Data processing agreement
Last updated 1 September 2026 · Effective On publication, following legal review · Version 1.0-draft
Draft — not yet reviewed by counsel.
This document is published so it can be read and corrected. It has not been through legal review and it does not yet bind anyone. If you are evaluating Rutba and need agreed terms, ask us and we will tell you where the review stands.
The short version
1. Scope and roles
This agreement applies where Rutba of Registered address available on request (“processor”) processes personal data on behalf of a customer (“controller”) in providing the Rutba platform. It gives effect to Article 28 of the UK GDPR and of Regulation (EU) 2016/679, and to equivalent obligations under other applicable data-protection law.
It does not cover personal data for which we are the controller — who signed up, who is billed, who raised a ticket. The privacy policy covers that, and section 1 of it explains the distinction.
It is incorporated into the terms of service and takes effect with them. Nothing has to be signed for it to bind us.
2. Processing on your instructions
We process personal data only on your documented instructions, which are: the terms of service, this agreement, the configuration you set in the products, and any further written instruction you give us.
If we believe an instruction breaches data-protection law, we will tell you rather than carry it out silently. If the law requires us to process beyond your instructions, we will tell you before doing so unless that law forbids it.
We do not use your data for our own purposes. Not to advertise, not to sell, not to train models, not to build a product. Aggregated operational statistics contain nothing identifying you, your users or your data subjects.
3. Annex A — what is processed
| Item | Detail |
|---|---|
| Subject matter | Provision of the Rutba products the controller subscribes to |
| Duration | For as long as the subscription is live, plus the export window and retention periods in section 11 |
| Nature and purpose | Hosting, storage, transmission, indexing, rendering, backup and restoration; and for the messaging products, sending and receiving on the controller’s behalf |
| Categories of data subject | The controller’s customers, prospects, employees, contractors, suppliers, and anyone else whose data it chooses to put into the platform |
| Categories of personal data | Contact and identity data, transaction and financial records, employment and payroll data where the HR products are used, correspondence and message content where the workspace products are used, files and documents, and technical identifiers |
| Special category data | Only where the controller chooses to enter it — for example health or trade-union data in HR records. Determining lawfulness is the controller’s responsibility. |
4. Confidentiality of personnel
Everyone we authorise to process personal data is bound by a duty of confidentiality that survives their engagement, and is given access only to what their role requires. Access for support purposes is logged to an audit trail available to you.
5. Security measures
We implement appropriate technical and organisational measures, including:
- encryption in transit (TLS 1.3) and at rest (AES-256), with keys rotated quarterly
- single sign-on with multi-factor authentication, and role-based access derived from organization membership
- tenant isolation: each organization’s records are separated at the data layer, and requests carry an organization context that the gateway verifies rather than trusts
- audit logging of administrative actions, permission changes and support access
- encrypted backups with a 35-day window, and tested restoration
- vulnerability management, dependency scanning, and patching on a defined schedule
- separation of production from development and test environments
The trust centre carries the current detail and states our certification position honestly. A completed security questionnaire is available on request.
6. Sub-processors
You give general authorisation for us to engage sub-processors. Every one is listed at /legal/sub-processors, with what it does and where it processes.
We will give 30 days’ notice before adding or replacing one. If you reasonably object on data-protection grounds within that period, we will work with you to find an alternative; if there is none, you may terminate the affected subscription and receive a refund of the unused prepaid portion.
Each sub-processor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
7. International transfers
Processing takes place primarily in the United Kingdom and the European Economic Area. Where personal data is transferred outside those, the transfer relies on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses — which are incorporated into this agreement by reference and completed with us as data importer and you as data exporter, together with a transfer risk assessment.
The sub-processor list names the processing location for each entry.
8. Assistance with your obligations
Taking into account the nature of the processing, we will assist you with:
- Data subject requests. The products give you the tools to find, correct, export and delete records yourself. Where a request cannot be answered that way, we will help. If a data subject comes to us directly, we will not answer on your behalf — we will refer them to you and tell you.
- security of processing, breach notification, and data protection impact assessments
- prior consultation with a supervisory authority, where one is required
9. Personal data breaches
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with what we know at the time: what happened, which categories and roughly how many records and data subjects are involved, the likely consequences, and what we are doing about it.
We will keep you updated as the picture develops, and we will not delay an initial notification in order to send a complete one.
10. Audit and information
We will make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits.
In practice: our security documentation and completed questionnaires satisfy most requests, and we would rather answer yours than have you take our word for it. Where you reasonably require an on-site or remote audit, we will agree scope and timing, no more than once in any twelve months except after a breach or where a regulator requires it, and each of us bears its own costs.
11. Return and deletion
You can export your data at any time while the subscription is live. After it ends, the data remains available for export for 30 days, after which we delete it. Encrypted backups age out within a further 35 days.
On written request we will confirm deletion. We keep data beyond these periods only where the law requires us to, and only for as long as it does.
12. Liability and precedence
The limitations of liability in the terms of service apply to this agreement, except where data-protection law does not permit them.
Where this agreement conflicts with the terms of service on the processing of personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail. This agreement is governed by the law of England and Wales.
13. Signing this
You do not need to. It applies automatically as part of the terms of service, and it is drafted to be signable exactly as it stands.
If your procurement process requires a countersigned copy, or your own paper, write to privacy@rutba.io and we will send one. We will also complete the Standard Contractual Clauses annexes for your jurisdiction on request.