Last updated: 27th July 2026
Data Processing Schedule
This Data Processing Schedule (“Schedule”) is incorporated into and forms part of the Terms and Conditions for accessing the Platform (“Agreement”) entered into between LOSTNRETURNED LIMITED (Company no. 16604363) (“Company”) and the User (as defined in the Platform Terms and Conditions made available on the Platform).
This Schedule becomes effective upon the User’s acceptance of the Agreement and describes how the Company and the User each handle Personal Data in connection with the website (lostnreturned.com) and any other websites the Company operates with the same domain name and different extensions (collectively, the “Platform”). The Platform provides a subscription-based lost and found service whereby subscribers (“owners”) receive unique QR codes linked to personal recovery pages, enabling individuals who have found items (“finders”) to report found items and facilitating owner-finder communications. This Schedule is made available to Users together with, and forms an integral part of, the Platform Terms and Conditions.
The Company processes Personal Data primarily as an independent Controller for all processing activities in connection with the Platform, including: (1) providing the lost and found service, managing User accounts (including owner and business accounts), hosting recovery pages, and facilitating finder-owner communications; (2) Platform operations, security, system monitoring, analytics, order fulfilment, billing, and service improvement; and (3) marketing and customer support. For certain business customers (for example, where a business customer integrates the Platform into its own lost property workflows or staff-access environment), if and only to the extent expressly agreed in writing in the Agreement or an order form, the Company may act as a Processor when processing that business customer’s Personal Data on specific documented instructions, in which case the additional processor terms in clause 3 and related provisions of this Schedule will apply. The Company does not act as a Processor for individual owners or finders. Each role carries distinct obligations under Applicable Privacy Laws, which are outlined in this Schedule.
DEFINITIONS
For the purposes of this Schedule, the terms “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing”, “Processor” and “Sub-Processor” shall have the meanings given to them in the UK GDPR (and, where applicable, the EU GDPR). The following additional terms shall have the meanings:
| Applicable Privacy Laws | all applicable data protection and privacy legislation in force from time to time in the UK including without limitation the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) (DPA 2018); the General Data Protection Regulation ((EU) 2016/679) to the extent applicable; the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended; and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of personal data (including, without limitation, the privacy of electronic communications), and the guidance and codes of practice issued by the Information Commissioner (ICO) or other relevant Supervisory Authority, in each case as applicable to a party; and |
| Protected Data | means the Personal Data processed through the Platform in connection with the Agreement, including but not limited to: (a) owner and subscriber account information (including names, email addresses, phone numbers, login credentials, subscription status, account settings, and recovery page content); (b) finder information (including contact details provided when reporting found items, descriptions of found items, location and timing information, and finder messages); (c) Direct Contact communications data (where enabled) (including message content, delivery status, and associated metadata such as timestamps and routing information, and any identifiers required to transmit messages via third-party messaging channels); (d) QR scan data and technical logs (including scan timestamps, IP addresses, device information, browser data, and usage analytics); (e) order and fulfilment data (including shipping addresses, order history, product selections, gift card and gift membership records); (f) payment references and billing data (processed via third-party payment processors); (g) business customer and business account information (including business contact details, account administrator information, and (where enabled) authorised user details for business accounts, and any uploaded logos or branding materials); (h) marketing preferences and communication records (including suppression list data); and (i) customer support, complaint-handling and correspondence data (including communications with owners, subscribers, finders and business customers), in each case as further described in the Company’s Privacy Policy. |
Any other capitalised terms in this Schedule shall have the meanings set out in the Agreement.
Schedule 1 Data Processing
1 SCOPE OF THIS SCHEDULE
For the purposes of this Schedule and the Agreement, the parties acknowledge and agree that:
(a) This Schedule does not apply to any data which does not, by itself, contain any information that would allow for the identification of an individual and therefore shall not constitute Personal Data under the Applicable Privacy Laws.
