Skip to content

Data Processing Agreement

How LinkSync handles personal information on behalf of each organisation that uses it. It meets the requirements of Article 28 of the UK GDPR and forms part of the Customer Agreement.

Drafted for review by a solicitor; not yet in force.

Last updated [date] · Version [version]

Summary

This summary is not part of the agreement; the clauses below are.

  • You (the organisation) are the controller of your visit records and the information about your staff and the people at the places you visit. We are your processor: we act only on your instructions.
  • We are a controller in our own right for a few things we need to run LinkSync safely for everyone: each person’s sign-in details and registered phone, our own security records, and the platform-wide verification rules. Section 3 explains this.
  • All personal information is stored in the UK. One step of the face check is processed in the European Economic Area, which UK law recognises as adequate. We tell you before anything else changes.
  • Only people who need to see your information can, and only for that purpose. Within LinkSync, access is limited to the staff who need it to run and support the Service, and every look is logged. [How you approve support access, once that is built.]
  • We use a small number of sub-processors, listed by category on our Sub-processors page. We give you [30] days’ notice of any change, and you can object.
  • We tell you about a personal data breach without undue delay, and in any case within [24] hours of becoming aware of it.
  • When the contract ends, [LinkSync exports your information for you on request, then deletes it within [30] days and confirms in writing].

1. Scope and how this works

  1. 1.1 This Data Processing Agreement (“DPA”) is between [Company name] (“LinkSync”, “we”) and the customer named in the Order (“you”). It applies whenever we process Customer Personal Data in providing the Service.
  2. 1.2 This DPA forms part of the Customer Agreement. Words defined in the Customer Agreement have the same meaning here. If this DPA and the rest of the Customer Agreement conflict about personal data, this DPA wins.
  3. 1.3 This DPA sets out the terms required by Article 28(3) of the UK GDPR. Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.

2. Definitions

Customer Personal Data
Personal data within Customer Data that we process on your behalf as your processor.
Data Protection Law
As defined in the Customer Agreement.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
Sub-processor
Any third party we engage that processes Customer Personal Data on our behalf.
Controller, processor, data subject, personal data, processing, special category data
Have the meanings given in the UK GDPR.

3. Roles of the parties

  1. 3.1 You are the controller of Customer Personal Data. You decide why it is processed (for example, to prove visits happened, keep people safe, evidence work you are paid or funded for and prevent fraud) and you make the decisions that matter about it: who is invited, where GeoSyncs are fitted, which visits are planned, whether to use face checks, how long records are kept within the ranges we allow, who sees them, how flagged visits are reviewed, and what you do with the results.
  2. 3.2 We are your processor for Customer Personal Data, and process it only to provide the Service.
  3. 3.3 We are an independent controller for the limited processing described in Annex 5, which we carry out for our own purposes of running a secure, consistent service for all customers. That processing is covered by our privacy notice, not by this DPA’s processor terms. In summary, it covers:
    • each person’s sign-in identity and their one registered phone, which apply across every organisation they work for;
    • our own security, fraud-prevention and audit records about the Service;
    • setting and maintaining the Verification Rules, and monitoring how the checks perform across all customers, using information that does not identify individuals wherever possible;
    • business contact, account and billing information about you and your staff who deal with us.
  4. 3.4 Verification Rules. We set the same Verification Rules for every customer (Customer Agreement clause 5). The parties agree that in doing so we decide technical and organisational means of the processing, for consistency and integrity of evidence, and that you remain the controller who decides whether to use the Service and its results, for which purposes, and with what consequences for individuals.
  5. 3.5 No joint control intended. The parties do not intend to be joint controllers of any personal data. If a court or the Information Commissioner decides that we are joint controllers of any processing, the parties will promptly agree an arrangement under Article 26 of the UK GDPR. Until then, and as a basis for that arrangement: (a) you will provide privacy information to your staff and Occupants about visit records; (b) we will provide privacy information about the processing in Annex 5; (c) requests from individuals will be handled by the party that receives them, with help from the other, as set out in clause 10; and (d) each party remains responsible for its own compliance.

