← Back to DianDot HR

DIANDOT HR · UK GDPR

Data Processing Addendum

This DPA forms part of the DianDot HR Terms when a customer uses the service to process personal data.

Effective 29 August 2026

Parties, roles and instructions

DianDot is the trading name of a sole trader operating in England. The customer is controller and the DianDot sole trader is processor for employee and workforce data. DianDot processes that data only on documented customer instructions, including the configuration and use of the service, unless UK law requires otherwise. DianDot is controller for its own account administration, security, billing and legal-compliance records.

Processing details

SubjectHosted HR records, scheduling, attendance, leave, employee self-service, documents and support.
DurationFor the service term and the deletion/backup period described in the retention schedule.
PeopleEmployees, workers, applicants, former workers, managers, owners and authorised contacts.
DataIdentity, contact, employment, schedule, attendance, leave, payroll-adjacent identifiers, location verification results, device tokens, account events and uploaded documents. Customers should not upload data unnecessary for HR administration.
PurposeProviding, securing, maintaining and supporting the contracted DianDot HR service.

Confidentiality and security

People authorised to process customer data are subject to confidentiality obligations. DianDot maintains workspace-scoped access controls, private file storage, password hashing, secure session cookies, rate limiting, audit records, daily backups and recovery controls appropriate to the risk.

Subprocessors and transfers

The customer gives general authorisation to the subprocessors on the published list. DianDot remains responsible for appropriate processor terms and will provide notice of material new subprocessors. Where data is transferred outside the UK, DianDot will use an applicable adequacy decision or contractual safeguard.

Rights, DPIAs and regulators

Taking account of the nature of processing, DianDot will provide reasonable assistance with data-subject requests, security enquiries, DPIAs and regulator consultations. Workspace owners can export workspace data; employees should normally submit requests to their employer.

Incidents

DianDot will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer's assessment and notifications. The customer remains responsible for regulator and individual notifications unless agreed otherwise.

Deletion, return and audit

On termination or verified account deletion, DianDot will delete or return customer data except where law requires retention. Residual backup data expires within 35 days. On reasonable written request, DianDot will provide information needed to demonstrate compliance; audits must protect other customers and service security.

Contact and signed copy

This online DPA is incorporated into the Terms. For procurement questions, the sole trader's legal identity and service address, or a countersigned copy, contact [email protected].