Data Processing Agreement
Our UK GDPR Article 28 processing terms, written for university procurement and information governance.
Last updated: October 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer organisation ("Controller") and UniTimesheet Ltd ("Processor"), based in the United Kingdom.
It is made under Article 28 of the UK General Data Protection Regulation (UK GDPR) and sets out how the Processor processes personal data for the Controller when providing UniTimesheet. Where the Controller is established in the European Economic Area, references to UK GDPR include the EU GDPR as applicable.
2. Definitions
- Personal Data: any information relating to an identified or identifiable natural person, as defined in UK GDPR Article 4(1)
- Processing: any operation performed on personal data, including collection, storage, use, disclosure and erasure
- Sub-processor: a third party engaged by the Processor to process personal data for the Controller
- Data Subject: the natural person whose personal data is processed
- Controller: the customer organisation, which determines the purposes and means of processing
- Processor: UniTimesheet Ltd, which processes personal data on the Controller's behalf
3. Scope and Purpose
The Processor processes personal data only to provide UniTimesheet to the Controller.
Data subjects
The Controller's staff and students who have UniTimesheet accounts.
Categories of personal data
Names, email addresses, roles, contracted hours, signature images, project allocations, timesheet hours and descriptions, approval and rejection records, and absences with their dates, types and notes.
Special category data
Absence types may include sick leave and maternity or paternity leave, which are special category data under UK GDPR Article 9. They are shown only to the person and those who approve their timesheets, are kept off signed PDFs and emails, and the Controller may switch off recording them.
Duration
Processing continues for the term of the service agreement. On termination, data is handled as set out in section 10.
4. Processor Obligations
The Processor shall:
- Process personal data only on the Controller's documented instructions, unless the law requires otherwise
- Ensure everyone authorised to process the personal data is bound by confidentiality
- Implement appropriate technical and organisational measures, including AES-256-GCM encryption of personal data and free text at rest under a per-organisation key wrapped by a master key held in a dedicated secrets manager, Postgres row-level security on all organisation data, keyed-hash lookup of email addresses, and an audit log that records no personal data
- Assist the Controller with data subject requests and data protection impact assessments
- Make available all information needed to demonstrate compliance with this DPA
- Delete or return all personal data at the end of the service, as set out in section 10
- Inform the Controller at once if, in its opinion, an instruction infringes data protection law
5. Sub-processors
The Processor uses the following sub-processors to provide the service. The Controller consents to them as of the date of this DPA.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk | Sign-in and session management | Name, email address | United States |
| Neon | Database hosting | All application data | London, UK |
| Fly.io | Application server hosting | All application data | London, UK |
| Cloudflare | File storage (R2) for signed timesheet PDFs, signature images and organisation logos; scheduling of nightly jobs; hosting of this website | Signed PDFs, signature images and logos; IP address and request metadata | European Union (file storage); global edge network (website) |
| Resend | Notification emails | Recipient name and email address, and the names of staff listed in approver summaries and escalations. Emails carry no timesheet descriptions, rejection reasons or leave details | United States |
| Vercel | Hosting of the application's web interface | IP address and request metadata | Global edge network |
The Processor shall notify the Controller of any intended change to its sub-processors and give it a reasonable opportunity to object. If the Controller objects on reasonable data protection grounds, the parties will discuss it in good faith; if no resolution is reached, the Controller may end the affected service.
6. International Transfers
The database and the application servers are hosted in London and stored files in the European Union, so no international transfer applies to core application data. Transfers to providers in the United States, namely Clerk (sign-in), Resend (email), Vercel (web interface hosting) and Cloudflare (edge network), are made under the UK International Data Transfer Agreement and/or the EU Standard Contractual Clauses as applicable. The Processor reviews the adequacy of sub-processor jurisdictions regularly.
7. Data Subject Rights
The Processor shall help the Controller respond to requests under UK GDPR Chapter III, including:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
UniTimesheet has these tools built in: every user can download their own data, authorised staff can download a person's data for them, names can be corrected in the app, and erasure anonymises a person while keeping the organisation's records consistent.
8. Data Breach Notification
If a personal data breach occurs, the Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of it, with enough information for the Controller to meet its obligations under UK GDPR Articles 33 and 34.
The notification shall describe the nature of the breach, including the categories and approximate numbers of data subjects and records concerned; its likely consequences; and the measures taken or proposed to address it and limit its effects.
9. Audit Rights
The Controller may audit the Processor's compliance with this DPA. The Processor shall make available the information needed to demonstrate compliance with this DPA and UK GDPR Article 28, allow for and contribute to audits by the Controller or an auditor it mandates, and cooperate reasonably.
Audits may be requested no more than once in any 12 months, with at least 30 days' written notice, during normal business hours and without unreasonably disrupting the Processor's operations. The Controller bears the cost of any third-party auditor.
10. Data Retention and Deletion
- When the Controller deletes a person, their personal data is erased after a delay the Controller sets, 90 days by default and never less than 30: name and email become placeholders, the signature image is deleted, descriptions, rejection reasons and leave notes are cleared, and special category leave types become a generic type
- Signed timesheet PDFs and audit logs are kept for the Controller's record retention period, 7 years by default, and then deleted
- At the end of the service the Controller exports its data, and everything it held, including stored files and its encryption keys, is permanently deleted 30 days after its account is removed
- Database backups are kept for at most 7 days for disaster recovery
The Controller may ask for written confirmation of deletion, which the Processor shall provide.
11. Controller Obligations
The Controller warrants that:
- It has a lawful basis under UK GDPR, or EU GDPR where applicable, for all personal data it puts into UniTimesheet, including any special category leave types
- It has given appropriate notice to the data subjects whose personal data is processed
- Its instructions to the Processor comply with data protection law
12. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law where the law does not allow it to be limited.
13. Term and Termination
This DPA takes effect when the Controller begins using UniTimesheet and continues for as long as the Processor processes personal data for it. It ends with the service agreement, subject to section 10.
14. Contact
Questions about this DPA: [email protected].
The Controller may also contact the Information Commissioner's Office (ICO) for guidance on data protection.