Skip to content
DutyHub

Legal

Data processing agreement

You are the controller of the personal data you put into DutyHub. We are your processor. This is the agreement that says so and sets the terms.

The DPA is being finalised alongside our terms of service and is not yet published. Ask at to be confirmed for the current version. If you need it reviewed before you commit to anything, that is a completely reasonable request and we would expect it.

What it will cover

  • The subject matter, duration, nature and purpose of the processing, and the categories of data and data subject — the Article 28(3) content, which you also need for your own records.
  • That we process only on your documented instructions.
  • Confidentiality obligations on our people.
  • The security measures we apply — see Security for what those are today.
  • Sub-processors, how the list is published, and how you are told before it changes.
  • Assistance with subject access requests, DPIAs and breach notification.
  • Notification to you without undue delay if we become aware of a breach affecting your data, so your own clock is not started late by us.
  • Deletion or return of your data at the end of the contract.
  • Audit and information rights.
  • International transfers and the safeguards relied on.

What you can rely on now

Some of this is product behaviour rather than contract drafting, and it exists today: records are scoped to your organisation in the query layer, retention and disposal run on schedules you configure, a person's records can be exported in full for a subject access request, and the audit trail is tamper-evident. The agreement will commit us to those; the product already does them.