1.1 This Data Processing Agreement ("DPA") forms part of the SaaS Terms and Conditions between Intellectual Bunch Limited t/a EveryShift (the "Processor") and the Customer (the "Controller"). It governs the Processor's processing of personal data within Customer Data on the Controller's behalf.
1.2 The Controller determines the purposes and means of processing Customer Data. The Processor processes it only on the Controller's documented instructions, as set out in this DPA and the Terms.
1.3 Terms defined in the SaaS Terms and Conditions have the same meaning here. "UK GDPR", "controller", "processor", "processing", "personal data", "special-category data", "data subject" and "personal data breach" have the meanings in the UK GDPR and the Data Protection Act 2018.
The Processor will:
2.1 If the Processor considers that an instruction infringes data protection law, it will inform the Controller.
3.1 Where the Controller uses the Care edition, Customer Data may include special-category data concerning health under Article 9 UK GDPR (for example care visit records and certain absence or training records).
3.2 The Controller is responsible for establishing the lawful basis and the Article 9 condition for such processing, for any Data Protection Impact Assessment, and for the privacy information provided to affected individuals.
3.3 The Processor will apply the enhanced security measures in Annex 2 to such data, including encryption at rest and in transit, strict access controls and logging, and will treat it as high-risk personal data for the purposes of breach handling.
4.1 The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex 3 to help deliver the Service.
4.2 The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to the Controller for its sub-processors' acts and omissions.
4.3 The Processor will give the Controller at least notice of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.
5.1 Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests from data subjects exercising their rights.
5.2 If the Processor receives a request directly from a data subject relating to Customer Data, it will not respond except on the Controller's instruction, and will promptly forward the request to the Controller.
6.1 The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and in any event in time to allow the Controller to meet its own notification obligations.
6.2 The notification will include, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available.
6.3 The Processor will take reasonable steps to contain and remediate the breach and will cooperate with the Controller.
7.1 The Processor will provide reasonable assistance to the Controller with data protection impact assessments and any prior consultation with the Information Commissioner's Office, taking into account the nature of processing and the information available to the Processor. This is particularly relevant to the Care edition.
8.1 The Processor will maintain records of its processing as required by Article 30 UK GDPR and will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28.
8.2 The Processor will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, no more than and on reasonable notice, subject to confidentiality and to not compromising other customers' data. The Processor may satisfy audit requests by providing an up-to-date third-party certification or report where available.
9.1 On termination of the Service, and at the Controller's choice, the Processor will delete or return all Customer Data and delete existing copies, unless UK law requires storage of the data.
9.2 The Processor will make Customer Data available for export for the period stated in the Terms before deletion. Deletion is scheduled against applicable statutory retention rules (for example payroll records commonly retained for at least six years, and care records for longer statutory periods) rather than performed immediately where the law requires longer retention.
10.1 The Processor will not transfer Customer Data outside the UK except as necessary to provide the Service through the sub-processors in Annex 3, and only where an appropriate safeguard under the UK GDPR is in place, such as UK adequacy regulations or the International Data Transfer Agreement / UK Addendum.
11.1 The liability provisions in the SaaS Terms and Conditions apply to this DPA. This DPA is governed by the laws of England and Wales.
11.2 If there is a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails.
| Item | Detail |
|---|---|
| Subject matter | Provision of the EveryShift workforce operations platform |
| Duration | The term of the Customer's subscription, plus any export/retention period |
| Nature and purpose | Hosting, storage and processing of workforce data to deliver scheduling, sign-off, timesheets, payroll-ready outputs, training, leave and (Care) visit records |
| Types of personal data | Identity and contact data; employment data (role, pay rate, availability, hours); rota, timesheet and sign-off records; training and leave records; uploaded documents; and, in the Care edition, health-related care visit data (special-category) |
| Categories of data subject | The Controller's employees, workers and staff; and, in the Care edition, the Controller's service users / clients |
| Controller | The Customer |
| Processor | Intellectual Bunch Limited t/a EveryShift |
Complete with your real measures Populate this annex to match what EveryShift actually implements. The list below is a realistic starting set drawn from the product security requirements already documented; confirm each item is true before publishing.
The Processor uses the following sub-processors. Complete with the live list.
| Sub-processor | Purpose | Location |
|---|---|---|
| [hosting provider] | Cloud hosting and storage | [UK / region] |
| [email provider] | Transactional and notification email | [region] |
| [SMS provider] | SMS notifications | [region] |
| [payment provider] | Payment processing | [region] |
| [analytics provider] | Website and product analytics | [region] |
Your wishlist is empty.
