Skip to main content
Digital development partner for Agencies

Drupal development partner for Agencies

Metadrop is the Drupal development partner that digital, marketing, branding and communications agencies across Europe put behind their own delivery. White-label when the client should never meet us, co-branded when the agency wants us in the room. We build new platforms, take over inherited ones and keep them running under SLA, while the client relationship, the brand and the credit stay with the agency.

They've Trusted Metadrop

From creative and design agencies to marketing and communications agencies, partners across Europe have relied on Metadrop as the Drupal team behind their client work, on platforms spanning dozens of countries and languages.

What our partners say

An agency-side view of what it is like to have us behind the delivery.

When agencies bring us in

When agencies bring us in

Two entry situations carry equal weight on this page. One is the planned partnership: a Drupal project already won, or a bid still open. The other is the technical rescue: a platform inherited, stalled or no longer supportable. Both arrive here regularly, and both are handled as routine work.

  • A client has asked for Drupal and the agency has no Drupal capability in-house, with no appetite for a hiring or retraining cycle to build one.
  • The pipeline holds more Drupal work than the team can ship against the deadlines already promised.
  • A tender or pitch needs a named technical partner, a methodology and certification evidence attached to it before submission.
  • An agency has inherited a platform, from a client's previous provider or with an account it has just won, and cannot yet say what state it is in.
  • A previous development supplier ended badly, so the agency's own reputation is what is being risked a second time.

What is being bought in all five cases is risk transfer: the technical work delivered to the client's standard, without the agency losing the relationship it built

White-label or co-branded: two ways to run the delivery

White-label or co-branded: two ways to run the delivery

The model is decided per project, not per relationship. The same agency can keep us invisible on one account and introduce us on the next.

White-label means the agency fronts the client end to end: we work to the agency's brief, deliver into its process, and the client sees the agency's people. Co-branded means we join client calls, workshops and technical reviews as the agency's technical partner, named and introduced, which is the usual choice when the client's own IT department wants a counterpart to talk architecture with.

Branding mechanics are settled at kick-off: repository names, project boards, chat channels, meeting invitations and deliverable documents carry whichever identity the model calls for, and the agency stays the single point of contact with its client. Governance runs on a yearly strategy meeting, a bi-monthly alignment meeting and ad-hoc technical syncs, with any other agencies on the account invited into the alignment meetings directly.

Three of Metadrop's long-running engagements are routed through a creative or marketing agency rather than contracted directly, two of them running since 2022, on DXP-class platforms: multilingual, multisite and integrated.

Confidentiality, and who talks to your client

Confidentiality, and who talks to your client

An NDA is in place before platform details are exchanged, and we work to the agency's paper where the agency has its own.

The end client belongs to the agency. We work to the agency's brief and do not approach its client for work outside the agency's scope. Where an agency wants that written down, it goes into the partnership agreement as a clause instead of staying a promise on a web page.

Invoicing runs to the agency, with a monthly report itemised by project and by team profile.

Publication is permission-based: no engagement becomes a case study, a logo or a talk slide without written agreement from whoever owns the client relationship. On this page and everywhere else, Metadrop describes agency work by sector, scale and situation rather than by client name.

Support access is Level 3 from first contact: the agency's team reaches the engineers who wrote the code, with no relay chain in between.

How we scope, estimate and handle change requests

How we scope, estimate and handle change requests

Estimates are produced from analysis, not from a feeling: the ticket is analysed, a solution is written into the card, and the estimate is reviewed against that analysis before work starts. A developer who finds the estimate no longer holds after analysis flags it and blocks the card.

Change requests follow a fixed four-step route: request, estimate in hours, the agency's written approval, then execution and delivery. Nothing outside the agreed scope is built before the approval exists. Scope is prioritised at a weekly alignment sync where consumption is updated in the open, and every invoice arrives with an itemised report by team profile.

Three commercial shapes are available, and the choice is the agency's: a scoped project, a monthly retainer with a dedicated cross-functional team (one month's notice in both directions), or prepaid time-and-materials hours. Rates are quoted per engagement and not published. Short-term extra scope runs as a parallel, time-boxed project rather than as a renegotiation of the retainer, and work runs in short iterations.

Metadrop has presented publicly on this problem: scope, budget and change-request management at DrupalCamp 2024, and agile contracting at DrupalCon 2024.

Technical rescue: taking over a platform you inherited

Technical rescue: taking over a platform you inherited

The audit comes before the plan. A timeboxed Drupal audit returns rated findings tied to evidence and a prioritised recommendation list with effort estimates.

