Skip to content
ManageMyStable

Last updated: 20 June 2026

Data Processing Agreement

This Data Processing Agreement ("Agreement") sets out the terms on which ManageMyStable processes personal data on behalf of its customers.

Parties: This Agreement is between ManageMyStable Limited, a company registered in England & Wales under company number 17375835, whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom, the operator of ManageMyStable ("Processor"), and the customer identified in their ManageMyStable account ("Controller"). It takes effect on the date the Controller accepts the ManageMyStable Terms of Service, or on the date of any separate written agreement referencing this DPA, whichever is earlier.

1. Definitions

  • "Agreement" means this Data Processing Agreement.
  • "Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any successor legislation, as amended from time to time.
  • "Controller" means the customer who determines the purposes and means of processing of Personal Data within the Service.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "Personal Data" has the meaning given in Applicable Data Protection Law.
  • "Processing" has the meaning given in Applicable Data Protection Law.
  • "Processor" means ManageMyStable Limited, the operator of ManageMyStable, which processes Personal Data on behalf of the Controller.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • "Service" means the ManageMyStable platform as described in the Terms of Service.
  • "Sub-processor" means any third party engaged by the Processor to carry out Processing activities on behalf of the Controller.
  • "UK GDPR" means the retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland.

2. Scope and relationship of the parties

2.1 This Agreement applies where and to the extent that the Processor processes Personal Data on behalf of the Controller in the course of providing the Service.

2.2 The Controller is the data controller in respect of Personal Data that it inputs into, or generates through its use of, the Service. The Processor is the data processor in respect of that Personal Data.

2.3 Each party shall comply with its obligations under Applicable Data Protection Law. This Agreement supplements but does not replace the Terms of Service, which continue to apply.

3. Details of processing

Subject matter Provision of the ManageMyStable stable management platform
Duration For the term of the Controller's subscription, plus any post-termination retention period
Nature of processing Storage, retrieval, display, backup, and deletion of Personal Data
Purpose Enabling the Controller to manage horses, contacts, calendars, health records, and related stable management activities
Types of Personal Data Names, contact details, email addresses, phone numbers, profile photographs, professional information, and any other Personal Data the Controller chooses to input
Categories of Data Subjects The Controller's account holders, staff, professional contacts (vets, farriers, instructors), and any other individuals whose data the Controller inputs

4. Processor obligations

The Processor shall:

  • 4.1 Process Personal Data only on the documented instructions of the Controller, which includes processing in accordance with the Terms of Service and this Agreement. The Processor will inform the Controller if it believes any instruction infringes Applicable Data Protection Law.
  • 4.2 Ensure that persons authorised to process the Personal Data are bound by appropriate obligations of confidentiality.
  • 4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
    • Encryption of Personal Data in transit (TLS) and at rest (AES-256 via AWS)
    • Access controls and authentication, including multi-factor authentication support
    • Regular testing and evaluation of security measures
    • Logical separation of Controller data from other customers' data
  • 4.4 Not engage any Sub-processor without prior general or specific authorisation from the Controller. The Controller provides general authorisation for the Sub-processors listed in Schedule 1. The Processor will notify the Controller of any intended changes to Sub-processors and give the Controller the opportunity to object.
  • 4.5 Assist the Controller, insofar as reasonably possible and taking into account the nature of the processing, in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
  • 4.6 Assist the Controller in ensuring compliance with its obligations in relation to security, notification of Security Incidents, data protection impact assessments, and prior consultation with supervisory authorities.
  • 4.7 At the Controller's option, delete or return all Personal Data on termination of the Service, and delete existing copies unless retention is required by applicable law.
  • 4.8 Make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement, and permit and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable prior notice and confidentiality obligations.

5. Controller obligations

The Controller shall:

  • 5.1 Ensure it has a valid lawful basis under Applicable Data Protection Law for all Personal Data it inputs into the Service and for directing the Processor to process it.
  • 5.2 Ensure that its privacy notices and other communications with Data Subjects accurately describe the processing carried out through the Service.
  • 5.3 Provide the Processor with clear and lawful instructions for the processing of Personal Data.
  • 5.4 Not instruct the Processor to process Special Category Data (as defined in UK GDPR Article 9) unless the Controller has confirmed it has an appropriate legal basis for doing so.

6. Sub-processors

6.1 The Controller provides general authorisation for the Processor to engage the Sub-processors listed in Schedule 1.

6.2 The Processor shall impose data protection obligations on Sub-processors equivalent to those in this Agreement.

6.3 The Processor remains liable to the Controller for the acts and omissions of its Sub-processors to the same extent as if the Processor were performing the processing directly.

6.4 The Processor will give the Controller at least 30 days' notice of any intended addition or replacement of a Sub-processor. If the Controller objects on reasonable data protection grounds, the parties will work in good faith to resolve the objection. If they cannot, the Controller may terminate the Service on written notice.

7. Security incidents

7.1 The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting the Controller's Personal Data.

7.2 Notification shall include, to the extent then known: the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

7.3 The Processor shall take reasonable steps to contain and remediate any Security Incident and shall cooperate with the Controller in any required notifications to supervisory authorities or Data Subjects.

8. International transfers

8.1 The Processor shall not transfer Personal Data outside the UK except where appropriate safeguards are in place in accordance with Applicable Data Protection Law.

8.2 Personal Data is stored and processed within AWS's eu-west-2 (London) region. Where the Processor's relationship with a Sub-processor involves a transfer outside the UK (including to the United States in the case of Amazon Web Services, Inc.), the Processor ensures that such transfers are covered by the UK International Data Transfer Agreement (IDTA) or equivalent approved safeguards.

9. Data subject rights

9.1 The Processor shall promptly forward to the Controller any requests received directly from Data Subjects exercising their rights under Applicable Data Protection Law.

9.2 The Processor shall provide such reasonable assistance, information, and functionality as is available within the Service to help the Controller respond to Data Subject requests within applicable time limits.

10. Deletion and return of data

10.1 On expiry or termination of the Service, or on written request from the Controller, the Processor shall, at the Controller's election, either securely delete or return all Personal Data processed on behalf of the Controller, and certify in writing that it has done so.

10.2 Deletion shall take place within 30 days of the request or termination, subject to any retention required by applicable law.

11. Liability

11.1 Each party's liability under this Agreement is subject to the limitations set out in the Terms of Service.

11.2 Nothing in this Agreement excludes either party's liability for breaches of Applicable Data Protection Law.

12. Term and termination

12.1 This Agreement remains in force for as long as the Processor processes Personal Data on behalf of the Controller.

12.2 Termination of the Terms of Service automatically terminates this Agreement, subject to clauses that by their nature survive termination, including clauses 4.7, 7, 8, and 10.

13. Governing law

This Agreement is governed by the laws of England and Wales. Any disputes arising under it are subject to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1: Approved Sub-processors

Sub-processor Location Purpose Safeguard
Amazon Web Services, Inc. (AWS) United States
(data stored in eu-west-2, London)
Cloud infrastructure, storage, authentication, and logging IDTA / Standard Contractual Clauses

This Schedule will be updated as Sub-processors are added or changed, with notice to Controllers as described in clause 6.4.

Questions about this Agreement

If you have any questions about this Agreement or wish to request a signed copy, please contact us:

Processor
ManageMyStable Limited (company number 17375835)
Registered office
128 City Road, London, EC1V 2NX, United Kingdom