1 Definitions
Capitalised terms have the meanings given in the UK GDPR. The following additional terms apply:
| "Controller" | The customer organisation entering into the Master Services Agreement with Vault Hire. |
| "Processor" | Vault Hire Limited. |
| "Services" | The Vault Hire applicant-tracking platform and any related professional services described in the MSA. |
| "Personal Data" | Personal data of Data Subjects processed by the Processor on behalf of the Controller in connection with the Services. |
| "Sub-processor" | Any third party engaged by the Processor to process Personal Data on the Processor's behalf in connection with the Services. Current list: /legal/sub-processors.html. |
| "Approved Sub-processors" | The Sub-processors listed in the Sub-processor list at the time of execution, deemed approved by the Controller on signature. |
2 Subject matter, duration & categories
| Subject matter | The provision of an applicant-tracking platform for regulated hiring. |
| Duration | Co-extensive with the MSA, plus the retention periods set out in §11. |
| Nature & purpose | Hosting, storage, encryption, retrieval, structured analysis (where the Controller chooses to use AI features), audit logging, and onward transmission (only on Data Subject consent). |
| Categories of Data Subjects | Candidates, employees of the Controller, contractor referees, hiring managers, regulatory references (under FCA SYSC 22). |
| Types of Personal Data | Identification data, contact data, employment history, qualifications, references, regulated identifier hashes (passport / NI / SSN / driving licence — never raw), interview notes, candidate self-submitted documents, audit logs. |
| Special category data | Only with explicit Data Subject consent (e.g. health data submitted for reasonable-adjustments). The Processor offers tooling to redact and minimise SCD. |
3 Scope & processing instructions
The Processor will process Personal Data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do so by UK or EU law. The Controller's instructions are set out in:
- The MSA and its order forms.
- The configuration the Controller makes via the Vault Hire administrative interface (including AI workflow toggles per IfU §5).
- Any written instructions agreed in advance.
The Processor will inform the Controller immediately if, in its opinion, any instruction infringes the UK GDPR or other data-protection law.
4 Processor obligations
The Processor will:
- Process Personal Data only as instructed (§3).
- Ensure that persons authorised to process Personal Data are under written confidentiality obligations.
- Implement appropriate technical and organisational measures (§7).
- Engage Sub-processors only on the conditions of §5.
- Take all reasonable steps to assist the Controller in responding to Data Subject rights requests (§10).
- Assist the Controller with DPIAs and consultations with the ICO (§10).
- Notify the Controller of any Personal Data breach (§8).
- On termination, return or delete Personal Data (§11).
- Make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for audits as set out in §9.
5 Sub-processors
The Controller grants the Processor general written authorisation to engage Sub-processors, provided:
- The Processor maintains a current list at /legal/sub-processors.html and notifies the Controller of any intended changes via email to the Controller's nominated DPO contact and on-platform notification.
- The Controller has 14 days from notification to object on reasonable data-protection grounds. If the Controller objects and the Processor cannot accommodate the objection, the Controller may terminate the affected Services on a pro-rata refund basis.
- The Processor flows down equivalent data-protection obligations to every Sub-processor in writing.
- The Processor remains fully liable to the Controller for the performance of every Sub-processor's data-protection obligations.
6 International transfers
Where any transfer of Personal Data outside the UK or EEA is necessary, the Processor will rely on one or more of:
- An adequacy decision under Article 45 / equivalent UK regulation.
- UK Standard Contractual Clauses (UK Addendum / IDTA) where the destination is outside the UK adequacy list.
- EU Standard Contractual Clauses (Decision 2021/914/EU, Module 2) where data leaves the EEA.
- Binding Corporate Rules of the Sub-processor if approved by the relevant supervisory authority.
The Processor maintains a Transfer Impact Assessment (TIA) for each material onward transfer; available to the Controller on request under NDA.
7 Technical & organisational measures
The Processor implements technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include, at minimum:
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (field-level encryption on identified PII fields; full-disk encryption otherwise).
- Access controls with role-based authorisation, principle of least privilege, multi-factor authentication for administrators.