(b) Independent Controllers: Except where Company acts as a Processor under clause 2(a), this Schedule does not govern the Parties’ respective obligations when each acts as an independent Controller of Personal Data. Company and the User (including individual subscribers/owners and business customers) operate as separate (and not joint) Controllers in respect of the Personal Data either Party may independently process in connection with the use of the Platform or otherwise, including Personal Data received through the Direct Contact feature or forwarded finder submissions. Accordingly:
(i) Company shall be deemed a separate Controller for any Personal Data it collects from its Users (including individual owners, subscribers and business account holders) and finders through operation of the Platform for its own business purposes as described in the Privacy Policy, including: (a) operating, securing and improving the Platform (including the QR code recovery service, finder notification and forwarding system, Direct Contact feature (where enabled), and account management features); (b) order fulfilment; (c) customer support; (d) service analytics; and (e) marketing.
(ii) User shall be deemed a separate Controller for Personal Data related to: (a) any individuals (including finders) whose data the User receives through the Platform (such as finder contact details and messages forwarded, routed or otherwise made available by the Company via email, Direct Contact, or similar features); and (b) (for business accounts only and where enabled) any staff, contractors, customers or other individuals whose data the User inputs into, uploads to, or otherwise makes available through the Platform.
(iii) The parties hereby undertake to respect applicable laws which apply to them as separate Controllers and to be liable separately for their own controllership obligations and responsibilities when acting as separate Controllers.
2 ROLES OF THE PARTIES
The parties agree that this Schedule shall apply to processing activities as follows:
(a) Where the Agreement or an applicable order form expressly states that, in respect of specified processing activities, a business User acts as Controller and Company acts as Processor, the provisions of clauses 3 to 13 (inclusive), Part A, Part B, and Part C of this Schedule shall apply to Company’s processing of Protected Data for those activities.
(b) For all other processing of Personal Data in connection with the Platform (including where the User (whether an individual owner/subscriber or a business customer) uses the Platform (including the Direct Contact feature) for its own organisational or personal purposes without an express processor designation in the Agreement), the Company acts as an independent Controller for its processing and the User acts as an independent Controller for its processing, and each party shall comply with Applicable Privacy Laws in respect of its own processing activities.
Nothing in this Schedule relieves either party of any of their respective responsibilities or liabilities under the Applicable Privacy Laws in respect of their own processing of Personal Data.
3 USER’S COMPLIANCE WITH APPLICABLE PRIVACY LAWS
When acting as Controller in respect of Protected Data for which Company acts as Processor under clause 2(a), User shall at all times comply with all Applicable Privacy Laws. User shall ensure all instructions given by it to the Company in respect of Protected Data (including the terms of this Schedule) shall at all times be in accordance with Applicable Privacy Laws. User shall be solely responsible for ensuring that it has obtained all applicable consents and has provided all advance notice and information of the processing contemplated hereunder to any Data Subjects (including its own staff, contractors, customers and other end-users), as required of it under Applicable Privacy Laws. Without limiting the foregoing, where a business User enables or uses the Direct Contact feature to communicate with finders or other individuals (including via SMS, WhatsApp or similar channels), User is responsible as an independent Controller for (i) providing any required privacy information and channel-specific notices, and (ii) ensuring it has a valid lawful basis and, where applicable under PECR/e‑privacy rules, the necessary consent to send such communications.
For business Users, Direct Contact is provided as a facilitation tool only. User acknowledges and agrees that: (i) User determines the purposes and means of any follow-up communications it sends to finders (or other individuals) using details received through the Platform and is solely responsible for such communications as an independent Controller; (ii) User will implement appropriate internal access controls and staff training to ensure only authorised personnel access and use finder/owner contact details and Direct Contact communications; and (iii) User will not use finder contact details for unrelated marketing unless it has a valid lawful basis and, where required, the necessary consent, and has provided an appropriate privacy notice.
