Doula Website Co — a trading name of Rabblepop Ltd
Version 1.0 — effective 13 September 2026
These terms apply when you buy a website from us. Please read them — they are written to be readable, and they explain what you get, what it costs, and what happens if you leave.
We are Rabblepop Ltd, a company registered in England and Wales, company number 17361712, registered office 320 Firecrest Court, Centre Park, Warrington, WA1 1RG, trading as Doula Website Co ("we", "us", "our").
You are the person or business buying the website ("you", "your").
1. AGREEING TO THESE TERMS
1.1 You agree to these terms when you tick the box at checkout and pay. That creates a contract between us. There is nothing else to sign. Our payment provider, Stripe, records that you accepted these terms, and we record which version you accepted.
1.2 By agreeing, you confirm that:
(a) you are buying this website for the purposes of your doula practice or business, and not as a consumer;
(b) you want us to start work straight away, and you understand that once we have built your website you cannot cancel and get your money back for that year; and
(c) the information you give us is accurate.
1.3 We may update these terms for new customers at any time. The version you agreed to at checkout applies to you until your next renewal. If we change the terms, we will email you at least 30 days before your renewal with what has changed, and you can cancel before the new version applies. Every version stays available at a permanent address on our website.
2. WHAT YOU GET
2.1 For your annual fee we will:
(a) design and build a website for your doula practice;
(b) write your initial page copy and source imagery for it;
(c) set it up so you can edit your own text, images and blog posts through a simple content management system;
(d) structure it properly for search engines;
(e) host it, keep it secure and up to date, and back it up; and
(f) provide support (see clause 7).
2.2 Your website has no page limit. Add as many as you need.
3. WHAT IT COSTS
3.1 The fee is £300 per year. There is no setup fee.
3.2 The fee is payable in advance, by card, when you sign up and on each renewal.
3.3 The fee is currently inclusive of VAT because we are not VAT registered. If we become VAT registered we will absorb the VAT for the remainder of your current year, and tell you at least 30 days before your next renewal what the fee will be.
3.4 We may change the fee for future years. We will tell you at least 30 days before your renewal date. If you do not want to pay the new fee you can cancel before it takes effect.
4. BUILDING YOUR WEBSITE
4.1 Before you buy, we will have a call about your practice. After you pay, we will confirm by email everything we need from you — typically your bio, services, photos, any testimonials, and your domain details.
4.2 We will aim to have your website ready to preview within 5 working days of receiving everything we need. If things take longer to arrive, that timescale moves accordingly.
4.3 You get two rounds of revisions on the design before it goes live. Further changes after that are chargeable, or you can make them yourself in the CMS.
4.4 Your website goes live once you approve it.
4.5 If you do not send us what we need, or respond to us, for 60 days, we may treat the build as finished. Your year runs from the date you paid either way.
5. YOUR CONTENT AND YOUR DOMAIN
5.1 Your content is yours. The words you give us, your photographs, your logo and your brand remain yours. The copy we write for you is yours too.
5.2 Your domain is registered in your name. If you already have one, you keep it. If you do not and we register one for you, we register it in your name and you own it. You can take it with you whenever you like.
5.3 You are responsible for what your website says. You confirm that your content is accurate and lawful, and that you hold the qualifications, memberships and insurance your website claims you hold.
5.4 Testimonials and birth stories. If your website includes testimonials, birth stories or anything else about the families you have worked with, you must have their permission. This information is personal to them and often includes health information, which carries extra protection under data protection law. You are responsible for obtaining and keeping a record of that consent. If you are not sure whether you have it, do not send it to us.
5.5 Enquiries from families. People who contact you through your website will often tell you they are pregnant, when they are due, or something about their health or a previous birth. That is health information, and data protection law treats it as a special category that needs extra care. You decide how enquiries are used, so you are responsible for handling them lawfully. To help, every website we build comes with:
(a) an enquiry form that asks only for what you need to reply, with a tickbox asking the enquirer to agree to you using what they tell you to respond to them;
(b) a privacy notice for your website, written for you to check and approve — it is yours to publish and you are responsible for it being accurate; and
(c) no file upload on your enquiry form.
If you ask us to add fields, uploads or anything else that collects more information, you are responsible for making sure you have a lawful basis for it.
