Skip to content
Tagwell
Draft for legal review. Not in force.

Data processing agreement

Draft of 2 October 2026. Not yet in force.

Parties

Tagwell is a product of Pixedi Ltd, a company registered in England and Wales, company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]. Pixedi Ltd is registered with the UK Information Commissioner's Office, registration number [ICO REG NO].

This Data Processing Agreement ("DPA") is between the customer who accepts the Tagwell terms of service ("Controller") and Pixedi Ltd ("Processor"). It forms part of those terms and meets Article 28 of the UK GDPR.

Subject matter and duration

  • Subject matter: hosting the Controller's digital business cards and receiving data that visitors submit on them.
  • Duration: as long as the Controller uses Tagwell, plus the deletion period below.
  • Nature and purpose: storage, display, counting, forwarding notifications and export, only to provide Tagwell.
  • Data subjects: visitors to the Controller's cards.
  • Personal data: name, email, phone, company, job title, message, preferred call time, consent records; cookieless visit records with no IP address.
  • No special category data is intended. The Controller must not collect it through Tagwell.

Processor obligations

  1. Process personal data only on the Controller's documented instructions, including these terms and the settings the Controller chooses, unless the law requires otherwise; we will tell the Controller before doing so unless the law forbids it.
  2. Make sure people who process the data are bound by confidentiality.
  3. Apply appropriate technical and organisational security measures (Article 32): encryption in transit, access limited to staff who need it, hashed session tokens, no stored IP addresses, logged admin access, backups.
  4. Use subprocessors only as set out below.
  5. Help the Controller answer data subject requests, including through in-app export and deletion.
  6. Help the Controller with security, breach notification, impact assessments and consultation with the ICO.
  7. Notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting their data.
  8. At the end of the service, delete the Controller's personal data within 30 days, unless the law requires us to keep it. The Controller can export it before then.
  9. Make available the information needed to show compliance with Article 28 and allow for reasonable audits, normally by written questionnaire.

Subprocessors

The Controller gives general authorisation for the subprocessors on our subprocessors page. We will give at least 30 days' notice of a new subprocessor by email and on that page; the Controller may object on reasonable grounds and, if we cannot resolve it, end the service. We impose the same data protection obligations on each subprocessor and remain liable for them.

International transfers

Where data is transferred outside the UK, we rely on adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Agreement or Addendum.

Controller obligations

  • Have a lawful basis for the data collected on its cards and give visitors the information they need. Tagwell shows a short notice on every card; the Controller can link its own privacy policy.
  • Use call back numbers only for the call that was requested, and respect marketing consent choices.