Note for the solicitor: LinkSync sets platform-wide verification rules and thresholds that determine the result shown for each visit, operates a cross-customer registry of people and phones, and monitors face check performance across customers. Please advise whether any of this makes LinkSync a joint controller with each customer (in particular for the verification outcome and face check processing), or an independent controller, rather than a processor, and whether an Article 26 arrangement should be put in place now rather than as a fallback. Clauses 3.3 to 3.5 and Annex 5 reflect our current position, not a settled view.

4. Processing on your instructions

  1. 4.1 We will process Customer Personal Data only on your documented instructions, including about transfers outside the UK, unless the law requires otherwise. In that case we will tell you before processing, unless the law forbids it on important grounds of public interest.
  2. 4.2 Your instructions are: this DPA and the Customer Agreement; the settings you and your Users choose in the Service; and any other written instructions you give us that are consistent with the Customer Agreement. Instructions that would change the Service or the Fees need to be agreed under the Customer Agreement.
  3. 4.3 We will tell you straight away if, in our opinion, an instruction breaks Data Protection Law. We may suspend acting on it until you confirm or change it.
  4. 4.4 We will not: sell Customer Personal Data; use it for advertising or marketing; use it to profile anyone for any other organisation; combine it with data from other customers except as needed for the cross-customer checks in Annex 5; or use it to train systems for anyone else.

5. Your duties as controller

  1. 5.1 You are responsible for: having a lawful basis and any condition for special category data; providing privacy information to your staff and Occupants; carrying out a data protection impact assessment; deciding retention periods; and making sure your instructions comply with Data Protection Law.
  2. 5.2 Before face checks are switched on, you must have recorded the sign-off set out in clause 7.6 of the Customer Agreement, including your appropriate policy document for processing biometric data without consent.
  3. 5.3 You must record each Occupant’s agreement, or a lawful decision on their behalf, before a GeoSync is fitted at a Place where they live. That agreement is permission to place the GeoSync; it is not your lawful basis for processing their information.
  4. 5.4 You must not put special category data, notes about people or other information the Service does not need into it, except in fields designed for it.

6. Confidentiality of our people

  1. 6.1 We will make sure everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, has been trained in data protection and security, and only has access to what their role needs.
  2. 6.2 Access to Customer Personal Data within LinkSync is limited to the staff who need it to run, support and secure the Service, and every action they take in the Service is logged. [Before launch: support staff see Customer Personal Data only through time-limited access you approve in the Service, recorded in your audit trail, except in an urgent security incident, which is logged in the same way and reported to you as soon as we can.]
  3. 6.3 Our staff who approve GeoSync installations see only what they need to decide, not who lives at the Place, and every look is recorded in your audit trail.

7. Security

  1. 7.1 We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, and the risks to individuals, as required by Article 32 of the UK GDPR. The measures are described in Annex 2.
  2. 7.2 We may update the measures over time, but we will not materially reduce the overall level of protection they give.

8. Sub-processors

  1. 8.1 You give us general authorisation to engage Sub-processors. Our current Sub-processors are listed on our Sub-processors page and in Annex 3. [The full list, with names, is provided to you with your Order and on request.]
  2. 8.2 Before a new Sub-processor starts processing Customer Personal Data, or before we change what an existing one does in a way that matters, we will give you at least [30] days’ notice by email to your administrators and on our Sub-processors page.
  3. 8.3 You may object on reasonable data protection grounds within that notice period. If you do, we will discuss your concerns in good faith and try to find a solution, such as not using that Sub-processor for your data. If we can’t, you may end the affected part of the Service by written notice before the change takes effect, and we will refund prepaid Fees for the period after it ends.
  4. 8.4 In an emergency, for example where a Sub-processor fails and we must replace it to keep the Service running, we may make a change with shorter notice. We will tell you as soon as we can, and your right to object still applies.
  5. 8.5 We will carry out appropriate checks on each Sub-processor, and impose on it by written contract data protection obligations that give at least the same protection as this DPA. We remain fully responsible to you for each Sub-processor’s performance.

