Data Processing Agreement
Last updated [2026-10-31]. Draft for legal review; bracketed fields are placeholders.
Draft — for legal review. Version 1.1, effective 2026-10-31. Sub-processor list version 2026-10-31.
How CLI Secure Ltd (WiFinger) processes personal data on your behalf when you use WiFinger: your instructions, security, sub-processors, breach notification, assistance with rights requests, and deletion at the end of the contract. Drafted against UK GDPR Article 28 and the ICO's guidance on controller–processor contracts.
Account owners accept this agreement when they sign up or in the WiFinger admin (Settings → Legal), where a PDF copy of the accepted version is available. Each acceptance is recorded with the version, time, user and IP address. When a new version is published, owners are emailed and asked to accept it.
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the WiFinger Terms of Service between the organisation that holds a WiFinger account (the "Customer") and CLI Secure Ltd ("WiFinger"). It applies whenever WiFinger processes personal data on the Customer's behalf in providing the service.
Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meaning given in the UK GDPR and the Data Protection Act 2018 ("Data Protection Law"). If the Customer is subject to the EU GDPR, references to the UK GDPR include the EU GDPR as applicable.
2. Roles [LAWYER TO REVIEW]
The Customer is the controller of the personal data of its guests and of the users it invites ("Customer Personal Data"). WiFinger is the Customer's processor.
WiFinger is a controller only for the account, billing and support information it needs to run its own business (for example the owner's name, email and invoices), as described in the WiFinger Privacy Notice.
Some parties that receive Customer Personal Data are not WiFinger's sub-processors: (a) sign-in providers a guest chooses on the portal (for example Google, Microsoft, Facebook, LinkedIn or Apple), which act as independent controllers under their own terms; and (b) services the Customer connects itself (for example its CRM, e-mail marketing tool, Zapier or Make, webhooks, review sites or its Wi-Fi vendor's cloud controller), which receive data on the Customer's instruction under the Customer's own agreement with them. WiFinger sends data to them only as the Customer configures.
3. Details of the processing
Subject matter and duration: provision of the WiFinger guest Wi-Fi, consent, analytics and marketing service for the term of the Customer's contract and the deletion period in section 11.
Nature and purpose: hosting a captive portal, recording guest sign-ins and consents, storing the guest database, sending the Customer's email and SMS messages, producing analytics, collecting feedback and reviews, and any other feature the Customer turns on.
Data subjects: the Customer's Wi-Fi guests and visitors; the Customer's staff who use the admin.
Categories of personal data: names, email addresses, mobile numbers, postcodes and other fields the Customer adds to its portal; hashed device identifiers (MAC addresses stored as keyed hashes); connection metadata (times, site, access point, data volume, device type from the browser user agent); consent records (wording, versions, time, IP address and user agent); marketing preferences; feedback and review replies; campaign delivery events. WiFinger never inspects the content of guest traffic.
Special category data: none is intended. The Customer must not configure portal fields that collect special category or criminal offence data.
4. Instructions
WiFinger processes Customer Personal Data only on the Customer's documented instructions, which are this DPA, the Terms of Service and the Customer's configuration of the service, unless UK law requires otherwise; in that case WiFinger will tell the Customer before processing unless the law forbids it on important grounds of public interest.
WiFinger will tell the Customer immediately if, in its opinion, an instruction infringes Data Protection Law.
4A. The Customer's obligations [LAWYER TO REVIEW]
The Customer is responsible for having a lawful basis for the processing it instructs, for the privacy notice and terms shown to guests on its portals, for any legitimate interests assessment or data protection impact assessment it needs, and for the accuracy of the portal wording it publishes.
The Customer must not instruct WiFinger to send marketing to anyone without valid consent, must not configure portal fields that collect special category or criminal offence data, and must keep its own users' access to the admin secure (including two-factor authentication where the Customer requires it).
The Customer's indemnity for marketing sent without a lawful basis, for the content it publishes through the service and for its own breach of Data Protection Law as controller is set out in section 11 of the Terms of Service.
