Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions and Order Form (collectively the "Agreement") entered into by and between Tailored Tech Labs LTD, a company registered in England and Wales under number 17264369 whose registered office is at 124 City Road, London, EC1V 2NX (the "Processor") and the customer identified on the applicable Order Form (the "Controller"). This DPA is effective as of the Commencement Date of the relevant Order Form.
WHEREAS:
(1) Under the Terms and Conditions and applicable Order Form (collectively, the “Agreement”) entered into between the Controller and the Processor, the Processor provides to the Controller the Services described in Schedule 1.
(2) The provision of the Services by the Processor involves it in processing the Personal Data described in Schedule 2 on behalf of the Controller.
(3) Under Article 28(3) of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) (the “UK GDPR”), the Controller is required to put in place an agreement in writing between the Controller and any organisation which processes personal data on its behalf governing the processing of that personal data.
(4) The Parties have agreed to enter into this Agreement to ensure compliance with the said provisions of the UK GDPR in relation to all processing of the Personal Data by the Processor for the Controller.
(5) The terms of this Agreement are to apply to all processing of Personal Data carried out for the Controller by the Processor and to all Personal Data held by the Processor in relation to all such processing.
IT IS AGREED as follows:
-
Definitions and Interpretation
- In this Agreement, unless the context otherwise requires, the following expressions have the following meanings:
“Commissioner” means the Information Commissioner (as defined in Article 4(A3) UK GDPR and section 114 Data Protection Act 2018;
“Controller” shall have the meanings given to the term “controller” by Article 4(7) of the UK GDPR and section 6 of the Data Protection Act 2018;
“Data Protection Legislation” means all applicable legislation in force from time to time in the United Kingdom applicable to data protection and privacy including, but not limited to, the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder); and the Privacy and Electronic Communications Regulations 2003 as amended;
“Data Subject” means an identified or identifiable living individual to whom Personal Data relates;
“Personal Data” means any information relating to an identified or identifiable living individual; an identified or identifiable living individual is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of the individual;
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed;
“Processor” means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of a Controller;
“processing”, “process”, “processed”, “processes” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Services” means those services described in Schedule 1 which are provided by the Processor to the Controller and which the Controller uses for the purposes described in Schedule 1; and
“UK GDPR” means Regulation (EU) 2016/679 General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
-
Unless the context otherwise requires, each reference in this Agreement to:
-
“writing”, and any cognate expression, includes a reference to any communication effected by electronic or facsimile transmission or similar means;
-
a statute or a provision of a statute is a reference to that statute or provision as amended or re-enacted at the relevant time;
-
“this Agreement” is a reference to this Agreement and each of the Schedules as amended or supplemented at the relevant time;
-
a Schedule is a schedule to this Agreement; and
-
a Clause or paragraph is a reference to a Clause of this Agreement (other than the Schedules) or a paragraph of the relevant Schedule.
-
a "Party" or the "Parties" refer to the parties to this Agreement.
-
-
The headings used in this Agreement are for convenience only and shall have no effect upon the interpretation of this Agreement.
-
Words imparting the singular number shall include the plural and vice versa.
-
References to any gender shall include any other gender.
-
References to persons shall include corporations.
-
-
Scope and Application of this Agreement
- The provisions of this Agreement shall apply to the processing of the Personal Data described in Schedule 2, carried out for the Controller by the Processor, and to all Personal Data held by the Processor in relation to all such processing, whether such Personal Data is held at the date of this Agreement or received afterwards.
- Schedule 2 describes the type(s) of Personal Data, category or categories of Data Subject, the nature of the processing to be carried out, the purpose(s) of such processing, and the duration of such processing.
- Subject to sub-Clause 2.4, this Agreement is subject to the terms of the Terms and Conditions and is hereby incorporated into the Agreement. Definitions and interpretations set out in the Service Agreement shall apply to the interpretation of this Agreement.
- The provisions of this Agreement supersede any other arrangement, understanding, or agreement made between the Parties at any time relating to the Personal Data.
- This Agreement shall continue in full force and effect for so long as the Processor is processing Personal Data on behalf of the Controller, and thereafter as provided in Clause 10.
