1. Scope and roles.
The customer is controller of personal data it supplies for workplace administration; Operations OS Ltd is its processor for that processing. The subject is the customer's workforce service for the contract duration and the instructed return/deletion period. Operations OS's separately determined account, Network, billing and security purposes are described in the privacy notice and are not converted into processor activities by this addendum.
2. Processing details.
Hosting, storing, displaying, transmitting, organising, calculating, exporting and deleting records support workplace access, agreements, availability, shifts, clocking, reviewed hours, leave, messages and selected plan features. Data subjects include owners, administrators, workers, contractors and people named in workplace communications. Data includes identifiers/contact details, roles, agreements/rates, work availability, shifts, clock records, hours/amounts, leave, messages/attachments and optional clock-location evidence. The customer must not introduce unnecessary special-category data or criminal-offence records; discuss any intended requirement before use.
3. Instructions and customer obligations.
Process only on documented customer instructions, including the accepted order, settings and authorised use of features, unless UK law requires otherwise. Inform the customer before legally required processing unless prohibited. Notify the customer if an instruction appears to infringe data-protection law. The customer must establish lawful purposes and bases, give necessary notices, authorise users, and provide lawful instructions. A new use or transfer outside this scope needs documented instructions and appropriate safeguards.
4. Confidentiality and security.
Persons allowed to process customer data must be bound to confidentiality. Apply appropriate technical and organisational measures under Article 32, including controlled access, secure communications, protected credentials, recoverability and regular assessment proportionate to risks. The security schedule must accurately identify measures used; it does not claim a certification or guaranteed immunity from incidents.
5. Subprocessors.
The customer generally authorises the providers identified in the applicable workplace processing schedule. Maintain equivalent Article 28 obligations with subprocessors and remain responsible for their performance of those obligations. Notify intended additions or replacements before they process customer data and allow a reasonable opportunity to object on data-protection grounds. Resolve an objection before the change affects that customer, including an alternative or ending affected processing if necessary. The schedule must distinguish processors from independent controllers rather than describing every integration as a subprocessor.
6. Transfers.
Do not make restricted international transfers without an applicable legal mechanism and documented instructions. Identify relevant provider processing locations and safeguards in the schedule. A London primary database does not mean that every provider processes only in the UK.
7. Rights and assistance.
Taking account of processing and available information, assist the customer with individual rights, security obligations, breach notifications, required impact assessments and regulator consultation. Refer requests about customer-controlled records to the customer, unless authorised or legally required to respond directly. Notify the customer without undue delay after becoming aware of a personal-data breach affecting its data, supplying available details and updates to support its legal duties. Do not wait for a complete investigation before notifying.
8. End of processing.
At the customer's choice return or securely delete its personal data and delete copies, unless UK law requires retention. Restrict any lawful retained data to that purpose. Protected backup copies must be put beyond ordinary use and removed through the documented backup lifecycle; restoration must reapply prior deletion instructions. Set out the actual timetable and process in the schedule, not an invented immediate-erasure promise.
9. Demonstration and audits.
Make information needed to demonstrate Article 28 compliance available and allow/contribute to customer or appointed-auditor audits and inspections. Agree practical arrangements that protect other customers and service security, without removing the audit right. Maintain records appropriate to processing obligations.
Workplace processing schedule · Company service terms · Data-processing addendum · Privacy notice · App content terms