DATA PROCESSING ADDENDUM

1. Scope, Order of Precedence and Parties

This Data Processing Addendum ("DPA") applies to the Processing of Personal Data by Brain Payroll UK Limited ("Brain Payroll") on behalf of customers using Brain Payroll's payroll software, implementation, technical support, consultancy or related services ("Services").

The Services are provided under the applicable Brain Payroll software license, services agreement, order form or other applicable agreement with the customer (collectively, the "Agreement"). This DPA is incorporated into and forms part of the Agreement.

In the event of a conflict between the Agreement and this DPA concerning the Processing or protection of Personal Data, this DPA shall prevail.

Where applicable, if there is a conflict between this DPA and an International Data Transfer Agreement ("IDTA"), UK Addendum, EU Standard Contractual Clauses or other mandatory international transfer mechanism, the mandatory terms of the applicable transfer mechanism shall prevail.

2. Definitions

"You", "Your" or "Customer" means the customer using Brain Payroll's Services.

"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 as amended from time to time, and the EU General Data Protection Regulation 2016/679 ("EU GDPR") where applicable.

"Controller", "Data Subject", "Personal Data", "Processor", "Process", "Processed" and "Processing" shall have the meanings given to them under Applicable Data Protection Laws.

"Customer Personal Data" means Personal Data Processed by Brain Payroll on behalf of the Customer in connection with the Services.

"Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise Processed.

"Sub-Processor" means any third party appointed by Brain Payroll to Process Customer Personal Data in connection with providing the Services.

"International Data Transfer Agreement" or "IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner's Office, including any replacement or successor version.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, including any replacement or successor version.

"EU Standard Contractual Clauses" or "EU SCCs" means the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, including any replacement or successor clauses.

3. Roles as Controller and Processor

For the purposes of this DPA, the Customer is the Controller of Customer Personal Data and Brain Payroll acts as Processor when providing the Services.

Where the Customer itself acts as a Processor on behalf of another Controller, Brain Payroll shall act as a Sub-Processor in respect of the relevant Personal Data.

The Customer is responsible for complying with its obligations under Applicable Data Protection Laws, including establishing an appropriate lawful basis for Processing, providing required privacy notices and ensuring that Personal Data provided to Brain Payroll has been collected and disclosed lawfully.

Brain Payroll shall comply with the obligations applicable to it as a Processor under Applicable Data Protection Laws.

4. Purpose and Instructions for Processing

Brain Payroll shall Process Customer Personal Data only:

  • for the purpose of providing the Services;
  • in accordance with the Agreement and this DPA;
  • on the Customer's documented instructions; or
  • where required by applicable law.

The Processing may include collection, access, recording, storage, retrieval, calculation, modification, transmission, support, backup, export and deletion of Customer Personal Data as necessary to provide the Services. Processing shall continue for the duration of the Services and for any lawful retention period following termination.

The Agreement, this DPA, the Customer's use and configuration of the Services and written requests submitted by authorised Customer personnel shall constitute documented instructions.

Where Brain Payroll is required by law to Process Personal Data other than on the Customer's instructions, Brain Payroll shall notify the Customer before carrying out such Processing unless prohibited from doing so by law.

Brain Payroll shall inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws.

Brain Payroll may use statistical or aggregated information derived from the Services provided that such information has been irreversibly anonymised and no longer constitutes Personal Data.

Optional AI Services

Where the Customer chooses to enable optional AI-powered features ("AI Services"), Brain Payroll may Process Customer Personal Data for AI-assisted payroll data migration, validation, transformation, analysis and related functionality.

AI Services are optional and are not required for Brain Payroll's core payroll calculation or payroll processing functionality.

Processing through AI Services shall be carried out in accordance with the Customer's instructions, this DPA, the applicable Brain Payroll AI Terms and Conditions and Applicable Data Protection Laws.

Depending on the AI feature used, Customer Personal Data transmitted for AI Processing may include limited, partial or full payroll-related information and uploaded documents where required for the selected functionality.

The Customer controls whether AI Services are enabled and is responsible for ensuring that it has an appropriate lawful basis for Personal Data submitted through those Services.

5. Data Subjects and Categories of Personal Data

The exact Personal Data Processed depends on the Services used and the information provided by the Customer.

Categories of Data Subjects may include:

  • current and former employees;
  • workers and contractors;
  • directors;
  • pension scheme members;
  • CIS subcontractors where applicable;
  • Customer administrators and authorised users; and
  • other individuals whose information is provided for payroll or related purposes.

Categories of Personal Data may include:

  • name, address and contact information;
  • date of birth;
  • National Insurance number;
  • employee and payroll identifiers;
  • employment information;
  • salary, pay, bonuses, expenses and deductions;
  • bank account and payment information;
  • tax codes and HMRC-related information;
  • pension information;
  • statutory payment and leave information;
  • timesheets and working hours;
  • payroll history;
  • user, audit and system information; and
  • Other Personal Data provided by the Customer that is reasonably required to provide the Services.
  • AI interaction data, where AI Services are enabled, including prompts, AI responses, user identity, feature usage and timestamps;
  • payroll, employee or uploaded document information included in an AI request where required by the selected AI functionality.