5.6 No tracking by default. We do not add analytics, tracking pixels or advertising tags to your website, so visitors are not asked to accept cookies. If you ask us to add them, you are responsible for obtaining visitors' consent, and we will add a consent banner as part of that work.
6. WHAT WE OWN
6.1 This is the part that is easy to misunderstand, so it is in plain terms.
6.2 We build your website at no upfront cost and recover that over the years you stay with us. So you are licensed to use the website for as long as you subscribe — you do not own the build itself. That covers the design, the templates, the code and the hosting setup.
6.3 The imagery we provide — whether licensed stock photography or images we create for you, including with AI tools — is licensed for use on your website only. It is not yours to reuse elsewhere.
6.4 The images are illustrative. Images we provide do not show your clients, their babies or their births. Do not present them as if they do, or use them to suggest outcomes, experience or families you have not worked with. If you want to show real families, use your own photographs with their permission under clause 5.4.
6.5 If you leave, you take your content, your copy and your domain. You do not take the website itself, and it will not be transferred to another host or developer.
6.6 We may show your website in our portfolio and marketing. Tell us if you would rather we did not.
7. SUPPORT
7.1 Support is included. Email us and we will help — we aim to respond within one working day on working days.
7.2 Support covers keeping your site running and helping you use it: fixing faults, security and platform updates, backups, and answering questions about the CMS.
7.3 Day-to-day content changes are for you to make in the CMS — that is what it is for, and it is quicker than waiting for us. We are happy to help when you are stuck.
7.4 Fair use. Support is provided on a fair use basis. If your requests go well beyond what is reasonable for £300 a year — for example, repeatedly asking us to rewrite or restructure your site — we will tell you and quote for the work rather than simply saying no. Redesigns, new functionality and substantial new content are not included.
8. HOW LONG IT LASTS
8.1 Your subscription runs for 12 months from the date you pay, and renews automatically each year unless you cancel.
8.2 We will email you a reminder at least 30 days before each renewal, telling you the date and the amount.
8.3 You can cancel at any time, and cancellation takes effect at the end of the year you have paid for. We do not refund part-years — the fee covers building and running your site for that year, and the build cost is spent at the start.
8.4 To cancel, email us. We will confirm in writing.
9. IF PAYMENT FAILS
9.1 If your renewal payment fails, we will try again and email you.
9.2 If it is still unpaid after 14 days, we may take your website offline.
9.3 We will keep your website and data for a further 30 days after that, so you can pay and have it restored, or ask us for an export. After that it may be permanently deleted.
9.4 Your domain is yours throughout and is not affected.
10. IF YOU LEAVE
10.1 At the end of your final paid year your website goes offline.
10.2 On request we will give you an export of your content — your text and the images you supplied — in a usable format, free of charge, within 30 days of your subscription ending.
10.3 Your domain remains yours and you can point it wherever you like.
11. WHAT WE DO NOT PROMISE
11.1 We build your website to be found on Google, but we cannot guarantee any particular ranking, position or amount of traffic or enquiries. Search engines are run by third parties and change how they work without notice.
11.2 Your website is hosted on third-party infrastructure. We will use reasonable efforts to keep it available, but we do not guarantee that it will never go offline, and we are not responsible for outages caused by a hosting or network provider.
11.3 We are not lawyers or accountants. You are responsible for making sure your business and your website comply with the law that applies to you.
12. DATA PROTECTION
12.1 Where we handle personal information on your behalf — for example, enquiries sent through your website — the Data Processing Agreement in Schedule 1 applies. You are the controller of that information and we are your processor. Schedule 1, including its annexes, sets out what we hold, where it is held, who helps us process it, and for how long.
12.2 Where we handle your own contact and billing details, we do that as a controller, and our privacy notice explains how.
13. LIABILITY
13.1 Nothing here limits our liability for death or personal injury caused by our negligence, for fraud, or for anything else that cannot legally be limited.
13.2 We are not liable for lost profits, lost business, lost bookings, or any indirect loss.
13.3 Otherwise, our total liability to you is limited to the fees you have paid us in the 12 months before whatever gave rise to the claim.
