Data processing addendum
Version 2026-10-06.1 · Prepared 6 October 2026
Parties, scope and instructions
This proposed addendum applies when UnionRelay operator — details awaiting completion processes customer-controlled personal data under an accepted service contract. Processing consists of storage, retrieval, research, drafting, communication and reporting during the service and agreed deletion period. The order identifies the controller and authorised instructions. Data may concern users, clients, professional contacts, candidates and applicants, with the fields described in the privacy notice. Special-category data is excluded unless separately agreed.
Processor commitments
Process only documented lawful instructions, including transfers, unless law requires otherwise. Warn the controller of an apparently unlawful instruction. Bind authorised personnel to confidentiality. Apply appropriate technical and organisational protection. Assist reasonably with rights requests, security obligations, breach response and impact assessments. Notify the controller of a personal-data breach without undue delay, with available facts and subsequent updates. These promises require operating procedures as well as software.
Providers, evidence and exit
Use authorised subprocessors under equivalent protective obligations. Maintain an actual register, give notice of material changes and a reasonable opportunity to object before a new subprocessor handles customer data. Provide compliance information and permit proportionate audits without overriding statutory inspection rights. At the controller’s choice, return or delete data after the service, except lawful retention, and apply the agreed backup-expiry schedule. The processor remains responsible for its subprocessor obligations.
Processing schedule and security
The client workspace and written brief define purposes and scope. Hosting and providers are listed in the register. Controls in the supplied build include hashed passwords, scoped permissions, encrypted saved provider secrets, approval history and queued-job records. The deployment must additionally operate secure transport, host access control, updates, backups, recovery, retention and incident handling. This description is not an ISO certification or independent security assurance. Retention: must be agreed and configured before live processing.
Related policies: Privacy · Terms · Cookies · Contact and complaints