Data Processing Agreement
Recordme acts as a data processor on behalf of its business customers (“controllers”) when processing personal data through the platform. This Data Processing Agreement (“DPA”) governs that processing relationship and satisfies the requirements of UK GDPR Article 28(3) and the Data Protection Act 2018.
For questions about these terms or about the processing relationship, email [email protected].
1. Processing on instruction only (UK GDPR Art-28(3)(a))
Recordme processes personal data solely on documented instructions from the Controller, including with regard to international transfers. If Recordme is required by law to process personal data beyond those instructions, it will inform the Controller unless prohibited by law from doing so.
2. Confidentiality (UK GDPR Art-28(3)(b))
Persons authorised by Recordme to process personal data on the Controller’s behalf are bound by contractual confidentiality obligations or applicable statutory duties of confidentiality. Access to personal data is limited to personnel who require it to perform the Service.
3. Technical and organisational security measures (UK GDPR Art-28(3)(c) / Art-32)
Recordme implements and maintains technical and organisational measures appropriate to the risks presented by processing, including:
- Encryption in transit;
- Database-enforced row-level tenant isolation between customer organisations;
- Role-based access controls and multi-factor authentication for user and administrator accounts;
- Append-only audit logging of processing actions on personal data, enforced at the database layer;
- Automated cross-tenant isolation and security regression tests run on every change, and regular evaluation of security measure effectiveness.
A summary of the technical measures we operate is published at recordme.io/security. A technical and organisational measures annex will be completed as part of each executed agreement. Questions about our security practices can be sent to [email protected].
4. Sub-processors (UK GDPR Art-28(3)(d), Art-28(2) and Art-28(4))
Controllers grant Recordme general written authorisation to engage sub-processors for the purpose of delivering the Service. The current list of all sub-processors — including their names, processing purposes, data categories, processing regions, and international transfer mechanisms — is maintained publicly at:
recordme.io/legal/sub-processors
Recordme will notify Controllers of any intended change to its sub-processor list (addition or replacement) in advance of the change taking effect. Controllers may subscribe to notifications at [email protected]. Controllers who object to a new sub-processor may raise that objection within the period specified in the executed DPA. Recordme imposes data-protection obligations on each sub-processor equivalent to those in the DPA (Art-28(4)) and remains fully liable for sub-processor performance.
5. Assistance with data subject rights (UK GDPR Art-28(3)(e))
Recordme assists the Controller to fulfil its obligations under Chapter III UK GDPR (data subject rights including access, rectification, erasure, restriction, portability, and objection) by appropriate technical and organisational means. Where a data subject submits a request directly to Recordme, we will forward it to the Controller within five working days and will not respond to the data subject on the Controller’s behalf without instruction.
6. Assistance with compliance obligations and breach notification (UK GDPR Art-28(3)(f); Arts 32–36)
Recordme assists Controllers in ensuring compliance with security (Art-32), personal data breach notification (Arts 33–34), data protection impact assessments (Art-35), and prior consultation with the ICO (Art-36).
In the event of a security incident affecting personal data processed under the DPA, Recordme will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the incident, providing all information required under Art-33(3) as soon as reasonably available. The Controller remains responsible for notifying the ICO and, where required, affected data subjects.
7. Return and deletion of data (UK GDPR Art-28(3)(g))
At the Controller’s election following termination or expiry of the contract, Recordme will delete or return all personal data processed under the DPA and delete existing copies, unless applicable law requires storage.
- Recordme will keep personal data available for export, on written request, for 90 days after termination.
- Recordme will delete personal data from live systems within 90 days of termination, subject to minimum statutory retention periods (allergen / PPDS records 2 years per Natasha’s Law, food-safety records 5 years, working-time records 2 years, legionella records 5 years, financial/payroll records 6 years).
- Written confirmation of deletion is provided on request.
8. Audit rights (UK GDPR Art-28(3)(h))
Recordme makes available to Controllers all information reasonably necessary to demonstrate compliance with this DPA and contributes to audits and inspections conducted by the Controller or a mandated auditor. Audits are subject to reasonable notice (specified in the executed DPA) and confidentiality obligations. Recordme does not yet hold third-party security certifications or independent audit reports; audit rights are currently satisfied by information provision, written responses, and inspection under the terms above. If and when independent reports (for example ISO 27001 or SOC 2 Type II) are obtained, Recordme may provide them in lieu of an on-site inspection.
9. Subject matter, duration, and data categories
The subject matter of processing is the delivery of the Recordme operations and compliance platform. Personal data categories processed may include: identity data, contact data, employment and workforce records, right-to-work documentation, health and safety data (where uploaded by the Controller), training records, operational records (temperature, allergen, audit), account and access data, and technical data. Categories of data subjects: the Controller’s employees, workers, and contractors, and — where the Controller records them — its customers, visitors, and supplier contacts. Full detail is set out in the executed DPA and the Privacy Policy.
10. International transfers
Any transfer of personal data to a third country or international organisation is made under an appropriate safeguard: UK adequacy decision (UK GDPR Art-45), UK-US Data Bridge (for DPF-certified US entities), UK International Data Transfer Agreement (IDTA), or UK Addendum to EU Standard Contractual Clauses (Art-46). Details are published on the sub-processors page.
11. Special-category data — return-to-work fitness assessments (UK GDPR Art-9(2)(b)/(h))
Where Controllers use the platform’s food-safety workforce module, Recordme processes food-handler fitness-to-work records on the Controller’s behalf. These records include gastrointestinal symptom flags, skin-condition indicators, injury markers, symptom-exclusion dates, and associated clinical notes. This data constitutes health data under UK GDPR Art-9 (special-category data).
- Lawful basis for processing: UK GDPR Art-9(2)(b) — necessary for carrying out obligations and exercising rights of the Controller or data subject in the field of employment law; and UK GDPR Art-9(2)(h) — necessary for the purposes of preventive or occupational medicine and assessment of the working capacity of the employee (Schedule 1, Data Protection Act 2018), in conjunction with the Food Safety Act 1990 and the FSA Safer Food Better Business (SFBB) food-handler fitness-to-work requirements.
- Retention: 6 years from employment end date (HMRC overlap — the most stringent applicable window per RETENTION-POLICY.md
return_to_work_recordsrow, 2190 days). - Security: records are protected by database-enforced row-level tenant isolation, changes are recorded in an append-only audit trail, and access is restricted to authorised personnel through role-based permissions.
- DPIA: a Data Protection Impact Assessment covering this Art-9 surface is maintained by the Controller per UK GDPR Art-35; Recordme provides assistance under Art-28(3)(f).
Request a signed DPA
To ask about a signed DPA for your organisation, email [email protected] with the subject line “DPA request — [your organisation name]”. Our team will respond within two business days. A signable form of the DPA will be finalised by independent legal counsel before we scale beyond our pilot phase; until then, the standard terms on this page govern platform processing.
Last reviewed: 29 July 2026, for consistency with current UK law, by Claude Fable 5 (AI) — not a solicitor. Independent solicitor review is planned before we scale beyond our pilot phase. For questions contact [email protected].