UK GDPR Data Processing Addendum (DPA)
Last updated: November 24, 2025
This GDPR Data Processing Addendum ("DPA") forms part of the Terms and Conditions or other agreement ("Agreement") between:
(1) Customer ("Controller")
(2) Fat Potato Ltd (registered in England and Wales, company number 09960235), Windsor House, Bayshill Road, Cheltenham, Gloucestershire, GL50 3AT, United Kingdom ("Processor", "Company")
This DPA ensures compliance with EU GDPR, UK GDPR, the Data Protection Act 2018, and other applicable data protection laws.
1. Definitions
Terms used in this DPA have the meanings given in the UK GDPR (as defined in s.3(10) of the Data Protection Act 2018) and the Agreement.
Key terms:
- "UK GDPR" - the United Kingdom General Data Protection Regulation, being the retained EU law version of Regulation (EU) 2016/679 as it forms part of UK law.
- "Personal Data" - any information relating to an identified or identifiable natural person.
- "Processing" - any operation performed on Personal Data.
- "Sub-processor" - a third party engaged by Processor to process Personal Data on behalf of Customer.
- "Supervisory Authority" - the Information Commissioner's Office (ICO).
2. Role of the Parties
- For Customer employee and HR-related data processed within the Service, Customer is the Data Controller and Fat Potato Ltd is the Data Processor.
- For account administration and billing data, Fat Potato Ltd may act as Data Controller as set out in the Privacy Policy.
- Where acting as Processor, Fat Potato Ltd will process Personal Data solely on documented instructions of Customer.
3. Scope, Nature, and Purpose of Processing
Processor will process Personal Data only for the following purposes:
- To provide the Chinchill.hr SaaS services.
- To support, maintain, secure, and improve the Service.
- To comply with legal obligations.
- For additional purposes expressly instructed by Customer in writing.
Processor shall not:
- sell Personal Data,
- process Personal Data for advertising or profiling unrelated to the Service,
- use Personal Data for its own analytics, except aggregated/anonymous metrics.
4. Controller Instructions
Customer's instructions are:
- those documented in the Agreement and this DPA;
- those reasonably necessary to use the Service;
- any other written instructions.
Processor shall notify Customer within 5 business days if, in its reasonable opinion, an instruction infringes UK GDPR or other applicable data protection law.
5. Confidentiality
Processor ensures that individuals authorised to process Personal Data are subject to confidentiality obligations, receive appropriate data protection training, and access Personal Data only when required to perform their duties.
6. Security Measures (Article 32 UK GDPR)
Processor shall implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication for privileged access
- Role-based access controls
- Network security and firewalls
- Logging, monitoring, and intrusion detection
- Regular vulnerability scanning and patch management
- Backup and business continuity procedures
- Secure software development practices
7. Sub-processors (Art. 28(2) UK GDPR)
Authorised Sub-processors
Customer authorises Processor to use Amazon Web Services (AWS) as the hosting provider. Customer data resides in the European Union or United Kingdom. Processor shall not instruct or configure AWS to relocate Customer data outside the European Union or United Kingdom without Customer's prior written consent.
Sub-processor Changes
Processor will notify Customer of new Sub-processors at least 30 days in advance. Customer may object on reasonable grounds related to data protection within 14 days of notification. If the objection cannot be resolved, Customer may terminate the affected services without penalty.
8. International Transfers (Ch. V UK GDPR)
Processor will not transfer Personal Data outside the European Union or United Kingdom unless: (a) Customer provides prior written consent; and (b) appropriate safeguards under UK GDPR are in place, such as UK adequacy regulations, International Data Transfer Agreement (IDTA), or UK Addendum to EU SCCs.
9. Assistance to Controller (Art. 28(3)(f) UK GDPR)
Processor shall assist Customer with data subject rights requests, responses to the ICO, Data Protection Impact Assessments (DPIAs), and data protection consultations where legally required. Processor may charge reasonable fees for assistance beyond routine requests, provided such fees are notified in advance.
10. Personal Data Breach Notification (Art. 33 UK GDPR)
Processor shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification shall include: (a) the nature of the breach; (b) categories and approximate number of data subjects affected; (c) likely consequences; and (d) measures taken or proposed to address the breach. Processor shall cooperate with Customer's obligations to notify the ICO and affected data subjects.
11. Audits & Compliance Reviews
Processor shall make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits conducted by Customer or an independent auditor, subject to reasonable notice (minimum 30 days) and confidentiality obligations. Customer may conduct one audit per calendar year at Customer's expense.
12. Data Return & Deletion
Upon termination of the Agreement, Processor shall make Personal Data available for export in a commonly used, machine-readable format (e.g., CSV, JSON) for 30 days. Thereafter, Processor shall securely delete all Personal Data within 90 days using industry-standard methods, unless retention is required by law. Processor shall provide written confirmation of deletion upon Customer's request.
13. Liability
The limitation of liability in the Agreement applies to this DPA, except for breaches of EU/UK GDPR or this DPA, where Processor's total aggregate liability shall not exceed two (2) times the total fees paid in the 12 months preceding the event.
14. Governing Law & Jurisdiction
This DPA is governed by the laws of England and Wales and the UK GDPR. The parties submit to the exclusive jurisdiction of the courts of England and Wales. The supervisory authority for this DPA is the Information Commissioner's Office (ICO).
Annex 1 - Description of Processing
A. Subject Matter
Provision of the Chinchill.hr SaaS HR platform and related services.
B. Duration
For the term of the Agreement and retention period defined in this DPA.
C. Categories of Data Subjects
Customer employees, Contractors, Administrators and authorised users.
D. Types of Personal Data
- Identification data (name, email, employee ID)
- Absence and leave records
- Timesheet and working hours data
- Documents and attachments uploaded by Customer
- User activity logs and authentication data (hashed passwords)
E. Special Category Data
Not intentionally processed by Processor. Where Customer uploads such data, Customer ensures a lawful basis under Articles 9 and 10 GDPR.
F. Processing Activities
Hosting and storage, Transmission, Backup and recovery, Support and maintenance, Logging and monitoring, Security and vulnerability management.