Data protection terms
WorkPulse Data Processing Addendum
The terms that apply when WorkPulse processes personal data in Customer Content on behalf of a Customer.
Last updated: 26 August 2026
1. Definitions and order of precedence
Customer Content has the meaning given in the Terms of Service. Data Protection Laws means applicable laws governing personal data, including the UK GDPR, the EU GDPR where applicable, and laws implementing or supplementing them. Terms such as controller, processor, personal data, data subject and personal data breach have the meanings given by Data Protection Laws.
If this DPA conflicts with the Terms on a matter relating to the processing of Customer Content, this DPA takes priority to the extent of the conflict.
2. Roles and instructions
The Customer determines the purposes and means of processing Customer Content and is responsible for ensuring that its instructions are lawful. WorkPulse will process Customer Content only on the Customer's documented instructions, including the Customer's use and configuration of the Service, unless Data Protection Laws require otherwise. If law requires WorkPulse to process Customer Content differently, WorkPulse will notify the Customer before doing so unless law prohibits notice.
The Customer must not instruct WorkPulse to process Customer Content in a way that infringes Data Protection Laws. WorkPulse will promptly inform the Customer if it reasonably believes an instruction infringes those laws.
3. Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the WorkPulse workforce-management, time-tracking, monitoring, communication, reporting and related support services. |
| Duration | For the subscription term and any post-termination period needed to return, delete, rotate or retain data as required by law or the applicable recovery process. |
| Nature and purpose | Hosting, storing, organising, displaying, transmitting, securing, supporting, backing up, reporting on and deleting Customer Content as selected or instructed by the Customer. |
| Data subjects | Customer personnel, employees, contractors, applicants, managers, administrators, workspace users, report recipients, customers and other individuals whose information the Customer submits or captures through the Service. |
| Personal data | Identity/contact data; account and security data; employment and work records; payroll-support data; messages and files; time, break, idle and location data; device and connection data; screenshots, recordings, key and click events, application/window-title context; and any other Customer Content. |
| Special categories | Only to the extent the Customer elects to submit, capture or make available such data. Monitoring features can incidentally capture special-category or other sensitive data in screenshots, recordings, keyboard events or window titles. |
4. Confidentiality
WorkPulse will ensure that people authorised to process Customer Content are subject to appropriate confidentiality obligations or are under an appropriate statutory duty of confidentiality.
5. Security measures
Taking account of the nature of processing, the risks to individuals and the state of the art, WorkPulse will implement appropriate technical and organisational measures designed to protect Customer Content. These measures include access controls within the Service, tenant-separated data handling, authentication controls, audit and security logging, and safeguards appropriate to the deployed hosting and storage environment. The Customer is responsible for its own user administration, device controls, lawful configuration and secure use of exports and integrations.
The Customer acknowledges the specific monitoring risks described in the Employee Monitoring Transparency Notice, especially the potential capture of typed characters, on-screen content, precise location and recordings.
6. Subprocessors
The Customer gives WorkPulse general authorisation to use subprocessors to provide the Service. WorkPulse may use hosting, database, file-storage, backup, email-delivery, notification, payment, support, AI and security providers. These can include Stripe for subscription payments, Firebase or browser-push providers for notifications, OpenAI for Customer-selected AI Time Reports, and deployment-configured storage or email providers.
WorkPulse will impose data-protection obligations on subprocessors that are materially consistent with this DPA for the processing they perform. The Customer may request current subprocessor and data-location information from support@workpulse.solutions. If a proposed subprocessor creates a material data-protection concern, the Customer may raise a reasoned written objection and the parties will work in good faith on a reasonable solution.
7. Assistance and rights requests
Taking account of the nature of processing, WorkPulse will provide reasonable assistance to enable the Customer to respond to requests from data subjects. If WorkPulse receives a request relating to Customer Content, it will direct the requester to the Customer where appropriate and will not respond except on the Customer's instructions or where required by law.
WorkPulse will provide reasonable information and assistance to the Customer in relation to data-protection impact assessments, consultations with supervisory authorities and security obligations, taking account of the information available to WorkPulse and the nature of the processing.
8. Personal data breaches
WorkPulse will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and will provide information reasonably available to it to help the Customer meet its notification obligations. The Customer is responsible for deciding whether and how to notify data subjects or authorities unless law requires WorkPulse to do so.
9. Return, deletion and backups
On termination of the Services, the Customer may request return or deletion of Customer Content, subject to the Customer's agreement, law and technical feasibility. WorkPulse will delete or return Customer Content in accordance with the Customer's documented instructions unless retention is required by law. Recovery and backup copies may remain until they are rotated or deleted in the normal course of the applicable backup process.
The Customer should request exports before its access ends and should not rely on the public data-deletion form as an automated deletion mechanism for all workforce data.
10. Audits and information
WorkPulse will make available information reasonably necessary to demonstrate compliance with this DPA. On reasonable written notice, no more than once in any twelve-month period unless a material incident justifies more frequent review, the Customer may conduct or appoint an independent auditor to conduct an audit of relevant WorkPulse processing controls. Audits must be conducted during normal business hours, avoid unreasonable disruption, protect the confidentiality and security of other customers, and be subject to reasonable confidentiality arrangements.
11. International transfers
If Customer Content is transferred outside the United Kingdom, European Economic Area or another restricted jurisdiction, the parties will use an appropriate transfer mechanism required by Data Protection Laws. If the UK International Data Transfer Addendum, EU Standard Contractual Clauses or another approved mechanism is required, the parties will execute or incorporate it on request.
12. Contact
For DPA, subprocessor or security questions, contact support@workpulse.solutions.
The Customer remains responsible for obtaining legal advice tailored to its workforce, jurisdictions, chosen monitoring features and data flows.