About this document
These are HoursBack Ltd’s standard data processing terms. They are written to be published here and incorporated by reference into a statement of work, letter of engagement or order, so that the document you actually sign stays short. They set out the terms Article 28 UK GDPR requires of a processor.
They are client-agnostic. Everything specific to one engagement - who the participants are, how long material is kept, any change to the sub-processor list - sits in the statement of work, which completes the Annexe at the foot of this page. Where a document incorporating these terms is signed electronically, that signature satisfies Article 28(9).
Parties and definitions
Parties. HoursBack Ltd, company number 17194563, of 11 Croydon Road, West Wickham BR4 9HT (“HoursBack”), and the client named in the statement of work that incorporates this agreement (“the Client”).
In this agreement. “Personal Data”, “controller”, “processor”, “process” and “personal data breach” have the meanings given in the UK GDPR. “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. “Services” means the services described in the statement of work. “Report” means the written report produced under it. “Working Day” means a day other than a Saturday, Sunday or bank holiday in England. “Annexe” means the annexe to this agreement, as completed by the statement of work.
1. Roles
The Client is the controller of the Personal Data processed under the statement of work, and HoursBack is the processor. That includes Personal Data relating to contractors and other non-employees whom the Client nominates to take part.
2. Particulars of the processing
Subject matter. Interviewing the people the Client nominates about how they work, and producing the Report.
Duration. From the first diagnostic session until the Personal Data is deleted or returned under paragraph 9.
Nature and purpose. Recording and transcribing video sessions, reading questionnaire answers, and analysing both in order to:
- produce the Report on where time and effort go in the Client’s business and what could be automated;
- where the statement of work provides for it, produce participant-level output for an individual participant and deliver it to that participant through an access-controlled link; and
- where the statement of work provides for it, make that same participant-level output available to the people the Client names, through an access-controlled view, on the basis that they see identical content to the participant. There is no separate or fuller version.
Participant-level output is a review of the role and its tasks. It is not an evaluation of the person, and paragraph 3.3 limits what it may be used for. HoursBack carries out this processing as processor on the Client’s documented instructions. The Client, as controller, remains responsible for the lawful basis and for any transparency notice.
Categories of Personal Data. Names, job roles, work email addresses, voice recordings, transcripts, and what each participant says about their own working day. HoursBack does not request special category data, performance records, salary or HR records, and will exclude any such data disclosed unprompted from the Report.
Data subjects. Employees, officers and contractors of the Client whom it nominates for interview, currently those identified in the Annexe. The Client will notify any change in writing and no amendment to this agreement is required.
3. The Client’s obligations
3.1 The Client confirms that it has identified and recorded a lawful basis for the processing, that it has given the participants the information required by Articles 13 and 14 UK GDPR, that its instructions comply with data protection law, and that it will not instruct HoursBack to process special category data.
3.2 Lawful basis. The Client decides and records the lawful basis. HoursBack does not decide it, and nothing in this agreement is legal advice. HoursBack’s understanding is that in an employer-employee relationship consent is often not the strongest basis, because staff may not feel free to refuse without risk of detriment, and a consent that is not freely given is not valid consent. The more defensible route is usually legitimate interests under Article 6(1)(f) supported by a clear transparency notice that tells the participant what will be processed, why, and what they will receive. Where a tick-box is used on a pre-session form, HoursBack will draft it as an acknowledgement that the participant has read the notice (“I understand”), not as a consent gate (“I agree”), unless the Client’s data protection function confirms that consent is the right basis. HoursBack will not finalise participant-facing wording until the Client has confirmed the basis in writing.
3.3 Use of participant-level output. Where the Services produce participant-level output, the Client will use it for the purposes of the engagement only. It will not use it as an input to performance management, appraisal, disciplinary or headcount decisions. HoursBack tells participants that the work is a review of the role and not an assessment of them; this restriction is what makes that statement true.
