Legal

Data processing agreement

Published in full so your legal team can read it before the first call, rather than after the third. We will execute it as a signed document on request.

Last updated: 4 August 2026 · Applies to: taskbithr.com and the TaskBit application

1. Scope and roles

This agreement forms part of the terms of service between TaskBit Ltd ("Processor") and the customer organisation ("Controller"). It applies whenever we process personal data on the Controller's behalf, and it prevails over the terms in the event of a conflict about data protection.

The Controller determines the purposes and means of processing. The Processor processes only on documented instructions from the Controller, which include the Controller's use of the product's features.

2. Details of processing

Subject matterProvision of the TaskBit workforce, rota and HR management platform
DurationFor the term of the agreement, plus the retention window in section 9
Nature and purposeHosting, storage, processing and display of workforce data; scheduling; attendance capture; timesheet and payroll calculation; document and compliance management; communication and notification
Categories of data subjectThe Controller's employees, workers, job applicants, and where applicable agency workers and client contacts
Categories of personal dataIdentity and contact details; employment details; scheduling and attendance records including geolocation captured at clock-in; leave and absence records; pay, tax, National Insurance, pension and bank details; documents, signatures and compliance evidence including right-to-work status; in-platform communications; account, security and audit data
Special categoriesNot required by the service. Health-related data may be inferred from sickness absence records the Controller chooses to store; the Controller is responsible for its lawful basis and for any Article 9 condition

3. Our obligations as processor

We will:

  • process personal data only on the Controller's documented instructions, including for international transfers, unless required otherwise by law — in which case we will inform the Controller first unless legally prohibited;
  • ensure that personnel authorised to process the data are bound by confidentiality;
  • implement the technical and organisational measures described in section 6;
  • not engage a sub-processor except in accordance with section 4;
  • assist the Controller as described in section 7;
  • make available the information necessary to demonstrate compliance, and permit audits as described in section 8;
  • notify the Controller if, in our opinion, an instruction infringes data protection law.

4. Sub-processors

The Controller grants general authorisation for the sub-processors listed on our sub-processors page, which is kept current. We will give at least 30 days' notice before adding or replacing a sub-processor, and the Controller may object on reasonable data protection grounds within that period. If we cannot resolve an objection, the Controller may terminate the affected service without penalty.

Each sub-processor is engaged under a written contract imposing obligations no less protective than those in this agreement, and we remain fully liable for their performance.

5. International transfers

Personal data is hosted in the UK/EU by default. Where a transfer outside the UK or EEA is necessary, it is made under an adequacy decision, or under the UK International Data Transfer Addendum or EU Standard Contractual Clauses together with a transfer risk assessment and any necessary supplementary measures.

6. Security measures

We maintain, at minimum:

  • encryption of personal data in transit (TLS 1.2+ with HSTS) and at rest, with application-layer encryption for particularly sensitive fields including bank details;
  • logical isolation between customer organisations, enforced on every request by an attribute-based access control layer and covered by automated negative testing;
  • authentication controls including password hashing, two-factor authentication, rate limiting, lockout after repeated failures and session revocation;
  • role-based access on a least-privilege basis for our own personnel, with access reviewed on change of role;
  • append-only audit logging of sensitive actions;
  • automated backups with point-in-time recovery and tested restores;
  • monitoring, structured logging and alerting on the service;
  • a documented change management process with review, automated testing and staged deployment.

We may update these measures provided the level of protection is not reduced. Current detail is published on our security page.

7. Assistance and breach notification

Taking account of the nature of processing, we will assist the Controller with:

  • Data subject requests. The product provides export and delete functions covering an individual's record, so most requests can be actioned directly by the Controller. Where a request reaches us, we will forward it promptly rather than respond on the Controller's behalf.
  • Impact assessments and prior consultation, by providing information about our processing that the Controller does not already hold.
  • Personal data breaches. We will notify the Controller without undue delay, and in any event within 48 hours of becoming aware, with the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

8. Audit

We will make available the information necessary to demonstrate compliance with this agreement, including completing security questionnaires and providing our architecture, sub-processor and control documentation. The Controller may audit no more than once in any 12-month period on 30 days' written notice, or more frequently following a breach or where required by a supervisory authority. Audits are conducted during business hours, without unreasonable disruption, and subject to confidentiality.

9. Return and deletion

The Controller may export its data at any time during the term. On termination, we retain the organisation for 30 days so that an accidental cancellation can be reversed, then delete it. Data persisting in backups is deleted as those backups roll off, no more than 35 days later, and remains protected by this agreement until then. We will confirm deletion in writing on request.

10. Signing this agreement

This agreement applies automatically to every customer as part of the terms of service — no signature is required for it to be in force. If your procurement process needs an executed copy, or you need us to sign your own DPA, write to legal@taskbithr.com and we will turn it around.