Where necessary for payroll or statutory purposes, limited Special Category Personal Data may also be Processed, including health-related information associated with sickness, statutory payments or other payroll requirements and trade union information where relevant to payroll deductions.

6. Sub-Processing

The Customer provides Brain Payroll with general authorisation to appoint Sub-Processors where reasonably necessary to provide, operate, maintain, secure or support the Services.

Brain Payroll shall maintain information concerning its relevant Sub-Processors and make such information available to Customers through its website or upon reasonable request.

Brain Payroll shall provide reasonable advance notice of any intended addition or replacement of a Sub-Processor that will Process Customer Personal Data.

The Customer may object to a proposed Sub-Processor where it has reasonable and documented grounds relating specifically to the protection of Personal Data. Brain Payroll and the Customer shall work in good faith to address any reasonable objection.

Brain Payroll shall ensure that Sub-Processors are subject to written agreements containing data protection obligations appropriate to the Processing and consistent with Brain Payroll's obligations under this DPA.

Brain Payroll shall remain responsible for the performance of its Sub-Processors' applicable data protection obligations to the extent required by Applicable Data Protection Laws.

Where a third-party AI provider Processes Customer Personal Data on behalf of Brain Payroll in connection with the AI Services, the requirements of this Section relating to Sub-Processors shall apply.

Where the Customer independently selects and configures a third-party AI provider using its own account or API credentials, the respective responsibilities of Brain Payroll, the Customer and the AI provider shall also be subject to the applicable AI Terms and Conditions and the contractual arrangements between the Customer and that AI provider.

7. International Transfers of Personal Data

Brain Payroll's core payroll application and Customer payroll data are hosted in the United Kingdom unless otherwise expressly agreed.

Certain authorised personnel or Sub-Processors located outside the United Kingdom, including in India, may remotely access Customer Personal Data hosted within Brain Payroll's UK environment where such access is necessary to provide support or related Services.

Where such remote access constitutes a restricted international transfer under Applicable Data Protection Laws, Brain Payroll shall ensure that an appropriate lawful transfer mechanism is in place.

Where applicable, this may include:

  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • the EU Standard Contractual Clauses; or
  • another transfer mechanism permitted under Applicable Data Protection Laws.

Where required, Brain Payroll shall undertake an appropriate transfer risk assessment or data protection test and implement additional technical and organisational safeguards where necessary.

International remote access is subject to appropriate security controls, which may include secure remote connectivity, multi-factor authentication, role-based access, managed devices or controlled virtual desktop environments, activity monitoring and restrictions on local storage or unauthorised export of Customer Personal Data.

8. Requests from Data Subjects

Brain Payroll shall provide reasonable assistance to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, taking into account the nature of the Processing.

Where Brain Payroll receives a Data Subject request directly relating to Customer Personal Data, Brain Payroll shall direct or forward the request to the relevant Customer where reasonably possible, unless prohibited by law.

Brain Payroll shall not respond substantively to a Data Subject request on behalf of the Customer unless authorised by the Customer or required by applicable law.

9. Security and Confidentiality

Brain Payroll shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Such measures shall take into account the nature, scope, context and purposes of the Processing and the risks to Data Subjects and shall be consistent with the requirements of Article 32 UK GDPR where applicable.

Brain Payroll maintains security measures relating to areas including:

  • access control and least privilege;
  • authentication and multi-factor authentication;
  • encryption in transit and at rest where appropriate;
  • Network, Firewall, WAF and infrastructure security;
  • logging and monitoring;
  • endpoint security;
  • vulnerability and patch management;
  • secure development and change management;
  • backup and disaster recovery;
  • incident response; and
  • personnel security and awareness.

Brain Payroll personnel authorised to Process Customer Personal Data shall be subject to appropriate confidentiality obligations and receive relevant information security and data protection training.

Brain Payroll may update its security controls from time to time provided that such changes do not materially reduce the overall level of protection provided to Customer Personal Data.

10. Personal Data Breach

Brain Payroll shall notify the affected Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where practicable, Brain Payroll shall provide initial notification within 24 hours after becoming aware of the Personal Data Breach.

Where available, the notification shall include:

  • the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects and Personal Data records;
  • the likely consequences of the Personal Data Breach;
  • the measures taken or proposed to contain, investigate and remediate the breach;
  • measures taken to mitigate possible adverse effects; and
  • appropriate contact details for further information.

Where all information is not immediately available, Brain Payroll may provide additional information in phases as the investigation progresses.

Brain Payroll shall provide reasonable assistance to the Customer in meeting applicable breach of assessment and notification obligations.

