Data Processing Agreement (DPA)

Last updated: 3 August 2025

This Data Processing Agreement forms part of the Terms of Service between Allocate Now (the "Processor") and the subscribing organisation (the "Controller"). It governs the processing of personal data in accordance with GDPR (EU) 2016/679.

1. Definitions

  • "Controller" means the organisation that subscribes to Allocate Now and determines the purposes and means of processing personal data.
  • "Processor" means Allocate Now, which processes personal data on behalf of the Controller.
  • "Sub-processor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1).
  • "Processing" means any operation performed on personal data as defined in GDPR Article 4(2).
  • "Data Subject" means the identified or identifiable natural person to whom the personal data relates.

2. Scope and Purpose of Processing

The Processor processes personal data solely for the purpose of providing the Allocate Now resource planning service to the Controller, including:

  • Storing and displaying resource profiles (names, skills, roles, availability)
  • Managing project allocations and capacity planning data
  • Generating reports and analytics based on allocation data
  • Managing user accounts and access permissions within the organisation
  • Processing subscription payments and generating invoices

3. Categories of Data Subjects and Personal Data

Data Subject Category Types of Personal Data
Platform Users Name, email address, password (hashed), role, login timestamps
Resources (employees/contractors) Full name, job title, skills, availability, allocation data, resource type (internal/external), daily rate
Billing Contacts Company name, billing email, address, VAT number

4. Obligations of the Processor

The Processor shall:

  • 4.1 Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
  • 4.2 Ensure that persons authorised to process personal data have committed themselves to confidentiality.
  • 4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR).
  • 4.4 Not engage another processor (sub-processor) without prior written authorisation of the Controller.
  • 4.5 Assist the Controller in responding to data subject requests (access, rectification, erasure, portability).
  • 4.6 Assist the Controller in ensuring compliance with obligations under Articles 32–36 GDPR (security, breach notification, DPIA).
  • 4.7 Delete or return all personal data at the end of the service provision, unless EU or Member State law requires storage.
  • 4.8 Make available all information necessary to demonstrate compliance and allow for audits.

5. Technical and Organisational Measures

The Processor implements the following security measures:

Measure Implementation
Encryption in transit TLS 1.2+ for all data transmission
Encryption at rest AES-256 encryption on database and storage (AWS RDS, S3)
Access control Role-based access control (RBAC), multi-tenant isolation
Authentication Secure password hashing (bcrypt), session management with JWT
Data isolation Organisation-level data segregation; each tenant can only access their own data
Backups Automated daily encrypted backups with point-in-time recovery
Infrastructure AWS EU (eu-north-1) with VPC isolation, security groups, and monitoring

6. Sub-processors

The Controller authorises the use of the following sub-processors:

Sub-processor Purpose Location Safeguards
Amazon Web Services (AWS) Infrastructure, database, storage EU (Stockholm) AWS DPA, ISO 27001
Stripe, Inc. Payment processing EU/US EU SCCs, PCI DSS Level 1
Zoho Corporation Email service EU Zoho DPA, ISO 27001

The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object within 14 days.

7. Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach. The notification shall include:

  • A description of the nature of the breach, including categories and approximate number of data subjects affected
  • The name and contact details of the data protection point of contact
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach

8. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligation to respond to data subject requests under GDPR Articles 15–22. The Processor provides the following capabilities:

  • Access: Export of all personal data associated with a data subject
  • Rectification: Ability to update resource profiles and user accounts
  • Erasure: Deletion of individual resources, users, or entire organisations
  • Portability: Data export in structured, machine-readable format (CSV/JSON)
  • Restriction: Ability to deactivate resources or user accounts without deletion

9. International Transfers

The Processor's primary infrastructure is located within the EU (AWS eu-north-1, Stockholm). Where personal data is transferred to sub-processors outside the EEA, the Processor ensures that appropriate safeguards are in place in accordance with GDPR Chapter V, including EU Standard Contractual Clauses (SCCs) and relevant adequacy decisions.

10. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA. Audits shall be conducted with reasonable notice (minimum 30 days), during normal business hours, and no more than once per year unless a data breach has occurred. The Controller shall bear the costs of any audit.

11. Duration and Termination

This DPA remains in effect for the duration of the service agreement. Upon termination of the service:

  • The Processor shall delete all personal data within 30 days, unless retention is required by law.
  • The Controller may request a copy of their data in a structured format before deletion.
  • The Processor shall provide written confirmation of deletion upon request.

12. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor shall be liable for damages caused by processing that does not comply with the GDPR or with the Controller's lawful instructions.

13. Governing Law

This DPA is governed by the same law that governs the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

14. Contact

For questions about this DPA or to exercise rights under this agreement:

Allocate Now — Data Protection

Email: support@allocate-now.com