3.4 Impact assessment screening. Where the Services produce individually attributable findings about how a person spends their working time, and people the Client names can see those findings, the processing is monitoring-adjacent. Systematic monitoring of employees is one of the Information Commissioner’s screening factors for a data protection impact assessment. The Client’s data protection function will make and record a screening decision rather than skip it. HoursBack will assist under paragraph 10.3.
4. Instructions
HoursBack will process the Personal Data only on the Client’s documented instructions, including as to any transfer outside the UK; the statement of work, this agreement and the transfers at paragraph 8 constitute those instructions. If domestic law requires HoursBack to process otherwise, it will inform the Client first, unless that law prohibits it on important grounds of public interest. If HoursBack considers an instruction to infringe data protection law, it will inform the Client immediately.
5. Confidentiality of personnel
Every person at HoursBack with access to the Personal Data is bound by an obligation of confidentiality. HoursBack is a one-person business: David Bevan alone conducts the sessions and writes the Report.
6. Security
HoursBack will implement the technical and organisational measures required by Article 32 UK GDPR, appropriate to the risk. They include:
- access limited to David Bevan, with no shared login and no outsourced support;
- multi-factor authentication on the accounts through which that access is exercised;
- full-disk encryption on the devices used to process the Personal Data;
- unique credentials for each service, held in a password manager;
- encryption in transit (HTTPS/TLS) for all traffic to and from HoursBack’s systems;
- storage of questionnaire answers, transcripts and report content in Supabase, hosted in the EU and encrypted at rest by the provider;
- access control on the administration area by password and signed session cookie, and on a client’s report pages by a six-character passcode issued only to that client;
- CSRF protection and rate limiting on public forms;
- no storage of card or bank details on HoursBack’s own systems; and
- no transmission of recordings or transcripts as attachments by ordinary email.
HoursBack will notify the Client if these measures materially change, and will give further detail on request.
7. Sub-processors
7.1 The sub-processors authorised for an engagement are those listed in the Annexe, and that list is the complete set authorised for it.
7.2 HoursBack will not add or replace a sub-processor without at least 14 days’ written notice. The Client may object within that period, and if it does HoursBack will not make the change. If that prevents delivery, either party may terminate the statement of work, with no charge for work not yet done.
7.3 HoursBack will impose data protection obligations equivalent to those in this agreement on each sub-processor by written contract, and remains liable to the Client for each sub-processor’s performance of them.
8. International transfers
8.1 Some sub-processors are established outside the UK. The table in the Annexe names, for each one, what it handles, where it is, and the transfer safeguard relied on for it.
8.2 HoursBack will put an appropriate transfer mechanism in place before any Personal Data is transferred outside the UK. Each transfer is made under the mechanism in that sub-processor’s own data processing agreement, being the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the EU standard contractual clauses, or the UK-US Data Bridge where that sub-processor is self-certified to it.
8.3 HoursBack will give the safeguard documentation for a sub-processor on request, and will accommodate the specific transfer-mechanism documentation the Client’s data protection function requires. HoursBack does not represent that the Personal Data remains in the UK.
9. Deletion and return
9.1 On termination, or on the Client’s written request at any time, HoursBack will delete or return the questionnaire answers, recordings, transcripts, report material, any participant-level output and the access codes issued for any of it, at the Client’s choice, and delete existing copies, including any working archive held with a sub-processor listed in the Annexe and any recording retained by the video platform. It will do so within 30 days and confirm in writing.
9.2 If the Client does not state its choice, HoursBack will hold the material for the default retention period stated in the Annexe, running from delivery of the Report, and then delete it. The Client may require earlier deletion at any time.
9.3 HoursBack will retain only what domestic law requires, and only for as long as it requires.
10. Assistance
10.1 If a data subject exercises a right under Chapter III UK GDPR, including access, rectification, erasure, restriction, portability or objection, HoursBack will pass the request to the Client within two Working Days and assist the Client in responding.
10.2 On becoming aware of a personal data breach, HoursBack will notify the Client without undue delay and give the information it holds - what happened, who is affected, what data is involved, the likely consequences and the measures taken - sufficient for the Client’s obligations under Articles 33 and 34 UK GDPR.