4 COMPANY’S COMPLIANCE WITH APPLICABLE PRIVACY LAWS
When acting as Processor under clause 2(a), Company shall process Protected Data in compliance with the obligations placed on it under Applicable Privacy Laws and the terms of this Schedule. When acting as Controller, Company shall comply with Applicable Privacy Laws in respect of its own processing activities as described in the Privacy Policy.
5 INSTRUCTIONS
Where Company acts as Processor under clause 2(a), Company shall only process (and shall ensure that its personnel and Sub-Processors only process) the Protected Data in accordance with the User’s documented instructions set out at Part A of this Schedule and the other terms of this Schedule, except to the extent: (a) that alternative processing instructions are agreed between the parties in writing; or (b) otherwise required by Applicable Privacy Laws (in which case, Company shall inform the User of that legal requirement before processing, unless applicable law prevents it doing so on important grounds of public interest). If the Company believes that any instruction received by it from the User is likely to infringe the Applicable Privacy Laws, it shall be entitled to cease to provide the relevant services under the Agreement, without liability, until the parties have agreed appropriate amended instructions which are not infringing.
6 SECURITY
To protect the Protected Data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access, the Company shall, where it acts as Processor under clause 2(a), implement and maintain as a minimum the following appropriate technical and organisational measures including, but not limited to: (a) encryption of data in transit using TLS/HTTPS and at rest using industry-standard protocols; (b) secure authentication and access controls for platform accounts and administrative access; (c) regular security assessments appropriate to the Company’s size and resources; (d) secure handling of finder notification emails, including appropriate transmission security; (e) logging and monitoring of QR scan activity and finder form submissions; (f) anti-abuse controls including rate limiting and CAPTCHA on public-facing finder forms; (g) secure processing of orders and fulfilment data with access limited to authorised personnel only; (h) secure backup systems for account and QR code data; (i) staff training on data protection and secure handling of personal data; (j) where the Direct Contact feature uses third-party messaging channels, secure management of any messaging credentials/tokens, least-privilege access, and reasonable data minimisation in message payloads; and (k) specific measures detailed in Part B of this Schedule.
7 SUB-PROCESSING
The Company’s current list of Third-Party Providers is set forth in Part C and includes payment providers, website hosting and management providers, email service providers, messaging and communications service providers (including any SMS or WhatsApp integration providers where enabled), shipping and delivery providers, and other service providers necessary for Platform operations. Where Company acts as a Processor under clause 2(a), those Third-Party Providers which process Protected Data on Company’s behalf shall act as Company’s Sub-Processors. Company shall maintain an up-to-date list of its Third-Party Providers and shall notify the User by email at least thirty (30) days in advance of any intended additions or replacements of any Sub-Processor used in connection with processing carried out by Company as a Processor. User may object to such changes within fourteen (14) days of receiving notice. If User objects to a new Sub-Processor and Company cannot reasonably accommodate that objection, User may terminate the affected processing and/or affected services under the Agreement by written notice without penalty and will receive a pro-rata refund of any pre-paid fees relating to those affected services.
8 DATA SUBJECTS RIGHTS
(a) Where Company acts as Processor under clause 2(a), Company shall (at the User’s reasonable cost) assist User in ensuring compliance with User’s obligations pursuant to Articles 32 to 36 of the GDPR (and any similar obligations under the Applicable Privacy Laws) taking into account the nature of the processing and the information available to Company. Taking into account the nature of the processing, Company shall (at the User’s cost) assist User by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the User’s obligations to respond to requests for exercising the Data Subjects’ rights under Chapter III of the GDPR (and any similar obligations under Applicable Privacy Laws) in respect of any Protected Data.
(b) Where Company acts as Processor under clause 2(a), Company shall promptly notify the User if it receives a request from a Data Subject under any Applicable Privacy Law in respect of the User’s Protected Data; and ensure that it does not respond to that request except on the documented instructions of the User or as required by applicable laws to which Company is subject, in which case Company shall to the extent permitted by applicable laws inform User of that legal requirement before responding to the request.
