The terms on which Deployed processes personal data on a customer’s behalf when composerID publishes decisions into the customer’s systems of record, including international transfers, security measures, sub-processors, breach notification, audit and deletion, with the UK Addendum to the EU Standard Contractual Clauses.
This Data Processing Agreement, including its Annexes (“DPA”), is entered into by Deployed, a company based in London, United Kingdom (“Deployed”), and the customer identified in the Agreement (“Customer”).
Deployed provides Triage, its decision-intelligence software, and composerID, the integration layer that publishes Triage’s decisions into Customer’s systems of record under one Intent ID (together, the “Service”). Providing the Service involves the Processing of Personal Data subject to Data Protection Laws. This DPA sets out the terms on which Deployed Processes that Personal Data. In the provision of the Service, Customer acts as Controller and Deployed acts as Processor. Where Customer is itself a Processor for its own client, Deployed acts as Sub-processor and references to Controller instructions include the instructions Customer passes on.
This DPA applies between the parties where a representative of Customer clicks to accept it, transfers Personal Data to Deployed for Processing by means of the Service, or otherwise indicates acceptance. By doing so you (a) agree to this DPA on behalf of the organisation for which you act (“Customer”) and (b) represent that you have authority to bind Customer and its Affiliates. If you do not have that authority, or do not agree with this DPA, do not transfer Personal Data to Deployed. Deployed may update this DPA; an update takes effect on the earlier of 30 days after posting and Customer’s continued transfer of Personal Data.
If Customer and Deployed have signed a written data processing agreement governing the Processing of Personal Data by means of the Service, that signed agreement supersedes this DPA. This DPA is incorporated into and forms part of the Agreement.
Capitalised terms have the meanings given here, in applicable Data Protection Laws, or in the Agreement.
Each party will comply with the Data Protection Laws applicable to it in connection with the Service.
Customer warrants that its instructions for the Processing of Personal Data under the Agreement and this DPA comply with Data Protection Laws and will not cause Deployed to breach them; that it has a lawful basis for the Processing and has given Data Subjects the information Data Protection Laws require; and that, to the extent it shares Personal Data with Deployed, it is responsible for the means by which that Personal Data was obtained. Customer is responsible for configuring the Service, including its Channel Map and the Destinations it connects, in a way that is consistent with those instructions.
4.1 Instructions. Deployed will Process Personal Data solely to provide the Service and in accordance with Customer’s documented instructions, which are set out in the Agreement, this DPA and Customer’s configuration of the Service, and otherwise only as required by law. Unless prohibited by law, Deployed will inform Customer if in its opinion an instruction infringes Data Protection Laws, and may suspend performance of that instruction without liability until Customer confirms in writing that it is lawful. Additional instructions require the parties’ written agreement.
4.2 Government requests. Deployed will not disclose Personal Data to any government or public authority except as required by law or a valid and binding order such as a court order. If Deployed receives such an order it will notify Customer before disclosing, unless legally prohibited from doing so, and will disclose only the minimum required.
4.3 Personnel. Deployed will ensure that persons authorised to Process Personal Data are bound by appropriate obligations of confidentiality and receive suitable training.
4.4 No sale; no other use. Deployed will not sell or share Personal Data, will not Process it for any purpose other than providing the Service under the Agreement and this DPA, will not combine it with Personal Data obtained from other sources except as the Service requires, and will not use it to train generalised artificial intelligence or machine-learning models.
4.5 Minimisation by design. The Service is designed so that a Destination receives only the fields it requires for a valid record plus the Intent ID. Diagnostic answers, scores and the Compliance File are never transmitted to a Destination. Deployed will maintain this design and publish, per Destination, what crosses the boundary and what is never sent.
4.6 Details of Processing. The duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are specified in Annex I and, more generally, in the Agreement.
5.1 Deployed will make a Restricted Transfer only in accordance with Data Protection Laws and this Section 5.
5.2 Transfers from the United Kingdom. Where a Restricted Transfer of UK Personal Data is made to a country not covered by UK adequacy regulations, the parties agree that the IDTA applies or, where the EU SCCs are also in place for the same transfer, that the UK Addendum in Annex IV applies to those EU SCCs.
5.3 Transfers from the European Economic Area. Where a Restricted Transfer of EU Personal Data is made to a country not the subject of an adequacy decision, the EU SCCs are incorporated into this DPA as follows: Module Two (controller to processor) applies where Customer is a Controller and Module Three (processor to processor) where Customer is a Processor; Clause 7 (docking clause) is included; the option in Clause 9(a) is Option 2 (general written authorisation) with the notice period in Section 11; the option in Clause 11(a) is not selected; Clauses 17 and 18 are completed as set out in Section 12; and Annexes I, II and III to this DPA serve as Annexes I, II and III to the EU SCCs.
