In short. When your organisation uses Rekro, it decides what personal data goes in and why, and we process that data for you. Data protection law requires a written contract for that arrangement. This is it. It forms part of our Terms of Service, so you do not need to sign anything separately.
If your organisation needs a signed copy for its records, write to legal@virtupay.co.uk.
1. About this addendum
This addendum forms part of the agreement between VirtuPay Limited (“we”, “us”) and the Customer under our Terms of Service. Words defined in the Terms of Service have the same meaning here.
In this addendum:
- “Data Protection Law” means the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and any other law about the protection of personal data that applies to the processing in question.
- “Customer Personal Data” means the personal data contained in Customer Data that we process on the Customer’s behalf to provide the Service.
- “controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings given in Data Protection Law.
If this addendum conflicts with the Terms of Service on a matter of data protection, this addendum prevails. An Order prevails over both.
2. Roles and scope
For Customer Personal Data, the Customer is the controller and we are its processor. Where the Customer itself acts as a processor for someone else, we are its sub-processor, and the Customer confirms that it is authorised to engage us on these terms.
Section 15 describes the processing: its subject matter, duration, nature and purpose, the types of personal data and the categories of data subject.
This addendum does not apply to the personal data for which we are a controller in our own right, such as sign-in and security information and our own business records. Our Privacy Policy describes that processing.
3. The Customer’s instructions
We will process Customer Personal Data only on the Customer’s documented instructions. The agreement, the way the Customer configures the Service, and what the Customer and its users ask the Service to do are the Customer’s instructions. Any further instruction must be agreed in writing.
We will tell the Customer if, in our opinion, an instruction infringes Data Protection Law, and may pause the processing concerned until the point is resolved.
If the law of the United Kingdom requires us to process Customer Personal Data in some other way, we will tell the Customer before doing so, unless that law prohibits us from telling it.
4. The Customer’s responsibilities
The Customer is responsible for complying with Data Protection Law as a controller, and in particular for:
- having a lawful basis for the Customer Personal Data it puts into the Service, and for each use it makes of it;
- giving data subjects the information the law requires, including about its use of Rekro and of any AI feature it switches on;
- deciding whether to collect identity documents, photographs of a person’s face or any other special category or criminal offence data, having a lawful basis and a condition for doing so, obtaining any consent that is needed, and carrying out a data protection impact assessment where one is required;
- the accuracy of Customer Personal Data, and deciding how long it is kept;
- configuring roles, permissions, automations and connections so that personal data is seen only by those who should see it; and
- responding to data subjects who exercise their rights.
The Customer must not use the Service to store payment card details, or any category of personal data that the Service is plainly not designed to hold.
5. Our people
We will make sure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, and that access is limited to those who need it to provide, secure or support the Service.
6. Security
We will maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Section 16 describes the measures in place.
We may change those measures as the Service and the threats to it develop, but we will not materially reduce the overall level of protection without telling the Customer first.
The Customer is responsible for deciding whether those measures are appropriate for the personal data it intends to put into the Service.
7. Sub-processors
The Customer gives us general authorisation to engage sub-processors. Those we use at the date of this addendum are set out in our list of sub-processors.
We will have a written contract with each sub-processor that imposes data protection obligations equivalent in substance to those in this addendum, and we remain responsible to the Customer for what each sub-processor does.
We will give the Customer at least 30 days’ notice before a new or replacement sub-processor starts to process Customer Personal Data, by updating the list and emailing the Customer’s Workspace owners. Where a replacement is needed urgently to protect the security or continuity of the Service, we may give shorter notice, and will give it as soon as we reasonably can.
The Customer may object to a new or replacement sub-processor on reasonable data protection grounds by writing to privacy@virtupay.co.uk within the notice period. We will discuss the objection with the Customer in good faith. If it cannot be resolved, the Customer may end the affected part of the Service by written notice before the change takes effect, and we will refund any Fees paid in advance for the period after it ends.
8. International transfers
Customer Personal Data in the Rekro database, and the documents stored with it, are held in the United Kingdom. The list of sub-processors shows where each sub-processor processes personal data.
We will transfer Customer Personal Data outside the United Kingdom only in compliance with Data Protection Law: to a country covered by UK adequacy regulations, to a recipient certified under the UK Extension to the EU–US Data Privacy Framework, or under the International Data Transfer Addendum or International Data Transfer Agreement issued by the Information Commissioner.
The Customer authorises the transfers that follow from our use of the sub-processors on the list.
9. Helping the Customer meet its obligations
The Service gives the Customer the means to find, correct, anonymise and erase the Customer Personal Data it holds. Taking into account the nature of the processing, we will give the Customer reasonable further help in responding to data subjects who exercise their rights.
If a data subject sends a request about Customer Personal Data to us, we will pass it to the Customer promptly and will not respond to it ourselves, other than to tell the data subject that we have passed it on, unless the law requires us to.
Taking into account the nature of the processing and the information available to us, we will give the Customer reasonable help with its obligations concerning the security of processing, personal data breaches, data protection impact assessments and consultation with the Information Commissioner.
Where help under this section goes materially beyond what the Service already provides, we may charge our reasonable costs, provided we tell the Customer what they will be before we incur them.
10. Personal data breaches
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We will send the notification by email to the Customer’s Workspace owners.