-
Provision of the Services and Processing Personal Data
- The Controller shall retain control of the Personal Data and shall, at all times, remain responsible for its compliance obligations under the Data Protection Legislation including, but not limited to, providing any and all required notices and obtaining any and all required consents, and for the written processing instructions given to the Processor.
- The Processor shall only provide the Services and process the Personal Data received from the Controller:
- for the purposes of those Services and not for any other purpose;
- to the extent and in such a manner as is strictly necessary for those purposes; and
- strictly in accordance with the express written authorisation and instructions of the Controller (which may be specific instructions or instructions of a general nature, or as otherwise notified by the Controller to the Processor).
-
Data Protection Compliance
- All instructions given by the Controller to the Processor shall be made in writing and shall at all times be in compliance with the Data Protection Legislation. The Processor shall act only on such written instructions from the Controller unless the Processor is required by law to do otherwise (as per Article 29 of the UK GDPR).
- The Processor shall promptly comply with any request from the Controller requiring the Processor to amend, transfer, delete, or otherwise dispose of the Personal Data, or to stop, mitigate, or remedy any unauthorised processing.
- The Processor shall transfer all Personal Data to the Controller on the Controller’s request in the formats, at the times, and in compliance with, the Controller’s written instructions.
- Both Parties shall comply at all times with the Data Protection Legislation and shall not perform their obligations under this Agreement or any other agreement or arrangement between them in such a way as to cause either Party to breach any of its applicable obligations under the Data Protection Legislation.
- The Controller hereby warrants, represents, and undertakes that the Personal Data shall comply with the Data Protection Legislation in all respects including, but not limited to, its collection, holding, and processing, and that the Controller has in place all necessary and appropriate consents and notices to enable the lawful transfer of the Personal Data to the Processor.
- The Processor agrees to comply with any reasonable measures required by the Controller to ensure that its obligations under this Agreement are satisfactorily performed in accordance with the Data Protection Legislation and any best practice guidance issued by the Commissioner.
- The Processor shall provide all reasonable assistance (at the Controller’s cost) to the Controller in complying with its obligations under the Data Protection Legislation with respect to the security of processing, the notification of Personal Data Breaches, the conduct of data protection impact assessments, and in dealings with the Commissioner. What is reasonable, for the purposes of this sub-Clause 4.7 shall take account of the nature of the Processor’s processing and the information available to the Processor.
- The Processor shall notify the Controller in a timely manner of any changes to the Data Protection Legislation that may adversely affect its performance of the Services or of its obligations under this Agreement.
- When processing the Personal Data on behalf of the Controller, the Processor shall:
- not transfer the Personal Data outside the United Kingdom without the prior written consent of the Controller (which is hereby granted for the Subcontractors listed in Schedule 4, subject to appropriate legal safeguards);
- not transfer any of the Personal Data to any third party without the written consent of the Controller and, in the event of such consent, the Personal Data shall be transferred strictly subject to the terms of a suitable agreement, as set out in Clause 11;
- process the Personal Data only to the extent, and in such manner, as is necessary in order to comply with its obligations to the Controller or as may be required by law;
- implement appropriate technical and organisational measures, including those described in Schedule 3, and take all steps necessary to protect the Personal Data against accidental, unauthorised, or unlawful processing, access, copying, modification, reproduction, display, or distribution of the Personal Data, and against its accidental or unlawful loss, destruction, alteration, disclosure, or damage;
- implement measures to ensure a level of security proportionate to the risks involved including, as appropriate:
- the pseudonymisation and encryption of Personal Data;
- the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
- the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident; and
- a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures;
- if so requested by the Controller, supply further details of the technical and organisational systems in place to safeguard the security of the Personal Data held;
- keep complete and accurate records and information concerning all processing activities carried out on the Personal Data in order to demonstrate its compliance with this Agreement and the Data Protection Legislation;
- make available to the Controller any and all such information as is reasonably required and necessary to demonstrate the Processor’s compliance with the Data Protection Legislation;
- on reasonable prior notice, submit to audits and inspections and provide the Controller with any information reasonably required in order to assess and verify compliance with the provisions of this Agreement; and
- inform the Controller immediately if it is asked to do anything that infringes the Data Protection Legislation.
