Back

Data Processing Agreement

Last updated: August 2026  ·  The Back Office Team Ltd

This Data Processing Agreement ("DPA") forms part of the Terms of Service between The Back Office Team Ltd ("Processor", "we", "us") and the business that uses the platform (the "Customer", "Controller", "you"). It governs our processing of personal data on your behalf and reflects our obligations under Article 28 of the UK GDPR and the Data Protection Act 2018. Where this DPA conflicts with the Terms of Service on the handling of personal data, this DPA prevails.

1. Roles of the Parties

For the personal data that you upload to, or generate within, the platform about your own staff, agents, and reps ("Customer Personal Data"), you are the data controller and we are your data processor. You are responsible for the accuracy and lawfulness of that data and for having a lawful basis to provide it to us. For our own account and billing data, we act as a controller in our own right, as described in our Privacy Policy.

2. Scope and Instructions

We will process Customer Personal Data only:

The subject matter, duration, nature, and purpose of the processing, together with the types of personal data and categories of data subjects, are set out in the Annex below.

3. Confidentiality

We ensure that any person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality and only accesses the data as needed to perform their role.

4. Security

We implement appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art and the risks involved. These include encrypted password storage, token-based authentication, role-based access controls, and storing each Customer's data in a separate, isolated database. Details are summarised in our Privacy Policy.

5. Sub-processors

You authorise us to engage the sub-processors listed in the Annex to help provide the platform. Each is bound by data protection obligations no less protective than those in this DPA. We remain responsible for their performance. We will give you reasonable notice of any intended change to our sub-processors, giving you the opportunity to object on reasonable data protection grounds.

6. Assistance to the Controller

Taking into account the nature of the processing, we will assist you, so far as reasonably possible, to:

7. Personal Data Breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information you reasonably need to meet your own reporting obligations to the Information Commissioner's Office and to affected individuals.

8. International Transfers

Some sub-processors store or process data outside the UK, including in the EU and the US. Where we transfer Customer Personal Data outside the UK, we rely on an appropriate safeguard such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses.

9. Deletion or Return of Data

On termination of your account, we will delete Customer Personal Data within the periods described in our Privacy Policy — generally 30 days after termination, except records we are legally required to keep for longer (such as signed agreements and billing records). On request within that window, we will make your data available for export.

10. Audits and Information

We will make available to you the information reasonably necessary to demonstrate our compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint, subject to reasonable notice, confidentiality, and frequency limits.

11. Liability and Governing Law

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of England and Wales, and disputes are subject to the exclusive jurisdiction of its courts.


Annex — Details of Processing

Subject matterProvision of The Back Office team-management platform to the Customer.
DurationFor the term of the Customer's subscription, plus the retention periods set out in the Privacy Policy.
Nature and purposeHosting, storage, display, and processing of personal data to operate the platform's features (accounts, rosters, pay and performance reporting, onboarding and training, contractor agreements, calendars, leaderboards, and communications).
Types of personal dataNames and contact details; login, access, and activity records; work performance, sales, and pay data; signed agreements and electronic signatures; profile pictures.
Categories of data subjectsThe Customer's admins, managers, team leaders, agents, and reps.

Annex — Sub-processors

ProviderPurpose
RailwayCloud hosting and database storage
ResendTransactional email delivery
StripePayment and subscription processing
Open DoorSales and venue data sync, where the Customer uses it

For any questions about this DPA, contact us at hello@the-backoffice.co.uk.