9. Where data is kept and international transfers

  1. 9.1 We store Customer Personal Data in the UK, including backups.
  2. 9.2 We will not transfer Customer Personal Data outside the UK, or allow a Sub-processor to, except as described in Annex 4, or with your prior written agreement. Any transfer will meet the requirements of Chapter V of the UK GDPR.
  3. 9.3 We will tell you in advance, under clause 8.2, of any change that would introduce a new transfer outside the UK.

10. Helping with people’s rights

  1. 10.1 Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures, to respond to requests from individuals exercising their rights under Data Protection Law, including access, rectification, erasure, restriction, objection, portability and rights about automated decision-making.
  2. 10.2 The Service lets your Data Protection Lead find a person and download the records about them, including their visit records, check results, review outcomes and audit trail, keep a log of the requests you receive, and place legal holds, so that you can answer most requests yourself.
  3. 10.3 Where you need more help, we will provide it within [5] Working Days of your request, or sooner where a deadline requires it.
  4. 10.4 If we receive a request directly about Customer Personal Data, we will pass it to you without undue delay, and will not respond ourselves except to confirm we have passed it on, unless you ask us to.
  5. 10.5 Visit records and other evidence in the Service are append-only and cannot be altered. Where a request asks for a correction, you may record your decision about a flagged visit, and may keep the person’s statement alongside your own records. [Solicitor to confirm whether this meets the right to rectification, including the option of a supplementary statement, without the Service storing one.]
  6. 10.6 Where a request asks for erasure of evidence you still need, or restriction, you decide whether an exemption or another lawful reason to keep it applies. Where erasure is required, we will delete the data from the Service at your written instruction, even if it is evidence. This is done by LinkSync on request; the Service does not delete it by itself.

11. Other help we give you

  1. 11.1 Taking into account the information available to us, we will help you meet your duties under Articles 32 to 36 of the UK GDPR: security, breach notification, data protection impact assessments, and prior consultation with the Information Commissioner.
  2. 11.2 In particular, we provide the LinkSync Policy Pack, which includes template policies, a model data protection impact assessment and a retention schedule, and we will answer reasonable questions about how the Service works to help you complete your own.
  3. 11.3 Reasonable help is included in the Fees. Where a request needs significant extra work beyond what the Service and the Policy Pack provide, we may charge reasonable costs, agreed in advance, unless the request arises from our breach.

12. Personal data breaches

  1. 12.1 We will tell you about a Personal Data Breach without undue delay, and in any case within [24] hours of becoming aware of it, by email to your administrators and data protection lead and, for serious breaches, by phone.
  2. 12.2 Our notice will include, as far as we know at the time: what happened; the categories and approximate number of people and records affected; the likely consequences; what we have done and propose to do to deal with it and reduce its effects; and a contact for more information. If we don’t have all of this at first, we will provide it in stages, without undue delay.
  3. 12.3 We will take reasonable steps to contain and investigate the breach and prevent it happening again, keep you updated, and cooperate with you in notifying the Information Commissioner and affected individuals where you decide to.
  4. 12.4 We will not tell the Information Commissioner, affected individuals or anyone else about a breach of Customer Personal Data on your behalf without your agreement, unless the law requires it.
  5. 12.5 Telling you about a breach is not an admission of fault or liability.