9 INTERNATIONAL TRANSFERS
Where Company acts as Processor under clause 2(a), Company shall not transfer or otherwise disclose any Protected Data to countries outside of the United Kingdom or European Economic Area (EEA) without implementing appropriate transfer mechanisms as required by Applicable Privacy Laws, including where applicable the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or other approved safeguards under Chapter V of the UK GDPR and/or EU GDPR (as applicable). The Company may process orders and fulfilment activities in both the United Kingdom and the Netherlands (EEA). The Company will make available to Users, upon request, reasonably necessary information about applicable international transfer safeguards relevant to the Services (including in relation to Sub-Processors, and any third-party messaging providers used for Direct Contact where enabled). Any transfers outside the UK/EEA shall be subject to appropriate safeguards and documented in accordance with Applicable Privacy Laws. If the transfer is required by law, Company will inform the User of the legal requirement before such transfer (to the extent permitted by law). Where required for the relevant cross-border transfers, the parties will implement the applicable Standard Contractual Clauses and/or UK transfer documentation.
10 AUDITS AND PROCESSING
Where Company acts as Processor under clause 2(a), Company shall, in accordance with Applicable Privacy Laws, make available to User such information that is in its possession or control as is necessary to demonstrate Company’s compliance with the obligations placed on it under this Schedule and to demonstrate compliance with the obligations on each party imposed by Article 28 of the GDPR (and under any equivalent Applicable Privacy Laws equivalent to that Article 28) for any Protected Data, and allow for and contribute to audits, including inspections, by User (or another auditor mandated by User) for this purpose (subject to a maximum of one audit request in any 12-month period, and provided that such audit is conducted on reasonable notice, during normal business hours in the United Kingdom, and results in minimal disruption to Company’s business, except where the audit relates to or follows a Personal Data Breach).
11 PERSONAL DATA BREACH
Where Company acts as Processor under clause 2(a), Company shall notify User without undue delay and in writing on becoming aware of any Personal Data Breach in respect of any Protected Data and provide all information that Company considers User would reasonably require in order to handle such Personal Data Breach. Company shall cooperate with User and take reasonable commercial steps as are directed by User to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
12 DELETION/RETURN
(a) Where Company acts as Processor under clause 2(a), upon termination of provision of the Services under the Agreement relating to the processing of Protected Data, at User’s cost and User’s option, Company shall either return the Protected Data that has been provided by the User only to User or securely dispose of such Protected Data that was provided by the User (and thereafter promptly delete all existing copies of it) except to the extent that any applicable law requires Company to store such Protected Data.
(b) Notwithstanding the foregoing Section 12(a), Company shall not be obligated to delete any data which has since become integrated to the Services or Company’s own database during or after the term of the Agreement, such data either not being Personal Data to the extent that it has been anonymised and aggregated so no Data Subject is personally identifiable and such data cannot be attributed to the User or any Data Subject, or Company becoming Controller of such data (it being Personal Data and not Protected Data), and thus being responsible for its own compliance with Applicable Privacy Laws in respect of such datasets and Company’s own Controller obligations.
13 JOINT-CONTROLLERSHIP.
(a) For the avoidance of doubt, the parties do not intend to act as joint controllers in respect of any processing of Personal Data in connection with the Platform. Each party acts as an independent Controller in respect of the Personal Data it determines the purposes and means of processing for and is separately responsible for its own compliance with Applicable Privacy Laws.
(b) Each party will provide a compliant data privacy notice to any end-users or other Data Subjects whose Personal Data it processes as Controller, in accordance with Articles 13 and 14 of the UK GDPR, informing such individuals of its identity, the purpose or purposes for which their Personal Data will be processed, the legal basis for processing, data retention periods, Data Subject rights, and any other information required under Applicable Privacy Laws to enable fair and lawful processing.
