1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Work For Future Ltd ("Processor", "we", "us") and the Employer ("Controller", "you") and sets out the terms under which we process personal data on your behalf in connection with the Services. This DPA is designed to ensure compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any applicable data protection legislation.
2. Definitions
In this DPA: "Personal Data" means any information relating to an identified or identifiable natural person processed under this agreement; "Processing" means any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, or erasure; "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates; "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller; "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
3. Scope and Purpose
The Processor shall process Personal Data solely for the purpose of providing the Services as described in the Terms of Service, which includes hosting job listings, processing candidate applications, generating AI-powered match scores, facilitating communication between the Controller and Talent users, and providing analytics on recruitment activity. The Processor shall not process Personal Data for any other purpose unless instructed in writing by the Controller or required by applicable law.
4. Obligations of the Controller
The Controller shall: (a) ensure that the processing of Personal Data is lawful and that appropriate legal bases exist under the UK GDPR; (b) provide clear and transparent privacy notices to Data Subjects whose Personal Data is shared with the Processor; (c) ensure that instructions given to the Processor comply with applicable data protection laws; (d) promptly notify the Processor of any changes to processing instructions or data protection requirements; (e) maintain a record of processing activities in accordance with Article 30 of the UK GDPR.
5. Obligations of the Processor
The Processor shall: (a) process Personal Data only on documented instructions from the Controller, unless required by law; (b) ensure that persons authorised to process Personal Data are bound by confidentiality obligations; (c) implement appropriate technical and organisational security measures; (d) not engage Sub-Processors without prior written authorisation from the Controller; (e) assist the Controller in fulfilling its obligations regarding Data Subject rights; (f) assist the Controller with data protection impact assessments where required; (g) make available all information necessary to demonstrate compliance with this DPA.
6. Categories of Data Subjects
The Personal Data processed under this DPA relates to the following categories of Data Subjects: (a) Talent users who apply to roles posted by the Controller; (b) employees and representatives of the Controller who use the Platform; (c) individuals whose contact details are provided by the Controller for account management purposes. The Processor does not determine the categories of Data Subjects; this is determined by the Controller's use of the Services.
7. Types of Personal Data
The types of Personal Data processed may include: (a) identification data such as name, email address, and profile photograph; (b) professional data such as CV, skills, work history, education, and salary expectations; (c) cause and values preference data; (d) application and communication data; (e) usage and analytics data related to Platform interactions; (f) payment data where the Controller uses paid Services. Special category data is not intentionally processed unless the Data Subject voluntarily provides it through free-text fields.
8. Sub-Processors
The Processor maintains a list of approved Sub-Processors, available upon request. The Processor shall notify the Controller at least 30 days in advance of any intended addition or replacement of a Sub-Processor, providing the Controller an opportunity to object. If the Controller objects on reasonable grounds, the parties shall work in good faith to resolve the objection. All Sub-Processors are bound by data processing agreements imposing obligations no less protective than those in this DPA.
9. International Transfers
The Processor shall not transfer Personal Data outside the United Kingdom without ensuring appropriate safeguards are in place. Transfers to countries without an adequacy decision from the UK Secretary of State shall be subject to Standard Contractual Clauses or other approved transfer mechanisms. The Processor shall inform the Controller of any intended international transfers and the safeguards applied. A list of current transfer destinations is available upon request.
10. Security Measures
The Processor implements the following technical and organisational measures to protect Personal Data: (a) encryption of data in transit using TLS 1.3 and at rest using AES-256; (b) role-based access controls with the principle of least privilege; (c) regular security assessments and penetration testing; (d) automated vulnerability scanning and patch management; (e) secure development practices including code review and static analysis; (f) employee security awareness training; (g) incident response procedures; (h) business continuity and disaster recovery plans with regular testing.
11. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a Data Breach affecting Personal Data processed under this DPA. The notification shall include: (a) a description of the nature of the breach, including the categories and approximate number of Data Subjects and records affected; (b) the name and contact details of the Processor's data protection point of contact; (c) a description of the likely consequences of the breach; (d) a description of the measures taken or proposed to address the breach. The Processor shall cooperate with the Controller in investigating and remediating any Data Breach.
12. Data Subject Rights
The Processor shall assist the Controller in responding to Data Subject requests to exercise their rights under the UK GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor shall promptly notify the Controller if it receives a request directly from a Data Subject and shall not respond to such requests except on the Controller's instructions, unless required by law. The Processor shall implement appropriate technical and organisational measures to facilitate the Controller's obligation to respond to such requests.
13. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. The Processor shall make available all information reasonably necessary to demonstrate compliance and shall allow for and contribute to audits conducted by the Controller or an independent auditor appointed by the Controller. Audits shall be conducted with reasonable prior notice (at least 30 days), during normal business hours, and shall not unreasonably interfere with the Processor's operations. The Processor may satisfy audit requests by providing relevant third-party audit reports or certifications.
14. Data Deletion and Return
Upon termination of the Services or upon the Controller's written request, the Processor shall, at the Controller's choice, return all Personal Data to the Controller in a commonly used, machine-readable format or securely delete all Personal Data within 30 days. The Processor shall provide written confirmation of deletion upon request. The Processor may retain copies of Personal Data only where required by applicable law, and such retained data shall remain subject to the protections of this DPA.
15. Term and Termination
This DPA shall remain in effect for the duration of the Processor's processing of Personal Data on behalf of the Controller. It shall automatically terminate when the Processor ceases to process Personal Data on behalf of the Controller. The obligations of the Processor under this DPA regarding confidentiality, data deletion, and security measures shall survive termination. In the event of a conflict between this DPA and the Terms of Service, the provisions of this DPA shall prevail with respect to data protection matters.
16. Contact Us
For questions regarding this Data Processing Agreement, please contact our Data Protection Officer at dpo@workforfuture.io or write to us at Work For Future Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.