Data Processing Terms – How These Terms Work
1. Definitions and priority
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and other applicable UK laws governing personal data. “Controller”, “processor”, “personal data”, “personal data breach”, “data subject”, “processing” and “special category data” have the meanings given by Data Protection Law. “Services” means the services described in the agreement. “Client Data” means personal data processed by the Processor on behalf of the Client.
These terms apply only to processor activities. Each party remains an independent controller for information it uses for its own business, professional, employment, contractual, billing, legal, security or compliance purposes. If these terms conflict with general service terms on a processor obligation, these terms take priority.
2. Roles and client responsibilities
The Client is the controller and the relevant service provider is the processor for the processing described in the agreement and Schedule 1. The Client is responsible for the lawfulness of its instructions, the data it provides, its privacy information, lawful bases, access decisions, accuracy and retention requirements. The Client must not instruct processing that infringes Data Protection Law.
The applicable Order Form, purchase confirmation, service description or contractual arrangement will identify whether Practical HR Ltd or Your Business Guide Ltd is the Processor. Where the Client contracts directly with Your Business Guide Ltd, Your Business Guide Ltd will normally be the Processor for Client-controlled data held within YourHR.space. Where Practical HR Ltd provides YourHR.space under its agreement with the Client, Practical HR Ltd may appoint Your Business Guide Ltd as its sub-processor and platform provider.
3. Processing instructions
The Processor will process Client Data only to provide the Services and in accordance with the Client’s documented instructions, including in relation to international transfers, unless applicable law requires the Processor to process the Client Data otherwise. Where legally permitted, the Processor will inform the Client of that legal requirement before carrying out the processing.
Documented instructions include the agreement, order form, agreed configuration, authorised platform activity, support request, workflow or written direction from an authorised Client representative. If the Processor considers an instruction to infringe Data Protection Law, it will inform the Client unless prohibited by law.
4. Confidentiality and personnel
The Processor will ensure that persons authorised to process Client Data are subject to appropriate confidentiality obligations and receive relevant security and data protection guidance. Access will be limited to those who need it for authorised purposes.
5. Security
The Processor will maintain appropriate and proportionate technical and organisational measures having regard to the nature, scope, context and purposes of the processing and the risks to individuals. Current measures are summarised in Schedule 2 and the External Security and Data Protection Pack. Security details may be updated where this does not materially reduce the overall level of protection.
6. Sub-processors
The Client gives general written authorisation for the Processor to use sub-processors needed for hosting, development, maintenance, support, communications, storage, backup and related services. The Processor will maintain a current record of material sub-processors and will make relevant information available on reasonable request. It will impose equivalent data protection obligations on sub-processors and remains responsible to the Client for their performance of those obligations.
Where a new sub-processor materially affects the processing of Client Data, the Processor will provide reasonable notice where practicable. The Client may raise a reasonable, evidence-based objection on data protection grounds. The parties will seek a practical solution; where none is reasonably available, the affected service may be ended in accordance with the agreement.
7. International transfers
The Processor will not make a restricted transfer of Client Data outside the UK unless instructed or authorised by the Client and a lawful transfer mechanism and required safeguards are in place. Core YourHR.space and YourHR.guide application hosting is intended to be within UK-based infrastructure, but approved business systems or support arrangements may involve overseas access or processing.
8. Assistance
Taking account of the nature of the processing and information available, the Processor will provide reasonable assistance with data subject requests, security obligations, breach assessment and notification, data protection impact assessments and prior consultation obligations. The Client remains responsible for deciding how to respond and for meeting its legal duties. Significant assistance outside the normal service may be chargeable at the agreed or current rates, except where the need arises from the Processor’s breach.
9. Personal data breaches
The Processor will notify the Client without undue delay after becoming aware of a personal data breach affecting Client Data. The notice will include available information about the nature of the breach, likely consequences, measures taken or proposed and a contact point. Information may be supplied in stages. The Processor will take reasonable steps to contain, investigate and mitigate the incident. The Client is responsible for notifications to the ICO and affected individuals unless otherwise agreed or required by law.
10. Return, deletion and end of service
At the Client’s choice and subject to the agreement, the Processor will return or delete Client Data at the end of the Services unless law requires retention. The Client must use available export facilities or request agreed assistance before access ends. Deleted information may remain temporarily in secure backups until overwritten through the normal backup cycle and will not be restored or used except for disaster recovery or legal requirements.
11. Records, information and audits
The Processor will keep information reasonably necessary to demonstrate compliance with these terms. It will provide proportionate information through its External Security and Data Protection Pack, relevant schedules and supporting evidence. Audits must be reasonable, relevant, normally limited to once in any 12-month period, arranged on reasonable notice, conducted during business hours, avoid unnecessary disruption and protect other clients’ confidentiality and system security. Independent reports or documentary evidence should be used before an onsite audit. The Client bears reasonable audit costs unless a material breach by the Processor is identified.
12. Liability and general terms
Liability under these terms is subject to the exclusions and limits in the main agreement, except to the extent liability cannot legally be limited. These terms continue for as long as the Processor processes Client Data. Changes required by law or reasonably necessary to maintain compliance may be made in accordance with the agreement’s change provisions.
Schedule 1: Processing details
Item | Details |
Subject matter | Provision of the agreed HR software, platform, digital service, platform administration, outsourced HR administration or related support. Where Practical HR Ltd is the contracting Processor, the processing may also include agreed HR administration or consultancy support carried out on the Client’s instructions. |
Duration | For the agreement and any limited offboarding, deletion, backup or legal retention period. |
Nature and purpose | Collection, hosting, storage, organisation, access, retrieval, consultation, use, communication, support, configuration, backup, export, amendment and deletion as needed for the Services. |
Types of personal data | Identity and contact details; employment, contractual, role, pay, holiday, absence, performance, conduct, grievance, capability, consultation and other HR information; documents, forms and communications; user, access, audit, support and technical records. |
Special category / criminal data | May include health, equality, trade-union or other special category data and, where lawfully relevant, criminal allegation or conviction information. |
Data subjects | Client employees, workers, contractors, applicants, former personnel, managers, representatives, dependants, witnesses and other individuals whose data is included in the Services. |
Controller instructions | The agreement, order form, configured use of the service, authorised support requests, agreed processes and written instructions from authorised Client contacts. |
Schedule 2: Security measures summary
role-based access and restricted administrator permissions;
strong authentication and multi-factor authentication where available and appropriate;
confidentiality obligations and secure-handling requirements for authorised personnel;
approved corporate systems and controlled storage;
HTTPS/TLS and secure transfer methods;
managed UK-hosted infrastructure for core platform services;
development, change, testing, patching, monitoring and vulnerability controls;
backup, recovery, continuity, incident and breach-management arrangements;
supplier and sub-processor due diligence proportionate to risk;
retention, offboarding and secure deletion co