14 LIABILITY
Each party shall only be liable for its own breach of the Applicable Privacy Laws or of this Schedule and shall not be jointly and/or severally liable for the other party’s breach. Accordingly, each Party agrees to indemnify the other Party for any losses, damages, costs, and expenses (including reasonable legal fees) incurred by the other Party due to the indemnifying Party’s breach of the Applicable Privacy Laws arising out of or in connection with its processing of Personal Data under or in connection with the Agreement. In all cases, Company’s liability to the User for any breach of this Schedule or the Applicable Privacy Laws shall be subject to the limitations and exclusions of liability contained in the Agreement, except where such limitations or exclusions are prohibited by law or would be unenforceable under Applicable Privacy Laws.
15 GENERAL TERMS.
(a) Confidentiality: The confidentiality provisions in the Agreement shall apply to all information and data contemplated under this Schedule.
(b) Notices: All notices and communications given under this Schedule must be in writing and will be sent by email or through the Platform’s notification system to the user account as set out in the Agreement or registered on the Platform. Notices sent through the Platform’s notification system shall be deemed received when made available in the user’s dashboard.
(c) Governing Law and Jurisdiction: This Schedule is governed by the laws of England and Wales. Any dispute arising in connection with this Schedule, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of England and Wales.
Part A Processing Activities
Processing of the Personal Data by Company under this Schedule and the Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of Personal Data and categories of Data Subjects set out in this Part A. The Company acts as an independent Controller when processing Personal Data for its lost and found service operations, including hosting personal recovery pages, facilitating finder-to-owner contact (including forwarding finder submissions and facilitating the Direct Contact feature where enabled), managing subscriptions and accounts (for both individual owners and business customers), processing orders, platform analytics, service improvement, marketing, and customer support, as described in the Company’s Privacy Policy. Where the Direct Contact feature uses third-party messaging channels (for example, SMS or WhatsApp), the Company may engage relevant service providers to transmit communications, and such providers will be treated as the Company’s processors (and, where Company acts as a Processor under clause 2(a), as Sub-Processors) for the relevant processing. Where the Company is expressly designated to act as a Processor in the Agreement or an order form for specific processing activities carried out on behalf of a business User, those activities and instructions will be documented in the relevant order form and/or written instructions and supplemented by this Schedule.
| Subject-matter of processing | To enable Company to provide the Services and perform its obligations under the Agreement for the provision of a subscription-based lost and found service through its online platform and mobile application, including personal QR code recovery pages, finder reporting and forwarding system, facilitation of finder-to-owner contact (including Direct Contact where enabled and any associated third-party messaging transmission), account and subscription management, order processing and fulfilment, and related services, where the same has been subscribed to by User through the Platform’s Terms of Service. |
| Duration of the processing | For the duration of the Agreement and for any additional period during which Company is required to process Personal Data, including any minimum retention periods agreed in the Agreement or required by law. Where Company acts as Processor: Upon termination, Personal Data processed as Processor shall be returned to the User or securely deleted in accordance with clause 12, unless retention is required by law. Where Company acts as Controller: Personal Data which Company processes as Controller will be retained and deleted in accordance with the Company’s Privacy Policy and Applicable Privacy Laws and will not be covered by the return/deletion obligations applicable to data processed as Processor. |
| Nature and purpose of the processing | To enable Company to provide the Services (namely lost and found facilitation services, including QR code recovery pages, finder reporting system, owner notification and communication facilitation (including Direct Contact where enabled), subscription and account management, order fulfilment, and customer support) to User pursuant to the terms of the Agreement. |
