Data Processing Agreement
Last updated: July 25, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between POBL SYSTEMS LTD, a company incorporated in the United Kingdom with company number [COMPANY NUMBER] and registered office at 15 Neptune Court, Vanguard Way, Cardiff, CF24 5PJ ("Pobl", "we", "us" or "our"), and the business using Pobl HR ("Customer", "you" or "your").
It explains how Pobl processes personal data for the Customer when providing Pobl HR. The processing details, security measures and current subprocessors are set out in the schedules at the end of this DPA.
1. Status of this DPA
This DPA is incorporated into and forms part of the Agreement. It takes effect when the Agreement takes effect and does not need to be separately signed. A person accepting the Agreement for the Customer also accepts this DPA and confirms that they have authority to bind the Customer.
This DPA applies where Pobl processes Customer Personal Data as a processor for the Customer. It continues for as long as Pobl processes that data, including during the post-termination deletion periods described below.
2. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Terms and Conditions. In this DPA:
- Agreement means the Terms and Conditions, the applicable Order, this DPA and any document expressly incorporated into them.
- Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018 and other privacy or data protection law that applies to the processing, including the EU GDPR where applicable, in each case as amended or replaced.
- Customer Personal Data means personal data contained in Customer Data that Pobl processes as a processor for the Customer.
- EU GDPR means Regulation (EU) 2016/679.
- Subprocessor means another processor appointed by Pobl to process Customer Personal Data in connection with the Service.
- UK GDPR has the meaning given in the Data Protection Act 2018.
The terms controller, processor, personal data, personal data breach, process, processing and data subject have the meanings given by Applicable Data Protection Law.
3. Scope and roles
The Customer is the controller of Customer Personal Data and Pobl is its processor. If the Customer processes personal data for another controller, the Customer is a processor and Pobl is its subprocessor for that data.
Each party remains a separate controller for personal data it processes for its own purposes. In particular, Pobl acts as a controller for its business contacts, account administration, billing records, fraud and abuse prevention, legal compliance and the operation of its own business. That controller processing is not governed by this DPA.
3.1 Partners and client companies
A client company managed through a Partner account remains the controller of its Customer Personal Data. Pobl acts as the processor. The Partner acts under the client company's authority and may be that client's processor or authorised representative, depending on their separate agreement.
The Partner is responsible for having a valid agreement, lawful instructions and all necessary authority from each client company. Pobl may rely on instructions given through properly authorised Partner access. The Partner remains responsible for its personnel, services and access decisions as described in the Agreement.
4. Customer instructions
Pobl will process Customer Personal Data only on the Customer's documented instructions, unless United Kingdom law requires otherwise. The Agreement, the Customer's configuration and use of the Service, actions taken by its Authorised Users, and written requests accepted by Pobl are documented instructions.
The Customer instructs Pobl to process Customer Personal Data to provide, host, maintain, secure and support the Service; carry out the processing described in Schedule 1; use the Subprocessors in Schedule 3; and comply with the Agreement. These instructions include transfers that are reasonably necessary to use those Subprocessors, subject to section 12.
If United Kingdom law requires Pobl to process Customer Personal Data outside the Customer's instructions, Pobl will tell the Customer before doing so unless the law prohibits that notice. Pobl will promptly inform the Customer if, in Pobl's opinion, an instruction infringes Applicable Data Protection Law.
Additional instructions must be consistent with the Agreement and Applicable Data Protection Law. If an instruction requires material work outside the Service's standard functionality, the parties will agree its scope, timing and reasonable charges before Pobl carries it out.
5. Customer obligations
The Customer must:
- ensure that its instructions and use of the Service comply with Applicable Data Protection Law;
- have a lawful basis, provide required privacy information and obtain all rights and permissions needed to place Customer Personal Data in the Service;
- meet any additional legal conditions for special category or criminal offence data;
- decide what Customer Personal Data is collected, how long it is needed and who is authorised to access it;
- configure roles, permissions, Partner access, employee visibility, security settings and retention appropriately;
- keep its Authorised User and administrator contact details accurate; and
- respond to data subjects and regulators as controller, with Pobl's assistance where this DPA requires it.
6. Pobl obligations
When acting as processor, Pobl will:
- comply with its applicable obligations as a processor;
- process Customer Personal Data only in accordance with section 4 and Schedule 1;
- ensure that authorised personnel are subject to appropriate confidentiality obligations;
- implement and maintain the measures described in Schedule 2;
- provide the assistance described in sections 9 and 10, taking into account the nature of processing and the information available to Pobl;
- meet the Subprocessor obligations in section 11;
- meet the return and deletion obligations in section 14; and
- make the information reasonably necessary to demonstrate compliance with this DPA available in accordance with section 13.
