DIANDOT HR · UK GDPR
Data Processing Addendum
This DPA forms part of the DianDot HR Terms when a customer uses the service to process personal data.
Effective 29 August 2026
Parties, roles and instructions
DianDot is the trading name of a sole trader operating in England. The customer is controller and the DianDot sole trader is processor for employee and workforce data. DianDot processes that data only on documented customer instructions, including the configuration and use of the service, unless UK law requires otherwise. DianDot is controller for its own account administration, security, billing and legal-compliance records.
Processing details
| Subject | Hosted HR records, scheduling, attendance, leave, employee self-service, documents and support. |
|---|---|
| Duration | For the service term and the deletion/backup period described in the retention schedule. |
| People | Employees, workers, applicants, former workers, managers, owners and authorised contacts. |
| Data | Identity, contact, employment, schedule, attendance, leave, payroll-adjacent identifiers, location verification results, device tokens, account events and uploaded documents. Customers should not upload data unnecessary for HR administration. |
| Purpose | Providing, securing, maintaining and supporting the contracted DianDot HR service. |
Confidentiality and security
People authorised to process customer data are subject to confidentiality obligations. DianDot maintains workspace-scoped access controls, private file storage, password hashing, secure session cookies, rate limiting, audit records, daily backups and recovery controls appropriate to the risk.
Subprocessors and transfers
The customer gives general authorisation to the subprocessors on the published list. DianDot remains responsible for appropriate processor terms and will provide notice of material new subprocessors. Where data is transferred outside the UK, DianDot will use an applicable adequacy decision or contractual safeguard.
Rights, DPIAs and regulators
Taking account of the nature of processing, DianDot will provide reasonable assistance with data-subject requests, security enquiries, DPIAs and regulator consultations. Workspace owners can export workspace data; employees should normally submit requests to their employer.
Incidents
DianDot will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer's assessment and notifications. The customer remains responsible for regulator and individual notifications unless agreed otherwise.
Deletion, return and audit
On termination or verified account deletion, DianDot will delete or return customer data except where law requires retention. Residual backup data expires within 35 days. On reasonable written request, DianDot will provide information needed to demonstrate compliance; audits must protect other customers and service security.
Contact and signed copy
This online DPA is incorporated into the Terms. For procurement questions, the sole trader's legal identity and service address, or a countersigned copy, contact [email protected].