The notification will describe, as far as we know it at the time, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and what we have done and propose to do about it. Where we do not yet have all of that information, we will provide it in stages as it becomes available.
We will take reasonable steps to contain and remedy the breach, and will co-operate with the Customer’s reasonable requests while it investigates.
The Customer is responsible for deciding whether to notify the Information Commissioner and the data subjects affected, and for doing so. Our notifying the Customer of a breach is not an admission of fault or liability.
11. Records, information and audits
We will keep the records of our processing on the Customer’s behalf that Data Protection Law requires a processor to keep.
On written request, and not more than once in any 12 months, we will give the Customer the information reasonably necessary to show that we comply with this addendum, including written answers to its reasonable questions about our security measures.
Where that information is not enough to show our compliance, where the Information Commissioner requires it, or following a personal data breach affecting Customer Personal Data, we will allow the Customer, or an independent auditor it appoints who is bound by a duty of confidentiality, to audit our compliance with this addendum. The Customer must give at least 30 days’ written notice, carry out the audit during our working hours with as little disruption as possible, bear its own costs, and must not be given access to any other customer’s data.
We cannot give the Customer access to a sub-processor’s premises or systems. We will instead share the assurance reports and security information that our sub-processors make available to us, as far as their terms allow.
12. Return and deletion
When the agreement ends, clause 14.7 of the Terms of Service applies: for 30 days the Customer may ask us for a copy of its Customer Data, and we will then delete Customer Personal Data from our live systems within 90 days of the date the agreement ended. Copies held in backups are deleted or overwritten in the ordinary course of the backup cycle.
If the law requires us to keep any Customer Personal Data for longer, we will tell the Customer, keep it only for as long as the law requires, and continue to protect it as this addendum provides.
13. Liability
Each party’s liability under this addendum is subject to the limits and exclusions in section 16 of the Terms of Service.
Nothing in the agreement limits the rights that a data subject has against either party under Data Protection Law, and each party is responsible for any penalty a regulator imposes on it for its own breach of Data Protection Law.
14. Changes and governing law
We may change this addendum in the way section 18 of the Terms of Service describes. A change that is needed to comply with Data Protection Law or with a requirement of the Information Commissioner may take effect on shorter notice.
This addendum is governed by the same law, and subject to the same courts, as the Terms of Service.
15. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing the Service to the Customer under the agreement. |
| Duration | The term of the agreement, and afterwards until Customer Personal Data has been deleted under section 12. |
| Nature and purpose | Hosting, storing, organising, retrieving, displaying and transmitting Customer Personal Data so that the Customer can run its recruitment operations; sending emails and notifications on the Customer’s behalf; and, where the Customer uses them, reading CVs and answering questions with an AI language model. |
| Data subjects | Candidates and contractors; contacts at the Customer’s clients; the Customer’s own staff who use the Service; and any other individual whose details the Customer records. |
| Types of personal data | Names and contact details; dates of birth and nationality; right to work status; CVs, work history, education, skills and certifications; pay and rate information; documents; notes; applications, placements and assignment terms; timesheets; billing names, addresses and VAT numbers, and invoices; identity and compliance evidence; account identifiers, roles and a record of actions taken; conversations with the AI assistant; and anything else the Customer chooses to record. |
| Special category and criminal offence data | The Service does not require any. It will hold identity documents, which can reveal nationality or ethnic origin, and photographs of a person’s face, where the Customer chooses to collect them, together with anything of that kind the Customer chooses to record in a CV, a note, a document or a field it has added. |
| Sub-processors | As set out in the list of sub-processors. |
16. Security measures
At the date of this addendum, the measures in place are these.
- Separation of customers. Every record belongs to one Workspace. The Workspace a request may act on is taken from the signed-in session on our servers, never from anything the browser or app supplies.
- A closed database. The database is reachable only by the application. It has no public data interface, and it denies access by default to any other means of reaching it.
- Access control. Roles and permissions set by the Customer are enforced on our servers for every operation, and an operation is refused unless a permission allows it.
- Confidential documents. Documents are classified by sensitivity. Opening a confidential document, such as identity evidence, requires a single-use code sent to the reader’s email address, and each viewing is recorded.
- Private file storage. Documents are held in private storage with no public address. They are uploaded through single-use links and served only through the application after a permission check.
- Authentication. Sign-in is handled by a specialist identity provider. We do not store passwords. Passkeys are supported, and a sign-in from an unrecognised device must be confirmed with a code sent by email.
- Encryption. Data is encrypted in transit using TLS, and is held at rest by hosting providers that encrypt their storage.
- Time-limited links. Invitations and other links that grant access are single-use, expire, and are stored only in hashed form.
- Protection against abuse. Requests are rate-limited, with tighter limits on public and sensitive routes.
- Audit trail. Changes to records are logged with who made them and whether they were made by a person, an automation, the AI assistant or a portal user.
- Controls on AI. The assistant is off until the Customer switches it on, acts only within the permissions of the person using it, asks for confirmation before changing records unless the Customer decides otherwise, and cannot send messages on its own.
- Careful diagnostics. Error monitoring is configured not to collect the content of forms, requests, cookies or headers, to remove access codes from page addresses, and not to record sessions.
- Change control. Changes to the Service are kept under version control and pass automated checks before they are released.
- Limited staff access. Access to production systems is restricted to the people who need it to run and support the Service.