13. Information and audits

  1. 13.1 We will make available to you all information reasonably necessary to show that we comply with Article 28 of the UK GDPR and this DPA.
  2. 13.2 We will first meet audit requests by providing: completed security questionnaires; summaries of our latest independent security test; [certificates we hold]; and written answers to reasonable questions.
  3. 13.3 If that information is not enough to show compliance, or if the Information Commissioner requires it, or after a Personal Data Breach affecting you, you (or an independent auditor you appoint, who is not our competitor and is bound by confidentiality) may audit our compliance, including by inspection. Unless the audit follows a breach or is required by a regulator, it will be: no more than once in any 12 months; on at least [30] days’ written notice; during business hours; and conducted so as not to disrupt the Service or compromise other customers’ data or our security.
  4. 13.4 Each party bears its own costs of an audit, unless it reveals a material breach of this DPA by us, in which case we pay your reasonable costs.
  5. 13.5 Audits of our Sub-processors are carried out through the reports and certifications they make available, which we will share where we are allowed to.

14. Deletion and return

  1. 14.1 During the Subscription Term, Customer Personal Data is deleted at the end of the retention periods in Annex 1. The Service does this automatically, in a check that runs every day, for the clocked-in route (90 days after the Service received it), the phone readings kept for checking a tap (90 days after the tap) and enrolment photos (30 days after the worker leaves, or after the photo is replaced or withdrawn); [for other data, LinkSync does it on request until automatic deletion and retention periods you can set are built].
  2. 14.2 When the Customer Agreement ends, [LinkSync will, on your request during the Exit Period, return your Customer Personal Data to you in a commonly used machine-readable format, as set out in clause 21 of the Customer Agreement]. [Self-service export of your whole organisation’s data is not yet available.]
  3. 14.3 [We will then delete all Customer Personal Data within [30] days after the Exit Period, and confirm deletion in writing. This is done by LinkSync on request; it is not yet automatic.] Copies in backups are overwritten within [35] days and are protected and not used in the meantime.
  4. 14.4 We may keep Customer Personal Data only where UK law requires us to store it. In that case this DPA continues to apply to it, and we will process it only for the purpose the law requires.

15. Requests from authorities

  1. 15.1 If a court, the police, a regulator or another public authority asks us for Customer Personal Data, we will refer them to you where we can, and tell you about the request unless the law forbids it.
  2. 15.2 If we must disclose, we will check the request is lawful, disclose only the minimum required, and keep a record.

16. Liability

Each party’s liability under this DPA is subject to the limits in clause 18 of the Customer Agreement, including the separate data protection cap. Nothing in this DPA limits either party’s liability to individuals under Article 82 of the UK GDPR, or to the Information Commissioner.

17. Term and changes

  1. 17.1 This DPA lasts for as long as we process Customer Personal Data, including after the Customer Agreement ends until deletion under clause 14.
  2. 17.2 If Data Protection Law changes, or the Information Commissioner issues standard clauses that apply, we may update this DPA to the extent needed to keep it compliant, by giving notice under clause 24 of the Customer Agreement.

Annex 1: Details of processing

Subject matterProviding LinkSync’s visit verification service to you.
DurationThe Subscription Term, the Exit Period, and until deletion under clause 14.
NatureCollecting, recording, storing, organising, checking, displaying, exporting, sending to systems you connect, and deleting personal data, through the app, the web admin, the API and integrations. Automated checks of each visit, with flagged visits referred to your managers for review.
PurposeTo prove that the right worker was at the right place at the recorded time; to help you keep people safe and evidence that work you are paid or funded for was delivered; to prevent and detect false visit records; to plan and match visits; and to report to you and the systems you choose.

Categories of data subjects

  • Your workers: employees, agency and bank staff, volunteers and contractors who use the app.
  • Your managers, administrators, staff who fit GeoSyncs, and data protection lead, who use the web admin.
  • Guests you give read-only access to, such as commissioners and auditors.
  • Occupants: the people who live at, work at or otherwise occupy each Place, or whom you serve there (for example residents, tenants, customers or site occupants), and anyone who acts for them, such as an attorney.