-
Data Subject Requests, Notices, Complaints, and Personal Data Breaches
- The Processor shall, at the Controller’s cost, assist the Controller in complying with its obligations under the Data Protection Legislation. In particular, the provisions of this Clause 5 shall apply to requests by Data Subjects to exercise their rights, information or assessment notices served on the Controller by the Commissioner under the Data Protection Legislation, complaints, and Personal Data Breaches.
- The Processor shall notify the Controller immediately in writing if it receives:
- a request from a Data Subject to exercise their rights; or
- any other complaint, notice, communication, or request relating to the processing of the Personal Data or to either Party’s compliance with the Data Protection Legislation.
- The Processor shall, at the Controller’s cost, cooperate fully with the Controller and assist as required in relation to any Data Subject request, or other complaint, notice, communication, or request:
- including providing the Controller with full details of the complaint, notice, communication, or request;
- providing the necessary information and assistance in order to comply with a request from a Data Subject;
- providing the Controller with any Personal Data it holds in relation to a Data Subject (within the timescales required by the Controller); and
- providing the Controller with any other information requested by the Controller.
- The Processor shall not disclose any Personal Data to any Data Subject or to any other third party unless instructed to do so by the Controller in writing, or as required by law.
- The Processor shall notify the Controller immediately if it becomes aware of any form of Personal Data Breach.
- If an event of the type described under sub-Clause 5.5 occurs:
-
Where recovery of the affected Personal Data is possible, the Processor shall recover the same as soon as possible.
-
The Processor shall, without undue delay, also provide the following information to the Controller:
-
a description of the nature of the event, including the category or categories of Personal Data affected, the approximate number of Personal Data records and Data Subjects involved;
-
the likely consequences of the event; and
-
a description of the measures that have been taken or will be taken in response, including those to mitigate potential adverse effects.
-
-
The Processor shall provide all reasonable co-ordination, co-operation, and assistance to the Controller in the Controller’s investigation and handling of the event.
-
The Processor shall not inform any third parties of the event without the Controller’s express written consent, unless required to do so by law.
-
The Controller shall have the sole right to determine whether to provide notice of the event to any Data Subjects, the Commissioner, other applicable regulators, law enforcement authorities, or other parties, as required by law or regulation or at the Controller’s discretion.
-
The Controller shall have the sole right to determine whether to offer any form of remedy to affected Data Subjects.
-
Where the Processor is required to take action and/or provide assistance at its own expense under this sub-Clause, the requirement for the Processor to cover such expenses shall not apply if the event arose from the Controller’s specific written instructions, negligence, wilful default, or breach of this Agreement. In such cases, the Controller shall cover all such reasonable expenses.
-
-
Staff
- The Processor shall ensure that all personnel who are to access and/or process any of the Personal Data:
- be informed of the confidential nature of the Personal Data and be bound by contractual use restrictions and confidentiality requirements;
- be given appropriate training on the Data Protection Legislation; and
- be made aware of both the Processor’s duties, and their personal duties and obligations under the Data Protection Legislation and this Agreement.
- The Processor shall ensure that all personnel who are to access and/or process any of the Personal Data:
-
Warranties
- The Processor warrants and represents that:
- its employees, agents, and any other person or persons accessing and otherwise handling the Personal Data on its behalf are appropriately trained;
- it, and any party acting on its behalf, will process the Personal Data in compliance with the Data Protection Legislation;
- nothing, in its reasonable belief, in the Data Protection Legislation prevents it from providing the Services;
- it will take all appropriate and proportionate technical and organisational measures to prevent the accidental, unauthorised, or unlawful processing of the Personal Data.
- The Controller warrants and represents that the Processor’s use of the Personal Data in its provision of the Services and as specifically instructed by the Controller shall comply with the Data Protection Legislation.
- The Processor warrants and represents that:
-
Liability and Indemnity
- The Controller shall be liable for, and shall indemnify (and keep indemnified) the Processor in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Processor arising directly or in connection with:
- any non-compliance by the Controller with the Data Protection Legislation;
- any processing carried out by the Processor in accordance with instructions given by the Controller that infringe the Data Protection Legislation; or
- any breach by the Controller of its obligations under this Agreement, except to the extent that the Processor is liable under sub-Clause 8.1.
