Data Processing Agreement
Last updated: 8 February 2026
This DPA forms part of your HyreDocs service agreement. To countersign, download the PDF and email a signed copy to contracts@hyredocs.com.
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- HyreDocs Ltd, a company registered in the United Kingdom ("Processor"); and
- The Customer identified in the underlying HyreDocs Service Agreement ("Controller").
2. Definitions
Terms used but not defined here have the meanings given in the UK GDPR.
- Personal Data: any information relating to an identified or identifiable natural person processed under the Service Agreement.
- Sub-processor: any third party engaged by the Processor to process Personal Data on the Controller's behalf.
- Service: the HyreDocs SaaS platform.
3. Subject matter and duration
The Processor processes Personal Data on behalf of the Controller solely for the purpose of providing the Service. Processing continues for the duration of the Service Agreement and any wind-down period agreed in writing.
4. Nature, purpose and categories of processing
- Nature: hosting, storage, transmission, signature collection, audit logging, integration with the Controller's connected ATS (Bullhorn).
- Purpose: enabling the Controller to collect candidate information and execute employment / onboarding documents.
- Data subjects: the Controller's candidates, contractors, clients and own employees.
- Categories of Personal Data: contact details, identification data, employment data, signed documents, and the categories listed in clause 2 of the Privacy Policy.
- Special categories: only where the Controller's template requires it (e.g. DBS certificates). The Controller is responsible for having a lawful basis for processing special-category data.
5. Obligations of the Processor
The Processor shall:
- process Personal Data only on documented instructions from the Controller, including with regard to transfers outside the UK / EEA;
- ensure persons authorised to process Personal Data are bound by a duty of confidentiality;
- take all technical and organisational measures required by Article 32 of the UK GDPR (see Schedule 1);
- engage Sub-processors only in accordance with clause 7 below;
- assist the Controller, by appropriate technical and organisational measures, in responding to data-subject requests (clause 8);
- assist the Controller in complying with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, DPIA, prior consultation);
- at the Controller's choice, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless UK law requires retention;
- make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable prior notice and subject to confidentiality.
6. Obligations of the Controller
The Controller warrants that it has a lawful basis for the processing it instructs the Processor to perform, that it has issued appropriate privacy notices to its data subjects, and that its instructions to the Processor will not cause the Processor to be in breach of any applicable data-protection law.
7. Sub-processors
The Controller grants the Processor a general written authorisation to engage Sub-processors. The current list is published at /legal/subprocessors and forms part of this DPA. The Processor will notify the Controller of any intended changes at least 30 days in advance, giving the Controller the opportunity to object. If the Controller raises a reasonable objection on data-protection grounds and the parties cannot agree a resolution within 30 days, the Controller may terminate the Service Agreement on written notice, with a pro-rata refund of pre-paid fees.
The Processor remains fully liable to the Controller for the performance of any Sub-processor's obligations.
8. Data-subject requests
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights. The Processor will respond to documented requests from the Controller within 5 working days.
9. Personal data breach
The Processor shall notify the Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach. The notification will include, to the extent known: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
10. International transfers
Where the Processor transfers Personal Data outside the UK / EEA, the parties incorporate the UK International Data Transfer Addendum (Version B1.0, in force 21 March 2022) to the EU Standard Contractual Clauses (Module Two: Controller to Processor) by reference, with the Controller as data exporter and the Processor as data importer.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the underlying Service Agreement.
12. Conflict
In the event of any conflict between this DPA and the Service Agreement, this DPA prevails on data-protection matters.
Schedule 1 — Technical and organisational measures
The Processor implements the following measures (non-exhaustive):
- TLS 1.2+ encryption in transit on every connection.
- Encryption at rest on the managed database tier (AES-256).
- Application-level encryption (Fernet / AES-128 GCM) for high-sensitivity secrets including OAuth tokens.
- Password hashing with
bcryptand per-password salts. - HTTP-only secure cookies for session tokens; no Personal Data in localStorage.
- Strict per-tenant data isolation enforced at the API layer.
- Role-based access controls and audit logging of administrative actions.
- Least-privilege access for engineers; quarterly review.
- Automated dependency vulnerability scanning.
- Documented backup and disaster-recovery procedures with periodic restore drills.
- Breach-response runbook with 48-hour notification commitment to controllers.
Signatures
For HyreDocs Ltd: ___________________________ Date: _______________
For the Customer: ___________________________ Date: _______________