Data processing agreement
Version 2026-09
This agreement forms part of the terms of service between [Company name] Ltd (“we”, the processor) and the organisation using RTW Track (“you”, the controller). It sets out how we process personal data on your behalf, as required by Article 28 of the UK GDPR. You accept it when you set up your organisation, and the date and version you accepted are recorded on your account.
1. What we process
Subject matter: monitoring right to work follow-up checks for your staff, sending requests to them, recording results and producing evidence.
Data subjects: your employed, bank and agency workers, your managers and other users, and external contacts you add.
Personal data: names, dates of birth, email addresses, mobile numbers, employment details, share codes, right to work status, permission end dates, work restrictions, photographs and results returned by the Home Office online checking service.
Special category data: we don’t intend to process it. Right to work results can indicate nationality or immigration status, which we treat with the same care.
Duration: for as long as you use the service, then as set out in clause 9.
2. Your instructions
We process personal data only on your documented instructions. Your use of the service, its settings and this agreement are those instructions. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data in another way, we will tell you first unless the law prevents it.
You are responsible for having a lawful basis for the processing, for the accuracy of the data you upload, and for telling your workers how their data is used.
3. Confidentiality
Everyone at [Company name] Ltd who can access personal data is bound by a duty of confidentiality, and access is limited to what their role needs.
4. Security
We maintain appropriate technical and organisational measures, including:
- encryption in transit (TLS 1.2 or higher) and at rest, with field-level encryption for dates of birth and share codes
- passwordless sign-in by emailed code, and role-based access within your organisation
- an append-only record of checks, so history can’t be edited or deleted by the application
- a log of every document view, export and evidence pack
- share codes deleted once a check is confirmed or has failed permanently
- daily backups with point-in-time restore
5. Sub-processors
You give general authorisation for us to use the sub-processors below. We have a written contract with each one that gives the same level of protection as this agreement, and we remain responsible for them.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft (Azure) | Hosting, database, file storage, email and text message sending | United Kingdom (UK South) |
| Stripe | Billing: your organisation's billing contact and payment details. No worker data | United States, Ireland |
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we can’t address it, you may end the service and we will refund any prepaid fees for the remaining period.
6. Where data is stored
Worker data, including right to work results, documents and photographs, and your users’ accounts are stored and processed in the United Kingdom. Billing details are held by our payment provider outside the UK. That transfer is covered by the UK Extension to the EU-US Data Privacy Framework or the UK International Data Transfer Addendum.
7. Helping you meet your obligations
Taking into account the nature of the processing, we will help you respond to requests from individuals exercising their rights (for example access or erasure), and with data protection impact assessments and consultations with the Information Commissioner where they relate to the service. The service lets you export a worker’s record yourself at any time.
8. Personal data breaches
We will tell you without undue delay, and in any case within 24 hours, after becoming aware of a personal data breach affecting your data. We will give you the information you need to assess it and to notify the Information Commissioner and affected individuals if required.
9. Deletion at the end of the service
When your subscription ends, you can export your full record for 30 days. After that we delete your personal data, including backups within their normal cycle, unless the law requires us to keep it. If you set up an organisation but never start a trial or subscription, we delete its data 14 days after you import staff, and email you before we do.
While the service is active, worker personal data is deleted automatically 2 years after the worker’s leaving date, with the event history kept in anonymised form.
10. Audits
We will make available the information needed to show we meet this agreement, including our security overview and certifications. You may audit us, or appoint an independent auditor, once a year on 30 days’ notice, or at any time following a personal data breach. Audits are at your cost and must not disrupt the service for other customers.
11. Liability and law
Each party’s liability under this agreement is subject to the limits in the terms of service. This agreement is governed by the law of England and Wales. If it conflicts with the terms of service on data protection, this agreement takes priority.
[Company name] Ltd, registered in England and Wales, company number [Company number]. Registered office: [Registered office address]. ICO registration [ICO registration number].
Questions about this agreement: contact@rtwtrack.co.uk