Lion & Stone and Safe-Scale®
Data Processing Agreement (DPA)
Last Updated: 23 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the parties and supplements the Lion & Stone and Safe-Scale® Terms & Conditions.
This DPA applies automatically whenever Lion & Stone Growth Advisory Ltd processes Personal Data on behalf of the Controller in connection with Lion & Stone services, Safe-Scale® or related Services.
Lion & Stone Growth Advisory Ltd, a private limited company incorporated in England and Wales with company number 16439253 and registered office at Ringwood, England, BH24 3AS, trading as Lion & Stone and operating the Safe-Scale® platform (“Processor”, “we”, “our”, “us”);
and
the client, business or organisation using Lion & Stone services, Safe-Scale® or related Services (“Controller”, “you”, “your”).
1. Purpose
The purpose of this DPA is to define the responsibilities of each party regarding the processing of Personal Data in accordance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Any other applicable data protection legislation
This DPA forms part of and supplements the applicable Lion & Stone and Safe-Scale® Terms & Conditions.
2. Definitions
For the purposes of this DPA:
Controller
The organisation which determines the purposes and means of processing Personal Data.
Processor
The organisation which processes Personal Data on behalf of the Controller.
Personal Data
Any information relating to an identified or identifiable natural person.
Data Subject
The individual to whom Personal Data relates.
Processing
Any operation performed on Personal Data including collection, storage, organisation, retrieval, use, disclosure, transfer or deletion.
Sub-processor
A third party engaged by the Processor to assist with the delivery of services involving Personal Data.
Applicable Data Protection Law
UK GDPR, Data Protection Act 2018 and any applicable data protection legislation.
3. Scope of Processing
The Processor may process Personal Data for the purpose of providing:
- Safe-Scale platform access
- CRM services
- Marketing automation
- Websites and funnels
- Appointment booking
- Contact management
- Email and SMS communications
- Customer support
- Reporting and analytics
- Related business support services
The categories of Personal Data processed may include:
- Names
- Email addresses
- Telephone numbers
- Postal addresses
- Business information
- CRM records
- Communication history
- Appointment data
- Marketing interaction data
The categories of Data Subjects may include:
- Customers
- Prospects
- Leads
- Suppliers
- Employees
- Contractors
- Website visitors
- Other business contacts
Processing shall continue for the duration of the service relationship unless otherwise required by law.
4. Controller Responsibilities
The Controller confirms that:
- It has the legal right to collect and process the Personal Data.
- It has provided any required privacy notices.
- It has obtained any required consents.
- It has identified an appropriate lawful basis for processing.
- It will comply with applicable data protection legislation.
- Any instructions provided to the Processor are lawful.
The Controller remains responsible for determining the purposes and means of processing Personal Data.
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller unless otherwise required by law.
- Maintain appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures.
- Assist the Controller in meeting its data protection obligations where reasonably possible.
- Notify the Controller of a Personal Data Breach without undue delay after becoming aware of it.
- Maintain records where required by applicable law.
- Comply with applicable data protection legislation.
The Processor shall not sell Personal Data.
6. Confidentiality
The Processor shall ensure that personnel authorised to process Personal Data:
- Are subject to confidentiality obligations; or
- Are under an appropriate statutory duty of confidentiality.
Access to Personal Data shall be restricted to individuals who require access for legitimate service delivery purposes.
7. Security Measures
The Processor shall implement reasonable technical and organisational measures designed to protect Personal Data against:
- Unauthorised access
- Accidental loss
- Destruction
- Alteration
- Disclosure
- Misuse
Security measures may include:
- Access controls
- User authentication
- Encryption where appropriate
- Logging and monitoring
- Secure infrastructure
- Backup procedures
The Controller acknowledges that no system can guarantee absolute security.
8. Sub-processors
The Controller authorises the Processor to engage Sub-processors where reasonably necessary to provide services.
Sub-processors may include providers of:
- CRM infrastructure
- Cloud hosting
- Telephony services
- Email delivery
- AI services
- Analytics
- Payment processing
- Website infrastructure
- Customer support systems
Current Sub-processors may include:
- CRM / LeadConnector
- Twilio
- OpenAI
- Microsoft
- Stripe
- Other service providers reasonably required to deliver services
The Processor shall ensure that Sub-processors are subject to appropriate contractual obligations regarding the protection of Personal Data.
9. International Transfers
The Controller acknowledges that Personal Data may be processed by the Processor or its Sub-processors in countries outside the United Kingdom.
Where a transfer of Personal Data outside the United Kingdom is a restricted transfer under applicable data protection law, the Processor will ensure that an appropriate transfer mechanism is in place before making that transfer.
This may include:
- a country covered by UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful transfer mechanism permitted under applicable data protection law.
Where required, the Processor will carry out the relevant assessment and implement any additional safeguards reasonably necessary to protect Personal Data.
10. Assistance with Data Subject Rights
Taking into account the nature of processing, the Processor shall provide reasonable assistance to enable the Controller to respond to requests relating to:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Portability
The Controller remains responsible for responding to Data Subject requests.
11. Personal Data Breaches
The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
Where reasonably available, the notification shall include:
- The nature of the breach.
- The categories of affected data.
- The likely consequences.
- Measures taken or proposed to address the breach.
The Controller remains responsible for determining whether notification to regulators or Data Subjects is required.
12. Audits and Information Requests
Where reasonably necessary to demonstrate compliance with this DPA, the Processor shall provide information regarding its processing activities.
The Processor may satisfy such requests through:
- Policies
- Security documentation
- Certifications
- Compliance documentation
- Written responses
The Processor is not required to disclose confidential information, proprietary information, trade secrets or information relating to other customers.
13. Deletion and Return of Data
Upon termination of services and subject to technical limitations, legal obligations and retention requirements, the Processor shall:
- Delete Personal Data; or
- Return Personal Data to the Controller where reasonably practicable.
The Controller acknowledges that certain records may remain in backups, logs or archives for a limited period as part of normal business continuity processes.
14. Liability
Liability relating to data protection matters shall be governed by the liability provisions contained within the applicable Terms & Conditions between the parties.
Nothing in this DPA limits or excludes liability where such limitation would be prohibited by law.
15. Governing Law
This DPA shall be governed by the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction regarding disputes arising under this DPA.
16. Contact
Questions relating to this DPA should be directed to:
Lion & Stone Growth Advisory
Lion & Stone website: www.lionandstone.co.uk
Safe-Scale website: www.safescale.co.uk
Safe-Scale platform: portal.safescale.co.uk
Lion & Stone email: [email protected]
Safe-Scale support email: [email protected]
ICO Registration Number: ZC183568