Last updated: 7 July 2026
1. Purpose and Scope
Majestic Mindsets (“we”, “us”, “our”, the “Controller”) is the data controller for personal data collected through majesticmindsets.com in connection with our online courses (the “Service”). In providing the Service, we engage certain third-party service providers who process personal data on our behalf (“Processors” or “Sub-processors”), such as our website hosting provider and email delivery provider.
This Data Processing Agreement (“DPA”) sets out the terms on which we require any such Processor to handle personal data on our behalf, in compliance with Article 28 of the UK GDPR. This DPA is published for transparency and forms part of our contractual arrangements with our Processors.
2. Definitions
- “UK GDPR” means the UK General Data Protection Regulation as it forms part of UK law, together with the Data Protection Act 2018.
- “Controller” means Majestic Mindsets, which determines the purposes and means of processing personal data collected via the Service.
- “Processor” means any third party which processes personal data on behalf of the Controller.
- “Personal Data”, “Processing”, “Data Subject”, and “Personal Data Breach” have the meanings given in the UK GDPR.
- “Services Data” means the email addresses and related account data collected via the Service, as described in our Privacy Policy.
3. Roles of the Parties
Majestic Mindsets acts as the Controller of Services Data. Any third party engaged to process Services Data on our behalf acts as our Processor and must process such data strictly in accordance with our instructions and this DPA.
4. Processor Obligations
Any Processor engaged by us must, in accordance with UK GDPR Article 28(3):
- process personal data only on our documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case it must inform us before processing, unless prohibited from doing so);
- ensure that persons authorised to process the data are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with UK GDPR Article 32;
- not engage a further sub-processor without our prior general or specific written authorisation, and impose the same data protection obligations on any sub-processor;
- assist us, insofar as reasonably possible, in responding to requests from data subjects to exercise their rights under UK GDPR;
- assist us in ensuring compliance with our obligations relating to security of processing, breach notification, and data protection impact assessments;
- at our choice, delete or return all personal data to us at the end of the provision of services, and delete existing copies unless retention is required by law;
- make available to us all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits or inspections conducted by us or an auditor we appoint; and
- notify us without undue delay after becoming aware of a personal data breach affecting Services Data.
5. Sub-processors
Our current categories of Sub-processor include our website hosting provider and our email delivery service, engaged solely to enable us to provide the Service. An up-to-date list of our current sub-processors is available on request by emailing support@majesticmindsets.com.
6. International Transfers
Where a Processor or Sub-processor processes personal data outside the UK, we require appropriate safeguards to be in place, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under UK GDPR.
7. Retention and Deletion
Personal data is retained only for as long as necessary for the purposes described in our Privacy Policy. On termination of a Processor’s services to us, the Processor must delete or return all personal data in accordance with Section 4 above, save where retention is required by applicable law.
8. Security Measures
We require our Processors to maintain appropriate technical and organisational security measures, which may include: encryption of data in transit, access controls limiting data access to authorised personnel, regular security updates and patching, and secure data storage.
9. Liability
Each party remains responsible for its own compliance with UK GDPR. Nothing in this DPA limits either party’s liability for breaches of data protection law to the extent such liability cannot lawfully be limited.
10. Term and Termination
This DPA applies for as long as a Processor processes personal data on our behalf in connection with the Service and terminates automatically when that processing ends, subject to Section 7.
11. Governing Law
This DPA is governed by the laws of England and Wales.
12. Contact Us
For questions about this DPA or to request our current sub-processor list, contact: support@majesticmindsets.com