Data Processing Agreement

Last updated: May 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Black Sheep Software Ltd ("Processor") and the customer organisation ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller in connection with the Clearpath HR platform.

1. Definitions

  • "Controller" — the customer organisation that determines the purposes and means of processing personal data within Clearpath HR.
  • "Processor" — Black Sheep Software Ltd, which processes personal data on behalf of the Controller.
  • "Data Protection Law" — UK GDPR, the Data Protection Act 2018, and any successor legislation.
  • "Personal Data" — any information relating to an identified or identifiable natural person as defined under Data Protection Law.
  • "Sub-processor" — any third party engaged by the Processor to process personal data on the Processor's behalf.

2. Subject matter and duration

The Processor shall process personal data as necessary to provide the Clearpath HR platform to the Controller. Processing shall continue for the duration of the customer subscription and for 30 days thereafter (to allow for data export), at which point all personal data shall be permanently deleted.

3. Nature and purpose of processing

The Processor processes personal data to:

  • Store and display employee records on behalf of the Controller
  • Facilitate leave, absence, onboarding, training, document, and policy management
  • Send transactional emails (leave notifications, portal invitations, HR digests)
  • Maintain an audit log of actions taken within the platform
  • Provide reports and compliance summaries to HR administrators

4. Types of personal data and data subjects

The personal data processed includes:

  • Employee identity and contact data (name, email, phone, address)
  • Employment data (job title, department, start date, contract, salary/rate)
  • Leave and absence records
  • Emergency contact details
  • Training and certification records
  • Uploaded documents (including right-to-work documentation)
  • Onboarding task status
  • Platform user account credentials

Data subjects are the employees, HR administrators, and other users of the Controller's organisation who have records or accounts within the platform.

5. Obligations of the Processor

The Processor shall:

  • Process personal data only on documented instructions from the Controller, except where required by law
  • Ensure that persons authorised to process the data are bound by appropriate confidentiality obligations
  • Implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure
  • Not engage a Sub-processor without prior written authorisation from the Controller (general authorisation is given for the Sub-processors listed in clause 7)
  • Assist the Controller, insofar as reasonably possible, with data subject rights requests (access, rectification, erasure, portability, restriction, objection)
  • Notify the Controller without undue delay upon becoming aware of a personal data breach
  • Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA
  • Delete or return all personal data on termination of the agreement (unless retention is required by law)

6. Security measures

The Processor maintains the following technical and organisational measures:

  • Encryption of personal data in transit (TLS 1.2 or higher)
  • Encryption of personal data at rest (database-level encryption)
  • Role-based access controls — data is segregated by organisation; roles restrict access within organisations
  • Complete audit logging of all data access and modification events
  • Authentication controls on all platform access points
  • Regular dependency and security updates

7. Sub-processors

The Controller provides general written authorisation for the Processor to use the following Sub-processors:

Sub-processorPurposeLocation
Supabase Inc.Database, authentication, and file storageEU (Ireland)
Vercel Inc.Application hosting and content deliveryEU / UK
Resend Inc.Transactional email deliveryUS (SCCs apply)

The Processor shall notify the Controller of any intended changes to Sub-processors and allow the Controller a reasonable opportunity to object before any change takes effect.

8. International transfers

Personal data is primarily stored in the European Union (Ireland). Where data is processed by Sub-processors outside the UK or EEA (such as Resend for email delivery), the Processor ensures appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved under UK GDPR.

9. Data subject rights

The Controller is responsible for responding to data subject rights requests. The Processor will assist the Controller where technically feasible. Controllers can export employee data packs, delete individual employee records, and export all data from within the platform settings.

10. Data breach notification

In the event of a personal data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, categories and approximate number of data subjects affected, and remediation steps taken or planned.

11. Governing law

This DPA is governed by the laws of England and Wales and forms part of the Terms of Service.

12. Contact

For data protection queries, contact:
Black Sheep Software Ltd
privacy@clearpathhr.example