StarterLegal

← All legal documents

Data Processing Addendum

Controller–Processor Terms — Version 1.0 — Effective 3 October 2026

Status

This Data Processing Addendum (“DPA”) is incorporated into the FlexiStarter Business Terms whenever FLEXIWORK LTD processes personal data on behalf of a Customer as a processor.

1. Roles and scope

For personal data submitted to FlexiStarter by or for a Customer in connection with the Customer’s workforce onboarding, the Customer is the Controller and FLEXIWORK LTD is the Processor, unless the parties expressly agree otherwise or applicable law determines a different role.

For certain information processed for FLEXIWORK LTD’s own purposes, such as business-user account administration, service security, billing, fraud prevention and legal compliance, FLEXIWORK LTD may act as an independent Controller. That processing is described in the Business User Privacy Notice and is outside the processor-only scope of this DPA.

2. Processing instructions

We will process Controller Personal Data only on documented instructions from the Customer, including the instructions contained in the Business Terms, this DPA, the Customer’s configuration and use of the Service, and any additional lawful written instructions we accept.

If we believe an instruction infringes applicable data protection law, we will inform the Customer unless prohibited by law. If we are legally required to process Controller Personal Data other than on the Customer’s instructions, we will inform the Customer before doing so unless the law prohibits that notice.

3. Processing details

Item

Details

Subject matter

Provision of the FlexiStarter employee/candidate onboarding service and related support.

Duration

For the term of the Customer’s use of the Service and any limited post-termination period needed to return, export, secure or delete data.

Nature of processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, transmission, generation, formatting, matching, access, restriction, deletion and other operations necessary to provide the configured onboarding workflow.

Purpose

To provide offers, contracts, e-signatures, onboarding forms, notices and acknowledgements, checks/evidence workflows, references, candidate communications, first-day preparation, readiness tracking, support and related administration on the Customer’s instructions.

Data subjects

Candidates, workers, employees, former candidates where retained by the Customer, referees, emergency contacts and authorised Customer users.

Personal data

Identity and contact details; employment/offer information; role, pay, hours, start date and work location; contract and policy records; signature/audit information; right-to-work and evidence documents; references; emergency contact details; bank/payroll/tax onboarding details where configured; communications; support requests; technical identifiers and access records.

Special category data

Where the Customer chooses to collect it: health, disability/access needs, workplace adjustments, equality-monitoring data and other special category information configured by the Customer.

Criminal offence data

Where lawfully configured by the Customer: declarations or evidence relating to criminal convictions/offences or related checks.

4. Customer obligations

The Customer is responsible for ensuring that its instructions and use of the Service comply with applicable data protection and employment law. This includes identifying an Article 6 lawful basis and, where applicable, an Article 9 condition or lawful basis for criminal offence data under Article 10 and the Data Protection Act 2018. Where an Appropriate Policy Document or other safeguard is legally required, the Customer is responsible for having it in place.

The Customer must configure access permissions appropriately and must not instruct us to collect information that is unnecessary, excessive or unlawful for the relevant onboarding purpose.

5. Confidentiality

We will ensure that personnel authorised to process Controller Personal Data are subject to appropriate confidentiality obligations and access it only where necessary for their role.

6. Security

We will maintain technical and organisational measures appropriate to the risk, taking into account the state of the art, costs of implementation, nature and scope of processing, and risks to individuals. Measures may include:

  • role-based access controls and least-privilege access;
  • authentication and secure session handling;
  • encrypted transport and provider-managed encryption at rest where available;
  • environment and secret-management controls;
  • logging, monitoring and incident-response procedures;
  • controlled storage and signed-access mechanisms for private documents where appropriate;
  • backup and resilience controls provided by our infrastructure providers; and
  • periodic testing and review of relevant security controls.

7. Sub-processors

The Customer gives general written authorisation for us to use sub-processors to provide the Service. Our current material sub-processors are listed in the Material Sub-processors document. We will require sub-processors to protect personal data under written terms that provide materially equivalent data protection obligations appropriate to the services they perform.

Where reasonably practicable, we will provide notice of a material new sub-processor before it begins processing Controller Personal Data. A Customer with a legitimate data-protection objection may contact us promptly. The parties will work in good faith to address the concern; if no reasonable solution is available, either party may terminate the affected Service in accordance with the Business Terms.

8. International transfers

Where Controller Personal Data is transferred outside the United Kingdom to a country that does not benefit from an applicable UK adequacy regulation, we will use an appropriate lawful transfer mechanism and safeguards required by UK data protection law, such as the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another valid mechanism.

9. Data subject rights

Taking into account the nature of processing, we will provide reasonable assistance to the Customer through appropriate technical and organisational measures to help the Customer respond to requests to exercise data-protection rights. If we receive a request relating primarily to Controller Personal Data, we may direct the individual to the Customer and will not respond substantively on the Customer’s behalf unless instructed or legally required.

10. Assistance and compliance

Taking into account the nature of processing and information available to us, we will provide reasonable assistance with the Customer’s obligations relating to security, personal data breaches, data protection impact assessments and prior consultation with supervisory authorities where those obligations relate to our processing under this DPA.

11. Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Controller Personal Data where notification is required under applicable law. We will provide information reasonably available to us to help the Customer assess and meet its notification obligations. Notification is not an admission of fault or liability.

12. Return and deletion

At the end of the Services, and subject to available product functionality, the Customer may export or retrieve Customer Content before termination. On termination or written instruction, we will delete or return Controller Personal Data as required by Article 28, unless applicable law requires continued storage. Residual copies may remain temporarily in protected backups until overwritten in the ordinary course, and will remain protected and unavailable for ordinary business use.

13. Audits and information

We will make available information reasonably necessary to demonstrate compliance with our processor obligations. Where that information is insufficient, the Customer may request a reasonable audit, no more than once annually unless required by a regulator or following a material incident. Audits must protect other customers, security and confidential information, and may be satisfied through independent reports or remote evidence where appropriate.

14. Liability and precedence

Liability under this DPA is subject to the liability provisions in the Business Terms unless applicable law requires otherwise. If this DPA conflicts with the Business Terms on processing of Controller Personal Data, this DPA prevails to the extent of the conflict.

FlexiStarter is provided by FLEXIWORK LTD · Company number 17116161 · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

Business TermsPrivacyCandidate privacyCookiesAll legal