GDPR & Data Processing Addendum

Last updated 20 July 2026 · This is a template pending legal review.

This DPA forms part of the agreement between your organisation (controller) and Deplyra (processor) and reflects Article 28 UK/EU GDPR requirements.

Roles

Your organisation is the controller and determines the purposes and means of processing. Deplyra is the processor and acts only on documented instructions.

Scope of processing

Subject matter: workforce operations. Duration: the term of the agreement. Nature and purpose: storing and processing forms, attendance, documents and compliance records. Categories of data subjects: your employees, contractors, visitors and (where relevant) service users.

Sub-processors

You authorise the sub-processors we list; we give notice of changes and remain liable for their processing.

International transfers

Enterprise customers may select EU data residency. Where transfers occur, we rely on appropriate safeguards (e.g. SCCs / UK IDTA).

Security & breach

We implement the technical and organisational measures described in our security overview and will notify you without undue delay of any personal-data breach affecting your data.

Assistance & deletion

We assist with data-subject requests, DPIAs and audits, and on termination we delete or return personal data at your choice. Data protection contact: help@deplyra.com.