Data Processing Agreement
Last updated: May 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Black Sheep Software Ltd ("Processor") and the customer organisation ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller in connection with the Clearpath HR platform.
1. Definitions
- "Controller" — the customer organisation that determines the purposes and means of processing personal data within Clearpath HR.
- "Processor" — Black Sheep Software Ltd, which processes personal data on behalf of the Controller.
- "Data Protection Law" — UK GDPR, the Data Protection Act 2018, and any successor legislation.
- "Personal Data" — any information relating to an identified or identifiable natural person as defined under Data Protection Law.
- "Sub-processor" — any third party engaged by the Processor to process personal data on the Processor's behalf.
2. Subject matter and duration
The Processor shall process personal data as necessary to provide the Clearpath HR platform to the Controller. Processing shall continue for the duration of the customer subscription and for 30 days thereafter (to allow for data export), at which point all personal data shall be permanently deleted.
3. Nature and purpose of processing
The Processor processes personal data to:
- Store and display employee records on behalf of the Controller
- Facilitate leave, absence, onboarding, training, document, and policy management
- Send transactional emails (leave notifications, portal invitations, HR digests)
- Maintain an audit log of actions taken within the platform
- Provide reports and compliance summaries to HR administrators
4. Types of personal data and data subjects
The personal data processed includes:
- Employee identity and contact data (name, email, phone, address)
- Employment data (job title, department, start date, contract, salary/rate)
- Leave and absence records
- Emergency contact details
- Training and certification records
- Uploaded documents (including right-to-work documentation)
- Onboarding task status
- Platform user account credentials
Data subjects are the employees, HR administrators, and other users of the Controller's organisation who have records or accounts within the platform.
5. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, except where required by law
- Ensure that persons authorised to process the data are bound by appropriate confidentiality obligations
- Implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure
- Not engage a Sub-processor without prior written authorisation from the Controller (general authorisation is given for the Sub-processors listed in clause 7)
- Assist the Controller, insofar as reasonably possible, with data subject rights requests (access, rectification, erasure, portability, restriction, objection)
- Notify the Controller without undue delay upon becoming aware of a personal data breach
- Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA
- Delete or return all personal data on termination of the agreement (unless retention is required by law)
6. Security measures
The Processor maintains the following technical and organisational measures:
- Encryption of personal data in transit (TLS 1.2 or higher)
- Encryption of personal data at rest (database-level encryption)
- Role-based access controls — data is segregated by organisation; roles restrict access within organisations
- Complete audit logging of all data access and modification events
- Authentication controls on all platform access points
- Regular dependency and security updates
7. Sub-processors
The Controller provides general written authorisation for the Processor to use the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, and file storage | EU (Ireland) |
| Vercel Inc. | Application hosting and content delivery | EU / UK |
| Resend Inc. | Transactional email delivery | US (SCCs apply) |
The Processor shall notify the Controller of any intended changes to Sub-processors and allow the Controller a reasonable opportunity to object before any change takes effect.
8. International transfers
Personal data is primarily stored in the European Union (Ireland). Where data is processed by Sub-processors outside the UK or EEA (such as Resend for email delivery), the Processor ensures appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved under UK GDPR.
9. Data subject rights
The Controller is responsible for responding to data subject rights requests. The Processor will assist the Controller where technically feasible. Controllers can export employee data packs, delete individual employee records, and export all data from within the platform settings.
10. Data breach notification
In the event of a personal data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, categories and approximate number of data subjects affected, and remediation steps taken or planned.
11. Governing law
This DPA is governed by the laws of England and Wales and forms part of the Terms of Service.
12. Contact
For data protection queries, contact:
Black Sheep Software Ltd
privacy@clearpathhr.example