Data Processing Addendum
Last updated: 17 August 2026
This Data Processing Addendum ("DPA") is intended to form part of the agreement between AssistHR ("processor", "we", "us") and the customer organisation that subscribes to AssistHR ("customer", "controller", "you"), and applies whenever we process personal data on your behalf.
It is written to reflect Article 28 of the UK GDPR. It sits alongside our Terms of Service and Subprocessors page. If you need a signed copy, or your own template reviewed, email info@assisthr.co.uk.
1. Roles of the parties
For personal data about your employees, workers, applicants and other individuals that you or your authorised users enter into the AssistHR platform, you act as controller and we act as processor.
We act as an independent controller for a limited set of data we need to run the service, such as account administrator contact details, billing contacts, security and audit logs, and aggregated operational information. That processing is described in our Privacy Notice.
Each party will comply with its own obligations under applicable data protection law. Terms such as controller, processor, personal data, processing and personal data breach have the meanings given in the UK GDPR.
2. Scope, duration, nature and purpose
- Subject matter. The provision of the AssistHR HR software service to you.
- Duration. For the term of your subscription, plus the limited period needed to complete export, return or deletion in line with section 9.
- Nature of processing. Hosting, storage, retrieval, organisation, display, transmission, backup, support, security monitoring, export and deletion of personal data through the platform and its features.
- Purpose. To provide, secure and support the service in accordance with the agreement and your instructions, including HR record keeping, leave and absence management, documents and e-signature workflows, working time and timesheets, reporting and the HR Help assistant.
- Categories of data and data subjects. As set out in Schedule 1.
3. Documented instructions
We will process personal data only on your documented instructions. The agreement, this DPA, the configuration choices you make in the product, and the support requests you send us together constitute your instructions.
We will not use your personal data for our own purposes, and we will not sell it. We will tell you if, in our view, an instruction appears to infringe applicable data protection law, and we may pause the relevant processing while we discuss it with you.
We may process personal data where required to do so by law. Where legally permitted, we will inform you before doing so.
4. Confidentiality of personnel
We will ensure that people authorised to process your personal data are subject to a duty of confidentiality, receive appropriate instruction about their obligations, and have access only where their role requires it.
5. Technical and organisational measures
We will implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, along with the risks to individuals.
The measures we currently rely on are described in Schedule 2. They are limited to controls that exist in the product today. We may update the measures over time, provided the overall level of protection is not reduced.
6. Subprocessors
You give us general authorisation to engage subprocessors to help provide the service. Our current subprocessors are listed on our Subprocessors page.
- We will impose data protection obligations on each subprocessor that are substantially the same as those in this DPA, so far as applicable to the work they perform.
- We remain responsible to you for the performance of our subprocessors' obligations.
- We will give you notice of a new or replacement subprocessor before it starts processing your personal data, or as soon as reasonably practicable where an urgent change is needed to keep the service running or secure.
- You may object on reasonable data protection grounds. We will work with you in good faith to find a solution. If we cannot, you may terminate the affected part of the service by written notice, without penalty for the unexpired period.
7. Assistance to the customer
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as reasonably possible, with:
- responding to requests from individuals exercising their rights, including access, rectification, erasure, restriction, portability and objection. The product includes export and erasure workflows you can use directly
- carrying out data protection impact assessments and any prior consultation with the Information Commissioner's Office, by providing information about the processing we perform
- responding to enquiries or investigations from a supervisory authority relating to our processing of your personal data
If an individual contacts us directly about data we hold as your processor, we will not respond to the substance of the request. We will refer them to you and tell you promptly, unless we are legally prevented from doing so.
8. Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data. Our notification will include the information reasonably available to us at the time, and we will provide further detail as our investigation progresses.
We will describe the nature of the breach, the categories and approximate number of records affected where known, the likely consequences, and the measures taken or proposed to address it and reduce any adverse effect.
We will cooperate with you so that you can meet your own notification duties. Our notification is not an admission of fault or liability.
9. Deletion or return of data
On termination or expiry of the service, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies, unless we are required by law to retain them.
Before deletion we will make the data available for export for a reasonable period so that you can retain your records. Backups and log entries are removed in line with their normal retention cycle.
10. Audit information and cooperation
We will make available to you the information reasonably necessary to demonstrate our compliance with this DPA, and will cooperate reasonably with audits and inspections carried out by you or an auditor you appoint.
