure monitoring;
  • Restricted administrative access; and
  • Incident response procedures.

Customer acknowledges that no security system, network, server, hosting platform, transmission method, or storage system can be guaranteed to be completely secure.

11. Personal Data Breaches

If Calico Design becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, Calico Design will notify Customer without undue delay as required by Applicable Data Protection Law.

To the extent reasonably available, notification may include information concerning:

  • The nature of the incident;
  • The types of Customer Personal Data affected;
  • The systems affected;
  • Known or reasonably suspected consequences;
  • Actions taken or planned to address the incident; and
  • Information reasonably necessary for Customer to satisfy applicable notification obligations.

Calico Design’s notification of a security incident does not constitute an admission of fault, liability, or violation of law.

Customer remains responsible for determining whether notification to Data Subjects, regulators, customers, insurers, law enforcement, or other parties is legally required.

12. Subprocessors

Customer provides Calico Design with general authorization to engage Subprocessors reasonably necessary to provide the services.

Subprocessors may provide services including:

  • Server and cloud infrastructure;
  • Data center services;
  • Content delivery networks;
  • Website security;
  • DNS services;
  • Backup and storage;
  • Monitoring;
  • Email delivery;
  • Customer support systems;
  • Payment processing;
  • Analytics;
  • Software platforms; and
  • Other infrastructure or operational services.

Calico Design will require Subprocessors that process Customer Personal Data on our behalf to be subject to contractual or other appropriate obligations concerning privacy, confidentiality, and security.

Calico Design may change Subprocessors as infrastructure, technology, vendors, and service requirements change.

Where required by Applicable Data Protection Law, Calico Design will provide reasonable notice of material changes to Subprocessors and provide Customer an opportunity to raise legitimate privacy concerns.

If Calico Design cannot reasonably resolve a valid objection concerning a new Subprocessor, Customer’s remedy may include discontinuing the affected service according to the Agreement.

13. Data Subject Requests

Customer is primarily responsible for responding to requests from Data Subjects relating to Customer Personal Data.

If Calico Design receives a request directly from a Data Subject concerning Customer Personal Data, Calico Design may direct the individual to Customer unless Applicable Data Protection Law requires otherwise.

Taking into account the nature of the processing and information reasonably available to us, Calico Design will provide reasonable assistance to Customer in responding to valid requests involving Customer Personal Data.

Such requests may include rights to:

  • Access Personal Data;
  • Correct Personal Data;
  • Delete Personal Data;
  • Obtain a portable copy;
  • Restrict processing;
  • Object to processing; or
  • Exercise other rights provided by Applicable Data Protection Law.

Calico Design may charge reasonable fees for assistance requiring substantial technical work beyond the Customer’s normal service plan where permitted by law and the Agreement.

14. Privacy Impact and Compliance Assistance

Taking into account the nature of the processing and information available to Calico Design, we will provide reasonable information necessary to assist Customer with applicable privacy compliance obligations related specifically to the services.

This may include reasonable assistance relating to:

  • Data protection impact assessments;
  • Security information;
  • Personal Data Breaches;
  • Data Subject requests; and
  • Regulatory inquiries concerning Calico Design’s processing of Customer Personal Data.

Customer remains responsible for its own compliance decisions and legal obligations.

15. U.S. State Privacy Laws

To the extent U.S. state privacy laws apply to Customer Personal Data, Calico Design will act as a service provider, contractor, processor, or equivalent entity as defined by applicable law.

Unless otherwise permitted by Applicable Data Protection Law, Calico Design will not:

  • Sell Customer Personal Data;
  • Share Customer Personal Data for cross-context behavioral advertising;
  • Retain, use, or disclose Customer Personal Data for purposes outside providing the services to Customer;
  • Retain, use, or disclose Customer Personal Data outside the direct business relationship between Calico Design and Customer; or
  • Combine Customer Personal Data with Personal Data received from unrelated third parties except where permitted by applicable law.

Calico Design acknowledges and agrees that Customer Personal Data is disclosed to Calico Design only for the limited and specified purposes described in the Agreement and this DPA.

16. GDPR and Similar International Privacy Laws

Where the European Union General Data Protection Regulation (“GDPR”), United Kingdom GDPR, Swiss data protection law, or similar privacy legislation applies, Calico Design will process Customer Personal Data as a Processor acting on Customer’s documented instructions.

Calico Design will provide the assistance and safeguards required of processors to the extent applicable to the services and required by law.

17. International Data Transfers

Calico Design is based in the United States, and Customer Personal Data may be processed in the United States or other countries where Calico Design or its Subprocessors operate.

If Applicable Data Protection Law requires a lawful transfer mechanism for Customer Personal Data transferred internationally, the parties agree to cooperate in implementing an appropriate mechanism.

Where applicable, this may include:

  • An adequacy decision;
  • Standard Contractual Clauses approved by the European Commission;
  • The United Kingdom International Data Transfer Addendum or other approved UK mechanism;
  • Contractual safeguards;
  • Applicable certification frameworks; or
  • Another transfer mechanism permitted by law.

To the extent required and legally applicable, the then-current European Commission Standard Contractual Clauses may be incorporated into this DPA by reference for transfers that require them.

18. Return and Deletion of Customer Personal Data

During active services, Customer may request reasonable assistance obtaining Customer Personal Data in a format available through the applicable website, database, hosting platform, or backup system.

Customers are responsible for exporting and maintaining any data they wish to retain before canceling or terminating services.

Once hosting or other applicable services are canceled or terminated, Calico Design does not guarantee that Customer Personal Data, websites, databases, backups, files, or other hosted information will remain available or recoverable.

Calico Design may delete Customer Personal Data from active systems after termination according to normal operational practices.

Customer Personal Data may temporarily remain in backup, archival, logging, security, or disaster recovery systems until those systems are overwritten or deleted through normal retention cycles.

Calico Design is not required to restore Customer Personal Data from backup systems after termination.

19. Backups

Calico Design may maintain backups as part of the services and will use commercially reasonable practices intended to reduce the risk of data loss.

However, backups are not guaranteed to be complete, available, current, or capable of successful restoration.

Customer is responsible for maintaining an independent copy of important Personal Data and other website information.

Calico Design backup systems should not be treated as Customer’s sole method of preserving important data.

20. Audits and Compliance Information

Where required by Applicable Data Protection Law, Calico Design will make available reasonable information necessary to demonstrate compliance with applicable processor obligations.

Customer should first satisfy audit or verification requirements through documentation, policies, security information, certifications, or other information reasonably made available by Calico Design.

If an additional audit is legally required, the parties will cooperate to establish a reasonable scope, timing, confidentiality arrangement, and method that minimizes disruption to Calico Design and other Customers.

Customer will be responsible for reasonable costs associated with extraordinary audit assistance unless Applicable Data Protection Law requires otherwise.

Audits may not provide Customer access to information concerning other Calico Design Customers, confidential security information that would create a security risk, or information Calico Design is prohibited from disclosing.

21. Government and Legal Requests

If Calico Design receives a legally binding request from a governmental authority for Customer Personal Data, we may disclose information as required by law.

Where legally permitted and reasonably practicable, Calico Design may notify Customer of such a request before disclosure.

Calico Design may challenge or seek clarification of a request when we reasonably believe doing so is appropriate and legally permissible.

22. Customer Security Responsibilities

Customer acknowledges that data protection is a shared responsibility.

Customer is responsible for implementing reasonable security measures within systems and accounts Customer controls, including:

  • Protecting passwords and credentials;
  • Managing WordPress users;
  • Managing administrator access;
  • Using multi-factor authentication when available;
  • Removing access for former employees or contractors;
  • Using secure devices and networks;
  • Configuring third-party software appropriately;
  • Avoiding untrusted plugins and software;
  • Maintaining appropriate privacy settings; and
  • Promptly notifying Calico Design of suspected security incidents.

23. Third-Party Applications and Integrations

Customer may choose to install or connect plugins, applications, APIs, analytics services, advertising platforms, payment systems, forms, email services, social platforms, or other third-party technologies.

Those third parties may independently process Customer Personal Data.

Unless Calico Design controls the applicable third party as a Subprocessor, Customer is responsible for evaluating the privacy, security, and legal terms of those third-party services.

Calico Design is not responsible for the privacy practices or processing activities of independent third-party services selected by Customer.

24. Liability

The limitations of liability contained in the Calico Design Terms of Service apply to this DPA to the fullest extent permitted by applicable law.

Nothing in this DPA expands Calico Design’s liability beyond the liability established under the Agreement except where Applicable Data Protection Law prohibits such limitation.

25. Changes to This DPA

Calico Design may update this DPA to reflect changes in privacy laws, hosting infrastructure, technology, Subprocessors, services, security practices, or business operations.

The effective date at the top of this page identifies the current version.

Material changes may be communicated through our website, customer portal, hosting platform, email, or another reasonable method.

Continued use of services after an updated DPA becomes effective constitutes acceptance of the updated DPA to the extent permitted by applicable law.

26. Term and Termination

This DPA remains in effect for as long as Calico Design processes Customer Personal Data on behalf of Customer under the Agreement.

Sections intended by their nature to survive termination, including confidentiality, deletion, security, liability, and legal compliance provisions, will survive as applicable.

27. Governing Law

Except where Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law provisions contained in the Calico Design Terms of Service.

28. Contact Information

Questions regarding this Data Processing Addendum may be directed to:

Calico Design LLC
St. Petersburg, Florida, United States
CalicoDesignStudio.com