Highrise Digital Ltd
Data Processing Agreement
Last updated: 4 August 2026
This Data Processing Agreement (the “DPA”) forms part of the agreement under which Highrise Digital Ltd provides services to the Customer (the “Service Agreement”).
Highrise Digital Ltd is registered in England and Wales under company number 09989726. Its registered-office and other corporate details are available on the Company Information page.
In this DPA, Highrise Digital Ltd is referred to as the “Supplier” and the other party to the Service Agreement is referred to as the “Customer”.
This DPA applies where the Supplier processes Personal Data on the Customer’s behalf when providing the Services. This may include:
- hosting websites, applications, databases, email, files or other systems;
- maintaining, supporting or developing websites and other digital services;
- creating development, staging or test environments;
- migrating, importing or exporting systems and data;
- providing recruitment websites, software or related technology services where agreed;
- accessing third-party accounts on the Customer’s documented instructions; and
- providing other services described in the Service Agreement.
Definitions
In this DPA:
- Agreement
- means the Service Agreement, this DPA and any applicable order form, statement of work or service schedule.
- Customer Personal Data
- means Personal Data processed by the Supplier on behalf of the Customer under the Agreement.
- Data Protection Laws
- means all data protection and privacy laws applicable to the processing, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003. It also includes the EU GDPR and other applicable national data protection laws where they apply to the processing. References to these laws include any amendments, replacements or re-enactments in force from time to time.
- EU GDPR
- means Regulation (EU) 2016/679.
- Personal Data Breach
- means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
- Restricted Transfer
- means a transfer of Personal Data that requires an adequacy decision, appropriate safeguard or other lawful transfer mechanism under applicable Data Protection Laws.
- Services
- means the services supplied under the Service Agreement.
- Sub-processor
- means another Processor appointed by the Supplier to process Customer Personal Data.
- UK GDPR
- means Regulation (EU) 2016/679 as it forms part of domestic law in the United Kingdom, as amended from time to time.
The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” have the meanings given to them in applicable Data Protection Laws. References to “including” or “includes” are illustrative and do not limit the words that precede them.
Roles and scope
For Customer Personal Data, the Customer is the Controller and the Supplier is the Processor, except where the Customer acts as a Processor for another Controller. In that case, the Supplier is the Customer’s Sub-processor.
Each party will comply with the obligations that apply to it under Data Protection Laws. The Supplier’s compliance with this DPA does not relieve the Customer of its own legal responsibilities.
The Customer is responsible for:
- ensuring that its instructions to the Supplier comply with Data Protection Laws;
- having a lawful basis for the processing;
- providing any privacy information required by law;
- ensuring that Customer Personal Data is adequate, relevant, accurate and limited to what is necessary;
- obtaining any required permissions from another Controller where the Customer acts as a Processor; and
- informing the Supplier where the processing requires additional safeguards not reasonably apparent from the nature of the Services.
The Supplier may process information about the Customer’s personnel and representatives for its own legitimate business purposes, including account administration, billing, fraud prevention, security, legal compliance and the establishment or defence of legal claims. For that processing, the Supplier acts as an independent Controller and will process the information in accordance with the Highrise Digital Privacy Policy.
Processing instructions
The Supplier will process Customer Personal Data only:
- on the Customer’s documented instructions;
- as necessary to provide, secure and support the Services;
- as described in the Agreement and Schedule 1; or
- where required by applicable law.
The Agreement, together with the Customer’s authorised use and configuration of the Services, constitutes the Customer’s documented instructions.
If applicable law requires the Supplier to process Customer Personal Data other than on the Customer’s instructions, the Supplier will inform the Customer before carrying out that processing unless the law prohibits it from doing so.
If the Supplier reasonably believes that an instruction infringes Data Protection Laws, it will inform the Customer without undue delay. The Supplier may suspend the affected processing until the parties agree a lawful instruction.
The Supplier will not sell Customer Personal Data or use it for advertising or for purposes unrelated to providing, securing or supporting the Services.
