Skip to content
P6 Schedule Analytics

TemplateFor legal review before launch. Bracketed text is a placeholder. This isn't legal advice.

Data processing agreement

Last updated: [DATE]

This agreement forms part of the Terms of service between [COMPANY LEGAL NAME] (the "processor") and the customer (the "controller"). It meets the requirements of Article 28 of the UK GDPR.

1. Subject matter and duration#

The processor processes personal data in files the controller uploads, only to provide the Service, for as long as the controller uses it and for the retention period after (see Security).

2. Nature, purpose and categories#

NatureStorage and automated analysis of programme files
PurposeProviding the analysis the controller requests
Data subjectsPeople named in the files, such as resources and responsible persons, and the controller's users
CategoriesNames, roles and work-related identifiers. No special category data is expected

3. Processor obligations#

The processor will:

  1. process personal data only on the controller's documented instructions;
  2. ensure people authorised to process it are bound by confidentiality;
  3. take appropriate technical and organisational measures (Schedule 1);
  4. engage sub-processors only as listed on the Security page, with the same obligations, and give [30] days' notice of changes;
  5. assist the controller with data subject requests and with its security, breach-notification and impact-assessment obligations;
  6. notify the controller without undue delay, and within [48] hours, of a personal data breach;
  7. delete or return the data at the end of the service, at the controller's choice;
  8. make available the information needed to demonstrate compliance, and allow audits [on reasonable notice, no more than once a year].

4. International transfers#

[Safeguards for any transfer outside the UK and EEA.]

Schedule 1: security measures#

  • Encryption in transit (HTTPS).
  • [Encryption at rest: TO CONFIRM with the hosting provider.]
  • Hosting in the EU (Frankfurt).
  • Passwords stored as salted scrypt hashes.
  • Role-based and activity-level access control, enforced on the server.
  • An activity log of sign-ins, uploads and exports.
  • [Staff access controls, backups and incident response: TO COMPLETE.]