7. Confidentiality and access
Pobl will restrict access to Customer Personal Data to authorised personnel who need access for their role. Those personnel must be bound by contractual or statutory confidentiality obligations and receive appropriate security and data protection guidance.
Pobl personnel will not manually access a Customer's Company or Customer Personal Data for ordinary support, maintenance or investigation unless an administrator of that Company has given consent. Access will be limited to what is necessary for the approved purpose, protected by production access controls and logged. This does not prevent automated processing required to provide the Service or access required by law.
8. Security
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risk to individuals, Pobl will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The measures in place at the date of this DPA are described in Schedule 2. Pobl may update them as technology and risks change, provided that the overall protection of Customer Personal Data is not materially reduced.
The Customer remains responsible for secure use of the Service, including its devices, networks, user accounts, permissions, exports and copies of Customer Data held outside Pobl HR.
9. Assistance and individual rights
Taking into account the nature of processing, Pobl will provide appropriate technical and organisational assistance, insofar as reasonably possible, to help the Customer respond to requests to exercise data protection rights. The Service may allow the Customer to access, correct, export and delete information directly.
If Pobl receives a request directly from a data subject concerning Customer Personal Data, it will direct the person to the Customer or notify the Customer where reasonably possible. Pobl will not respond substantively unless instructed by the Customer or required by law.
Taking into account the processing and information available to it, Pobl will also provide reasonable assistance with security obligations, breach assessment and notification, data protection impact assessments, and prior consultation with the Information Commissioner or another competent authority.
Pobl may charge reasonable costs for assistance that is unusually extensive, repetitive or outside the standard Service, unless the assistance is required because Pobl breached this DPA.
10. Personal data breaches
Pobl will notify the Customer without undue delay and, where feasible, within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. Notice will be sent to the Customer's administrator contact or another contact the Customer has designated.
As information becomes reasonably available, Pobl will describe the nature of the breach, affected data and data subjects, likely consequences, measures taken or proposed, and a contact for further information. Pobl may provide information in phases and will take reasonable steps to contain, investigate and mitigate the incident.
The Customer remains responsible for deciding whether to notify the Information Commissioner, another authority or affected individuals, unless Applicable Data Protection Law places that duty directly on Pobl. A notification is not an admission of fault or liability.
11. Subprocessors
The Customer gives Pobl general written authorisation to appoint the Subprocessors listed in Schedule 3 and to replace or add Subprocessors in accordance with this section. Pobl will assess each Subprocessor's ability to protect Customer Personal Data before appointment.
Pobl will enter into a written contract with each Subprocessor that imposes data protection obligations providing materially equivalent protection to the obligations in this DPA, to the extent applicable to the services supplied. Pobl remains responsible to the Customer for each Subprocessor's performance of those obligations.
Schedule 4 identifies a provider used for Pobl's separate controller activities. A provider is not a Subprocessor under this DPA merely because it processes limited business contact or billing data for Pobl's own purposes.
11.1 Changes and objections
Pobl will give at least 30 days' advance notice before a material new Subprocessor begins processing Customer Personal Data. Notice may be provided by email to the Customer's administrator contact and by updating Schedule 3. Where an urgent security, availability or legal requirement makes 30 days' notice impracticable, Pobl will give as much advance notice as reasonably possible and explain the reason.
The Customer may object during the notice period on reasonable, evidenced data protection grounds. The parties will work in good faith to address the objection, which may include additional safeguards or a commercially reasonable alternative.
If no reasonable solution is available, the Customer may terminate the part of the Service materially affected by the new Subprocessor before that Subprocessor begins processing its Customer Personal Data. Pobl will refund any prepaid Fees for the terminated part covering the period after termination. This is the Customer's sole remedy for an objection to a new Subprocessor, without limiting rights that cannot lawfully be restricted.
12. International transfers
Pobl's principal hosting is in the AWS Europe (London) region in the United Kingdom. Pobl will not make a restricted transfer of Customer Personal Data unless it has taken the steps required by Applicable Data Protection Law.
Where required, Pobl will use an applicable adequacy regulation, the International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, the Standard Contractual Clauses themselves, or another legally recognised safeguard. Pobl will carry out an appropriate transfer risk assessment and implement supplementary measures where required.
Pobl will ensure that its contracts with relevant Subprocessors contain the transfer safeguards required for their processing. If a transfer directly between the Customer and Pobl requires additional standard clauses, the parties will cooperate to put the applicable mechanism in place.