Confidentiality
The Supplier will ensure that people authorised to process Customer Personal Data:
- access it only where necessary for their work;
- are bound by an appropriate contractual or statutory duty of confidentiality;
- receive appropriate data protection and security guidance; and
- process it only in accordance with the Agreement and the Customer’s documented instructions.
The Supplier will not disclose Customer Personal Data to a third party except as authorised by the Customer, permitted by the Agreement or required by law.
If the Supplier is legally required to disclose Customer Personal Data, it will inform the Customer before disclosure and provide a reasonable opportunity to challenge the requirement, unless the law prohibits this.
Security
The Supplier will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
When determining appropriate measures, the Supplier will take account of:
- the nature, scope, context and purposes of the processing;
- the likelihood and severity of risks to individuals;
- the state of the art and the cost of implementation; and
- the nature of the Services and information available to the Supplier.
The Supplier’s current minimum security measures are described in Schedule 2. The Supplier may update those measures as technologies and risks change, provided that the overall protection of Customer Personal Data is not materially reduced.
Personal Data Breaches
The Supplier will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent the relevant information is available to the Supplier, its notification will include:
- a description of the nature of the breach;
- the categories and approximate numbers of affected Data Subjects and records;
- the likely consequences of the breach;
- the measures taken or proposed to investigate, contain and mitigate it; and
- a contact point from whom further information can be obtained.
The Supplier may provide this information in phases as it becomes available and will take reasonable steps to investigate, contain and mitigate the breach.
The Customer is responsible for deciding whether notification to a Supervisory Authority or affected Data Subjects is legally required. At the Customer’s reasonable request, the Supplier will assist with those notifications, taking account of the nature of the processing and the information available to it.
Data Subject requests
If the Supplier receives a request from a Data Subject concerning Customer Personal Data, it will notify the Customer without undue delay and will not respond except:
- on the Customer’s documented instructions;
- to direct the Data Subject to the Customer; or
- where required by law.
Taking account of the nature of the processing, the Supplier will provide reasonable assistance to help the Customer respond to requests concerning Data Subject rights, including access, rectification, erasure, restriction, objection and data portability.
Compliance assistance
Taking account of the nature of the processing and the information available to it, the Supplier will provide reasonable assistance to help the Customer comply with its obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- data protection impact assessments;
- consultation with a Supervisory Authority; and
- other obligations under Articles 32 to 36 of the applicable GDPR.
The Supplier may charge reasonable fees for assistance that is unusually extensive or falls outside the ordinary provision of the Services. The Supplier will not charge for assistance required as a direct result of its breach of this DPA.
Sub-processors
The Customer gives the Supplier general written authorisation to appoint Sub-processors in accordance with this section.
The Supplier may appoint a Sub-processor only where:
- its services are reasonably necessary to provide, support, secure or maintain the Services;
- the Supplier has assessed its data protection and security arrangements as appropriate to the processing;
- it is bound by a written agreement providing protections substantially equivalent to those required by this DPA;
- it processes Customer Personal Data only for the agreed purposes and on documented instructions; and
- any international transfer is protected by a lawful transfer mechanism.
The Supplier will maintain an internal record of its current Sub-processors and will provide that information to the Customer on reasonable request.
The Supplier will give the Customer at least 14 days’ written notice before appointing a new Sub-processor or replacing an existing Sub-processor that will process Customer Personal Data. The notice will identify the Sub-processor, the service it provides and, where relevant, its processing location.
The Customer may object during the notice period where it has reasonable grounds relating to the protection of Customer Personal Data. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, the Supplier may offer an alternative that avoids the relevant Sub-processor or allow the Customer to terminate the affected part of the Services.
Where urgent action is reasonably necessary to maintain security or service continuity, the Supplier may appoint or replace a Sub-processor on shorter notice. It will inform the Customer as soon as reasonably practicable.
The Supplier remains responsible to the Customer for the performance of its Sub-processors’ data protection obligations.
