Legal

Data Processing Addendum

This addendum describes the data-protection terms intended to apply when ComplyClock processes personal data for a Customer.

Last updated: 19 August 2026

Contract template — legal review required. This DPA is not ready for execution until every [LEGAL REVIEW] item is completed and a qualified solicitor approves the full agreement.

1. Parties and status

This Data Processing Addendum (DPA) is between the Customer identified in the applicable order or workspace and ComplyClock Ltd (ComplyClock).

Company number
[LEGAL REVIEW] Insert the company registration number
Registered office
[LEGAL REVIEW] Insert the registered office address
Execution
[LEGAL REVIEW] Confirm how this DPA is incorporated into the Terms or signed, and identify the effective date.

2. Definitions and priority

Data Protection Laws means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and other applicable UK data-protection law. Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given by Data Protection Laws. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails. [LEGAL REVIEW] Confirm the complete definition set and order of precedence.

3. Roles and scope

The Customer is controller and ComplyClock is processor for personal data the Customer submits to or generates in the Service (Customer Personal Data). Each party will comply with its obligations under Data Protection Laws.

The Customer is responsible for its processing instructions, notices, lawful bases, data accuracy and permissions for Authorised Users. ComplyClock remains controller for its own account administration, security, billing and legal-compliance processing as described in the Privacy Notice.

4. Documented instructions

ComplyClock will process Customer Personal Data only on documented instructions from the Customer, including the Terms, this DPA, configured features and lawful support requests, unless UK law requires other processing. Where legally permitted, we will tell the Customer before processing required by law.

We will inform the Customer if, in our reasonable opinion, an instruction infringes Data Protection Laws and may pause the affected processing while the parties resolve it.

5. Confidentiality

Anyone authorised by ComplyClock to process Customer Personal Data will be bound by confidentiality obligations or an appropriate statutory duty and will receive access only as needed for their responsibilities.

6. Security

Taking account of the state of the art, implementation cost, processing context and risk, ComplyClock will maintain appropriate technical and organisational measures. Current measures include:

  • tenant-, role- and entity-scoped access controls;
  • HTTPS, secure sessions and password hashing;
  • private AES-256 server-side encrypted object storage and short-lived download URLs;
  • audit events for meaningful workspace changes;
  • dependency, application-security and error monitoring; and
  • [LEGAL REVIEW] Confirm and document the deployed backup design, restoration process, recovery targets, incident-response process and approved security schedule before representing them as current measures.

[LEGAL REVIEW] Approve whether the security measures form a binding minimum, how material reductions are handled, and whether a separate security exhibit is required.

7. Sub-processors

The Customer gives general written authorisation for ComplyClock to use the providers on the Sub-processors page. We will impose data-protection obligations that provide substantially equivalent protection for the relevant processing and remain responsible for our sub-processors as required by Data Protection Laws.

[LEGAL REVIEW] Approve the advance notice period for additions or replacements, the Customer objection process, available remedy if an objection cannot be resolved, and the initial authorised list.

8. International transfers

ComplyClock will not transfer Customer Personal Data outside the United Kingdom unless the transfer complies with Data Protection Laws. [LEGAL REVIEW] Confirm provider locations, adequacy coverage, the UK International Data Transfer Agreement or UK Addendum used where required, transfer risk assessment responsibilities, supplementary measures and how the relevant terms are incorporated.

9. Data-subject requests

Taking account of the nature of the processing, ComplyClock will provide reasonable assistance through product functionality and appropriate operational measures so the Customer can respond to requests under Data Protection Laws. If we receive a request concerning Customer Personal Data, we will refer it to the Customer unless law requires us to respond. [LEGAL REVIEW] Confirm any charge for exceptional assistance.

10. Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide information reasonably available to help the Customer meet its notification duties. Notification is not an admission of fault. [LEGAL REVIEW] Approve the notification channel, target timeframe, content, update cadence and incident-contact details.

11. Assessments and regulatory consultation

Taking account of the nature of processing and information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultation relating to the Customer's use of the Service. [LEGAL REVIEW] Confirm the scope, timing and charging position for assistance beyond standard documentation.

12. Information and audits

We will make available information reasonably necessary to demonstrate compliance with UK GDPR Article 28. Audits must protect other customers, security and confidential information and avoid unreasonable disruption.

[LEGAL REVIEW] Approve evidence supplied as standard, audit frequency, notice, independent-auditor requirements, on-site access, allocation of costs and treatment of regulator requests.

13. Return and deletion

At the Customer's choice and subject to applicable law, ComplyClock will return or delete Customer Personal Data after the Service ends. [LEGAL REVIEW] Approve the self-service export period, deletion deadline, backup and non-current object retention, legal holds, deletion certification and any transition-assistance charge.

14. Liability and general terms

[LEGAL REVIEW] Confirm how the Terms' liability limits apply to this DPA, whether any separate cap or indemnity applies, governing law, jurisdiction, notices, amendment procedure and third-party rights.

Schedule 1 — Processing details

Subject matter
Providing the ComplyClock compliance tracking, workflow, reminder, document and integration Service.
Duration
For the Subscription and the approved return, deletion and backup-retention periods. [LEGAL REVIEW] Insert those periods.
Nature and purpose
Hosting, organising, retrieving, displaying, calculating, transmitting, backing up and deleting data on Customer instructions.
Data subjects
Customer staff, practice staff, client contacts, company officers, contractors, advisers and people who respond to client requests.
Personal data
Names, business contact details, roles, authentication and activity data, company/compliance records, communications, assignments, documents, filenames and technical data.
Special categories
Not intentionally required by the Service. [LEGAL REVIEW] Confirm restrictions and safeguards if a Customer uploads them.
Customer instructions
The Terms, this DPA, workspace configuration, Authorised User actions and documented support instructions.