ORG HEALTH CHECK - Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into between Org Health Check Ltd ("Processor", "we", "us"), company number 17381071, and the client organisation identified in the applicable order form ("Controller", "Client", "you"). This DPA is a contractual addendum to, and forms part of, the SaaS Terms of Service. Capitalised terms not defined here have the meaning given in the Terms.

This DPA reflects the requirements of UK GDPR (the retained EU General Data Protection Regulation as it forms part of UK law) and the Data Protection Act 2018.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in UK GDPR. "Client Personal Data" means personal data uploaded to the Platform by or on behalf of the Client, principally relating to the Client's employees.

2. Roles of the Parties

2.1 The Client is the Controller of Client Personal Data uploaded to the Platform. The Client determines the purposes and means of that processing, including what data to upload and the lawful basis for doing so, and warrants that it has, and will maintain, a valid lawful basis for such uploads, including informing its employees as required under UK GDPR.

2.2 Org Health Check is the Processor and will process Client Personal Data only on the Client's documented instructions, as set out in this DPA, the Terms of Service, and any subsequent written instructions, unless required to do otherwise by law (in which case we will inform the Client before processing, unless prohibited from doing so).

2.3 For billing and account administration data relating to the Client's own personnel who use the Platform (e.g. named account administrators), Org Health Check acts as an independent Controller, as set out in the Privacy Policy (Document 3).

3. Nature and Purpose of Processing

3.1 Processing is carried out to provide the Org Health Platform: ingesting workforce data, calculating organisational metrics, generating AI-assisted narrative insights, and presenting these via a client-specific dashboard.

3.2 Categories of Data Subjects: the Client's current (and, where uploaded, former) employees.

3.3 Categories of Personal Data: name, job title, department, manager/reporting line, salary or salary band, tenure/start date, and location, together with any other fields the Client includes in its CSV upload. The Client must not upload special category data (e.g. health, ethnicity, religion, trade union membership); the Platform is not designed for such data and the Client warrants it will not upload it.

3.4 Duration: for the term of the Client's subscription, plus the 30-day post-termination retention period in clause 8.

4. AI Processing Safeguard

4.1 Raw, identifiable Client Personal Data (e.g. employee names) is processed only within the isolated database layer to calculate aggregated metrics, and is never transmitted to the AI sub-processors listed in clause 6.

4.2 Only aggregated, de-identified organisational data (e.g. departmental averages, span-of-control statistics, headcount by layer) is sent to Anthropic's Claude API for narrative generation and job title classification.

4.3 Job title classification via Anthropic's Claude API may involve individual job titles but not names or other direct identifiers.

4.4 We do not use Client Personal Data to train underlying third-party foundation models.

4.5 We have executed Anthropic's own standard commercial API-tier terms directly with Anthropic, under which they act as our sub-processor and confirm they do not use data submitted via their API to train their models. Copies of the relevant provider terms can be made available to the Client on reasonable request for audit purposes under clause 9. We will notify the Client if Anthropic's position changes materially.

5.1 Processor Obligations (UK GDPR Article 28)

Org Health Check will:
  (a) process Client Personal Data only on documented instructions from the Client, including regarding international transfers, unless required otherwise by law;
  (b) ensure persons authorised to process Client Personal Data are subject to confidentiality obligations;
  (c) implement appropriate technical and organisational security measures (clause 7);
  (d) not engage another processor (sub-processor) without the general authorisation described in clause 6;
  (e) assist the Client, insofar as reasonably possible, in responding to Data Subject rights requests and in meeting its obligations under Articles 32–36 UK GDPR;
  (f) notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data (clause 10);
  (g) make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described in clause 9;
  (h) at the Client's choice, delete or return all Client Personal Data at the end of the subscription, subject to clause 8.

5.2 Chargeable Assistance for Data Subject Requests: To the extent that the Client requests manual, complex, or extensive administrative or engineering assistance from Org Health Check to respond to a Data Subject Request (such as a Subject Access Request or erasure request under Articles 15 or 17 UK GDPR), and such assistance goes beyond standard self-service platform features or automated reports, Org Health Check reserves the right to charge the Client for its reasonable time and materials at its standard professional services rate of £150 per hour (plus VAT), provided that Org Health Check: (a) provides the Client with a written estimate of the anticipated time and costs; and (b) obtains the Client's prior written approval before commencing such work.

6. Sub-processors — General Written Authorisation

6.1 The Client provides general written authorisation for Org Health Check to engage the sub-processors listed in the table below, and to add, remove, or replace sub-processors from time to time, without obtaining the Client's prior individual approval for each change, subject to the process in this clause 6.

6.2 We will maintain an up-to-date list of sub-processors. Where we intend to add or replace a sub-processor with access to Client Personal Data, we will notify the Client (by email or in-app notice) at least 14 days before the change takes effect.

6.3 The Client may object to a new sub-processor on reasonable data protection grounds by written notice within that 14-day window. If the Client objects, the parties will discuss in good faith; if the concern cannot be resolved, the Client may terminate the affected part of the Service (or, if the sub-processor is integral to the Service, the subscription as a whole) without penalty, by written notice, effective before the new sub-processor is engaged in relation to that Client's data.