5.4 Transfers from Switzerland. Where the Swiss Federal Act on Data Protection applies, the EU SCCs apply as modified to the extent necessary to satisfy it, with the Swiss Federal Data Protection and Information Commissioner as competent authority for Swiss Personal Data.
5.5 Alternative mechanism. If Deployed adopts an alternative lawful transfer mechanism recognised under Data Protection Laws, that mechanism applies in place of the above to the extent it covers the transfer, and Customer will reasonably cooperate in implementing it. If a transfer mechanism is amended or replaced by the competent authority, the replacement applies.
Deployed will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the risks presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. The measures are described in Annex II. Deployed may update them provided the overall level of security is not reduced.
Deployed will assist Customer in responding to requests from Data Subjects exercising their rights under Data Protection Laws. Deployed will, to the extent permitted by law, promptly notify Customer of any request it receives directly from a Data Subject without responding to it except to direct the Data Subject to Customer, and will, on Customer’s written request, provide the information reasonably available to it to help Customer respond within the statutory deadline. The Service’s Intent ID and append-only timeline are designed to make locating a Data Subject’s records straightforward.
Where Customer is required to carry out a data protection impact assessment, or to consult a Supervisory Authority beforehand, Deployed will on written request provide reasonable assistance in relation to Customer’s use of the Service, to the extent Customer does not otherwise have access to the relevant information.
Deployed will make available to Customer the information necessary to demonstrate compliance with this DPA. On written request, not more than once in any 12-month period unless required by a Supervisory Authority or following a Personal Data Breach, Customer may verify Deployed’s compliance by (i) submitting a reasonable security questionnaire and, (ii) if the responses do not reasonably satisfy Customer, conducting an audit by way of interviews with Deployed’s security and engineering leads and review of relevant documentation, on a mutually agreed date and with minimum disruption to Deployed’s operations. Customer may use a mutually agreed independent auditor bound by a non-disclosure agreement, and is responsible for its auditor’s actions and for its own costs. Information disclosed under this Section is Deployed’s Confidential Information, and Customer will not share an audit report with any third party except as required by law or a Supervisory Authority. Deployed will remedy material deficiencies identified by an audit within a mutually agreed timeframe.
If Deployed becomes aware of a Personal Data Breach affecting Personal Data it Processes for Customer, Deployed will notify Customer without undue delay and in any event within 72 hours of becoming aware, providing the information reasonably available to it at that time and updating it as the investigation progresses: the nature of the breach, the categories and approximate numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Deployed will cooperate with Customer and take the reasonable steps agreed with Customer to investigate, mitigate and remediate the breach, and will provide the support Customer reasonably needs to meet its own notification obligations. Notification is not an acknowledgement of fault or liability.
Customer gives Deployed general written authorisation to engage Sub-processors, including Deployed’s Affiliates, to provide the Service. Deployed will restrict each Sub-processor’s Processing to what is necessary for that purpose, will impose on it written data protection obligations no less protective than those in this DPA, and remains responsible for the Sub-processor’s performance of those obligations.
Deployed’s current Sub-processors are listed in Annex III. Deployed will give Customer at least 15 days’ notice, by email to the address on Customer’s account or by updating Annex III and the changelog, before adding or replacing a Sub-processor. Customer may object in writing on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected part of the Service, and the Agreement to the extent it depends on it, without penalty, and Deployed will refund any prepaid fees for the terminated period.
This DPA is governed by the law of England and Wales and is subject to the jurisdiction provisions of the Agreement, unless Data Protection Laws require otherwise. For the purposes of Clause 17 of the EU SCCs, where they apply, the parties select Option 1 and agree that the EU SCCs are governed by the law of Ireland; for Clause 18, disputes arising from the EU SCCs are resolved by the courts of Ireland. For Clause 13, the competent Supervisory Authority is the authority applicable to the data exporter. Where the IDTA or UK Addendum applies, the law of England and Wales governs and the courts of England and Wales have jurisdiction, as those instruments provide.
On termination or expiry of the Agreement, and at Customer’s written election, Deployed will return Personal Data to Customer in a structured, machine-readable format (Intent Records, timelines and receipts as JSON conforming to the published schemas) or delete it, and will delete existing copies, within 30 days of the election or, absent an election, within 90 days of termination, except to the extent Data Protection Laws or other law require retention, in which case Deployed will isolate and protect the retained data. Copies in routine backups are deleted in the ordinary backup cycle.