5. Confidentiality
WiFinger ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality and accesses it only as needed to provide and support the service. Staff access to a Customer's account is recorded in that Customer's audit log.
5A. Staff access to guest personal data [LAWYER TO REVIEW]
CLI Secure Ltd personnel access guest personal data only on the Customer's documented instructions or where UK law requires it (UK GDPR Article 28(3)(a)), and only for one of these purposes: a support request from the Customer (the venue); a data subject request; a legal obligation; or a security incident.
Access is limited to named staff who are trained and bound by confidentiality, requires a fresh two-factor authentication (MFA step-up) and is time-limited. Access for a legal obligation also requires the approval of a second authorised person.
Every access is recorded in the append-only audit log, which the Customer can see in the WiFinger admin, and the Customer is notified of it, except where the law prohibits notification.
A request from law enforcement or another public authority is referred to the Customer unless CLI Secure Ltd is legally compelled to act on it itself.
CLI Secure Ltd never uses guest personal data for its own purposes. The staff procedure is documented in the WiFinger platform data access procedure (docs/PLATFORM-DATA-ACCESS.md).
6. Security
WiFinger implements the technical and organisational measures in Schedule 2, appropriate to the risk as required by UK GDPR Article 32, and reviews them regularly. WiFinger may update the measures provided the overall level of protection is not reduced.
7. Sub-processors
The Customer gives WiFinger general written authorisation to engage the sub-processors listed at wifinger.com/subprocessors (Schedule 3). Some are used only when the Customer turns the related feature on.
WiFinger will give the Customer at least 30 days' notice of any intended addition or replacement of a sub-processor by email to the account owners and by a notice in the admin. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for it.
WiFinger imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to the Customer for its sub-processors' performance.
8. International transfers
Customer Personal Data is hosted in the United Kingdom (London). WiFinger transfers Customer Personal Data outside the UK only where the transfer complies with UK GDPR Chapter V, for example under UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework for certified recipients), the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment where required. The safeguard for each sub-processor is listed in Schedule 3.
9. Assistance
Taking into account the nature of the processing, WiFinger assists the Customer by appropriate technical and organisational measures to respond to data subject requests. The service provides self-service tools for this: guest data export, erasure requests with due dates, consent withdrawal, the suppression list and the consent evidence record. WiFinger will forward to the Customer, without undue delay, any request it receives directly from a data subject about Customer Personal Data.
WiFinger also assists the Customer, using the information available to it, with its obligations on security, breach notification, data protection impact assessments and prior consultation with the ICO (UK GDPR Articles 32 to 36).
10. Personal data breaches [LAWYER TO REVIEW]
WiFinger notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases.
Notifications are sent by e-mail to the account owners of each affected organisation and recorded in the Customer's audit log; updates follow as more is known. Notifying or reporting a breach is not an admission of fault or liability by WiFinger.
WiFinger keeps a register of personal data breaches and the actions taken. The Customer, as controller, decides whether to notify the ICO within 72 hours and the affected individuals; WiFinger supports that decision with the information it holds.
11. Deletion or return at the end of the contract [LAWYER TO REVIEW]
Before closing its account the Customer can export its guest data (CSV reports of visitors, sessions, consents and feedback) and the consent evidence record (PDF) from the admin. Exports, including any export provided at the end of the contract, follow the same visibility rule as the admin: they contain contact details only for guests whose marketing consent is still active. Contact details that are hidden from the Customer (guests who have not given, or have withdrawn, marketing consent) are not released to the Customer at the end of the contract; they are removed from the service within 30 days of the guest's last visit. This does not change how data subject requests are handled: they continue to be dealt with as described in sections 5A and 9. For 30 days after the account is closed WiFinger can, on request, reopen the account or provide an export; after that period WiFinger deletes the Customer Personal Data held in the live service (sites, portals, guest contact data, sessions, campaigns, analytics and integrations), unless UK law requires it to be kept.