International transfers
The Supplier will not make a Restricted Transfer of Customer Personal Data unless:
- the transfer is made to a country or recipient covered by applicable adequacy regulations or an adequacy decision;
- appropriate safeguards are in place, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, applicable EU Standard Contractual Clauses or another legally recognised safeguard; or
- another lawful exception applies.
Where required, the Supplier will undertake or assist with a transfer risk assessment or other applicable data protection test and implement reasonable supplementary measures.
The Customer authorises transfers to the locations identified in the Agreement or in information about the Supplier’s Sub-processors provided to the Customer, subject to the safeguards in this section.
Each party will reasonably cooperate in entering into any additional transfer documentation required by Data Protection Laws.
Return and deletion
On termination or expiry of the Services, the Supplier will, at the Customer’s choice, return or delete Customer Personal Data unless applicable law requires its continued retention.
Unless the Agreement states otherwise:
- the Customer must request any return or export of Customer Personal Data before the Services end or within 30 days afterwards;
- the Supplier may delete active copies of Customer Personal Data 30 days after the Services end;
- temporary migration and development copies will be deleted within 30 days after the relevant work is completed;
- Customer Personal Data remaining in backups will be protected from ordinary use and deleted through the normal backup-rotation process within 90 days; and
- the Supplier may retain information that it processes as an independent Controller where necessary for legal, accounting, security or dispute-resolution purposes.
If deletion from a particular system is not immediately technically practicable, the Supplier will isolate the relevant Customer Personal Data from further use and delete it during the next applicable deletion or backup cycle.
Compliance information and audits
The Supplier will make available information reasonably necessary to demonstrate its compliance with this DPA and Article 28 of the applicable GDPR.
Where reasonably sufficient, the Supplier may meet this obligation initially by providing:
- responses to reasonable security and compliance questionnaires;
- relevant policies, certifications or independent assessment reports; and
- other appropriate evidence of its security and data protection practices.
If that information is not reasonably sufficient, the Customer may conduct an audit itself or through an independent auditor. Unless a Personal Data Breach, reasonable evidence of non-compliance or a requirement from a Supervisory Authority justifies otherwise:
- the Customer must give at least 30 days’ written notice;
- an audit may take place no more than once in any 12-month period;
- the audit must take place during normal business hours;
- the audit must not unreasonably disrupt the Supplier’s operations or compromise another customer’s confidentiality or security;
- the auditor must be bound by appropriate confidentiality obligations; and
- the Customer will bear its own costs and the Supplier’s reasonable costs of supporting the audit.
The Supplier will inform the Customer without undue delay if, in its reasonable opinion, an audit instruction would infringe Data Protection Laws or compromise the rights of another customer or Data Subject.
Term and precedence
This DPA takes effect when the Service Agreement begins and continues for as long as the Supplier processes Customer Personal Data.
If there is a conflict concerning the processing of Customer Personal Data, the following order of precedence applies:
- any mandatory Standard Contractual Clauses, UK Addendum or International Data Transfer Agreement;
- this DPA;
- the Service Agreement; and
- any other document forming part of the Agreement.
The limitations and exclusions of liability in the Service Agreement apply to this DPA to the fullest extent permitted by law.
Schedule 1: Processing details
Subject matter
Personal Data stored in, submitted to, transmitted through or otherwise processed using the Services, together with Personal Data accessed by the Supplier when providing support, maintenance, development, migration or other agreed services.
Duration
For the term of the Services and the return, retention and deletion periods described in the Agreement.
Nature of the processing
The processing may include:
- collection and recording;
- hosting and storage;
- organisation, structuring and retrieval;
- access, consultation and use;
- transmission, import, export and migration;
- alteration, correction and software development;
- backup, restoration and disaster recovery;
- security monitoring and troubleshooting;
- restriction, anonymisation and pseudonymisation; and
- return, deletion and destruction.
Purposes
To provide, maintain, secure and support the contracted Services in accordance with the Customer’s documented instructions. This may include:
- hosting websites, applications, databases, email, files or other systems;
- providing website, software or recruitment technology services;
- carrying out maintenance and development work;
- responding to support requests;
- migrating or importing data;
- maintaining backups and service continuity; and
- protecting the Services against unauthorised access, abuse and technical failure.