This DPA takes effect when Customer accepts it and continues until the later of termination or expiry of the Agreement and the completion of the deletion or return under Section 13. It cannot be terminated separately from the Agreement except where Processing ends earlier, in which case it terminates automatically on completion of Section 13.
Except as amended by this DPA, the Agreement remains in full force and effect. In the event of conflict between the Agreement and this DPA, this DPA controls with respect to the Processing of Personal Data. In the event of conflict between this DPA and the EU SCCs, IDTA or UK Addendum, that transfer instrument controls.
| Data exporter | Data importer | |
|---|---|---|
| Party | Customer, as identified in the Agreement | Deployed, London, United Kingdom |
| Role | Controller (or Processor, where Customer acts for its own client) | Processor (or Sub-processor) |
| Activities relevant to the transfer | Purchase of access to and use of the Service under the Agreement | Processing of Personal Data to provide the Service under the Agreement |
| Contact | The account owner identified in the Agreement | Jamie Gannaway, Chief Technology and Product Officer, jamie.gannaway@deployed.co |
| Categories of Data Subjects | End Users interacting with the Service at Customer: requesters, hiring managers, approvers, procurement and HR staff. Individuals named in a work request where Customer’s process requires it, such as a named contractor or supplier contact. |
|---|---|
| Categories of Personal Data | Business contact details of End Users (name, work email, role, organisational unit). Work request content Customer chooses to route through the Service: role title, location, dates, rates and budget references, cost centre, supplier or worker identifiers, and free-text descriptions of the work. Identifiers issued by Destinations (external IDs, deep links). The Intent ID and the audit timeline (who did what, when). The Service does not require special category data; Customer should not route it through the Service. |
| Sensitive data | None by design. Any special category data would be present only because Customer’s End Users entered it in free text; Deployed processes it only as part of the record and applies the measures in Annex II. |
| Frequency | Continuous during the term of the Agreement, as End Users submit requests. |
| Nature of the Processing | Receiving decisions from Triage; minting an Intent ID; validating against Destination requirements; publishing records into Destinations via their APIs; receiving Destination events by webhook or polling; reconciling drift; maintaining the append-only timeline; making records available to Customer through the API. |
| Purpose | To provide the Service to Customer under the Agreement: publishing Customer’s workforce decisions into its systems of record under one Intent ID with a complete audit trail. |
| Retention | For the term of the Agreement and until return or deletion under Section 13, or earlier deletion by Customer through the Service. |
| Transfers to Sub-processors | Subject matter, nature and duration as above, limited to the function of each Sub-processor listed in Annex III, for the term of the Agreement. |
The Information Commissioner’s Office for UK Personal Data; for EU Personal Data, the Supervisory Authority applicable to the data exporter, as notified to Deployed under Section 12.
Deployed Processes Personal Data received from or for Customer under this DPA in conformity with the following measures.
Customer has authorised the use of the following Sub-processors. Changes are notified under Section 11 and recorded in the changelog.
| Sub-processor | Function | Location of Processing |
|---|---|---|
| Clerk, Inc. | Identity and access management for developer and customer accounts | United States |
| Vercel Inc. | Hosting of the composer.id website, documentation and edge functions; server logs | United States, with edge delivery worldwide |
| Resend, Inc. | Transactional email (account alerts, service notices) | United States |
The hosting provider for the production composerID API will be added to this Annex, with the notice Section 11 requires, before the production service goes live.
This Annex IV is the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022), and applies to Restricted Transfers of UK Personal Data where the EU SCCs are also in place under Section 5.3.
| Start date | The date Customer accepts this DPA |
|---|---|
| The parties | Exporter (who sends the Restricted Transfer): Customer, as listed in Annex I. Importer (who receives the Restricted Transfer): Deployed, as listed in Annex I. |
| Parties’ details and key contacts | As listed in Annex I, Part A |
| Signature | Acceptance of this DPA in accordance with its opening provisions |
The Addendum EU SCCs are the version of the EU SCCs incorporated into this DPA by Section 5.3, including the Appendix Information, with the modules, options and clauses selected there: Module Two or Module Three as applicable; Clause 7 included; Clause 9(a) Option 2 with a 15-day notice period; Clause 11(a) option not selected; Clauses 17 and 18 as set out in Section 12.
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in: Annex 1A (List of Parties): Annex I, Part A of this DPA. Annex 1B (Description of Transfer): Annex I, Part B of this DPA. Annex II (Technical and organisational measures): Annex II of this DPA. Annex III (List of Sub-processors): Annex III of this DPA.
Which Parties may end this Addendum as set out in Section 19 of the Mandatory Clauses: neither Party.
The Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the Information Commissioner and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses, are incorporated by reference.