Hard to Ignore

Data processing agreement

The paperwork, published before you ask for it.

When you upload a list of people to post to, that list is your data about your prospects. You are its controller and we are your processor, and Article 28 of the UK GDPR says the arrangement has to be governed by a written contract. This is that contract.

It is free, it is not conditional on order size, and it is on this page rather than behind a request form so your legal team can read it tonight and tell you whether it is acceptable before anybody has to email anybody.

Last updated 20 August 2026

1. Parties and status

This agreement is between you (the business that places the order and uploads the list, acting as controller) and Charlie Hollinrake, a sole trader trading as Hard to Ignore, acting as your processor.

Address for service: [ TRADING ADDRESS: TO BE ADDED ]. Contact for anything in this agreement: hello@charliehollinrake.co.uk.

It sits alongside our service terms. Where the two disagree about personal data, this one wins.

Not yet published

The trading address is being set up. Rather than print an address that would fail the first check anyone ran on it, it is left visibly blank here, and the signed copy you receive carries the real one. Ask and it comes back the same day.

2. What is being processed

Article 28(3) requires this to be set out precisely rather than described in general terms, so here it is precisely.

Subject matter
Producing and posting a physical direct-mail campaign to the people on a list you supply, and reporting back on what was delivered.
Duration
From the moment you upload a list until the campaign is fulfilled and the list is deleted under section 9 below, or until you ask for it to be deleted, whichever comes first.
Nature and purpose
Checking that each named person and address is current and deliverable; personalising a card and an object for each of them; printing address labels; posting; recording tracking and delivery; and, where a parcel carries one, recording that its QR code was scanned.
Type of personal data
Business-contact data: name, job title, employer, business postal address, and where you supply it, a business email or phone number. Nothing special-category is asked for and none should be sent.
Categories of data subject
The individuals you have chosen to write to (your prospects, customers or contacts) in their professional capacity.

You remain responsible for having a lawful basis to hold the list and to share it with us. For B2B outreach to named individuals at their work address that is usually legitimate interests, but it is your assessment to make and to document, not ours.

3. We process your list only on your instructions

We use the list only to produce and post the campaign you ordered, and to report back on it. Your order, your uploaded file and anything you tell us in writing about it are your documented instructions. We will not use it for our own marketing, will not use it for anyone else's campaign, and will not enrich, resell or share it. If we ever think an instruction would breach data protection law, we will say so before acting on it.

4. Everyone who touches it is bound to confidentiality

In practice one named person handles every list: Charlie Hollinrake, who is bound by this agreement personally. If anyone else is ever brought in to help with fulfilment, they will be under a written confidentiality obligation before they see a single name, and they will be added to the sub-processor list below before they start.

5. Security

Your list travels to us over an encrypted connection and is stored in a database in London. Access is limited to the one person who fulfils the order; the ops area that displays it is password-protected and is excluded from search engines. The links that take you back to your own order are signed and unguessable rather than sequential, so an order cannot be found by counting. Card details never reach our servers at all. Stripe handles them under its own PCI-DSS systems. On the physical side, the paper your list becomes (address labels and spoiled or spare cards) is printed for one batch only and destroyed once that batch has been posted.

6. Sub-processors, named

You give general authorisation for the sub-processors below. If one is added or replaced we will tell you at least 30 days beforehand, and if you object you can cancel any unfulfilled work and take a full refund of it.

Supabase

The database and file storage holding your order and the list you upload.

London, United Kingdom (AWS eu-west-2).

Netlify

Hosting and serving the site and its upload endpoint.

Global content delivery network; the operator is US-headquartered.

Stripe

Taking payment. Handles your billing details, not your prospect list. Card data never reaches our own servers.

US-headquartered, operating in the UK and EU.

Resend

Sending the transactional email attached to your order: the receipt, the link back to your upload, and the delivery-day report, which names the recipients it is reporting on.

US-headquartered.

Anthropic

Used only for one bespoke printed item that is not in the public catalogue, and only where you have commissioned it. Where it is used, the recipient's name, employer and job title are sent to the model to draft the printed copy. No catalogue campaign uses it.

US-headquartered.

Royal Mail (or a named courier)

Carrying the parcel. They receive the recipient's name, job title and delivery address, because that is the parcel.

United Kingdom.

Each is engaged under its own written data protection terms, and we remain fully liable to you for what any of them does with your data.

7. We help you meet your own duties

If one of your prospects asks you what you hold about them, asks for it to be corrected, or asks to be removed, tell us and we will act on it and confirm in writing. We will not make you chase it. The same applies if you need information from us to complete a data protection impact assessment or to answer the ICO. Any request that reaches us directly from one of your prospects is passed to you rather than answered on your behalf, because the decision is yours to make.

8. If something goes wrong

If we become aware of a personal data breach affecting your list, we will tell you without undue delay and in any case within 24 hours of becoming aware of it, sooner than the law requires of us, because you have 72 hours to report it to the ICO and you cannot start that clock until we have started yours.

You will be told what happened, which records were involved, what the likely consequences are and what we have done about it. If we do not know all of that yet, you will be told what we do know rather than made to wait for a complete account.

9. Deletion and return

Your uploaded list is kept only for as long as it takes to fulfil the campaign, and is deleted after that, sooner if you ask, and we will confirm in writing once it is gone. Ask before deletion and you get a copy back in the format you sent it.

Two things are deliberately kept longer, and it is worth being straight about both:

  • The order record (what was bought, for how much, and when) for the six years UK tax law requires financial records to be kept. It contains your billing details, not your prospects’ contact data.
  • The parcel photograph and proof of posting: one image per parcel, showing the label. It is the evidence behind the free-resend guarantee and behind any Royal Mail claim, so it necessarily shows a name and an address. Ask for it to go early and it goes, but the guarantee on that parcel goes with it, and we will say so before doing it rather than after.

10. Information and audit

Ask, and you get whatever you need to satisfy yourself that this agreement is being kept: what is held for you, where it sits, who has touched it, and the answers to a security questionnaire if your process requires one. An audit or an inspection can be arranged on reasonable notice, once a year or after a breach, and we will not charge you for the first one.

Being honest about scale: this is a one-person business, so what you get is a direct and complete answer from the person who does the work, not a certification report. If your policy requires an independent audit report before you can buy, we do not have one, and it is better that you know that on this page than three weeks into a procurement process.

11. International transfers

Your list is stored in the United Kingdom. Some of the services that surround it (hosting, payment, transactional email) are run by US-headquartered providers, which is normal for a business of this size and is worth telling you rather than glossing over. Where personal data reaches one of them, it is transferred under the safeguards that provider offers for UK data, and we will show you which one on request.

We will not add a provider outside the UK that stores your prospect list itself without telling you first, under the 30 days’ notice in section 6.

12. Getting it signed

Email us and a signed copy of this exact text comes back, with your company named as controller. There is no charge, no minimum order, and no need to be a customer first. Plenty of buyers need the paperwork approved before they are allowed to spend anything at all.

If your legal team would rather we signed yours, send it. We will read it properly and tell you honestly which clauses a one-person business cannot meet, rather than signing something we would quietly fail.

hello@charliehollinrake.co.uk

See also what happens to an uploaded list and our business details.

free resend on failed delivery

dispatch SLA: posted within 5 working days of receiving your list & copy

tracked postage included