Data Processing Agreement
Last updated 3 September 2026.
This Data Processing Agreement ("DPA") forms part of the agreement between your Company ("Controller") and MadyHR.ai ("Processor") for the personal data of employees, candidates and other individuals your Company enters into the Service. It reflects the requirements of UK GDPR Article 28.
1. Roles
Your Company is the data controller for the personal data it enters — it decides what data to collect and why. MadyHR.ai is the data processor — we process that data only on your Company's documented instructions, given through your use of the Service.
2. Subject matter and duration
Processing covers employee, candidate and — where used — sponsored-worker records (identity, contact, employment, leave and attendance, documents, and Right to Work evidence) for as long as your Company's account is active, plus the retention period described in our Privacy Policy.
3. Sub-processors
We use the following categories of sub-processor: a payment processor (Stripe), a hosting provider (application and PostgreSQL database hosting), an object-storage provider for documents, and AI model providers for the Ask MadyHR and public chat features. We'll give reasonable notice before adding a new sub-processor that changes how your Company's data is handled.
4. Security measures
Company-scoped access control enforced at both the application and database layers; encryption of sensitive fields (National Insurance number, passport number, bank details) at the application layer, in addition to encryption at rest; masked display of sensitive fields until deliberately revealed; malware scanning and type/size checks on document uploads; an append-only audit log for sensitive changes; and signed, short-lived URLs for document downloads rather than permanent public links. Full detail: our security page.
5. Assistance with data subject requests
Where an individual exercises a data subject right (access, correction, erasure) directly against your Company, we'll provide reasonable assistance, including tools within the Service to view, correct and — subject to legal retention requirements — erase records.
6. International transfers
Where a sub-processor handles data outside the UK, we rely on an appropriate transfer mechanism (such as the UK International Data Transfer Addendum) to keep that transfer compliant with UK GDPR.
7. Breach notification
We'll notify your Company without undue delay after becoming aware of a personal data breach affecting your Company's data, with enough detail to let you meet your own notification obligations.
8. Deletion on termination
On termination of your Company's account, we'll delete or return your Company's data within a reasonable period, except where we're required to retain it by law.
Contact
Questions about this agreement or a request for a signed copy: support@madyhr.ai.