13. Information and audits
Pobl will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer will first use generally available documentation, policies, responses, certifications and independent assurance reports where those materials reasonably meet its requirements.
If those materials are insufficient, the Customer may conduct an audit itself or through an independent auditor. Unless a competent authority requires otherwise, or an audit is reasonably necessary following a personal data breach or credible evidence of material non-compliance, audits are limited to once in any 12-month period and require reasonable advance written notice.
The parties will agree a reasonable scope, timing, duration and confidentiality protocol. An audit must take place during normal business hours, avoid access to another customer's information, protect Pobl's systems and confidential information, and avoid unnecessary disruption.
The Customer bears its audit costs and Pobl's reasonable costs of assistance beyond normal compliance materials. Pobl will bear its own reasonable assistance costs if the audit identifies a material breach of this DPA by Pobl.
14. Return and deletion
The Customer may export Customer Personal Data using available Service functionality while its Company remains accessible. If requested before access ends or, where technically feasible, during the seven-day live-data retention period, Pobl will provide reasonable assistance with an available export.
Unless the Customer lawfully instructs Pobl to return particular data before deletion, the Customer instructs Pobl to delete Customer Personal Data when the relevant Company is deleted or the Service ends. Deleting a Company requires two separate confirmations.
Following confirmed deletion, or after a cancelled Subscription ends and the Company is closed, live Customer Data remains recoverable for seven days. Pobl will then permanently delete it from live systems.
Encrypted backups are retained for up to 30 days as part of Pobl's normal backup cycle. Data remaining only in a backup is put beyond ordinary use, protected from further processing and deleted when that backup expires. A backup will be restored only where necessary for disaster recovery or security, and deleted Customer Personal Data will be removed again in accordance with this section.
Pobl may retain particular information where United Kingdom law requires it, but will isolate and protect that information and process it only for the legally required purpose. At the Customer's written request, Pobl will confirm completion of deletion.
15. Liability and conflict
The exclusions and limitations of liability in the Agreement apply to this DPA to the fullest extent permitted by law. Nothing in this DPA limits liability or rights that cannot lawfully be limited.
If there is a conflict concerning the processing of Customer Personal Data, an applicable mandatory transfer mechanism takes priority, followed by this DPA, followed by the rest of the Agreement.
The governing law and dispute provisions in the Terms and Conditions apply to this DPA.
16. Changes and contact
Pobl may update this DPA where reasonably necessary to reflect a change in the Service, Subprocessors or Applicable Data Protection Law. Pobl will not materially reduce the protection given to Customer Personal Data during a current Subscription without a valid legal, regulatory or security reason.
A change to a Subprocessor is handled under section 11.1. For another material change, Pobl will give reasonable advance notice where practicable. The "Last updated" date identifies the current version.
Questions, instructions and data protection requests may be sent to hello@poblhr.com.
Schedule 1 — Processing details
- Subject matter: provision of the Pobl HR company-scoped HR and workplace management Service.
- Purpose: hosting, storing and organising Customer Data; enabling HR and workplace workflows; authenticating users; applying permissions; securing, maintaining and supporting the Service; sending transactional emails; and carrying out the Customer's documented instructions.
- Duration: for the term of the Agreement, followed by seven days for live data and up to 30 days for backup expiry, unless law requires longer retention.
- Nature and operations: collection, recording, organisation, structuring, storage, retrieval, consultation, display, transmission, restriction, export, backup, restoration and deletion, as initiated by the Customer, its Authorised Users or the operation of the Service.
- Frequency: continuous or as initiated by the Customer and its Authorised Users during the Agreement.
- Data subjects: current and former employees, workers, contractors, applicants where the Customer chooses to record them, Authorised Users, managers, Partner users, client contacts, emergency contacts and other individuals whose information the Customer lawfully places in the Service.
- Personal data: names, identity and contact information, dates of birth, addresses, National Insurance numbers, employment and contractual details, attendance and leave information, salary and pay information, expenses and receipts, documents, form answers, goals, training and compliance records, workplace incidents, assets, notes, communications, emergency contacts, account identifiers, audit trails, and sign-in and security activity.
- Special category data: health, sickness, disability, racial or ethnic origin, religious or philosophical beliefs, trade union membership, sexual orientation and other special category data, but only where the Customer chooses to submit it and has authority to do so.
- Criminal offence data: allegations, investigations, convictions or offence information may be included in incident, document, form or employment records where the Customer chooses to submit it and has authority to do so.
- Customer rights: the Customer determines the purposes of processing, controls its Customer Data and Authorised Users, configures available features and may access, correct, export and delete information using available functionality.