Types of personal data

CategoryExamples
Identity and work detailsName, work email, staff reference, role, the parts of your organisation they work in, and custom fields you add
Phone detailsThe registered phone’s public security key, model and operating system version, and checks that the phone and app are genuine
Visit recordsClock-in and clock-out times, the GeoSync and Place, the result of each check, and whether the visit matched a planned visit
LocationThe phone’s location and its accuracy at each tap, and about once a minute while clocked in
Readings at the moment of a tapReadings from the phone used to confirm the GeoSync is where it was fitted, including the wireless networks nearby, recorded in scrambled form
Face check (if switched on)Enrolment photo; a manager’s confirmation that it matches ID; liveness and match results. Live images at visits are checked straight away and never stored.
ReviewsFlags, review outcomes and reasons, reviewer, and dates
Planned visitsVisits planned for each Place and assigned workers, from your systems or the Service’s own schedule
GeoSync installation recordsWhere each GeoSync is fitted, location and readings taken at fitting, who fitted it, and approval [and two photos of the GeoSync and its position, once photos are built]
Occupant detailsName, address, address history, the visits planned for them, and the record of agreement to a GeoSync, including who gave it and on what basis
Audit trailWho looked at or changed what, and when
Sign-in recordsSign-in events, failed sign-ins and lockouts

Special category data

  • Biometric data (the enrolment photo, and match results) where you switch on face checks, processed to confirm a worker’s identity.
  • Data concerning health, where visits can reveal information about an Occupant’s health, for example where they receive care or support at a Place where they live.

Additional safeguards: face images are used only to confirm identity at visits; live images are checked in memory and never stored; the enrolment photo is deleted automatically 30 days after the worker leaves, or 30 days after it is replaced or withdrawn, unless a legal hold applies; only people you allow can see an enrolment photo, to confirm it matches the worker’s ID; no special category data is placed in logs.

Retention

The defaults below apply. [You will be able to set retention periods within the ranges below once that is built.] The Service deletes these automatically, in a check that runs every day: the clocked-in route 90 days after the Service received it, the phone readings kept for checking a tap 90 days after the tap, and enrolment photos 30 days after the worker leaves or the photo is replaced or withdrawn; [other data is deleted by LinkSync on request until automatic deletion is built]. Nothing under a legal hold is deleted.

DataDefaultRange you can set
Visit summary (worker, Place, Occupant where recorded, times, result, review outcome)6 years from the visit[minimum] to [maximum]
Clocked-in route, and phone readings kept for checking90 days[minimum] to [maximum]
Location and phone readings inside the signed record of each tap (the evidence that the tap is genuine)The same as the visit summary [under review]Fixed
Detailed data under a legal hold you placeUntil you release the holdYour choice
Phone security key (public part) and detailsWhile registered, then as long as the visit records it signed, because it proves they came from that phoneFixed
Phone and app genuineness checksInside the signed record of each tap: the same as the visit summaryFixed
GeoSync installation recordWhile the GeoSync is active, plus 12 months[range]
Record of an Occupant’s agreement to a GeoSyncWhile the GeoSync is active, plus 6 years[range]
Audit trail6 yearsFixed
Face check enrolment photoUntil the worker leaves, or the photo is replaced or withdrawn, plus 30 daysFixed
Face check live imagesNever storedFixed
Backups35 days, rollingFixed

Annex 2: Security measures

We describe our measures in general terms here, because publishing exact details would help attackers. More detail is available to customers under confidentiality. See also our public Security page.