Audits will be requested with reasonable notice, will happen no more than once a year unless a regulator requires otherwise or there has been a personal data breach, will be limited in scope to the processing carried out for you, and will be conducted so as not to disrupt the service or compromise the confidentiality of other customers.
Where available, we may satisfy an audit request by providing written responses, documentation about our controls, or third-party reports relating to our subprocessors.
11. International transfers
Where processing involves a transfer of personal data outside the United Kingdom, we will ensure an appropriate transfer mechanism is in place, such as UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with any additional measures the transfer requires.
Processing locations depend on how each provider is configured, so we do not state a single location here. Contact info@assisthr.co.uk for the current position for your account.
12. Liability and order of precedence
The liability provisions of the agreement apply to this DPA. Liability under this DPA is subject to the exclusions and limits set out in our Terms of Service or in your signed agreement, except where applicable law does not allow that.
If there is any inconsistency, this DPA takes priority over the Terms of Service on data protection matters, and a signed agreement or order form between us takes priority over both.
Schedule 1: Details of processing
Categories of data subject
- employees and workers of the customer
- contractors, temporary staff and other individuals the customer records in the platform
- job applicants and candidates, where the customer uses the platform for recruitment activity
- authorised users such as HR administrators, managers and account owners
- emergency contacts and next of kin, where the customer records them
Categories of personal data
- identification and contact details, such as name, work and personal contact details and address
- employment details, such as job title, department, manager, start date, contract type and working pattern
- leave, absence and holiday entitlement records
- working time, timesheets and hours submitted or approved
- HR documents, policies, letters and e-signature records including signature metadata
- performance, task and workflow records created by the customer
- payroll-related reference information the customer chooses to record
- account, authentication and audit information relating to authorised users
- support correspondence and, where consented, diagnostic reports
Special category data and criminal offence data are not required by the service. If the customer chooses to record such data in free-text or document fields, the customer is responsible for having a valid basis and any additional condition required by law, and should apply appropriate access restrictions.
Processing operations
- collection and storage of records entered by the customer and its users
- organisation, retrieval, display and search within the customer's workspace
- document storage, generation and e-signature workflows
- sending transactional email such as invitations, sign-in and notification messages
- hosting, backup and disaster recovery of the underlying database and storage
- security monitoring, rate limiting, audit logging and incident investigation
- provision of the HR Help assistant using sanitised, minimised input
- data export and erasure at the customer's request
- support and troubleshooting at the customer's request
Frequency and duration
Processing is continuous for the duration of the subscription, and continues for the limited period needed to complete export, return or deletion.
Schedule 2: Security measures
The measures below describe controls implemented in the AssistHR platform today. We do not claim any certification, audit report or testing programme in this schedule.
| Measure | What this means in practice |
|---|---|
| Tenant isolation | Each customer workspace is separated at the database level using row level security policies, so queries are scoped to the workspace of the requesting user. |
| Access control | Role-based access controls determine what an authorised user can see and do. Roles are held separately from user profile records so that permissions cannot be changed by editing a profile. |
| Authentication | Accounts are authenticated through our backend platform provider. New and changed passwords are screened against known leaked-password data using a k-anonymity method that sends only a five-character hash prefix. |
| Audit logging | Significant actions are recorded in audit logs to support accountability and investigation. |
| Document delivery | Documents are held in private storage and delivered through short-lived signed links in the normal application workflows, rather than public URLs. One template editor path is still being verified, so we do not claim that every document path in the product is private. |
| Abuse protection | Rate limiting is applied to sensitive endpoints to reduce automated abuse and credential attacks. |
| AI data minimisation | Input to the HR Help assistant is sanitised, restricted to allowlisted fields and minimised, so whole records are not passed to the model. The assistant is not used to make solely automated decisions with legal or similarly significant effects. |
| Support diagnostics | Diagnostic reports are only sent with the user's consent and are designed to exclude form values, tokens, cookies, local storage contents and request headers. |
| Data subject workflows | Export and erasure workflows are available so that customers can respond to individuals' requests and manage retention. |
| Transport security | Access to the service is over encrypted connections using HTTPS. |
| Personnel measures | Access is limited to people who need it for their role, and those people are bound by confidentiality obligations. |
To request a countersigned DPA or ask about a specific control, email info@assisthr.co.uk.
See also our Security page and Subprocessors list.