The takeover runs over three weeks. Week 1 is discovery and access: kick-off with the outgoing provider, access to infrastructure, repositories, boards and the open-issue log, a documentation review, and static analysis of modules, components and search indexes. Its output is an initial platform health report, the baseline for every later improvement. Week 2 is joint Q&A compilation: one structured question set per domain (infrastructure, backend, frontend), sent to the outgoing provider in advance. Week 3 is three knowledge-transfer workshops run by the outgoing team, with more scheduled where the Q&A exposed gaps. Under a tender deadline the three weeks compress to about two by merging discovery and Q&A, though the workshops are not compressed. One small unblocking win is scheduled inside the first two weeks.

Findings are batched by exposure, not by effort: anything carrying legal or brand exposure (plaintext credentials, unauthenticated endpoints, unsupported versions) ships outside the normal release cadence, while performance, accessibility and SEO findings go into scheduled releases. Where test coverage is thin, functional (Behat) and visual-regression (BackstopJS) baselines are established during the takeover.

Takeover conditions are stated up front: full access and documentation, a platform stable at the point of transfer, and a joint deficiency review with the outgoing provider, plus no structural rebuilds in the first months. A change of cloud provider is scoped as its own project.

The roles we cover, and what gets built

The roles we cover, and what gets built

Whole delivery profiles, not a single developer: project lead (agile management), tech lead (architecture and functional design), backend and frontend developers, QA specialists and DevOps engineers, on all of the delivery or only the part the agency cannot staff, in a composition that can change between projects.

What gets built: DXP-class corporate platforms, multisite and multilingual estates, editorial component systems, search (Solr, Acquia Search, SearchStax), CRM integrations (Salesforce, Microsoft Dynamics), European payment methods (Stripe, PayPal, Redsys, Bizum), and migrations from WordPress, Joomla, TYPO3 or Magento. Major-version work is routine: see Drupal upgrade. Where an account already has several providers, Metadrop can hold the independent technical governance role described under Drupal consulting.

Work moves across a shared board the agency can see at any time: To do, In progress, QA, Approval, Deploy, Done. Anything carrying a client-facing SLA takes precedence over ordinary sprint planning, and displaced items are moved back to the backlog explicitly.

Quality gates run in CI and block a change that fails: static analysis, the test suite and a dependency security audit, then peer review and manual QA on staging across the supported browser and device matrix. The toolchain that enforces it (Aljibe) is public and inspectable. Contributed modules are preferred over custom code as a stated engineering principle.

Support and maintenance under a written SLA

Support and maintenance under a written SLA

Response and resolution commitments are severity-based and contractual rather than best-effort. Inside the standard support window, a critical incident carries a response commitment of one working hour and a resolution target of three working hours, with High, Medium and Low graded behind it. The standard window is 08:00 to 16:00 CEST on the Madrid working calendar, and cover outside it is contracted as a named extended window. Metadrop does not claim round-the-clock availability.

Most incidents are opened by us, not reported by the agency: infrastructure and uptime monitoring alerts in real time, and a critical incident gets a dedicated channel with direct access to the technical team. A fix does not ship until the agency validates and approves it, because the Approval stage is an explicit column on the shared board, with an action on both sides.

Every significant bug closes with a root-cause analysis and a regression test, so a recurrence of the same failure is caught by the test suite rather than on the agency's watch. Maintenance also includes a recurring web audit report across technical status, security, SEO, performance, accessibility and GDPR, which is what turns maintenance into proactive engineering instead of ticket-taking. Full scope: Drupal maintenance & support.

What your agency keeps if we stop working together

What your agency keeps if we stop working together

Code, configuration and documentation live in a version-controlled repository throughout, so the whole platform can be redeployed to a new environment at any point by whoever holds it.

The exit is a named, capped obligation: a reversibility phase agreed by both parties and capped at 25 working days, delivering the information and technical assistance an incoming team needs to take on the platform's operation. It is quoted separately as additional work. On termination for breach, every document, data set, manual, plan and source file produced is placed at the client's disposal within fifteen days, separately from that phase.

The exit package is specific: architecture overview and software inventory, a content-architecture analysis, the complete source repository, an administration and maintenance manual, and the validated data and asset export. Content is exported through Drupal's APIs into a documented structured format rather than as a raw database dump, with a representative subset delivered first so the incoming team can test its import routines. Content relationships are mapped before export (Entity Mesh), so broken or unreachable internal links surface before the migration, and the incoming team is invited to re-run the same tooling to verify integrity.

Metadrop Icon
distintivo_ens_certificacion
Logo acreditativo certificación ISO 9001
Logo acreditativo certificación ISO 14001
Logo WCAG

Why an EU-based Drupal partner

The whole team is in Spain, and therefore inside EU jurisdiction: personal data handled on our side stays under EU law, so the third-country transfer question a DPA or a tender asks does not arise. One working calendar (Madrid) and one timezone across the team is what makes the response and resolution commitments above holdable rather than a best effort passed between handoffs.

