Data Processing Agreement (DPA)
Last updated: 3 August 2025
This Data Processing Agreement forms part of the Terms of Service between Allocate Now (the "Processor") and the subscribing organisation (the "Controller"). It governs the processing of personal data in accordance with GDPR (EU) 2016/679.
1. Definitions
- "Controller" means the organisation that subscribes to Allocate Now and determines the purposes and means of processing personal data.
- "Processor" means Allocate Now, which processes personal data on behalf of the Controller.
- "Sub-processor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1).
- "Processing" means any operation performed on personal data as defined in GDPR Article 4(2).
- "Data Subject" means the identified or identifiable natural person to whom the personal data relates.
2. Scope and Purpose of Processing
The Processor processes personal data solely for the purpose of providing the Allocate Now resource planning service to the Controller, including:
- Storing and displaying resource profiles (names, skills, roles, availability)
- Managing project allocations and capacity planning data
- Generating reports and analytics based on allocation data
- Managing user accounts and access permissions within the organisation
- Processing subscription payments and generating invoices
3. Categories of Data Subjects and Personal Data
| Data Subject Category | Types of Personal Data |
|---|---|
| Platform Users | Name, email address, password (hashed), role, login timestamps |
| Resources (employees/contractors) | Full name, job title, skills, availability, allocation data, resource type (internal/external), daily rate |
| Billing Contacts | Company name, billing email, address, VAT number |
4. Obligations of the Processor
The Processor shall:
- 4.1 Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
- 4.2 Ensure that persons authorised to process personal data have committed themselves to confidentiality.
- 4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR).
- 4.4 Not engage another processor (sub-processor) without prior written authorisation of the Controller.
- 4.5 Assist the Controller in responding to data subject requests (access, rectification, erasure, portability).
- 4.6 Assist the Controller in ensuring compliance with obligations under Articles 32–36 GDPR (security, breach notification, DPIA).
- 4.7 Delete or return all personal data at the end of the service provision, unless EU or Member State law requires storage.
- 4.8 Make available all information necessary to demonstrate compliance and allow for audits.
5. Technical and Organisational Measures
The Processor implements the following security measures:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all data transmission |
| Encryption at rest | AES-256 encryption on database and storage (AWS RDS, S3) |
| Access control | Role-based access control (RBAC), multi-tenant isolation |
| Authentication | Secure password hashing (bcrypt), session management with JWT |
| Data isolation | Organisation-level data segregation; each tenant can only access their own data |
| Backups | Automated daily encrypted backups with point-in-time recovery |
| Infrastructure | AWS EU (eu-north-1) with VPC isolation, security groups, and monitoring |
6. Sub-processors
The Controller authorises the use of the following sub-processors:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, database, storage | EU (Stockholm) | AWS DPA, ISO 27001 |
| Stripe, Inc. | Payment processing | EU/US | EU SCCs, PCI DSS Level 1 |
| Zoho Corporation | Email service | EU | Zoho DPA, ISO 27001 |
The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object within 14 days.
7. Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach. The notification shall include:
- A description of the nature of the breach, including categories and approximate number of data subjects affected
- The name and contact details of the data protection point of contact
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
8. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligation to respond to data subject requests under GDPR Articles 15–22. The Processor provides the following capabilities:
- Access: Export of all personal data associated with a data subject
- Rectification: Ability to update resource profiles and user accounts
- Erasure: Deletion of individual resources, users, or entire organisations
- Portability: Data export in structured, machine-readable format (CSV/JSON)
- Restriction: Ability to deactivate resources or user accounts without deletion
9. International Transfers
The Processor's primary infrastructure is located within the EU (AWS eu-north-1, Stockholm). Where personal data is transferred to sub-processors outside the EEA, the Processor ensures that appropriate safeguards are in place in accordance with GDPR Chapter V, including EU Standard Contractual Clauses (SCCs) and relevant adequacy decisions.
10. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. Audits shall be conducted with reasonable notice (minimum 30 days), during normal business hours, and no more than once per year unless a data breach has occurred. The Controller shall bear the costs of any audit.
11. Duration and Termination
This DPA remains in effect for the duration of the service agreement. Upon termination of the service:
- The Processor shall delete all personal data within 30 days, unless retention is required by law.
- The Controller may request a copy of their data in a structured format before deletion.
- The Processor shall provide written confirmation of deletion upon request.
12. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor shall be liable for damages caused by processing that does not comply with the GDPR or with the Controller's lawful instructions.
13. Governing Law
This DPA is governed by the same law that governs the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.
14. Contact
For questions about this DPA or to exercise rights under this agreement:
Allocate Now — Data Protection
Email: support@allocate-now.com