Data Processing Agreement
Last updated: 21 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between LRC Innovation Ltd, trading as Pasture (the “Processor”), and the shop using the Platform (the “Controller”). It applies whenever Pasture processes personal data on the Controller’s behalf, and reflects the requirements of Article 28 of the UK GDPR. Where this DPA conflicts with the Terms on data protection, this DPA prevails.
1. Definitions and roles
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and all other applicable data protection and privacy law. Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in Data Protection Law.
For the personal data of the Controller’s customers processed through the Platform, the Shop is the Controller and Pasture is the Processor. This DPA does not apply to data for which Pasture is itself the controller (such as shop owner account data), which is governed by the Privacy Policy.
2. Processing on documented instructions
Pasture processes the personal data only on the Controller’s documented instructions, including for international transfers, unless required to do otherwise by law (in which case Pasture will inform the Controller first, unless the law prohibits it). The Terms, this DPA and the Controller’s use of the Platform’s features are the Controller’s complete and final instructions. Pasture will tell the Controller if, in its opinion, an instruction infringes Data Protection Law.
3. Scope and details of processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
4. Confidentiality
Pasture ensures that people authorised to process the personal data are bound by an appropriate duty of confidentiality and process the data only as needed to provide the service.
5. Security
Taking account of the state of the art, the costs of implementation and the risks to data subjects, Pasture implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.
6. Sub-processors
- The Controller gives Pasture a general authorisation to engage sub-processors. A current list is at [SUB-PROCESSOR LIST] and in Annex 3.
- Pasture will give the Controller advance notice of any new or replacement sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.
- Pasture imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to the Controller for its sub-processors’ acts and omissions.
7. Assistance to the Controller
Taking into account the nature of the processing, Pasture assists the Controller with:
- responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection), by appropriate technical and organisational measures so far as possible;
- its obligations to keep personal data secure, to notify personal data breaches, and to carry out data protection impact assessments and prior consultations with the ICO; and
- promptly forwarding any data subject request it receives that relates to the Controller’s data, rather than responding to it directly.
8. Personal data breach
Pasture notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and provides the information the Controller reasonably needs to meet its own breach-notification obligations.
9. Return or deletion of data
On termination of the service, and at the Controller’s choice, Pasture deletes or returns the personal data and deletes existing copies, unless Data Protection Law requires it to keep the data. The Controller will have a reasonable window to export its data before deletion, as described in the Terms.
10. Information and audits
Pasture makes available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and allows and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates — subject to reasonable notice, frequency limits, confidentiality, and not compromising other customers’ security. Pasture may satisfy this by providing relevant certifications or reports where available.
11. International transfers
Where processing involves transferring personal data outside the UK, Pasture ensures an appropriate safeguard is in place — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — before the transfer takes place [CONFIRM SAFEGUARD PER SUB-PROCESSOR].
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
13. General
This DPA takes effect when the Controller accepts the Terms and continues for as long as Pasture processes personal data on the Controller’s behalf. It is governed by the law of England and Wales.
Annex 1 — Details of processing
- Subject matter — provision of the Pasture ordering and shop-management Platform to the Controller.
- Duration — the term of the Terms of Service, plus any period needed for return or deletion of data.
- Nature and purpose — hosting, storing and processing orders and customer records so the Controller can take orders, arrange collection and delivery, take payment and manage its shop.
- Categories of data subjects— the Controller’s customers (and any staff the Controller adds).
- Types of personal data — names, contact details, delivery addresses, order history and amounts, and marketing preferences [CONFIRM DATA TYPES].
- Special category data — none is intended to be processed.
Annex 2 — Technical and organisational measures
Pasture maintains measures including:
- encryption of personal data in transit;
- hashing of passwords and protection of credentials;
- access controls so staff and shops can access only the data they need, with tenant isolation between shops;
- use of reputable hosting and infrastructure providers;
- logging, backups and measures to restore availability after an incident; and
- regular review of these measures [CONFIRM / EXPAND MEASURES].
Annex 3 — Approved sub-processors
- Stripe — payment processing.
- [HOSTING / DATABASE PROVIDER] — hosting and data storage.
- [EMAIL PROVIDER] — transactional and notification email.
The current list, including locations and transfer safeguards, is maintained at [SUB-PROCESSOR LIST].