| Type of Personal Data | The Personal Data processed includes, but is not limited to: (i) owner and subscriber account information (including names, contact details, login credentials, subscription data, and account preferences); (ii) finder information (including names, contact details, found item descriptions, location and timing information, and messages); (iii) Direct Contact communications data (including message content and delivery metadata, and identifiers needed to transmit messages via third-party messaging channels where enabled) (iv) QR scan logs and usage data (including timestamps, IP addresses, device information, and analytics data); (v) order and shipping information (including delivery addresses and order history); (vi) payment references and billing data (processed via third-party payment processors); (vii) business account data (including business contact details, administrator and (where enabled) authorised user information, and uploaded branding materials); (viii) communication records and customer support correspondence; and (ix) any other Personal Data as contemplated in the Company’s Privacy Policy made available on the Platform. |
| Categories of Data Subjects | Subscribers and owners (individual consumers), finders (individuals who scan QR codes and submit found item reports), business customers and business account administrators, authorised users of business accounts (where such functionality is enabled), gift card and gift membership purchasers and recipients, and other individuals whose Personal Data is processed through the Platform’s lost and found service (including individuals who contact customer support or whose details appear in communications related to the service). |
Part B Technical and organisational security measures
In accordance with Applicable Privacy Laws, the Company implements: (a) role-based access controls with strong authentication (including multi-factor authentication where appropriate based on risk assessment) for administrative access to platform systems; (b) regular security assessments and vulnerability management, with frequency and scope appropriate to the risks presented by the processing and the Company’s size and resources; (c) documented incident response procedures with timelines designed to support User’s obligations under Applicable Privacy Laws; (d) secure backup systems for account data, QR code configurations, and finder submissions; (e) staff training on data protection at onboarding and periodically thereafter; (f) secure email transmission for finder notification emails to owners, including appropriate transport security; (g) anti-abuse and security measures for public-facing finder forms and Platform services, including rate limiting, CAPTCHA, web application firewall (WAF) protections, distributed denial-of-service (DDoS) mitigation, bot detection and management, and monitoring for spam, malicious activity, or unauthorised access attempts; (h) access logging and monitoring for administrative activities; (i) secure order processing procedures with access limited to authorised fulfilment personnel in the UK and Netherlands; (j) where Direct Contact uses third-party messaging channels (e.g., SMS/WhatsApp), reasonable safeguards to reduce unauthorised access and misuse (including credential protection, least-privilege access, and monitoring for abuse); and (k) those matters mentioned in Articles 32(1)(a) to 32(1)(d) (inclusive) of the GDPR. Where Company acts as Processor, Company shall notify User without undue delay after becoming aware of any Personal Data Breach affecting Personal Data processed on behalf of User, to allow User to make its own determination of risk to the rights and freedoms of natural persons and meet its regulatory obligations. Where Company acts as Controller, Company shall handle Personal Data Breaches in accordance with its obligations under Applicable Privacy Laws, its internal Data Breach Policy and Incident Response Procedures, and its Privacy Policy. Such notifications shall be made by email to the designated contact person or through the Platform’s notification system.
Part C Company’s Third-Party Providers
| Third-Party Providers | Processing Activity | Location (inside or outside of the UK or EEA) | Compliance URL | International Transfer Mechanism |
| Stripe | Payment processing (processing payments and storing payment card details on Stripe’s systems; providing payment references/transaction status to Company) | Global processing, including the European Union, United States and India. | https://stripe.com/privacy | EU-US Data Privacy Framework, UK Extension to the EU-US Data Privacy Framework and Swiss-US Data Privacy Framework where applicable; otherwise EU SCCs and/or UK IDTA/UK Addendum as applicable, plus supplementary measures where required. |
| Mitchell Digital | Hosting infrastructure / data storage and related operational support | United Kingdom (UK) | https://mitchelldigital.co.uk/legal/professional-privacy-policy/ | Not applicable — UK-to-UK processing |