6.4 Current sub-processors as at the date of this DPA:

Sub-processor Purpose Location / Transfer Mechanism
Airtable (Formagrid Inc.) Primary database — client workforce data US. Transfer covered by Airtable's standard DPA, which incorporates the EU SCCs and UK SCCs (UK Addendum) — executed directly with Airtable, no Enterprise plan required.
Make (Celonis / Integromat) Automation and pipeline orchestration EU. UK-EU transfer covered by UK adequacy regulations — no SCC/IDTA required.
Noloco Client-facing dashboard hosting EU/UK
Anthropic (Claude API) AI narrative generation — aggregated, de-identified data only US — UK IDTA / SCCs or UK-US Data Privacy Framework (UK-US Data Bridge).
Stripe Billing and subscription payment processing UK/EU (Stripe Payments UK Ltd / Stripe Payments Europe Ltd); PCI-DSS Level 1 compliant — cardholder data is tokenised and handled by Stripe directly, not by Org Health Check.

6.5 We remain fully liable to the Client for the acts and omissions of our sub-processors as if they were our own acts and omissions, and impose data protection obligations on sub-processors no less protective than those in this DPA.

7. Security Measures

We maintain technical and organisational measures appropriate to the risk, including:
  (a) encryption of data in transit (TLS) and at rest, to the extent supported by each sub-processor;
  (b) per-client data isolation — each client's data is held in a dedicated, separate database with no cross-client access;
  (c) role-based access controls limiting internal access to personnel who need it to deliver the Service;
  (d) the AI processing safeguard in clause 4, which minimises personal data exposed to third-party AI models;
  (e) regular review of sub-processor security and data handling practices.

8. Retention and Deletion

8.1 Retention and Deletion: Upon the termination or expiry of the subscription (for Subscription Model clients) or the expiry of the 14-day One-Off Access Window (for One-Off Report Model clients), we shall retain the Client Personal Data for a strict period of thirty (30) days to permit export or reactivation. Upon the expiry of this 30-day period, we shall permanently delete all Client Personal Data from our active production systems, unless required by applicable law to retain copies of such data.

9. Audit Rights

On reasonable written notice (at least 30 days, no more than once per 12-month period, unless required following a Personal Data Breach or by a supervisory authority), the Client may request evidence of compliance with this DPA. Given the scale of our operations, on-site audits are not offered as standard, but we will engage in good faith to satisfy reasonable Controller obligations under Article 28(3)(h), including by providing summaries of security practices, relevant sub-processor certifications, and the provider terms referenced in clause 4.5.

10. Personal Data Breach

10.1 We will notify the Client without undue delay, and in any event within 72 hours of becoming aware, of any confirmed Personal Data Breach affecting Client Personal Data, providing information reasonably available to help the Client meet its own notification obligations under Articles 33–34 UK GDPR

10.2 We will take reasonable steps to contain, investigate, and remediate any such breach, and will keep the Client informed of material developments.

11. International Transfers

11.1 Make (our automation layer) stores and processes Client Personal Data within the European Union. Transfers of Client Personal Data from the UK to the EU are covered by the UK's own adequacy regulations in respect of the EEA, so no separate Standard Contractual Clauses or International Data Transfer Addendum are required for this transfer specifically.

11.2 Where Client Personal Data is transferred outside the UK and the EEA — including to US-based sub-processors listed in Schedule 1 (Airtable, Anthropic, Vercel) — we will ensure an appropriate transfer mechanism is in place before the transfer occurs. For Airtable specifically, this is achieved by executing Airtable's own standard Data Processing Addendum, which incorporates both the EU Standard Contractual Clauses and the UK Standard Contractual Clauses (UK Addendum) and is available to customers on any plan tier, not only Enterprise Scale. For Anthropic and Vercel, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or, where the relevant sub-processor is a certified participant, the UK Extension to the EU-US Data Privacy Framework ("UK-US Data Bridge").

11.3 In addition to the contractual safeguard, we maintain a Transfer Risk Assessment for transfers to the United States, documenting that the nature of Client Personal Data processed (organisational and role data, excluding special category data) supports the appropriateness of the safeguards in clause 11.2.

12. Assistance with Data Subject Rights

Where we receive a request directly from a Data Subject regarding Client Personal Data, we will promptly forward it to the Client and will not respond directly (other than to confirm receipt and redirect the individual), unless instructed otherwise. We will provide reasonable assistance to the Client in fulfilling such requests.

13. Liability Alignment

13.1 Any financial liability, loss, cost, or indemnity arising out of or in connection with this DPA — including in respect of any Personal Data Breach, regulatory fine, or third-party claim relating to Client Personal Data, and including any liability connected to AI-generated Output under clause 4 of this DPA and clause 10 of the Terms of Service — is strictly subject to, capped by, and aggregated with (not additional to) the limitation of liability set out in clause 13 of the Terms of Service.

13.2 For the avoidance of doubt, there is no separate, uncapped, or unlimited liability for data protection breaches or AI-related claims under this DPA; all such liability falls within, and counts towards, the single aggregate cap in clause 13.1 of the Terms of Service.

13.3 Nothing in this clause 13 limits either party's own direct regulatory liability to the Information Commissioner's Office or affected Data Subjects, which exists independently of this Agreement and cannot be limited as between the parties by contract.

14. Term

This DPA takes effect on the date the Client's subscription commences and remains in effect for as long as we process Client Personal Data on the Client's behalf, including during the post-termination retention window in clause 8.

15. Contact

Data protection queries relating to this DPA can be sent to info@orghealthcheck.co.uk.