Metadrop is ENS certified under Spain's National Security Scheme, Categoría Media (RD 311/2022), the standard that is mandatory for public-sector providers; it incorporates GDPR principles and builds on the ISO 27001/27002 controls. ISO 9001 (quality management) and ISO 14001 (environmental management) are both certified as well, and the company is a Drupal Association Silver Certified Partner, renewed annually, with Acquia and Upsun partnerships alongside.

Behind the certificates sit 15+ years building Drupal platforms, 120+ contributed modules and 500+ issue credits on drupal.org, and 50+ talks at DrupalCon, Drupal Dev Days and DrupalCamp. By contributed-project count, that places Metadrop among the roughly 25 most active Drupal companies worldwide.

Accessibility and compliance work is routine rather than a specialism bolted on. WCAG 2.1 AA is treated as today's legal baseline under the EAA and EN 301 549, with national schemes (RGAA and equivalents) handled where a market requires them. Metadrop supplies the technical translation of these obligations, not the legal opinion (an interpretation, not legal advice). The agency can hand its client a documentation package it did not have to write, covering certification scope, accessibility conformance evidence and audit reports, which is usually what a tender or a procurement review actually asks for.

Frequently asked questions

  • How does white-label Drupal development work with an agen

    White-label Drupal development means the agency fronts its client end to end while Metadrop's engineers work behind the agency's brand, inside the agency's process and to the agency's brief. Boards, repositories, channels, meeting invitations and deliverable documents carry the agency's identity, agreed at kick-off and not improvised mid-project. The alternative is co-branded delivery, where we are introduced and join client calls as the agency's technical partner. The choice is made per project, and it is reversible on the next one.

  • Will you approach our client directly?

    The end client belongs to the agency: Metadrop works to the agency's brief and does not pursue its client for work outside the agency's scope. Where an agency wants the commitment in writing, it goes into the partnership agreement as a clause, alongside the NDA that is signed before platform details are exchanged. Metadrop's public copy describes agency work by sector, scale and situation only, and no engagement becomes a case study, a logo or a talk slide without written permission from whoever owns the relationship.

  • How long does a Drupal platform takeover take?

    A Drupal platform takeover runs three weeks by default: discovery and access, joint Q&A compilation, then the knowledge-transfer workshops. It compresses to about two weeks under a tender deadline by merging discovery and Q&A, provided the outgoing provider is responsive, while the workshops themselves are not compressed. The timeline depends on the incumbent's participation, which is why access and a joint deficiency review are agreed as conditions of the takeover instead of being requested later.

  • How do you keep a fixed brief from turning into scope creep?

    Scope creep is handled by procedure, not goodwill: every change request is estimated in hours and waits for the agency's written approval before any work begins. Estimates are re-checked against the written analysis of the ticket, and a developer who finds the original number no longer holds blocks the card and raises it instead of absorbing it. Priorities and consumption are reviewed at a weekly sync, and every invoice carries an itemised report by team profile, so the position is visible during the month rather than at the end of it.

  • Who owns the code when a development partnership ends?

    Code, configuration and documentation sit in a version-controlled repository for the whole life of the partnership, so the platform can be redeployed elsewhere from it at any point. The exit runs as a reversibility phase capped at 25 working days, quoted separately as additional work, delivering the architecture overview, software inventory, full source repository, administration manual and a validated data export. On termination for breach, every document, data set, manual, plan and source file produced is placed at the client's disposal within fifteen days.

  • What changes when a Drupal partner is EU-based rather than offshore?

    An EU-based Drupal partner keeps personal data under EU law, so the third-country transfer question in a DPA or a public tender does not arise on the supplier's side. Metadrop's whole team works on one calendar and one timezone (Madrid, CEST), which is what makes the severity-based response and resolution commitments holdable, with no handoff between timezones. The compliance evidence an agency's client asks for exists as documentation: ENS (Categoría Media), ISO 9001, ISO 14001 and accessibility conformance reporting.

Tell us about your Drupal project or platform

A tech lead reads the brief and comes back with questions or a first view of the technical scope, rather than an autoresponder or a routing queue.

Useful in the first message, if it exists: the Drupal version, who runs the hosting, whether you have repository access, and the deadline you are working against. A rough answer is enough to start. No commitment and no rate card are required to begin, and the brief is not shared outside the people who would do the work.

Escribe tu mensaje aquí...
I have read and accepted the privacy policy regarding data processing.
Answers are generated automatically by AI and may not be accurate.