Data Processing Addendum

Published: July 2026


This Data Processing Addendum (“DPA“) is incorporated into, and forms part of, the agreement governing the use of Zelt’s services (the “Agreement”) entered into between the customer identified in the Agreement (whether via a completed order form or the Zelt platform) (“Customer“) and Zelt Ltd (12881631) of 123 Buckingham Palace Road, London SW1W 9SH (“Zelt“), and reflects the parties’ agreement regarding the Processing of Personal Data by Zelt on behalf of the Customer. Capitalised terms not defined in this DPA have the meaning given to them in the Agreement. If there is a conflict between this DPA and the Agreement as to the Processing of Personal Data, this DPA prevails to that extent only.

1. Definitions

1.1 “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of, or the power to vote, more than 50% of the voting interests of that entity.
1.2 “Authorised Affiliate” means an Affiliate of the Customer that is permitted to use the Services under the Agreement but has not signed its own agreement with Zelt and is not itself a “Customer” under the Agreement.
1.3 “Controller“, “Member State“, “Processor“, “Processing” and “Supervisory Authority” have the meanings given to them in the GDPR.
1.4 “Data Protection Laws” means the GDPR, the UK GDPR, and any other applicable law or regulation relating to the protection of personal data, in each case to the extent applicable to the Processing of Personal Data under this DPA.
1.5 “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
1.6 “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
1.7 “UK GDPR” means the General Data Protection Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.
1.8 “Personal Data” means any information relating to an identified or identifiable natural person that is Processed by Zelt solely on behalf of the Customer under this DPA and the Agreement.
1.9 “Services” means the services provided to the Customer by Zelt under the Agreement.
1.10 “Security Documentation” means Zelt’s technical and organisational measures documentation applicable to the Services, as updated from time to time and made available to the Customer on request.
1.11 “Standard Contractual Clauses” means: (a) for an EEA Transfer, the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, updated or replaced from time to time (the “EU SCCs“); and (b) for a UK Transfer, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A(1) of the DPA 2018, version B1.0, in force from 21 March 2022, as revised (the “UK Addendum“), or, where the UK Addendum is not used, the International Data Transfer Agreement issued by the Information Commissioner on the same basis.
1.12 “Sub-processor” means any third party engaged by Zelt to Process Personal Data on Zelt’s behalf.

2. Processing of Personal Data

2.1 Roles of the parties
As between the parties, and solely in respect of the Processing of Personal Data under this DPA, the Customer is the Controller and Zelt is the Processor. References to “Controller” and “Processor” below mean the Customer and Zelt respectively.

2.2 Customer’s responsibilities
The Customer shall comply with Data Protection Laws in its use of the Services and in the instructions it gives to Zelt, and shall have and maintain any legal basis needed to collect, Process and transfer Personal Data to Zelt and to authorise Zelt’s Processing of it.

2.3 Zelt’s Processing
Zelt shall Process Personal Data only: (a) to provide the Services under the Agreement and this DPA; (b) in accordance with the Customer’s documented instructions that are consistent with the Agreement; (c) to render Personal Data anonymous or non-identifiable; and (d) where required by law applicable to Zelt or by a competent court or authority, in which case Zelt shall inform the Customer of that legal requirement before Processing unless prohibited from doing so on public interest grounds. If, in Zelt’s reasonable opinion, an instruction from the Customer infringes Data Protection Laws, Zelt shall inform the Customer without undue delay. If Zelt cannot comply with an instruction, Zelt may, without liability to the Customer, pause Processing of the affected Personal Data (other than secure storage) until the issue is resolved; the Customer’s sole remedy in that case is to terminate the Agreement as to the affected Processing, with fees due up to the termination date remaining payable.

2.4 Details of Processing
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects, are set out in Schedule 1.

3. Data Subject Requests

Where legally permitted, Zelt shall notify the Customer of, or refer to the Customer, any request it receives from a Data Subject to exercise their rights under Data Protection Laws. Taking into account the nature of the Processing, Zelt shall provide reasonable assistance to help the Customer respond to such requests, including by making available relevant self-service features of the Services where appropriate.

4. Confidentiality

Zelt shall ensure that personnel and advisors engaged in the Processing of Personal Data are subject to a duty of confidentiality.

5. Sub-processors

5.1 The Customer authorises Zelt to engage its Affiliates and third-party Sub-processors to Process Personal Data in connection with providing the Services.
5.2 Zelt shall make available to the Customer its current list of Sub-processors, including their identity, location, and the nature of the service provided (the “Sub-Processor List“). The Sub-Processor List in place as at the Customer’s first use of the Services is deemed authorised on that first use.
5.3 The Customer may object, on reasonable grounds relating to the protection of Personal Data, to a new Sub-processor by notifying Zelt in writing within ten days of Zelt’s notice of the change. If the Customer does not object within that period, the new Sub-processor is deemed accepted. Where the Customer reasonably objects, Zelt shall use reasonable efforts to offer a change to the Services or configuration that avoids use of the objected-to Sub-processor; if Zelt cannot do so within thirty days, the Customer may, as its sole remedy, terminate the Agreement as to the affected Services on written notice, with fees due up to the termination date remaining payable. Zelt may replace a Sub-processor at short notice where urgently necessary to provide the Services, notifying the Customer as soon as reasonably practicable and preserving the Customer’s right to object.
5.4 Zelt has entered into a written agreement with each Sub-processor imposing data protection obligations materially equivalent to those in this DPA, including appropriate technical and organisational measures. Zelt remains liable to the Customer for a Sub-processor’s performance of those obligations.

