Ersolutions

// DPA

Data Processing Agreement

Last updated: 22 July 2026

Loading...

This Data Processing Agreement ("DPA") describes how ERSOLUTIONS processes personal data on behalf of clients when acting as a processor under applicable data protection laws, including the UK GDPR / EU GDPR where relevant.

Roles Where ERSOLUTIONS processes personal data on a client's instructions for a contracted project, the client is the controller and ERSOLUTIONS is the processor (unless otherwise agreed in writing).

Scope of processing Processing is limited to the personal data types, categories of data subjects, and purposes set out in the applicable statement of work or data schedule.

Obligations of ERSOLUTIONS We will: - process personal data only on documented instructions from the client - ensure personnel authorised to process personal data are bound by confidentiality - implement appropriate technical and organisational security measures - not engage a sub-processor without prior notice/agreement as required by the contract - assist the client, where reasonably possible, with data subject requests and security incidents - delete or return personal data at the end of the engagement, unless retention is required by law

Security We maintain security controls appropriate to the risk, including access controls, encryption in transit where applicable, and secure development practices.

International transfers If personal data is transferred internationally, we will use appropriate transfer mechanisms required by applicable law.

Sub-processors We may use infrastructure and tooling providers (for example cloud hosting) as sub-processors. A current list can be provided on request.

Contact For DPA or data protection enquiries: info@ersolutions.co.