Consent records and audit logs are append-only evidence. They are retained after closure, with guest profiles already anonymised, so that the Customer can demonstrate that consent was given (UK GDPR Article 7(1)); they are not used for any other purpose. WiFinger does not currently delete them, including after the end of the consent retention period the Customer set (six years by default). WiFinger intends to keep the evidence of a closed account for no longer than six years after closure; the deletion procedure will be introduced in a later version of this DPA, and until then the records are kept.
Invoices, subscription and SMS credit records are WiFinger's own records and are kept for 6 years after the end of the contract for accounting and tax purposes, then deleted.
Encrypted backups are kept off the production server, with Amazon Web Services in its London region (eu-west-2), for up to 12 months (daily copies for 7 days, weekly for 4 weeks and monthly for 12 months) and are deleted as they age out, so deleted data leaves the backups within 12 months. Backups are encrypted before they leave the production server and are used only to restore the service after a failure.
12. Information and audits [LAWYER TO REVIEW]
WiFinger makes available to the Customer the information necessary to demonstrate compliance with UK GDPR Article 28 and allows for and contributes to audits, including inspections, by the Customer or an auditor it mandates, on reasonable notice, during business hours and subject to confidentiality. The Customer's auditor must be bound by confidentiality and must not be a competitor of WiFinger.
Once in each 12-month period the Customer may carry out a remote audit, by questionnaire and review of documentation, free of charge. WiFinger may answer with recent independent security assessment reports where they answer the Customer's questions.
Any further audit in the same period, and any on-site audit, is at the Customer's cost, including WiFinger's reasonable time and expenses, and is agreed in advance on reasonable notice. Nothing in this section limits an audit or inspection by the ICO or another supervisory authority.
13. General
If this DPA conflicts with the Terms of Service on data protection, this DPA prevails. Liability under this DPA is subject to the limitations in section 11 of the Terms of Service, including the separate limit for data protection claims, except where the law does not allow it.
WiFinger may update this DPA to reflect changes in law or in the service. A new version is published at wifinger.com/dpa with its version number, account owners are notified by email and asked to accept it in the admin, and every acceptance is recorded with the version, time, user and IP address.
This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.
Schedule 1 — Processing details
See section 3. Frequency: continuous while the service is used. Retention: as configured by the Customer in Settings → Data protection (defaults: sessions and events 13 months, inactive guests erased after 24 months, contact details of guests without marketing consent removed 30 days after their last visit, consent records 6 years) and section 11 at the end of the contract.
Schedule 2 — Technical and organisational measures [LAWYER TO REVIEW]
Tenant isolation enforced in the data-access layer; role-based access control; mandatory two-factor authentication for WiFinger staff and optional or mandatory MFA for customer users.
Encryption in transit (TLS, HSTS) and at rest (encrypted storage; AES-256-GCM field encryption for credentials, secrets and reversible device addresses); passwords hashed with scrypt; device MAC addresses stored as keyed hashes.
Append-only audit log and consent ledger enforced by database triggers; security headers, input validation, rate limiting and SSRF protection; dependency scanning.
Nightly backups, encrypted before they leave the server and stored away from it with Amazon Web Services in London (eu-west-2), kept for up to 12 months, with restore tests (staff are reminded monthly); documented retention schedule enforced by an automatic job; personal data breach register and response procedure; staff confidentiality obligations and data protection training.
WiFinger staff cannot see guest contact details by default: access requires an individual grant, a stated purpose and reference, a fresh two-factor code and, for legal requests, a second approver; it lasts 30 minutes for one guest and is logged and shown to the Customer (section 5A).
Schedule 3 — Sub-processors
The current list, with the purpose, location and transfer safeguard of each sub-processor, is published at /subprocessors and forms part of this DPA.
Version history
| Version | Effective | Status |
|---|---|---|
| 1.0 | 2026-10-01 | Draft — for legal review |
| 1.1 | 2026-10-31 | Draft — for legal review |