13.4 Clause 11 applies to any claim about search rankings or about your website being unavailable.
14. ENDING THIS AGREEMENT EARLY
14.1 Either of us can end this agreement immediately if the other seriously breaks it and does not put it right within 14 days of being asked in writing.
14.2 We may suspend or end your website immediately if you use it for anything unlawful, or to publish content that infringes someone else's rights.
14.3 If we end this agreement without good reason, we will refund the unused part of your year.
15. GENERAL
15.1 We may transfer this agreement to another company in our group by telling you in writing. You may not transfer it without our agreement.
15.2 We may use subcontractors, but we remain responsible for the work.
15.3 Notices from you go to zeki@rabblepop.com. Notices from us go to the email address you gave at checkout — keep it up to date.
15.4 These terms are the whole agreement between us.
15.5 If part of these terms turns out to be invalid, the rest still applies.
15.6 These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
SCHEDULE 1 — DATA PROCESSING AGREEMENT
Version 1.0
This Schedule forms part of the Doula Website Co Terms of Service. In it, "the Agreement" means those Terms, "the Client" means you, the customer, and "Rabblepop" means us.
1. DEFINITIONS
1.1 In this Schedule:
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other law relating to the processing of personal data applicable to a Party.
"UK GDPR" has the meaning given in section 3(10) of the Data Protection Act 2018.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the UK GDPR.
"Client Personal Data" means Personal Data processed by Rabblepop on behalf of the Client under the Agreement, as described in Annex 1.
"Sub-processor" means a processor engaged by Rabblepop to process Client Personal Data.
2. ROLES AND SCOPE
2.1 The Parties acknowledge that, in respect of Client Personal Data, the Client is the Controller and Rabblepop is the Processor.
2.2 This Schedule applies only where and to the extent Rabblepop processes Client Personal Data on the Client's behalf. It does not apply to Personal Data which Rabblepop processes as a Controller in its own right — including the Client's contact and billing details, and enquiry data — which is governed by Rabblepop's privacy notice.
2.3 Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subject. The Client confirms that Annex 1 is accurate and complete, and will notify Rabblepop if it ceases to be so.
2.4 Each Party will comply with its obligations under Data Protection Legislation. Nothing in this Schedule relieves either Party of its own obligations.
3. CLIENT OBLIGATIONS
3.1 The Client warrants that:
(a) it has a valid lawful basis for the processing, and where consent is relied on, that it has obtained and can evidence that consent;
(b) it has provided all necessary privacy information to Data Subjects;
(c) its instructions to Rabblepop comply with Data Protection Legislation; and
(d) where Client Personal Data includes special category data or criminal offence data, it has identified an additional condition for processing under Articles 9 or 10 of the UK GDPR and has notified Rabblepop in Annex 1.
3.2 The Client is responsible for the accuracy, quality and legality of the Client Personal Data and of the means by which it acquired it.
4. RABBLEPOP'S OBLIGATIONS
4.1 Instructions. Rabblepop will process Client Personal Data only on the Client's documented instructions, including as set out in the Agreement and Annex 1, unless required to do otherwise by law — in which case Rabblepop will inform the Client of that requirement before processing, unless the law prohibits it.
4.2 Rabblepop will inform the Client if, in its opinion, an instruction infringes Data Protection Legislation. Rabblepop may suspend the relevant processing until the instruction is confirmed, amended or withdrawn.
4.3 Confidentiality. Rabblepop will ensure that any person authorised to process Client Personal Data is subject to a duty of confidence.
4.4 Security. Rabblepop will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. The measures in place at the date of the Agreement are set out in Annex 2. Rabblepop may update them provided the level of protection is not reduced.
4.5 Assistance with Data Subject rights. Taking into account the nature of the processing, Rabblepop will assist the Client by appropriate technical and organisational measures, insofar as reasonably possible, in responding to requests from Data Subjects exercising their rights under Chapter III of the UK GDPR. Rabblepop will notify the Client without undue delay if it receives such a request directly, and will not respond to it except on the Client's instructions or as required by law.
4.6 Assistance with compliance. Rabblepop will provide reasonable assistance to the Client with data protection impact assessments, prior consultation with a Supervisory Authority, and the Client's obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the processing and the information available to Rabblepop.
4.7 Rabblepop may charge at its standard rates for assistance under clauses 4.5 and 4.6 where the request is not caused by Rabblepop's breach and where the assistance required is more than trivial.