Governance
A named person responsible for security and data protection; written security policies reviewed at least yearly; risk assessment before significant changes; [certification held or targeted].
People
Confidentiality obligations in all contracts; [background checks appropriate to the role]; security and data protection training on joining and yearly; access removed on the day someone leaves.
Access control
Access by role and on a least-privilege basis; sign-in with a one-time code sent by email, with no passwords; app sign-in tied to the worker’s registered phone; [planned before launch: a second sign-in step for all web admin users and all LinkSync staff]; short-lived sessions that are checked on every request and can be revoked immediately; support access limited to the LinkSync staff who need it, and logged [customer approval for support access, once built].
Separation of customers
Each customer’s data is kept separate from every other customer’s at the database level as well as in the application, and this separation is covered by automated tests that must pass before any change is released.
Encryption
Personal data is encrypted in transit over the internet and at rest, including backups. Face images are additionally encrypted with dedicated keys. Secret keys for GeoSyncs are held in a separate, managed key store and never in the application database or on phones.
Integrity of evidence
Visit records, check results, reviews and face check results are append-only and cannot be altered or deleted except by the retention rules. Each tap is signed by a security key held on the worker’s registered phone, and checked against a one-time challenge so it can’t be replayed. The phone and app are checked as genuine at registration and at each tap.
Audit trail
Every read and write of personal data is recorded, with who, what and when, in a tamper-resistant audit trail that customers can see. Audit entries hold references, not personal data.
Logging and monitoring
Security events are logged and monitored, with alerts for unusual activity. No biometric data is placed in logs.
Secure development
Code review for every change; automated tests; additional independent review and testing for changes to security-critical areas; dependency and vulnerability scanning; separate development, test and production environments, with no customer personal data used in development.
Testing
Independent security testing at least yearly, and after major changes. A public responsible disclosure process.
Resilience
Hosting in the UK designed to keep running if a single data centre fails [confirm]; automated backups kept in the UK for 35 days; tested restore procedures; a business continuity and disaster recovery plan tested at least yearly. The app stores taps securely when offline and sends them later.
Incident response
A documented incident response plan, with roles, severity levels, customer notification within the time in clause 12, and a written review after each significant incident.
Suppliers
Security and data protection checks before engaging a sub-processor, written contracts, and periodic review.
Physical security
Our hosting providers’ data centres have controlled entry, surveillance and environmental protection. We have no customer personal data on office premises. GeoSyncs hold no personal information.

Annex 3: Sub-processors

The categories of Sub-processor we use, and where they process Customer Personal Data, are listed on our Sub-processors page, which forms part of this Annex. [The named list provided with your Order also forms part of this Annex.]

Annex 4: International transfers

  1. 4.1 All Customer Personal Data is stored in the UK, including backups.
  2. 4.2 Face check. Where face checks are switched on, one step of each check (confirming the person is live and present) is processed in the European Economic Area, and the result returned to the UK. Images are not stored there. This transfer relies on the UK’s adequacy regulations for the European Economic Area.
  3. 4.3 Notifications. LinkSync does not currently send notifications to phones from its servers; tap-out reminders are set on the phone itself. [If phone notifications or text messages are added, they will be listed here and on the Sub-processors page, with their transfer mechanism, before they start.]
  4. 4.4 We will not make any other transfer of Customer Personal Data outside the UK without notice under clause 8.2 and, where a transfer is to a country without UK adequacy regulations, appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

Annex 5: LinkSync as controller

ProcessingPurposeLawful basis
Each person’s sign-in email, and their one registered phone across all organisationsTo sign people in securely, and to make sure each person has one phone and each phone one person, so nobody can clock in for someone else at any organisationLegitimate interests
Security, fraud-prevention and service logsTo protect the Service and detect misuseLegitimate interests
Setting the Verification Rules, and monitoring check performance across all customers, including face check failure ratesTo keep evidence consistent and to find and fix inaccuracy and unfairnessLegitimate interests [and, for biometric data, a condition to be confirmed by the solicitor]
Customer account, contact and billing informationTo manage our relationship with youContract and legitimate interests

Where possible, monitoring uses information that does not identify individuals. Our privacy notice explains this processing to the people concerned.

Signed for and on behalf of [Company name]: ____________ Name: ____________ Date: ____________
Signed for and on behalf of [Customer]: ____________ Name: ____________ Date: ____________