- Network security including private networking between application tiers and the data store.
- Audit logging of every access to Personal Data with at least 6 years' retention for SMCR-aligned customers.
- Backup & restore testing performed at minimum quarterly, with documented RTO / RPO targets shared on request under NDA.
- Incident response with a documented runbook and a 24/7 monitored security contact.
- Personnel security with documented onboarding/offboarding processes, confidentiality undertakings and access-review rotations.
The full TOM register, including current controls and roadmap controls (SOC 2 Type I readiness target Q3 FY26, ISO 27001 certification target FY27), is available under NDA.
8 Personal-data breach
The Processor will notify the Controller of any Personal Data breach affecting the Controller's data without undue delay and in any case within 48 hours of becoming aware. The notification will include, where known:
- The nature of the breach, including the categories and approximate number of Data Subjects and Personal Data records concerned.
- The likely consequences.
- Measures taken or proposed.
- Contact details for further information.
The Processor will not notify the relevant supervisory authority or Data Subjects on the Controller's behalf unless expressly instructed in writing.
9 Audit rights
The Controller may, no more than once per 12-month period and on at least 30 days' written notice (or, in case of a material breach, immediately), conduct an audit of the Processor's compliance with this DPA. The audit will be conducted:
- By the Controller or a mutually-acceptable independent third party (not a competitor of the Processor) under NDA.
- During normal business hours.
- In a manner that does not unreasonably interfere with the Processor's business operations.
- At the Controller's cost, save where the audit uncovers a material breach by the Processor, in which case the Processor will bear reasonable audit costs.
The Processor may satisfy this obligation by providing the Controller with a current SOC 2 Type II report or ISO 27001 certificate once available.
10 Assistance with Data Subject rights & DPIAs
Taking into account the nature of processing, the Processor will assist the Controller in:
- Responding to Data Subject rights requests (Articles 15–22). Most requests are self-service via the user's "Data & Privacy" panel; the Processor will provide reasonable assistance for any request that cannot be self-served.
- Carrying out Data Protection Impact Assessments (Article 35) — the Processor publishes a DPIA template at /legal/dpia-template.html.
- Consultations with the supervisory authority (Article 36).
- Compliance with Article 32 (security), Article 33 (breach notification), and Article 36 (prior consultation).
11 Return & deletion
On termination of the MSA, the Processor will, at the Controller's election:
- Return all Personal Data in machine-readable JSON format within 30 days, then delete its copies.
- Delete all Personal Data within 30 days, save Personal Data that the Processor is required to retain by law (e.g. 6-year regulatory-reference retention under FCA SYSC 22, audit log retention).
Where the Processor is required to retain Personal Data, the retained data will be quarantined in a state with restricted access to compliance personnel only, and will be deleted at the end of the legal retention period. Tombstone records may remain in audit logs after deletion — they do not contain Personal Data beyond a SHA-256 hash of the original record.
12 Liability, term & counterpart
Liability under this DPA is subject to the limitation of liability clauses in the MSA. This DPA will terminate automatically on termination of the MSA, save the provisions of §11 (Return & deletion) and §9 (Audit) which survive termination for as long as the Processor holds Personal Data.
This DPA may be executed in counterparts, each of which is an original, and which together form one document. An electronic signature (including DocuSign or a scanned PDF signature page) is valid.
For the Controller
Authorised signatory · name
Title
Date
For the Processor — Vault Hire Limited
Authorised signatory · name
Title · Director
Date
★ Submit a counter-signed copy
If you have signed the DPA on your side, upload the counter-signed PDF here. We will counter-sign and return a fully-executed version within 1 working day. You must be signed in to your Vault Hire account to upload — that binds the submission to your identity for audit purposes.
In-product signature flow
Pre-fill the controller signature block with your identity. We will give you a unique reference that chain-of-custody-links to the file you upload below.
Not legal advice
This DPA is provided as a template ready to incorporate. Your procurement / DP counsel should review it before signature. Vault Hire will negotiate reasonable amendments without unreasonable delay.