- The Processor shall be liable for, and shall indemnify (and keep indemnified) the Controller in respect of any and all action, proceeding, liability, cost, claim, loss, expense, or demand suffered or incurred by the Controller arising directly or in connection with the Processor’s processing activities that are subject to this Agreement:
- only to the extent that the same results from the Processor’s breach of, or non-compliance with, this Agreement, the Controller’s instructions, or the Data Protection Legislation; and
- not to the extent that the same is, or are contributed to, by any breach of this Agreement by the Controller.
- The Controller shall not be entitled to claim back from the Processor any sums paid in compensation by the Controller in respect of any damage to the extent that the Controller is liable to indemnify the Processor under sub-Clause 8.1.
- Nothing in this Agreement shall relieve either Party of, or otherwise affect, the liability of either Party to any Data Subject, or for any other breach of that Party’s direct obligations under the Data Protection Legislation.
- The Controller shall be liable for, and shall indemnify (and keep indemnified) the Processor in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Processor arising directly or in connection with:
-
Intellectual Property Rights
All copyright, database rights, and other intellectual property rights in the Personal Data shall belong to the Controller or to any other applicable third party from whom the Controller has obtained the Personal Data under licence. The Processor is licensed to use such Personal Data only for the purposes of providing the Services, and in accordance with this Agreement.
-
Confidentiality
- The Processor shall maintain the Personal Data in confidence, and in particular, unless the Controller has given written consent for the Processor to do so, the Processor shall not disclose any Personal Data supplied to the Processor by, for, or on behalf of, the Controller to any third party.
- The Processor shall ensure that all personnel who are to access and/or process any of the Personal Data are contractually obliged to keep the Personal Data confidential.
- The obligations set out in this Clause shall continue for a period of 12 months after the cessation of the provision of Services by the Processor to the Controller.
- Nothing in this Agreement shall prevent either Party from complying with any requirement to disclose Personal Data where such disclosure is required by law.
-
Subcontractors
- The Processor shall not subcontract any of its obligations or rights under this Agreement without the prior written consent of the Controller. The Controller hereby provides written consent for the Processor to engage the specific Subcontractors listed in Schedule 4.
- If the Processor appoints a subcontractor (with the written consent of the Controller), the Processor shall:
- enter into a written agreement with the subcontractor which shall impose upon the subcontractor the same obligations as are imposed upon the Processor by this Agreement;
- ensure that the subcontractor complies fully with its obligations under that agreement and the Data Protection Legislation;
- maintain control over all Personal Data transferred to the subcontractor; and
- the agreement between the Processor and the subcontractor shall terminate automatically upon the termination or expiry of this Agreement for any reason.
- In the event that a subcontractor fails to meet its obligations under any such agreement, the Processor shall remain fully liable to the Controller for failing to meet its obligations under this Agreement.
-
Deletion and/or Disposal of Personal Data
- The Processor shall, at the written request of the Controller, delete or otherwise dispose of the Personal Data or return it to the Controller within a reasonable time after the earlier of the following:
- the end of the provision of the Services under the Service Agreement; or
- the processing of that Personal Data by the Processor is no longer required for the performance of the Processor’s obligations under the Service Agreement.
- For the avoidance of doubt, deactivation of a user account within the application does not itself constitute deletion of the Personal Data associated with that account. Deletion of an individual user’s Personal Data (including cascaded deletion of that user’s overtime and leave records where applicable) shall be effected only where the Controller (or an authorised user of the Controller using the application’s user administration functions) instructs or performs deletion, or where deletion is carried out under sub-Clause 12.1.
- Following the deletion, disposal, or return of the Personal Data from live systems, the Processor shall not actively retain further copies of the Personal Data, provided that residual copies may persist in automated backups maintained by the Processor’s infrastructure providers until those backups expire or are overwritten in the ordinary course, unless retention of such copies is required by law
- The Processor shall, at the written request of the Controller, delete or otherwise dispose of the Personal Data or return it to the Controller within a reasonable time after the earlier of the following:
-
Law and Jurisdiction
- This Agreement (including any non-contractual matters and obligations arising therefrom or associated therewith) shall be governed by, and construed in accordance with, the laws of England and Wales.
