Data Processing Agreement
In effect from —
This agreement is between your company (the “controller”) and [LEGAL NAME] (the “processor”). It governs our processing of personal data on your behalf and satisfies Article 28(3) of Regulation (EU) 2016/679 (GDPR).
1. What is being processed, and why
- Subject matter
- Providing the WorkPilot service to you under the Terms of Service.
- Duration
- For as long as you use the service, plus the ninety-day recovery period after it ends.
- Nature and purpose
- Recording, storing, organising, calculating on and exporting workforce data so that you can manage attendance, scheduling, timesheets, payroll preparation, leave, expenses and the commercial records that accompany them.
- Categories of data subject
- Your employees, your subcontractors and other people you give access to; and the individual contacts at your customers and suppliers whose details you record.
- Categories of personal data
- Identity and contact details; employment details including role and pay rate; attendance records including timestamps, check-in photographs and GPS positions; schedules; leave and absence records; expenses; internal messages; and national identifiers where you choose to record them, such as a personnummer or a codice fiscale.
- Special categories
- The service is not designed to process special-category data under Article 9. A sickness absence recorded as leave may imply health information; do not record diagnoses or other health detail in free-text fields.
2. What we undertake
- We process personal data only on your documented instructions. Your use of the service is the instruction; anything beyond it needs to be agreed in writing.
- If the law requires us to process it otherwise, we will tell you before doing so unless that law forbids us from telling you.
- Everyone we authorise to access personal data is bound by an obligation of confidentiality.
- We implement the technical and organisational measures required by Article 32, described in section 4.
- We help you meet your own obligations under Articles 32 to 36 — security, breach notification and impact assessments — taking account of what we know and what we can see.
- We help you respond to requests from individuals exercising their rights, by the tools in the service and, where those are not enough, directly.
- At your choice, at the end of the service we return or delete the personal data, unless a law requires us to keep it.
- We make available the information needed to demonstrate compliance with this Article, and allow and contribute to audits as set out in section 6.
3. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published on our sub-processors page and forms part of this agreement.
Each is bound by data protection obligations no less protective than these, and we remain fully liable to you for their performance.
Before adding or replacing one, we will give you at least thirty days' notice by email. If you reasonably object on data protection grounds within that period, we will work with you to find a solution; if none can be found, you may terminate the affected part of the service and we refund the unused period pro rata.
4. Security measures
These are the measures actually in place, not a wish list:
- Tenant isolation enforced in the database and in file storage, so one customer's records cannot be read by another. This is a rule at the data layer, not a filtered screen.
- Role-based access within a customer, so a worker cannot open a colleague's record or read their pay rate.
- Encryption in transit (TLS) and at rest.
- Authentication through a managed identity provider, with sessions revocable immediately — suspending someone ends the session they are already in, not only the next one.
- Attestation of the calling application before privileged operations are accepted.
- Administrative access limited to what is needed to operate the service, and separated from customer-facing roles.
- Automated backups with point-in-time recovery.
- Server-side logging of security-relevant events and an audit trail visible to the customer.
5. Personal data breaches
If we become aware of a personal data breach affecting your data we will notify you without undue delay and in any event within forty-eight hours, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Notifying your supervisory authority is your decision as controller, and we will give you what you need to make it.
6. Audits
We will answer reasonable written questions about our processing and provide any certifications and reports we hold. Where that is genuinely not enough to demonstrate compliance, you may audit us — once in any twelve months unless a breach or a regulator says otherwise — on thirty days' notice, during working hours, without disrupting the service, and subject to confidentiality. You bear your own costs.
7. International transfers
Personal data is stored in Zurich, Switzerland, which is covered by a European Commission adequacy decision. Where a sub-processor transfers data outside the EEA without adequacy, it does so under the standard contractual clauses or another Chapter V mechanism, as noted against it on the sub-processors page.
8. Your responsibilities as controller
Some things only you can do, and this agreement does not move them to us:
- Establishing a lawful basis for what you record about your workers.
- Informing your workers under Articles 13 and 14 — including, specifically, that check-in photographs and locations are recorded if you enable those features.
- Consulting employee representatives where your national law or collective agreement requires it. Monitoring at work is regulated beyond the GDPR in both Italy and Sweden.
- Deciding retention, and keeping the data you hold accurate and no more than you need.
9. Precedence and term
This agreement takes effect when you begin using the service and ends when all personal data has been returned or deleted. Where it conflicts with the Terms of Service on the processing of personal data, this agreement prevails.