Data Processing Addendum · version 1 September 2026
A narrow processing job, with a defined end.
This addendum applies when a business buyer supplies personal data in operational files. The buyer is controller and Administrative Burden Ltd, trading as Modest Ambitions, is processor for that material. It supplements the commercial terms and requires legal review before live checkout.
Scope and duration
Processing is limited to validating, reconciling or reviewing the fixed sample described in the paid scope and returning the agreed outputs. It starts when usable files are received and ends when the outputs are delivered and the 30-day deletion period expires, except for a shorter agreed period or a legal preservation duty.
Data and people
Depending on the purchased service, source files may contain business contact, invoice, job, asset, delivery, payment-allocation or exception data concerning the buyer’s customers, suppliers, workers or business contacts. The buyer must remove fields and records that are not necessary and must not provide special-category, criminal-offence, full card, account credential or unrelated identity data unless separately agreed in writing.
Documented instructions
The paid scope, minimum-file checklist and written delivery correspondence are the buyer’s instructions. Modest Ambitions processes data only on those instructions or as required by applicable law, and will inform the buyer before legally required processing unless prohibited.
People and security
Access is limited to authorized people bound by confidentiality. Controls include least-privilege operator access, MFA, encrypted transfer, encrypted application fields and provider storage, access logging, separated secrets, patching, recovery testing and deletion checks appropriate to the risk.
Subprocessors
The approved hosting, backup, email and secure-transfer providers in the processor register may process data only under written terms imposing equivalent protections. Material additions or replacements will be notified before they process operational files, allowing the buyer a reasonable opportunity to object on data-protection grounds.
Transfers
Personal data is not transferred outside the approved processing locations unless an applicable adequacy decision or contractual safeguard is documented. The buyer may request the current provider, location and safeguard record.
Assistance
Taking account of the processing, Modest Ambitions will reasonably assist the buyer with data-subject requests, security and breach obligations, impact assessments and regulator consultation. Requests must identify the paid scope and must not include operational files in ordinary email.
Incidents
Modest Ambitions will notify the buyer without undue delay after becoming aware of a personal-data breach affecting buyer-controlled data and will provide available information needed for the buyer’s assessment and notification duties.
Return and deletion
Agreed outputs are returned through the approved route. Source and working files are deleted within 30 days after delivery unless the buyer requests a shorter period. On termination, remaining buyer-controlled personal data is deleted or returned at the buyer’s choice unless applicable law requires retention. Backup deletion follows the documented provider lifecycle and puts expired data beyond operational use.
Evidence and audit
Modest Ambitions will provide information reasonably necessary to demonstrate these obligations and permit a proportionate audit or independent evidence review on reasonable notice, subject to confidentiality, security and third-party restrictions. The buyer should first use existing policies, reports and provider evidence.
Questions and current subprocessor details: hello@modestambitions.studio.
← Back to the offers