GDPR & Data Processing Addendum
Last updated 20 July 2026 · This is a template pending legal review.
This DPA forms part of the agreement between your organisation (controller) and Deplyra (processor) and reflects Article 28 UK/EU GDPR requirements.
Roles
Your organisation is the controller and determines the purposes and means of processing. Deplyra is the processor and acts only on documented instructions.
Scope of processing
Subject matter: workforce operations. Duration: the term of the agreement. Nature and purpose: storing and processing forms, attendance, documents and compliance records. Categories of data subjects: your employees, contractors, visitors and (where relevant) service users.
Sub-processors
You authorise the sub-processors we list; we give notice of changes and remain liable for their processing.
International transfers
Enterprise customers may select EU data residency. Where transfers occur, we rely on appropriate safeguards (e.g. SCCs / UK IDTA).
Security & breach
We implement the technical and organisational measures described in our security overview and will notify you without undue delay of any personal-data breach affecting your data.
Assistance & deletion
We assist with data-subject requests, DPIAs and audits, and on termination we delete or return personal data at your choice. Data protection contact: help@deplyra.com.