BookKeptevidence chain
Legal

Data processing agreement

The Article 28 terms between an agency as controller and COM Computing Limited as processor. This is the document your compliance officer will ask for, so it is written to be handed straight to them.

Version 1.0 · 15 August 2026 · forms part of the terms of service

Draft pending legal review, and this one needs it most. An Article 28 agreement is a contract with statutory content requirements. This draft is accurate about what the system does, which is the part a template cannot get right, but it must be reviewed by a solicitor before it is signed. Two clauses in particular need advice: international transfers, and the liability position where a sub-processor fails.

1. Roles

The agency is the controller. COM Computing Limited is the processor. Where the agency is itself processing on behalf of an end client, the agency is a processor and we are a sub-processor, and the same obligations apply down the chain.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the BookKept service.
DurationThe term of the subscription, plus the deletion period in clause 10.
Nature and purposeStoring, organising and presenting the agency's records so it can evidence its statutory obligations; generating documents from those records; transmitting notifications on the agency's behalf.
Types of dataName, email, phone, postal address, postcode, date of birth, National Insurance number, personal service company name and number, VAT number, right-to-work check records and evidence, Key Information Documents, engagement and assignment details, hours worked, pay and charge rates, and audit records of the above.
Categories of data subjectThe agency's workers and candidates; contacts at the agency's clients; the agency's own staff users.
Special category dataNot required by the service and not requested by it. If the agency chooses to place it in a free-text field, the agency remains responsible for that decision and for its lawful basis.

3. Instructions

We process personal data only on the agency's documented instructions, which are: these terms, the configuration the agency sets in the product, and what the agency's authorised users do through the interfaces we provide. We will tell the agency if we believe an instruction breaches data protection law.

We do not use the agency's data for our own purposes. Specifically: not to train models, not for advertising, not to build products, and never to serve another customer.

4. Confidentiality

Everyone with access to the agency's data is bound by confidentiality. Today that access is limited to the personnel of COM Computing Limited who need it to operate and support the service. Support access into a tenant is recorded in that tenant's own audit chain, so the agency can see it happened.

5. Security

The technical and organisational measures are set out in the privacy notice and form part of this agreement: per-tenant isolation on every record and query; bcrypt password hashing; session tokens and integration keys stored only as hashes; AES-GCM encryption of third-party tokens with a refusal to store them unencrypted; a hash-chained audit trail; scoped API keys with the operator plane, key management and subject rights closed to every key; HTTPS throughout.

Measures may change as the service develops, but not in a way that materially lowers the level of protection.

6. Sub-processors

The agency authorises the sub-processors listed in the privacy notice: hosting, transactional email, and optional CV enrichment. We remain liable for their performance.

We will give at least 30 days' notice before adding or replacing a sub-processor. If the agency reasonably objects on data protection grounds, it may end the subscription before the change takes effect and receive a refund of the unused period.

7. International transfers

Where the data sits. The service is hosted in the European Economic Area, in Amsterdam, so processing of UK and Isle of Man personal data involves no restricted international transfer by us. Sub-processors are listed in the privacy notice with what each of them sees, and any change to that list carries 30 days' notice under clause 6. This clause previously recorded a United States region; the deployment moved on 16 August 2026, before any agency's production records were loaded.

8. Assisting the agency

We assist the agency, so far as reasonably possible and taking account of the nature of the processing:

9. Personal data breach

We will notify the agency without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the agency's data, with what we know at that point: what happened, which categories and roughly how many records, likely consequences, and what we are doing about it. Further detail follows as we establish it. The agency, as controller, decides what is reported to a regulator or to data subjects.

10. Return and deletion

At any time during the subscription the agency can export its whole tenant, in the importer's own format, with documents and the audit chain, round-trip verified.

On termination we delete the agency's personal data within 90 days, except where law requires retention. Backups age out on their own cycle and are not restored except to recover the service.

11. Audit

We will make available the information reasonably needed to demonstrate compliance with this agreement, and will accept an audit or inspection by the agency or its auditor on reasonable notice, no more than once in any 12 months unless a regulator requires otherwise or a breach has occurred. We have no third-party certification such as ISO 27001 or SOC 2 today, and say so rather than implying one.

12. Liability and law

The liability provisions of the terms of service apply, except that nothing in this agreement limits either party's liability to a data subject or a regulator under data protection law. Governing law follows the terms of service.

13. Signing it

This page is the current version. A counter-signable copy is provided at onboarding and the executed version is what governs. Ask for it before loading any real records: corey@comcomputing.im.