5. PERSONAL DATA BREACH
5.1 Rabblepop will notify the Client without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Client Personal Data.
5.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, it may be provided in phases without undue further delay.
5.3 Rabblepop will take reasonable steps to contain and mitigate the breach and will co-operate with the Client in its investigation and in any notification the Client is required to make. Rabblepop will not notify a Supervisory Authority or any Data Subject on the Client's behalf unless the Client instructs it to do so in writing, or Rabblepop is required to do so by law.
6. SUB-PROCESSORS
6.1 The Client gives Rabblepop general written authorisation to engage Sub-processors. The Sub-processors authorised at the date of the Agreement are listed in Annex 3.
6.2 Rabblepop will give the Client at least 14 days' written notice before adding or replacing a Sub-processor. The Client may object on reasonable data protection grounds within that period, giving reasons in writing. If the Parties cannot resolve the objection within a further 14 days, either Party may terminate the affected Services on written notice, and the Client will pay for Services performed up to that date.
6.3 Rabblepop will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this Schedule, and remains fully liable to the Client for the performance of each Sub-processor's obligations.
7. INTERNATIONAL TRANSFERS
7.1 Rabblepop will not transfer Client Personal Data outside the United Kingdom unless it has taken the measures necessary to ensure the transfer is lawful, which may include transferring to a country covered by UK adequacy regulations, or putting in place the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
7.2 Where the Client instructs Rabblepop to transfer Client Personal Data outside the United Kingdom, the Client is responsible for ensuring that the transfer is lawful, and will provide Rabblepop with any transfer mechanism required.
7.3 Annex 3 identifies any Sub-processor which processes Client Personal Data outside the United Kingdom and the transfer mechanism relied on.
8. AUDIT AND INFORMATION
8.1 Rabblepop will make available to the Client, on written request, the information reasonably necessary to demonstrate compliance with this Schedule and with Article 28 of the UK GDPR.
8.2 Rabblepop will allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client, subject to the following: audits may be carried out not more than once in any 12-month period (unless required by a Supervisory Authority or following a Personal Data Breach); on at least 30 days' written notice; during business hours; without unreasonably disrupting Rabblepop's business; and subject to appropriate confidentiality undertakings.
8.3 The Client will bear its own costs and will reimburse Rabblepop's reasonable costs of assisting with an audit at Rabblepop's standard rates, unless the audit reveals a material breach of this Schedule by Rabblepop.
8.4 Rabblepop may satisfy its obligations under this clause 8 by providing a relevant third-party certification, audit report or security documentation, including that of its Sub-processors.
9. RETURN AND DELETION
9.1 On termination or expiry of the Agreement, or earlier on the Client's written request, Rabblepop will at the Client's option return or delete Client Personal Data.
9.2 Unless the Client requests otherwise in writing within 30 days of termination, Rabblepop will delete Client Personal Data after that period. Rabblepop may retain Client Personal Data to the extent required by law, and copies held in routine backups will be deleted in accordance with Rabblepop's backup cycle, remaining subject to this Schedule until deleted.
10. LIABILITY
10.1 The limitations and exclusions of liability in the Agreement apply to this Schedule and to any claim arising out of or in connection with it.
11. TERM AND PRECEDENCE
11.1 This Schedule takes effect on the date of the Agreement and continues for as long as Rabblepop processes Client Personal Data.
11.2 If there is a conflict between this Schedule and the rest of the Agreement in relation to the processing of Client Personal Data, this Schedule prevails.
SCHEDULE 1 — DATA PROCESSING AGREEMENT: ANNEXES
Doula Website Co customer websites
ANNEX 1 — DETAILS OF PROCESSING
| Subject matter | Building, hosting, maintaining and supporting the Customer's doula practice website. |
| Duration | The term of the Customer's subscription, plus the periods below. |
| Nature and purpose | Hosting and serving the website; storing content in the content management system; receiving enquiries through the website and notifying the Customer by email; backups, security updates and fault correction. |
| Categories of Data Subject | People who contact the Customer through the website, typically expectant parents, their partners and families; people whose testimonials or stories appear on the website; the Customer, as the holder of a CMS account; visitors to the website. |
Types of Personal Data
| Source | Data |
|---|---|
| Enquiry form | Name; email address; telephone number (optional); free-text message; record that the enquirer ticked the consent box, and when |
| Website content | Testimonials, birth stories and names supplied by the Customer for publication |
| CMS account | The Customer's name, email address and hashed password |
| Technical | Request metadata including IP addresses, recorded by the hosting provider at platform level |
Special category data — processed as a matter of course
Enquiries to a doula routinely contain health data. An enquirer will commonly disclose a pregnancy, a due date, a previous birth, or a health condition. Pregnancy is data concerning health. So is much of the content of a birth story or testimonial.
