Data Processing Addendum - UK GDPR
Last updated: 26 May 2026
This DPA applies when you use HR Launch Box to generate documents using personal data you supply. It forms part of our Terms of Service and sets out how we process personal data as your processor under UK GDPR. Consumers buying for personal use are not covered by this DPA.
Between Kinnin Technologies Ltd t/a HR Launch Box (Processor) and Customer (Controller).
1. Introduction and scope
1.1 This DPA forms part of the agreement between Kinnin Technologies Ltd trading as HR Launch Box ("HR Launch Box", "we", "us", "our") and the purchasing customer ("Customer", "you") (the "Agreement") where, in providing the Services, we process Customer Personal Data on your behalf as a processor under UK GDPR and, where applicable, EU GDPR.
1.2 This DPA applies only to processing of Customer Personal Data that we carry out on your documented instructions in order to generate documents and provide related support ("Processing"). It does not apply to personal data we process as an independent controller for our own purposes (for example fraud prevention, service analytics, platform security, billing, or where third-party platforms or providers process personal data as independent controllers for their own purposes). Those activities are governed by our Privacy Policy and, where relevant, the platform provider's privacy notices.
2. Definitions
"Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and, where applicable, the EU GDPR and local member-state laws. "Customer Personal Data" means personal data you supply or make available for Processing under the Agreement. "UK GDPR" has the meaning given in s.3(10) DPA 2018. "EU GDPR" means Regulation (EU) 2016/679. "SCCs" means the EU Commission 2021 Standard Contractual Clauses (Module 2: Controller to Processor). "UK IDTA/UK Addendum" means the UK International Data Transfer Addendum or UK Addendum to the SCCs, as applicable. Other capitalised terms have the meanings in Data Protection Laws.
3. Roles of the parties
3.1 Controller/Processor. For the Processing described in Schedule 1, you are the controller and we are the processor.
3.2 Independent controllers. Each party may act as an independent controller for separate, non-overlapping purposes (for example invoicing, anti-fraud, service improvement). No joint controllership is intended.
4. Instructions
4.1 We shall process Customer Personal Data only on your documented instructions, including as set out in this DPA, the Agreement, your submitted forms and your use of the Services.
4.2 If we reasonably believe an instruction infringes Data Protection Laws, we will notify you. We may suspend the relevant Processing until the instruction is clarified or modified.
5. Confidentiality and personnel
5.1 We shall ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and receive data protection training.
6. Security
6.1 We will implement and maintain appropriate Technical and Organisational Measures ("TOMs") to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, costs, and the nature, scope, context and purposes of Processing (see Schedule 2 for a high-level overview).
7. Personal data breach
7.1 We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notice will describe the nature of the breach, likely consequences, and measures taken or proposed to address it, with reasonable updates to assist your compliance with Articles 33 and 34 UK/EU GDPR.
8. Sub-processors
8.1 You give general written authorisation to our use of sub-processors reasonably required to provide the Services (for example hosting, storage, email delivery and support tooling). We will ensure that each sub-processor is bound by written data protection terms that provide a level of protection for Customer Personal Data no less protective than this DPA, and we remain responsible for the performance of those sub-processors to the extent required by Data Protection Laws.
8.2 We will maintain and make available on request a current list of our sub-processors or sub-processor categories, including material information about their role. We will notify you of any material changes to sub-processing at least 14 days in advance (email or posting suffices). You may object on reasonable grounds relating to data protection. If the parties cannot resolve the objection within a reasonable period, you may terminate the affected Services and receive a pro-rata refund of any prepaid unused fees for those affected Services as your sole and exclusive remedy.
9. International transfers
9.1 Where the Processing involves a restricted transfer of Customer Personal Data outside the UK or, where applicable, outside the EEA to a jurisdiction not recognised as providing an adequate level of protection, we shall ensure that an appropriate lawful transfer mechanism is in place, including as applicable the UK IDTA, the UK Addendum to the EU SCCs, the EU SCCs and any supplementary measures required by Data Protection Laws.
9.2 If the SCCs or IDTA are replaced, amended or invalidated, the parties will promptly implement alternative lawful transfer mechanisms.
10. Assistance and data subject requests
10.1 Taking into account the nature of the Processing, we shall assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Data Protection Laws.
10.2 We will refer any data subject request received directly to you without undue delay and will not respond except on your documented instructions or where required by law.
10.3 We shall, on reasonable request, assist with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of Processing and the information available to us.
11. Records and audits
11.1 We will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for audits or inspections by you or an independent auditor appointed by you, and will allow for audits or inspections by you or an independent auditor appointed by you, provided that any such auditor is bound by appropriate confidentiality obligations, is not a competitor of ours, and is otherwise reasonably acceptable to us. Audits may take place no more than once in any 12-month period (unless required by a supervisory authority or following a material personal data breach affecting Customer Personal Data), during business hours, on reasonable written notice and in a manner that minimises disruption. You shall bear your own audit costs. We may satisfy audit or inspection requests, in whole or in part, by providing recent third-party audit reports, certifications or other documentation covering the relevant scope, where available.