10.3 HoursBack will assist the Client with any data protection impact assessment or consultation with the Information Commissioner relating to the Services.
11. Audit
HoursBack will make available the information the Client reasonably requires to demonstrate compliance with this agreement, and will allow for and contribute to an audit or inspection by the Client or an auditor it appoints, on reasonable written notice, in working hours, no more than once a year unless there has been a personal data breach. It need not disclose anything that would compromise another client’s confidentiality.
12. Liability
HoursBack’s liability under this agreement is limited as set out in the statement of work that incorporates it. Nothing in this agreement limits any liability HoursBack owes directly to an individual under data protection law.
13. Precedence and changes
13.1 This agreement prevails over HoursBack’s published privacy policy. Where the statement of work and this agreement conflict, the statement of work prevails.
13.2 The version of this agreement that applies to an engagement is the version identified in the statement of work. Later changes to this page do not apply to that engagement unless both parties agree in writing.
13.3 Where the document incorporating this agreement is signed electronically, it is in writing in electronic form for the purposes of Article 28(9) UK GDPR.
13.4 If the Client prefers to use its own data processing agreement, the parties will use it instead, provided it works with the sub-processors listed in the Annexe and does not extend HoursBack’s liability beyond the limit in the statement of work, whether by an uncapped data protection indemnity, a data-breach losses provision or otherwise. Where the two conflict, the statement of work prevails on fees, liability and scope, and the Client’s agreement prevails on data protection terms.
Annexe - engagement particulars
The statement of work completes this annexe. Where it is silent, the defaults below apply.
Data subjects. The participants named or described in the statement of work.
Default retention period (paragraph 9.2). 24 months from delivery of the Report.
Sub-processors (paragraph 7). The standard set is:
| Sub-processor | Processing | Location | Transfer safeguard |
|---|---|---|---|
| Cal.com | Booking; participant name, email address, booking-form answers | US | Cal.com’s standard data processing agreement. HoursBack has requested the executed copy and, until that is confirmed, relies on the general position in paragraph 8.2 |
| Zoom | Session video and auto-generated transcript | US | The EU standard contractual clauses and the UK Addendum, under Zoom’s Global DPA, which is incorporated into Zoom’s terms for all customers |
| Supabase | Database and storage; questionnaires, transcripts, report content, participant-level output and access codes | EU-hosted | Within the EEA. No UK transfer safeguard required |
| Anthropic, PBC (Claude API) | Drafting the Report from the questionnaires and transcripts. No training on API data | US | The EU standard contractual clauses and the UK Addendum, under Anthropic’s data processing addendum. Anthropic is also self-certified to the UK-US Data Bridge |
| Resend | Transactional email to participants; email address, email content, delivery and click status | Ireland (eu-west-1) | Hosted in the EEA. Resend’s own data processing terms and the standard contractual clauses cover any access from its US entity |
| Google Workspace (Drive) | Working archive; copy of transcripts, questionnaires and Report on sending. Held on HoursBack’s Google Workspace account, accessed by a Google Cloud service account, not a consumer Google account | Globally distributed; no single guaranteed residency | Google’s EU and UK data protection terms under the Google Cloud Data Processing Addendum, entered into with Google Cloud EMEA Limited, incorporating the EU standard contractual clauses and the UK International Data Transfer Addendum. Google is certified to ISO/IEC 27001 and SOC 2 Type II |
| Vercel | Hosting of the website, its serverless functions and any access-controlled report or dashboard view | US | The UK International Data Transfer Addendum to the EU standard contractual clauses, under Vercel’s data processing addendum |
Stripe and PostHog appear in HoursBack’s privacy policy. They are used only where the statement of work says so, and are not part of the standard set above.
Additions or removals for this engagement. As stated in the statement of work.
Contact
Questions about this agreement, or a request for a sub-processor’s safeguard documentation: email hello@hoursback.co.uk. These terms sit alongside our terms of service and our privacy policy.