- Any dispute, controversy, proceedings or claim between the Parties relating to this Agreement (including any non-contractual matters and obligations arising therefrom or associated therewith) shall fall within the jurisdiction of the courts of England and Wales.
SCHEDULE 1: Services
Description of Services: Provision of the Service (as defined in the Terms and Conditions), specifically the web-based workforce management application, associated mobile applications, and underlying infrastructure, facilitating staff authentication, automated workflows, administration, and related transactional notifications on behalf of the Controller.
SCHEDULE 2: Personal Data
- Type of Personal Data: Names; business email addresses; personnel / payroll numbers; job roles within the application; team identifiers (where used); manager and organisational hierarchy identifiers; hourly rates and calculated financial amounts; working hours and request records (including descriptions, statuses, approval or rejection details, and related comments); leave records (including leave type, dates, statuses, and related comments); user authentication credentials and tokens; and system-generated technical data reasonably required to operate and secure the Services (such as session identifiers and infrastructure logs). Additional data types may be processed if explicitly specified in the applicable Order Form.
- Category of Data Subject: Employees, contractors, and authorised personnel of the Controller.
- Nature of Processing Carried Out: Collection, storage, organisation, retrieval, disclosure (to authorised users of the Controller within the application), transmission (including transactional email), and automated processing of workforce via the application.
- Purpose(s) of Processing: To facilitate request management, approvals, reporting, data export, user administration, and related notifications on behalf of the Controller.
- Duration of Processing: For the duration of the active subscription between the Parties under the Agreement. Individual user accounts may be deactivated within the application without deletion of the associated Personal Data; such Personal Data continues to be retained for the duration of the Services unless and until deleted in accordance with Clause 12. Following termination or expiry of the Services, or upon the Controller’s written request, the Processor shall delete or return the Personal Data in accordance with Clause 12. Residual copies may remain in automated infrastructure backups for a limited period thereafter in accordance with the Processor’s hosting providers’ standard backup retention practices (currently up to seven (7) days for the production database hosting plan), after which such backups are overwritten or expire in the ordinary course.
SCHEDULE 3: Technical and Organisational Data Protection Measures
The Processor shall ensure that, in respect of all Personal Data it receives from or processes on behalf of the Controller, it maintains security measures to a standard appropriate to the harm that might result from unlawful or unauthorised processing, and the nature of the Personal Data. In particular, the Processor shall:
- Ensure that appropriate security safeguards are in place to protect the hardware and software which is used in processing the Personal Data in accordance with best industry practice.
- Prevent unauthorised access to the Personal Data via strict Row-Level Security (RLS) database policies and Role-Based Access Control (RBAC).
- Protect the Personal Data using encryption, explicitly utilizing industry-standard TLS/HTTPS protocols for encryption in transit, and AES-256 encryption at rest across all database infrastructure.
- Ensure that its storage of Personal Data conforms with best industry practice such that access by personnel is strictly monitored and controlled.
- Password protect all access to infrastructure, ensuring that passwords are secure and not shared under any circumstances.
- Have a secure procedure for backing up electronic Personal Data and storing back-ups securely via primary infrastructure providers. Production database backups are performed automatically on a daily basis by the database hosting provider and retained on a rolling basis in accordance with that provider’s plan (currently seven (7) days).
SCHEDULE 4: Authorised Subcontractors (Sub-processors)
The Controller provides written consent for the Processor to engage the following subcontractors:
| Subcontractor Name | Purpose of Processing | Processing Location | Safeguard / Legal Mechanism |
|---|---|---|---|
| Vercel, Inc. | Application hosting and compute | United Kingdom (London) | Processed within UK |
| Supabase, Inc. | Database hosting and authentication | United Kingdom (London) | Processed within UK |
| Resend, Inc. | Transactional email delivery | United States | UK Addendum to EU SCCs / IDTA |