12. Return and deletion
12.1 At the end of the Services, we will, at your choice, delete or return Customer Personal Data (and delete existing copies) within a reasonable period, unless we are required by law to retain it. If you do not give a written instruction within 30 days of the end of the Services, we may delete the Customer Personal Data in accordance with our retention practices. Routine backups will be overwritten in the ordinary course.
12.2 We may retain and use aggregated or anonymised data (which is not personal data) for legitimate business purposes, provided it does not identify you or any data subject.
13. Special categories and Customer responsibilities
13.1 Our Services are not intended to process special categories of personal data or criminal offence data unless clearly necessary for a specific document type. You are responsible for ensuring a lawful basis, satisfying applicable schedule and appropriate-policy requirements under UK law, and minimising such data in your inputs.
13.2 You warrant that (a) you have provided all necessary notices to data subjects; (b) you have a lawful basis for Processing; (c) the Customer Personal Data is accurate and limited to what is necessary; and (d) your use of the Services will comply with law.
14. Liability and indemnities
14.1 Each party's aggregate liability under this DPA is subject to and limited by the limitations and exclusions of liability in the Agreement, except to the extent such limitation is prohibited by law.
14.2 Nothing in this DPA limits liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot lawfully be limited.
15. Precedence and changes
15.1 In the event of a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict concerning the Processing of Customer Personal Data.
15.2 We may update this DPA to reflect changes in law or our Processing, providing prior notice where required. Material adverse changes will not apply without your agreement, except where mandated by law.
16. Governing law and jurisdiction
16.1 This DPA and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it shall be governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales, save that a party may seek urgent injunctive relief in any competent court.
17. Contact
For privacy and data protection matters, contact support@hrlaunchbox.com.
Schedule 1 – Description of Processing
Subject matter. Processing of Customer Personal Data input by Customer into HR Launch Box forms and tools to generate HR documents and to provide related support.
Duration. For the term of the relevant order or subscription and any agreed support period, plus limited retention as set out in our Privacy Policy and this DPA (for example short-term logs and backups).
Nature and purpose of Processing. Collection, receipt, storage, structuring, formatting and merging, generation, display, transmission and limited troubleshooting necessary to deliver the Services, produce documents and provide support.
Types of Customer Personal Data. Names, job titles, role details, start and end dates, work addresses, employee addresses, emails, pay and frequency bands, policy selections, company officers' details, signatories and other data you choose to include in free-text fields. Special categories and criminal offence data are not intended but may be incidentally submitted by you; if so, you are responsible for lawful submission and minimisation.
Categories of data subjects. Your organisation's employees, workers, candidates, contractors, officers and directors, referees and emergency contacts (if you submit them) and your internal users and administrators.
Processing operations. As necessary to generate documents and deliver the Services (including storage, access, duplication for backup, formatting, transmission and deletion or return).
Location of Processing. UK and (where relevant to sub-processors) other jurisdictions subject to appropriate safeguards (see clause 9).
Schedule 2 – Technical and Organisational Measures (TOMs)
We maintain measures appropriate to the risk, which include:
Governance and access control
• Role-based access; least-privilege; unique accounts; MFA for admin interfaces where available.
• Joiner, mover and leaver processes; periodic access reviews.
Data security
• Encryption in transit (TLS). Encryption at rest where supported by underlying platforms.
• Segregation of environments; restricted production access; secure key and secret handling.
Reliability and availability
• Backups and recovery testing appropriate to service needs.
• Change management and deployment controls.
Vulnerability and patch management
• Regular patching, dependency updates and vulnerability remediation on a risk basis.
• Third-party component monitoring.
Logging and monitoring
• Security and event logging for administrative actions and access to Customer Personal Data where feasible.
• Alerting for anomalous activity in critical systems.
Development security
• Secure coding practices; review and approval for material changes.
• Test data separation from production data.
Incident response
• Documented incident response procedures, escalation paths and breach notification workflow.
• Post-incident review and remediation tracking.
Supplier management
• Sub-processor due diligence and contractual data-protection commitments; periodic reviews.
• Data transfer assessments for international flows.
Data minimisation and retention
• Collection limited to what is necessary for stated purposes.
• Retention aligned to service delivery needs and legal requirements; deletion routines for aged data.
Personnel and training
• Confidentiality obligations; periodic privacy and security training and awareness.
Schedule 3 – Sub-processor information
Authorised sub-processor categories (examples):
• Infrastructure, hosting and storage (for example cloud platform services)
• Commerce and transaction platform (storefront, checkout, order handling)
• Email delivery and support ticketing
• Document generation and formatting utilities
• Customer communications and analytics (aggregated, service-level)
A current list of sub-processors, or where appropriate sub-processor categories, is available on request (email support@hrlaunchbox.com). We will notify you of any material changes before engagement as set out in clause 8.2.
Acceptance
By purchasing or using Services that involve document generation, or by clicking to accept at checkout, the parties agree to this DPA, which is incorporated into and forms part of the Agreement.