This is not incidental. It is the ordinary function of the website, and it is treated as special category data under Article 9 throughout.
The Customer is the Controller and is responsible for having an Article 9 condition. To support that, the enquiry form on every website:
- asks only for name, contact details and a message by default;
- carries a consent tickbox that must be ticked before an enquiry can be sent, recording the enquirer's agreement to the Customer using what they share to respond; and
- does not accept file uploads.
Any additional fields, uploads or forms added at the Customer's request are the Customer's responsibility under clause 5.5 of the Terms.
The website sets no analytics, advertising or tracking cookies and runs no third-party tracking scripts, unless the Customer asks for them under clause 5.6 of the Terms.
Retention
| Data | Retained for |
|---|---|
| Enquiries held in the CMS | 12 months from receipt, then deleted automatically, unless the Customer asks in writing for a different period |
| Enquiry notification emails | Held in the Customer's own mailbox, outside the Systems — the Customer's responsibility |
| Testimonials and website content | For as long as they are published, or until the Customer removes them |
| CMS account | The term of the subscription |
| Hosting request logs | Per the hosting provider's standard retention |
| Everything, on termination | Retained for 30 days after the subscription ends so the Customer can take an export, then deleted |
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES
Encryption. All traffic is served over TLS. Data at rest is encrypted by the hosting and database providers named in Annex 3.
No third-party code on the public site by default. No analytics, tag manager, tracking pixel or advertising script runs in a visitor's browser, so no third party can observe a visitor writing an enquiry.
Enquiry handling. An enquiry is stored before any notification email is sent, and a failed email does not fail the submission, so an email outage cannot lose an enquiry. A hidden honeypot field rejects automated spam.
No uploads on enquiry forms. The enquiry form does not accept files.
Access. Enquiries are readable only by a signed-in CMS account. Each Customer has their own account. Accounts are individual and must not be shared.
Public imagery. Images stored for display on the website are public by design and contain no enquiry data.
Reviews. Where a website shows Google reviews, they are fetched on the server. No visitor data is sent to Google and no Google script runs in a visitor's browser.
Secrets. Database credentials and API keys are held as hosting platform environment variables, not in source code.
Personnel. Anyone with access to Customer Personal Data is bound by a duty of confidence.
Incidents. Suspected incidents are investigated when identified, contained where possible, and notified in accordance with clause 5 of the Data Processing Agreement.
Not represented. Neither party represents that penetration testing, formal certification (such as ISO 27001 or SOC 2), intrusion detection or a documented incident response process is in place for the platform. The providers in Annex 3 hold their own certifications; the platform does not.
ANNEX 3 — AUTHORISED SUB-PROCESSORS
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Vercel Inc. | Hosting, content delivery, server functions, image storage | Request metadata including IP addresses; website content | Server functions in London (lhr1); content served from Vercel's global network |
| Neon | PostgreSQL database — CMS content and enquiries | Enquiries, testimonials, CMS account | London (aws-eu-west-2) |
| Resend, Inc. | Enquiry notification emails | Full enquiry content | United States |
| Google (Places API) | Reviews displayed on the website, where used | No visitor data — server-side only | — |
The transfer mechanism for each is that provider's own data processing terms.
Enquiry emails are a second copy. Each enquiry is emailed to the Customer in full. That copy sits in Resend's infrastructure and the Customer's mailbox, outside the CMS and its 12-month deletion. The Customer is responsible for their mailbox, including when responding to an access or erasure request.
Images created with AI tools are generated from general prompts. Customer and enquirer personal data is not included in prompts, so the image generation provider is not a sub-processor. If that ever changes, it will be added here with 14 days' notice.