| Klaviyo | Email marketing automation (managing mailing lists, sending marketing emails, segmentation, campaign analytics) | United States (US) | https://www.klaviyo.com/legal/privacy | EU-US Data Privacy Framework, UK Extension to the EU-US Data Privacy Framework and Swiss-US Data Privacy Framework where applicable; otherwise EU SCCs and/or UK IDTA/UK Addendum as a fallback. |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery (sending service emails such as account verification, notifications, password resets, support confirmations) | United States (US) | https://postmarkapp.com/privacy-policy | EU-US Data Privacy Framework and UK Extension to the EU-US Data Privacy Framework (where applicable); otherwise Standard Contractual Clauses (SCCs) and/or the UK International Data Transfer Addendum (IDTA) as applicable, together with supplementary safeguards where required. |
| Google Workspace (Google LLC) | Business email and collaboration (processing customer/support emails; storing communications and attachments; admin and security logs) | Global processing, including Ireland, United States and other countries where Google or its sub-processors operate. | https://policies.google.com/privacy | Adequacy where applicable; otherwise EU Standard Contractual Clauses and/or UK IDTA/UK Addendum as applicable, plus supplementary measures where required. |
| Google Analytics (Google LLC) | Website analytics (usage measurement, event tracking, device/browser information, IP handling and reporting). | Global processing, including Ireland, United States and other countries where Google or its sub-processors operate. | https://policies.google.com/privacy | Adequacy where applicable; otherwise EU Standard Contractual Clauses and/or UK IDTA/UK Addendum as applicable, plus supplementary measures where required. |
| WooCommerce / Automattic group | E-commerce platform functionality (order processing, customer accounts, checkout data, store administration; customer/order data stored in the store database) | Global processing, including Ireland, United States and other countries where WooCommerce, Automattic or their sub-processors operate | https://automattic.com/privacy/ | Adequacy where applicable; otherwise EU SCCs and/or UK IDTA/UK Addendum (as applicable) plus supplementary measures where required |
| 123 Reg | Domain registration and (if applicable) web hosting / DNS management (website availability, DNS records; potential access to server logs and limited personal data depending on configuration) | United Kingdom (UK). Personal data may be transferred internationally via 123 Reg’s group companies and service providers where necessary to provide services. | https://www.123-reg.co.uk/terms/privacy/ | UK adequacy regulations where applicable; otherwise UK IDTA/Addendum and/or EU Standard Contractual Clauses (SCCs) with supplementary safeguards, as described in 123 Reg’s Privacy Notice and DPA. |
| Xero (UK) Limited / Xero group | Accounting and bookkeeping (processing invoices/transactions; storing customer billing/contact details; financial reporting) | Global processing, including Australia, New Zealand and the United States. | https://www.xero.com/uk/about/terms/privacy/ | Adequacy where applicable, including New Zealand where applicable; otherwise Standard Contractual Clauses and/or UK-approved equivalent safeguards, plus supplementary measures where required. |
| Cloudflare, Inc. | Content delivery network (CDN), website security, DDoS protection, DNS services, caching, SSL/TLS encryption and website performance optimisation. May process IP addresses, request metadata and security logs. | Global processing, including the United States, European Union and other countries where Cloudflare or its service providers operate. | https://www.cloudflare.com/privacypolicy/ | EU-US Data Privacy Framework and UK Extension where applicable; otherwise EU Standard Contractual Clauses (SCCs) and/or UK IDTA/UK Addendum together with supplementary measures where required. |
| Royal Mail Group Limited | Shipping label creation, parcel collection, delivery, tracking and related postal services. Processes customer delivery information required to fulfil orders. | United Kingdom (UK). International shipments may involve trusted overseas postal operators and courier partners. | https://www.royalmail.com/privacy-notice | Not applicable for LostnReturned’s relationship with Royal Mail. Royal Mail generally acts as an independent data controller for postal and delivery services under its own privacy notice and terms. |
| PostNL N.V. | Shipping label creation, parcel delivery, tracking and related postal services. Processes customer delivery information required to fulfil orders. | Netherlands (EEA). International shipments may involve trusted postal operators and courier partners. | https://www.postnl.nl/en/privacy-statement/ | Not applicable for LostnReturned’s relationship with PostNL. PostNL generally acts as an independent data controller for postal and delivery services under its own privacy statement. |
