Data Processing Agreement (DPA)
 

Data Processing Agreement

1. Scope and roles

1.1 This Data Processing Agreement ("DPA") forms part of the SaaS Terms and Conditions between Intellectual Bunch Limited t/a EveryShift (the "Processor") and the Customer (the "Controller"). It governs the Processor's processing of personal data within Customer Data on the Controller's behalf.

1.2 The Controller determines the purposes and means of processing Customer Data. The Processor processes it only on the Controller's documented instructions, as set out in this DPA and the Terms.

1.3 Terms defined in the SaaS Terms and Conditions have the same meaning here. "UK GDPR", "controller", "processor", "processing", "personal data", "special-category data", "data subject" and "personal data breach" have the meanings in the UK GDPR and the Data Protection Act 2018.

2. Processor obligations

The Processor will:

  • process personal data only on the Controller's documented instructions, including as to international transfers, unless required to do otherwise by law (in which case it will inform the Controller, unless legally prohibited);
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (Annex 2);
  • respect the conditions in section 4 for engaging sub-processors;
  • assist the Controller, taking account of the nature of processing, in responding to data-subject requests (section 5);
  • assist the Controller with its obligations on security, breach notification, data protection impact assessments and prior consultation (sections 6 and 7);
  • at the Controller's choice, delete or return personal data at the end of the services, and delete existing copies unless retention is required by law (section 9);
  • make available information necessary to demonstrate compliance, and allow for and contribute to audits (section 8).

2.1 If the Processor considers that an instruction infringes data protection law, it will inform the Controller.

3. Special-category and health data (Care edition)

3.1 Where the Controller uses the Care edition, Customer Data may include special-category data concerning health under Article 9 UK GDPR (for example care visit records and certain absence or training records).

3.2 The Controller is responsible for establishing the lawful basis and the Article 9 condition for such processing, for any Data Protection Impact Assessment, and for the privacy information provided to affected individuals.

3.3 The Processor will apply the enhanced security measures in Annex 2 to such data, including encryption at rest and in transit, strict access controls and logging, and will treat it as high-risk personal data for the purposes of breach handling.

4. Sub-processors

4.1 The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex 3 to help deliver the Service.

4.2 The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to the Controller for its sub-processors' acts and omissions.

4.3 The Processor will give the Controller at least notice of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.

5. Data-subject rights

5.1 Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests from data subjects exercising their rights.

5.2 If the Processor receives a request directly from a data subject relating to Customer Data, it will not respond except on the Controller's instruction, and will promptly forward the request to the Controller.

6. Personal data breach

6.1 The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and in any event in time to allow the Controller to meet its own notification obligations.

6.2 The notification will include, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available.

6.3 The Processor will take reasonable steps to contain and remediate the breach and will cooperate with the Controller.

7. DPIAs and prior consultation

7.1 The Processor will provide reasonable assistance to the Controller with data protection impact assessments and any prior consultation with the Information Commissioner's Office, taking into account the nature of processing and the information available to the Processor. This is particularly relevant to the Care edition.

8. Records, audits and information

8.1 The Processor will maintain records of its processing as required by Article 30 UK GDPR and will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28.

8.2 The Processor will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, no more than and on reasonable notice, subject to confidentiality and to not compromising other customers' data. The Processor may satisfy audit requests by providing an up-to-date third-party certification or report where available.

9. Return and deletion

9.1 On termination of the Service, and at the Controller's choice, the Processor will delete or return all Customer Data and delete existing copies, unless UK law requires storage of the data.

9.2 The Processor will make Customer Data available for export for the period stated in the Terms before deletion. Deletion is scheduled against applicable statutory retention rules (for example payroll records commonly retained for at least six years, and care records for longer statutory periods) rather than performed immediately where the law requires longer retention.

10. International transfers

10.1 The Processor will not transfer Customer Data outside the UK except as necessary to provide the Service through the sub-processors in Annex 3, and only where an appropriate safeguard under the UK GDPR is in place, such as UK adequacy regulations or the International Data Transfer Agreement / UK Addendum.

11. Liability and governing law

11.1 The liability provisions in the SaaS Terms and Conditions apply to this DPA. This DPA is governed by the laws of England and Wales.

11.2 If there is a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails.

Annex 1. Details of processing

Item Detail
Subject matter Provision of the EveryShift workforce operations platform
Duration The term of the Customer's subscription, plus any export/retention period
Nature and purpose Hosting, storage and processing of workforce data to deliver scheduling, sign-off, timesheets, payroll-ready outputs, training, leave and (Care) visit records
Types of personal data Identity and contact data; employment data (role, pay rate, availability, hours); rota, timesheet and sign-off records; training and leave records; uploaded documents; and, in the Care edition, health-related care visit data (special-category)
Categories of data subject The Controller's employees, workers and staff; and, in the Care edition, the Controller's service users / clients
Controller The Customer
Processor Intellectual Bunch Limited t/a EveryShift

Annex 2. Technical and organisational security measures

Complete with your real measures Populate this annex to match what EveryShift actually implements. The list below is a realistic starting set drawn from the product security requirements already documented; confirm each item is true before publishing.

  • Encryption of personal data in transit (TLS) and at rest;
  • Role-based access controls and least-privilege access; multi-tenant isolation enforced at the data layer;
  • Two-factor authentication available to all users and enforceable by administrators;
  • Password policy, brute-force protection and account lockout;
  • Audit logging of material actions and access;
  • Regular backups and a tested restoration process;
  • Vulnerability management and, prior to the Care edition serving live providers, penetration testing;
  • Staff confidentiality obligations and data protection training;
  • Enhanced measures for special-category (health) data in the Care edition;
  • Documented breach response and incident management process.

Annex 3. Authorised sub-processors

The Processor uses the following sub-processors. Complete with the live list.

Sub-processor Purpose Location
[hosting provider] Cloud hosting and storage [UK / region]
[email provider] Transactional and notification email [region]
[SMS provider] SMS notifications [region]
[payment provider] Payment processing [region]
[analytics provider] Website and product analytics [region]
Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare