About This DPA
This DPA applies automatically when you use Hurema to process personal data of your employees or other individuals. You are the Data Controller; Hurema is the Data Processor. This DPA is incorporated by reference into the Terms of Service.
1. Introduction
This Data Processing Addendum ("DPA") is entered into between you ("Controller", "Customer") and Hurema ("Processor") and supplements the Hurema Terms of Service ("Agreement").
This DPA applies where and to the extent that Hurema processes Personal Data on behalf of the Controller in the course of providing the Hurema HR management platform and associated services.
By using Hurema to manage employee data or other personal data, you acknowledge and agree to the terms of this DPA.
2. Definitions
In this DPA, the following terms have the meanings set out below:
- "Controller" means the entity that determines the purposes and means of processing Personal Data (i.e., the Customer).
- "Processor" means Hurema, which processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law.
- "Processing" means any operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates (e.g., an employee).
- "SubProcessor" means any third party engaged by Hurema to process Personal Data on behalf of the Controller.
- "Applicable Data Protection Law" includes GDPR (EU) 2016/679, UK GDPR, the Information Technology Act 2000 and applicable rules (India), and any other applicable data protection legislation.
- "Security Incident" means any accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of Personal Data.
3. Scope & Roles
3.1 Controller Role
The Controller determines why and how Personal Data of its employees and other data subjects is processed. The Controller is responsible for ensuring it has a valid legal basis for processing and for complying with applicable data protection law as a controller.
3.2 Processor Role
Hurema processes Personal Data strictly on the documented instructions of the Controller namely, to provide the Hurema HR platform and features the Controller uses. Hurema will not process Personal Data for any other purpose unless required by applicable law.
3.3 Compliance
Each party shall comply with its respective obligations under applicable data protection law. Hurema shall promptly inform the Controller if it believes any instruction from the Controller infringes applicable data protection law.
4. Processor Obligations
Hurema commits to the following as Data Processor:
- Process Personal Data only on documented instructions from the Controller
- Ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations
- Implement appropriate technical and organisational security measures (see Section 7)
- Assist the Controller in responding to Data Subject rights requests (see Section 9)
- Notify the Controller of any Security Incidents without undue delay (see Section 8)
- Delete or return all Personal Data upon termination of the Agreement (see Section 12)
- Provide all information necessary to demonstrate compliance with this DPA
- Not engage SubProcessors without the Controller's general or specific authorisation (see Section 6)
5. Controller Obligations
The Controller is responsible for:
- Ensuring it has a valid legal basis (e.g., employment contract, legitimate interest, or consent) for each category of Personal Data processed through Hurema
- Providing accurate and uptodate privacy notices to data subjects (employees) describing the use of Hurema
- Ensuring the accuracy and quality of Personal Data submitted to Hurema
- Complying with applicable employment laws in its jurisdiction regarding employee data
- Obtaining any necessary consents for processing sensitive or biometric data
- Configuring Hurema's access controls appropriately to limit access to Personal Data on a needtoknow basis
6. SubProcessors
The Controller provides general authorisation for Hurema to engage SubProcessors to assist in providing the Service. Hurema currently uses subprocessors for the following categories of services:
- Cloud infrastructure & hosting for storing and processing customer data
- Email delivery for sending transactional emails (payslips, notifications)
- Analytics for anonymised platform usage analysis
- Customer support tooling for managing support tickets
Hurema shall: (a) impose data protection obligations on all SubProcessors equivalent to those in this DPA; (b) remain liable to the Controller for SubProcessor failures; and (c) maintain and publish an uptodate list of SubProcessors on request.
Hurema will provide at least 14 days' notice of any new SubProcessor. If the Controller objects to a new SubProcessor, it may terminate the relevant service by written notice within the notice period.
7. Technical & Organisational Security Measures
Hurema implements and maintains the following security measures to protect Personal Data:
7.1 Encryption
- Data at rest: AES256 encryption
- Data in transit: TLS 1.2 or higher (HTTPS enforced)
- Passwords: bcrypt hashing with individual salts
7.2 Access Controls
- Role-based access control (RBAC) with least-privilege principles
- Multifactor authentication available for all accounts
- Privileged access to production systems restricted to vetted personnel
- Access to production data requires approval and is logged
7.3 Availability & Resilience
- Automated daily backups with geographically distributed storage
- Redundant cloud infrastructure with automatic failover
- Disaster recovery procedures with defined recovery time objectives
7.4 Monitoring & Testing
- Continuous security monitoring and intrusion detection
- Comprehensive audit logs of all data access and modification events
- Regular vulnerability scanning and penetration testing
- Security incident response procedures
8. Security Incident Notification
In the event of a confirmed Security Incident affecting Personal Data processed under this DPA, Hurema will:
- Notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of the incident
- Provide all available information about the nature of the incident, categories of data affected, estimated number of data subjects affected, likely consequences, and measures taken or proposed
- Cooperate fully with the Controller's response and mitigation efforts
- Not make public disclosures about the incident without prior agreement with the Controller (unless required by law)
The Controller is responsible for notifying relevant supervisory authorities and data subjects as required by applicable law.
9. Data Subject Rights Assistance
Hurema will assist the Controller in fulfilling its obligations to respond to Data Subject rights requests, including rights of access, rectification, erasure, restriction, portability, and objection. Hurema will:
- Provide tools within the Hurema platform for Controllers to access, export, correct, and delete employee Personal Data
- Forward any Data Subject rights requests received directly by Hurema to the Controller within 5 business days
- Not respond directly to Data Subject rights requests without prior instruction from the Controller (except where required by law)
10. International Data Transfers
Where Personal Data is transferred outside the country of origin or the EEA, Hurema will ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) adopted by the European Commission for EEA transfers
- UK International Data Transfer Agreements (IDTA) for UK transfers
- Equivalent transfer mechanisms as required by applicable law
Details of transfer mechanisms for specific subprocessors are available on request.
11. Audit Rights
Hurema will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable written notice (at least 30 days), and no more than once per calendar year, Hurema will allow the Controller (or a mutually agreed thirdparty auditor) to conduct an audit of Hurema's data processing activities relevant to this DPA. The Controller shall bear the reasonable costs of any such audit.
Hurema may satisfy audit requests by providing relevant certifications, thirdparty audit reports, or security documentation in lieu of an onsite audit.
12. Return & Deletion of Data
Upon termination or expiry of the Agreement, or upon the Controller's written request, Hurema will:
- Provide the Controller with a complete data export in CSV or standard machinereadable format within 30 days
- Securely delete all Personal Data from Hurema systems (including backups) within 90 days of termination, unless longer retention is required by applicable law
- Provide written confirmation of deletion upon request
Schedule A: Details of Processing
| Category |
Details |
| Subject matter | HR management services including employee records, payroll, attendance, leave, performance, and access control |
| Duration | For the duration of the Agreement and 90 days post-termination |
| Nature of processing | Collection, storage, retrieval, use, structuring, display, and deletion of Personal Data via the Hurema platform |
| Purpose | To provide HR management software services as described in the Hurema Terms of Service |
| Data categories | Name, contact details, employment details, salary & compensation, attendance records, leave records, performance data, identification documents, emergency contacts. Potentially: health data (sick leave), biometric data (if device integration used - stored on-device only) |
| Data subjects | Employees, contractors, and other workers of the Controller |
| Special categories | Health data (for sick leave); biometric data only if device integration is used (stored locally on device, not transmitted to Hurema cloud) |
Questions about this DPA?
If you need a signed copy of this DPA, require amendments for specific compliance needs, or have questions about our data processing practices, please contact us.