Avieo legal & privacy

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the agreement between a customer and Williams Media Design for use of Avieo where Avieo processes personal data on the customer's behalf.

Last updated: 3 October 2026

1. Roles and scope

For customer-controlled workspace content, including employee, document, task, time, leave, health-and-safety and collaboration data, the customer is normally the controller and Williams Media Design acts as processor through Avieo. Williams Media Design, established at 2 Pretoria Road, Patchway, Bristol, BS34 5PT, United Kingdom, remains a controller for information it determines the purposes and means of processing itself, such as account administration, billing, fraud prevention, service security and its own legal obligations.

2. Processing details

Subject matter: providing the Avieo business-workspace service. Duration: for the customer's use of Avieo and any limited retention period required for deletion, backup, security or legal obligations.

Nature and purpose: hosting, organising, retrieving, displaying, transforming, sharing and otherwise processing data as necessary to provide customer-selected Avieo features.

Data subjects: customer users, employees, workers, contractors, clients, suppliers and other people whose information the customer places in Avieo.

Data types: identity/contact details, employment/work records, time and leave data, tasks, communications, documents, signatures, form responses, health-and-safety records and other information submitted by the customer. Customers must use particular care with special-category or criminal-offence data.

3. Customer instructions

We will process customer personal data only on the customer's documented instructions, including instructions inherent in the customer's use and configuration of Avieo, unless UK law requires otherwise. If law requires processing outside those instructions, we will inform the customer beforehand unless prohibited by law.

4. Confidentiality and security

People authorised to process customer personal data are required to handle it confidentially. We will maintain technical and organisational measures appropriate to the risk, including access controls, tenant/workspace separation, authentication, private storage where used, and measures intended to preserve confidentiality, integrity and availability.

5. Subprocessors

The customer gives general authorisation for Avieo to use subprocessors necessary to provide the Service. Current key providers are listed on the Subprocessors page. We will impose data-protection obligations on subprocessors as required by law and remain responsible for our processor obligations in relation to their processing.

6. Rights requests and compliance assistance

Taking into account the nature of processing, we will provide reasonable assistance to enable the customer to respond to data-subject rights requests and to meet applicable obligations relating to security, breach notification, data-protection impact assessments and regulator consultation, insofar as the relevant information is available to us.

7. Personal-data breaches

If we become aware of a personal-data breach affecting customer personal data for which we act as processor, we will notify the affected customer without undue delay and provide available information reasonably needed for the customer to meet its legal obligations.

8. International transfers

Where processing involves a restricted transfer outside the UK, we will ensure an appropriate lawful transfer mechanism is available, such as UK adequacy regulations, the UK International Data Transfer Agreement/Addendum, or another recognised safeguard where applicable.

9. Return and deletion

On termination, and subject to the customer's choices and applicable law, we will delete or return customer personal data within our control and delete remaining copies when no longer required, except where law requires retention or limited backup/security retention applies.

10. Information and audits

We will make information reasonably necessary to demonstrate compliance with our processor obligations available to the customer and will support reasonable audits or inspections where required by applicable data-protection law, subject to proportionate confidentiality, security, scope and scheduling arrangements.

11. Customer responsibilities

The customer is responsible for the lawfulness of its instructions and customer personal data, including providing required privacy information, selecting lawful bases, limiting access, configuring users appropriately, and ensuring Avieo is suitable for the sensitivity of the information being processed.