DATA PROCESSING AGREEMENT
Data Processing Agreement
Article 28 GDPR — agreement between you (controller) and PersoHR (processor)
1. Introduction
This Data Processing Agreement ("DPA") forms part of the master subscription agreement between Labb Holding Ltd, a Cyprus private company limited by shares with its registered office at Anthipolochagou Georgiou M.Savva 26, Shop 1-2, 8201 Paphos, Cyprus, registered under HE 424230 (operating the PersoHR platform, the "Processor"), and the customer (the "Controller"). It governs the processing of personal data that the Processor carries out on behalf of the Controller in connection with the PersoHR platform and is designed to comply with Regulation (EU) 2016/679 (the "GDPR"). Where any provision of this DPA conflicts with the master agreement, this DPA prevails for matters of personal data processing. Capitalised terms used but not defined here have the meaning given to them in the master agreement or, where applicable, in the GDPR.
2. Subject matter, duration, nature and purpose
The Processor processes personal data for the sole purpose of providing the PersoHR HR-management service. The processing covers the management of employee records, leave and absence, onboarding, offboarding, time tracking, payroll preparation, performance reviews, recruitment, document storage, internal communication and other HR workflows configured by the Controller. Processing runs for the duration of the Controller's subscription, plus any retention periods required by law or by section 13 of this DPA. The Controller acknowledges that the precise scope and depth of processing depend on the modules and configuration the Controller chooses to enable.
3. Categories of personal data
The categories of personal data processed depend on the Controller's configuration of the platform and may include: personnel master data (name, contact details, postal address, date of birth, photograph); employment master data (job title, department, employment type, start and end dates, working hours, manager); document content (employment contracts, certifications, identity documents, other files uploaded by the Controller); performance and development data (objectives, reviews, feedback, training records); leave and absence data (requests, balances, public holidays); time-tracking data (clock-in / clock-out events, timesheets, overtime); payroll-preparation data (salary records, IBAN where supplied, tax and social-security identifiers where supplied); recruitment data (applications, CVs, interview notes, references); communication and chat data; authentication and security data (login timestamps, IP addresses, device fingerprints, two-factor state); and any other personal data the Controller chooses to upload or generate within the platform. The Controller is responsible for ensuring that any special-category data within the meaning of Article 9 GDPR it uploads has an appropriate legal basis.
4. Categories of data subjects
Categories of data subjects, in respect of the Controller and any affiliates the Controller chooses to administer through the platform, typically include: current employees, contractors, freelancers and other personnel; former employees, contractors and personnel; applicants and candidates in active or past recruitment processes; and dependants or emergency contacts disclosed by any of the foregoing. The Controller is responsible for the lawfulness of including any specific data subject within the scope of processing.
5. Instructions and right to refuse
The Processor will process personal data only on the documented instructions of the Controller — including with regard to international transfers — unless required to do otherwise by Union or Member State law (in which case the Processor will inform the Controller before processing, except where that law prohibits such notice on grounds of important public interest). The Controller designates the persons exclusively authorised to issue processing instructions through the platform; in the absence of such designation, only natural persons authorised to legally represent the Controller may issue instructions. If the Processor reasonably believes that an instruction infringes the GDPR or other applicable data-protection law, it will notify the Controller without undue delay and may suspend execution of that instruction until the matter has been resolved between the parties.
6. Confidentiality
The Processor ensures that any natural person authorised to process personal data on its behalf is bound by an obligation of confidentiality, whether by contract or by statutory duty. Each party further agrees to keep confidential any non-public information it receives from the other party in connection with this DPA, including the contents of audits, security documentation and incident reports, and to use such information solely for the performance of the master agreement and this DPA. Information that is publicly known, was independently developed without use of the disclosing party's confidential information, was lawfully received from a third party without confidentiality obligation, or is required to be disclosed by binding legal process is excluded. Confidentiality obligations survive the termination of the master agreement for a period of five years.
7. Security of processing (Article 32)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects' rights and freedoms, the Processor implements and maintains appropriate technical and organisational measures, including: encryption of personal data in transit (TLS 1.2 or higher) and at rest; role-based access control with the principle of least privilege; comprehensive audit logging; regular vulnerability scanning and patching; EU-only data residency for primary processing; time-limited access tokens; mandatory two-factor authentication for privileged roles; and regular backups with tested restoration. The current technical and organisational measures ("TOMs") are published as a public annex at /legal/security and may be updated from time to time, provided that any update does not materially reduce the overall level of security.
8. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed at /legal/sub-processors. The Processor will inform the Controller in writing (including email) at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within 14 days of that notification; absent a timely objection, the change is deemed approved. If the parties cannot resolve a justified objection within a further 30 days, either party may terminate the master agreement on written notice without further liability, in which case the Controller is entitled to a pro-rata refund of any prepaid fees that cover the unused remainder of the subscription term. The Processor enters into written agreements with each sub-processor that impose data-protection obligations equivalent to those in this DPA, and remains responsible for the acts and omissions of its sub-processors.
9. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in responding to requests under Chapter III GDPR (access, rectification, erasure, restriction, portability and objection). The platform exposes self-service tools for the most common requests (data export under Article 20, erasure under Article 17, rectification of self-managed fields). For requests that the Controller cannot fulfil through these tools, the Processor will provide reasonable additional assistance. If a data subject contacts the Processor directly, the Processor will refer the request to the relevant Controller and notify the Controller without undue delay.
10. Personal data breach notification
The Processor notifies the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. The Processor cooperates with the Controller as reasonably required for the Controller's own notification obligations under Articles 33 and 34 GDPR.
11. DPIA and prior consultation
The Processor assists the Controller, on reasonable request, with data protection impact assessments under Article 35 and prior consultations with supervisory authorities under Article 36, taking into account the nature of the processing and the information available to the Processor.
12. Audits and inspections
The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Controller may inspect the Processor's compliance, or appoint a qualified independent auditor to do so on its behalf, on at least 30 days' written notice, during normal business hours, no more than once per calendar year (an "On-site Audit"). The Processor may require any auditor to enter into reasonable confidentiality undertakings before the audit, and may object to a Controller-appointed auditor that is in direct competition with the Processor or that the Processor reasonably considers unsuitable. Each party bears its own costs of an On-site Audit. In lieu of an On-site Audit the Processor may, at its discretion, satisfy this obligation by providing a current independent certification or attestation report (such as ISO/IEC 27001, SOC 2 Type II, or an approved certification under Article 42 GDPR), copies of penetration-test summaries, or its TOMs documentation; in that case the On-site Audit may be refused. Where an audit is triggered by a confirmed personal data breach or a more than insignificant breach of this DPA (an "Event-related Audit"), the notice period and frequency limit do not apply, and the Processor will cooperate fully without limit on scope or frequency.
13. Return or deletion of personal data
On termination of the master agreement, the Processor retains the Controller's personal data for 30 days. During that period the Controller may either (a) export its data via the in-app tenant export under Article 20 GDPR or (b) instruct the Processor in writing to delete the data immediately. If the Controller takes neither action within the 30-day period, the Processor will delete the data automatically at the end of that period. Backups are subject to the documented backup retention schedule and are overwritten in due course; until then, restored data remains subject to this DPA. Personal data that the Processor is legally required to retain (for example, billing data for tax purposes) is excluded from deletion for the duration of that legal obligation.
14. International transfers
The Processor primarily processes personal data within the European Union. Where the Processor or any sub-processor needs to transfer personal data to a country outside the European Economic Area, the transfer is made only on the basis of an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR — typically the European Commission's Standard Contractual Clauses (Decision 2021/914/EU) supplemented, where required, by additional technical and organisational measures. The current list of recipients and applicable transfer mechanisms is published at /legal/sub-processors.
15. Insolvency, seizure and third-party events
If the Controller's personal data is at risk because of seizure, confiscation, insolvency or composition proceedings, or any other action by a third party that could affect the Processor's ability to comply with this DPA, the Processor will inform the Controller without undue delay and inform the third party in writing that the data is the responsibility of the Controller as data controller within the meaning of the GDPR. The Processor will take reasonable steps to protect the integrity and availability of the Controller's data pending resolution of the third-party action.
16. Liability
Each party is liable for damage caused by its own breach of this DPA in accordance with Article 82 GDPR and applicable law. Nothing in this DPA excludes or limits any liability that cannot be excluded or limited by law, including for death or personal injury, fraud, fraudulent misrepresentation or wilful misconduct. In all other respects, the limitations and exclusions of liability set out in the master agreement apply equally to this DPA.
17. Severability and final provisions
Amendments and supplements to this DPA require text form (which includes email exchange under Article 28(9) GDPR) and an explicit indication that they amend or supplement this DPA. If any provision of this DPA is or becomes invalid, illegal or unenforceable, the validity of the remaining provisions is not affected; the parties will replace the invalid provision with a valid one whose economic effect comes as close as possible to that of the invalid provision. This DPA may be executed and updated electronically and supersedes any prior data-processing arrangements between the parties for the same subject matter.
18. Governing law and jurisdiction
This DPA is governed by the laws of the Republic of Cyprus, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods. The courts of Paphos, Cyprus have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to any mandatory consumer-protection or data-subject venue rights under the GDPR.
19. Contact
For matters relating to this DPA, contact Labb Holding Ltd at privacy@persohr.eu, or write to Labb Holding Ltd, Anthipolochagou Georgiou M.Savva 26, Shop 1-2, 8201 Paphos, Cyprus. The Controller's contact point for data protection is the user account designated as OWNER in the PersoHR platform.