Categories of Data Subject
Depending on the Services and the Customer’s use of them, Data Subjects may include:
- the Customer’s personnel, contractors and authorised users;
- website and application visitors;
- customers, prospective customers and account holders;
- job applicants, candidates and prospective candidates;
- employers, recruiters, hiring managers and referees;
- suppliers and business contacts;
- people who submit forms, comments, messages or other content;
- email senders and recipients;
- people identified in documents, correspondence or uploaded content; and
- other people whose Personal Data the Customer chooses to process using the Services.
Categories of Personal Data
Depending on the Services and the Customer’s use of them, Customer Personal Data may include:
- names, titles and contact details;
- addresses and location information;
- account, profile and authentication information;
- employment, education and professional information;
- CVs, applications, recruitment records and interview information;
- customer-service and support communications;
- orders, purchases, transaction records and payment-related information;
- information submitted through forms, comments and messages;
- email and other electronic communications;
- documents, photographs, audio, video and other uploaded content;
- online identifiers, including IP addresses, cookie identifiers and session identifiers;
- device, browser, log, usage and analytics information; and
- other Personal Data selected or submitted by the Customer or its users.
Special-category and criminal-offence data
The Services are not intended to require special-category or criminal-offence data unless this is inherent in the agreed Services or expressly agreed with the Customer.
If the Customer submits such data, it is responsible for ensuring that it has an appropriate lawful basis and condition for processing it. The Customer must inform the Supplier where additional measures are reasonably required because of the sensitive nature or scale of the processing.
Customer’s rights
The Customer may:
- issue lawful and documented processing instructions;
- configure and use the Services as permitted by the Agreement;
- request reasonable assistance under this DPA;
- receive information about relevant Sub-processors;
- object to new or replacement Sub-processors on reasonable data protection grounds;
- request the return or deletion of Customer Personal Data; and
- verify compliance through the information and audit provisions in this DPA.
Schedule 2: Security measures
The Supplier will apply measures appropriate to the relevant Services and risks, including the following where applicable:
Access and authentication
- Access to Customer Personal Data is limited according to role and business need.
- Users are provided with individual accounts where supported.
- Access is reviewed and removed when no longer required.
- Strong, unique credentials are generated and stored using appropriate credential-management tools.
- Multi-factor authentication is used for privileged and sensitive systems where supported.
Encryption and devices
- Encryption in transit is used where appropriate, including HTTPS or an equivalent secure protocol.
- Encryption at rest is used where appropriate to the service and risk.
- Work devices used to access Customer Personal Data are protected by encryption, authentication and automatic screen locking.
- Reasonable controls are used to protect devices against malicious software and unauthorised access.
System and software security
- Supported software is maintained and security updates are applied according to risk and severity.
- Systems are configured to reduce unnecessary access and functionality.
- Vulnerabilities and security alerts are assessed and addressed according to risk.
- Development and administrative access is restricted to authorised personnel.
- Logging and monitoring are used where appropriate to the Services.
Development and testing
- The use of live Personal Data in development and test environments is minimised where reasonably practicable.
- Personal Data is anonymised, pseudonymised or reduced where reasonably practicable and appropriate to the work.
- Development and migration copies are retained only for as long as reasonably necessary.
- Secrets and credentials are not intentionally placed in publicly accessible source-code repositories.
Backup and resilience
- Backups are maintained where included in or reasonably required for the Services.
- Backup access is restricted to authorised personnel and systems.
- Restoration and continuity arrangements are periodically reviewed or tested as appropriate.
- Backups are retained and deleted according to documented rotation schedules.
Organisational measures
- Personnel with access to Customer Personal Data are subject to confidentiality obligations.
- Personnel receive appropriate security and data protection guidance.
- Procedures are maintained for identifying, reporting and responding to security incidents.
- Service providers that process Customer Personal Data are subject to appropriate contractual data protection and security obligations.
- Security measures are periodically reviewed and updated in response to material changes in technology, risk and the Services.