Schedule 2 — Security measures
Pobl's technical and organisational measures include:
- Hosting and physical security: production infrastructure and files are hosted through AWS in its Europe (London) region, with physical safeguards managed by AWS.
- Encryption: Customer Personal Data is protected by encryption in transit and at rest.
- Logical separation: Companies are logically separated, and requests are scoped to the active Company context.
- Customer access control: unique user accounts, role-based permissions, employee visibility rules and configurable Partner access restrict the records and functions available to each Authorised User.
- Account protection: users may enable authenticator-based two-factor authentication. A sign-in from a new device requires additional verification, using an authenticator code where two-factor authentication is enabled and otherwise a one-time code sent by email.
- Sessions: users can configure their idle sign-out period, and security events can revoke sessions and trusted devices.
- Production administration: administrative access is restricted, uses multi-factor authentication, follows least-privilege principles and is logged. Manual access to a Company's data requires consent from a Company administrator, except where access is required by law.
- Auditability: meaningful changes and security-sensitive activity are logged to support investigation and accountability.
- Backups and recovery: encrypted backups are maintained for resilience and disaster recovery and expire after 30 days.
- Secure development: changes are reviewed and tested before release. Dependencies, vulnerabilities and infrastructure are maintained and updated using risk-based processes.
- Personnel: access is limited by role and need, subject to confidentiality obligations, and removed when it is no longer required.
- Incident management: Pobl maintains processes to identify, investigate, contain, mitigate and communicate security incidents.
- Data minimisation: diagnostic monitoring is configured to avoid Customer Data and identifying content, and advertising or unrelated analytics are not used within the Pobl HR application.
Schedule 3 — Subprocessors
The following providers are authorised to process Customer Personal Data for the Service. A location describes the principal data-storage or processing location and does not exclude limited protected access expressly described below.
Amazon Web Services
| Legal entity | Amazon Web Services EMEA SARL |
|---|---|
| Purpose | Cloud infrastructure through Amazon EC2, file and backup storage through Amazon S3, and transactional email delivery through Amazon SES. |
| Data | Customer Personal Data hosted in the Service; account and technical information; and recipient addresses and message content needed to send transactional emails. |
| Location | Core hosting and storage in the United Kingdom, AWS Europe (London), eu-west-2. Email is delivered to the location selected by its recipient. |
| Safeguards | AWS Data Processing Addendum and UK GDPR Addendum, including applicable transfer safeguards for authorised AWS affiliates and service providers. |
More information is available from AWS in its GDPR centre and AWS subprocessor list.
Microsoft 365
| Legal entity | Microsoft Corporation and the applicable Microsoft contracting affiliate |
|---|---|
| Purpose | Business email and mailbox services used to receive and respond to customer support communications. |
| Data | Sender and recipient details, message content, attachments and related delivery information. Customers should provide only the information needed for their support request. |
| Location | Microsoft 365 service locations applicable to Pobl's tenant, with protected access from other authorised Microsoft locations where required to provide and support the service. |
| Safeguards | Microsoft Products and Services Data Protection Addendum, including applicable Standard Contractual Clauses and United Kingdom transfer safeguards. |
More information is available in Microsoft's Products and Services Data Protection Addendum.
Sentry
| Legal entity | Functional Software, Inc., doing business as Sentry |
|---|---|
| Purpose | Error monitoring, diagnosis and application reliability. |
| Data | Pobl configures Sentry to receive anonymised and minimised technical error information, not Customer Data. Sentry is listed as a precaution because an error event could unexpectedly contain limited technical identifiers or other personal data. No special category data is intentionally submitted. |
| Location | European Union data-storage region. Functional Software, Inc. is established in the United States, and protected access may occur from the United States or through authorised Sentry subprocessors. |
| Safeguards | Sentry Data Processing Addendum, including the UK Addendum to the Standard Contractual Clauses and other lawful transfer mechanisms where applicable. |
Pobl does not enable Sentry AI features for Customer Personal Data. More information is available in Sentry's Data Processing Addendum and subprocessor list.
Schedule 4 — Other providers
Pobl uses Stripe for Subscription billing and payment processing. Stripe receives only the minimum business identity, billing-contact, transaction and payment information required to manage payment. It does not receive employee records or other HR data from Pobl HR.
Pobl determines why billing information is used as a separate controller for its business administration. Stripe acts as a processor or independent controller depending on the payment activity and its own legal obligations. Stripe is therefore not appointed as a Subprocessor of Customer Personal Data under this DPA.
Further information is available in Stripe's Data Processing Agreement and Privacy Policy.