The Customer remains responsible for determining whether notification to a Supervisory Authority or affected Data Subjects is legally required where the Customer acts as Controller.

11. Information and Assistance

Brain Payroll shall make available information reasonably necessary to demonstrate compliance with its obligations as a Processor under Applicable Data Protection Laws.

Taking into account the nature of the Processing and the information available to Brain Payroll, Brain Payroll shall provide reasonable assistance to the Customer with applicable obligations relating to:

  • Security of Processing;
  • Personal Data Breaches;
  • Data Protection Impact Assessments;
  • consultation with Supervisory Authorities; and
  • Data Subject rights.

Where customer requests assistance that requires significant work outside the normal scope of the Services, Brain Payroll may charge reasonable additional fees after informing the Customer of the applicable basis of charge.

Brain Payroll shall not charge for obligations that Applicable Data Protection Laws require Brain Payroll to perform at its own cost.

12. Return, Retention and Deletion of Personal Data

During the term of the Services, Customers may access and export Customer Personal Data using functionality made available through the Services.

Customers should download or export information they require before terminating their Services.

Following termination or expiry of the Services, Brain Payroll shall, at the Customer's choice and subject to Applicable Data Protection Laws, return or delete Customer Personal Data.

Where a Customer requests post-termination retrieval of retained Personal Data, Brain Payroll shall provide reasonable assistance. Data may be provided in commonly used formats appropriate to the information requested, including CSV, XLSX, or PDF.

Brain Payroll will normally aim to fulfil standard post-termination data retrieval requests within five working days. Where a request is complex, involves significant volumes of information, archive restoration or custom extraction, Brain Payroll shall communicate at an appropriate timescale based on the complexity of the request.

Post-termination data extraction, restoration or custom reporting outside standard export functionality may be chargeable. Where reasonably practicable, Brain Payroll shall communicate on the basis of any applicable charges before commencing such work.

Following deletion from active systems, copies of Customer Personal Data may remain within secured backup or disaster recovery systems where immediate granular deletion is not reasonably technically practicable. Such information shall remain protected and shall not be returned to ordinary operational use except where required for recovery purposes.

In accordance with Brain Payroll's documented retention and offboarding arrangements, retained backup information may remain available for up to three full tax years following termination, subject to the Customer's valid deletion instructions, applicable backup deletion cycles and any legal or regulatory retention requirements.

Brain Payroll shall continue to apply the protections of this DPA to retain Customer Personal Data until it has been securely deleted or rendered irretrievable.

13. Audit

Brain Payroll shall make available information reasonably necessary to demonstrate compliance with the requirements of this DPA and Applicable Data Protection Laws.

Where available documentation and assurance information are not reasonably sufficient for the Customer to meet its obligations, the Customer may request an audit of Brain Payroll's relevant Processing activities.

Except where otherwise required by Applicable Data Protection Laws, a Supervisory Authority, following a material Personal Data Breach or where there are reasonable grounds to suspect material non-compliance, Customer audits shall ordinarily be limited to once in any twelve-month period.

The Customer shall provide at least three weeks' reasonable prior written notice and a proposed audit scope.

Audits shall:

  • relate only to Processing relevant to the Customer;
  • be conducted during normal business hours;
  • minimise disruption to Brain Payroll's operations;
  • comply with Brain Payroll's confidentiality and security requirements; and
  • be carried out at the Customer's own cost.

Where relevant audit requirements are already covered by a recent independent assessment, certification, penetration test, or third-party audit, Brain Payroll may provide evidence to reduce unnecessary duplication.

A Customer may appoint an appropriately qualified independent auditor, subject to reasonable confidentiality and security requirements.

Brain Payroll shall cooperate with a competent Supervisory Authority to the extent required by Applicable Data Protection Laws.

14. Data Protection Officer

Questions relating to this DPA or Brain Payroll's Processing of Personal Data may be directed to:

Data Protection Officer
Brain Payroll UK Limited
Email: dataofficer@brainpayroll.co.uk

15. Term

This DPA becomes effective when the applicable Agreement becomes effective or when Brain Payroll first Processes Customer Personal Data on behalf of the Customer, whichever occurs first.

This DPA shall remain in effect for as long as Brain Payroll Processes or retains Customer Personal Data on behalf of the Customer.

Following termination of the Agreement, the provisions relating to confidentiality, security, international transfers, Personal Data Breaches, retention, deletion and audit shall continue to apply for as long as Brain Payroll retains Customer Personal Data.

This DPA does not require a separate signature where it has been incorporated into the applicable Brain Payroll Agreement by reference.

RTI Real Time Information compliant
CIS Construction Industry Scheme certified
Automatic enrolment certified
ISO certified
Cyber Essentials certified
RTI Real Time Information compliant
CIS Construction Industry Scheme certified
Automatic enrolment certified
ISO certified
Cyber Essentials certified

Solution Is Our DNA!

Let's talk and find them for all your payroll needs

Book A Demo