WEEKLI
Back to Weekli · Legal Centre

Data Processing Addendum

Version · Effective

This DPA applies where Weekli processes personal data for a customer to provide the service.

1. Roles

The customer is normally Controller and Weekli is Processor for Customer Personal Data. Weekli is an independent Controller for data it determines to process for billing, direct customer relationship management, platform security, fraud/abuse prevention, legal compliance and corporate administration.

2. Processing details

Subject/duration: provision of Weekli during the subscription plus lawful exit/deletion period. Nature/purpose: hosting, organising, calculating, displaying and generating workforce/operational records; authorised email/push delivery; support; security. Data subjects: customer employees/workers, Office users, contractors, customer/site contacts and other people lawfully entered. Data: identity/contact, account, timesheet, pay/rate, holiday/absence, work/site/vehicle, forms/certificates, signatures, photographs, audit/security/support metadata.

3. Special-category information

Weekli does not require medical diagnoses in general absence fields. Special-category data can arise if a customer/user enters health or other sensitive information in absence/free-text records. The customer is responsible for the Article 6 basis, Article 9 condition, any DPA 2018 Schedule 1 condition and Appropriate Policy Document required for that processing.

4. Documented instructions and confidentiality

Weekli processes Customer Personal Data only on documented customer instructions (including the contract, customer configuration and authorised user actions), unless UK law requires otherwise. Personnel authorised to process the data are subject to confidentiality obligations and access is limited to what is reasonably required.

5. Security

Weekli will maintain appropriate technical and organisational measures, including authenticated access, tenant-isolation controls, role-based permissions, privileged MFA controls, restricted support administration, encrypted HTTPS transport, private storage where configured and audit mechanisms. Measures may evolve as risks and technology change.

6. Subprocessors

The customer grants general written authorisation for the subprocessors listed in the Subprocessor Notice. Weekli will impose appropriate data-protection obligations, remain responsible for its processor obligations and provide reasonable notice of material new/replacement subprocessors where practicable, allowing reasonable data-protection objections.

7. International transfers

Where Weekli initiates a restricted international transfer, Weekli will use an applicable lawful transfer route and complete any required assessment/data-protection test. This may include UK adequacy regulations, the UK IDTA, the UK Addendum to EU Standard Contractual Clauses or another lawful safeguard.

8. Rights and compliance assistance

Taking account of processing and information available, Weekli will reasonably assist the customer with data-subject rights, security obligations, personal-data breach response, DPIAs and regulator consultation. Requests clearly concerning customer-controlled workforce data may be referred to the customer.

9. Personal data breaches

Weekli will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data and provide reasonably available information to support the customer's risk assessment and legal notification obligations.

10. Return/deletion

At the end of processing, Weekli will, at the customer's choice, return/export or delete Customer Personal Data and delete copies unless law requires retention. Protected backups may expire through the normal backup cycle where they are put beyond ordinary use.

11. Audit and information

Weekli will provide information reasonably necessary to demonstrate Article 28 compliance. Audit requests must be proportionate and protect other customers' confidentiality/security. Documentation/questionnaires should normally be used before intrusive inspection.

12. Customer responsibility and priority

The customer remains responsible for lawful basis, fairness, transparency, minimisation, accuracy, retention, staff privacy information and lawful instructions. This DPA prevails over conflicting commercial terms on Customer Personal Data, and mandatory transfer clauses prevail where required by law.

Weekli legal documents · Privacy · Cookies · User Terms · Subprocessors