Legal

Data Processing Agreement

Data Processing Agreement

The processor terms that apply whenever Yardstick handles personal data on a customer’s behalf. This DPA forms part of the Terms of Service.

Last updated

19 September 2026

Effective

1 October 2026

Version

1.0

01

Roles and scope

For candidate and employee personal data processed in the workspace, the customer is the controller and Yardstick is the processor. For account and billing data about the customer’s own staff, Yardstick is the controller and the Privacy Policy applies instead.

This DPA applies automatically to every customer. You do not need to sign a separate copy, though we will sign one on request.

02

Definitions

Controller, processor, personal data, processing, data subject and supervisory authority carry the meanings given in the GDPR. Customer Personal Data means personal data the customer or its users put into the service.

Applicable Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP, and any other law governing the processing under this agreement.

03

Processing instructions

We process Customer Personal Data only on the customer’s documented instructions. The Terms of Service, this DPA, and the configuration of the workspace together make up those instructions.

If we believe an instruction breaches Applicable Data Protection Law we will say so before acting on it. If we are legally required to process data beyond the instructions, we will tell the customer first unless the law forbids it.

04

Confidentiality

Everyone we allow near Customer Personal Data is bound by a written confidentiality obligation that survives the end of their engagement, and is trained on handling it.

Access is granted on a need-to-know basis, reviewed quarterly, and revoked the day someone leaves.

05

Security measures

We maintain technical and organisational measures appropriate to the risk, described in Annex II and summarised here.

  • Encryption in transit with TLS 1.2 or better, and at rest with AES-256.

  • Role-based access control, mandatory multi-factor authentication, and hardware keys for production access.

  • Segregated environments, with no customer data in development or test.

  • Logging and alerting on access to production data, retained for twelve months.

  • Annual penetration testing by an independent party, and a documented vulnerability management process.

06

Sub-processing

The customer gives general authorisation for us to engage sub-processors. Our current list is published on the sub-processors page, and every sub-processor is bound by written terms no less protective than this DPA.

We give thirty days notice before adding or replacing a sub-processor. A customer who reasonably objects on data protection grounds within that window may terminate the affected part of the service without penalty.

07

Data subject requests

The product lets customers find, export, correct and delete personal data without our help. Where a request cannot be handled in the product, we will assist, taking account of the nature of the processing.

If a data subject contacts us directly we will not answer on the customer’s behalf. We will forward the request without undue delay and tell the customer we have done so.

08

Personal data breach

We will notify the customer without undue delay, and in any case within seventy-two hours of becoming aware of a personal data breach affecting Customer Personal Data.

The notice will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken. We will send what we know at the time rather than waiting to be complete, and follow up as we learn more.

09

International transfers

Customer Personal Data is hosted in the European Union by default. Where a transfer outside the EEA is necessary, it is made under the Standard Contractual Clauses, which are incorporated into this DPA by reference, with the UK Addendum where the UK GDPR applies.

Module Two applies where the customer is a controller and we are a processor. Module Three applies between us and an onward sub-processor. Annex I sets out the parties, the processing, and the competent supervisory authority.

10

Audit, deletion and return

On request we provide our current security documentation, penetration test summary, and the answers to a reasonable security questionnaire once a year. A customer who needs more may audit us on thirty days notice, at their own cost, no more than once a year unless a regulator requires otherwise.

On termination we delete or return Customer Personal Data at the customer’s choice, within ninety days, unless the law requires us to keep it. Backups age out within a further thirty days.

All policies

How we handle personal data

The contract for using Yardstick

What we set in your browser

Our processor terms for customers

Third parties that touch customer data

Create a free website with Framer, the website builder loved by startups, designers and agencies.