6. Security and Audits

6.1 Zelt shall maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as further described in the Security Documentation, and shall provide reasonable assistance to the Customer, at the Customer’s cost, in complying with the Customer’s obligations under Articles 32 to 36 of the GDPR or the UK GDPR, as applicable.
6.2 On no less than 14 days’ written notice, and no more than once in any 12-month period, Zelt shall make available to the Customer (or the Customer’s independent third-party auditor, provided neither is a competitor of Zelt or in conflict with Zelt, and each is subject to confidentiality undertakings) information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits and inspections conducted by them. Information and results arising from an audit may be used only to assess compliance with this DPA and may not be disclosed to any third party without Zelt’s prior written approval. Where the Standard Contractual Clauses apply, nothing in this clause varies them or affects any Supervisory Authority’s or Data Subject’s rights under them.
6.3 The Customer shall ensure that any audit or inspection under clause 6.2 does not damage or disrupt Zelt’s premises, equipment, personnel or business, other than to a minimal and unavoidable extent.
6.4 The audit rights in clause 6.2 apply only to the extent the Agreement does not already give the Customer audit rights meeting the relevant requirements of Data Protection Laws, including Article 28(3)(h) of the GDPR or the UK GDPR, as applicable.

7. Security Breach Notification

Zelt maintains security incident management policies and procedures and shall, where required under Data Protection Laws, notify the Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data Processed by Zelt under this DPA (a “Security Breach“). Zelt shall take reasonable steps to identify and mitigate the cause of the Security Breach to the extent within its reasonable control. The Customer shall not make any public statement, admission of liability, or notification to a regulator or affected individual that identifies Zelt in connection with a Security Breach without Zelt’s prior written approval, except to the extent the Customer is legally compelled to do so, in which case the Customer shall give Zelt reasonable prior notice and an opportunity to object, and shall limit disclosure to the minimum required.

8. Return and Deletion of Personal Data

Within 30 days of termination of the Agreement, Zelt shall delete all Personal Data it Processes on the Customer’s behalf, and shall delete existing copies, unless the Customer instructs Zelt in writing, prior to termination, to return the Personal Data instead, in which case Zelt shall return the Personal Data to the Customer and thereafter delete existing copies. Zelt is not required to delete Personal Data to the extent Data Protection Laws require continued retention. Zelt and the Customer may agree that Zelt may retain a copy solely for evidence, legal claims, or compliance purposes where authorised or required by law.

9. International Transfers

9.1 Personal Data may be transferred from EU Member States, Iceland, Norway and Liechtenstein (together, the “EEA“) or the United Kingdom (the “UK“) to a country that offers an adequate level of data protection under an adequacy decision published by the European Commission or, as applicable, adequacy regulations made under section 17A of the Data Protection Act 2018 (each, an “Adequacy Decision“), without further safeguard.
9.2 If Zelt’s Processing involves a transfer, whether directly or by onward transfer, of Personal Data from the EEA (an “EA Transfer“) or from the UK (a “UK Transfer“) to a country not covered by an Adequacy Decision, and no alternative recognised transfer mechanism applies, then: (a) the terms set out in Part 1 of Schedule 2 apply to any EEA Transfer; and (b) the terms set out in Part 2 of Schedule 2 apply to any UK Transfer.
9.3 For the avoidance of doubt, Zelt will only transfer Personal Data originating from the EEA or the UK to a country not covered by an Adequacy Decision under the Standard Contractual Clauses.

10. Authorised Affiliates

10.1 By entering into this DPA, the Customer does so on behalf of itself and, where applicable, its Authorised Affiliates, each of which agrees to be bound by the Customer’s obligations under this DPA to the extent Zelt Processes Personal Data on its behalf. Use of the Services by an Authorised Affiliate in breach of the Agreement or this DPA is treated as a breach by the Customer.
10.2 The Customer remains responsible for all communications with Zelt under this DPA, including on behalf of its Authorised Affiliates.

11. Government and Law Enforcement Requests

If Zelt becomes aware that a government or law enforcement authority seeks access to, or a copy of, Personal Data, Zelt shall, unless legally prohibited or subject to a mandatory compulsion requiring otherwise: (a) inform the authority that Zelt is a Processor and has not been authorised by the Customer to disclose the Personal Data, and that requests should be directed to the Customer; and (b) use reasonable, commercially available legal means to challenge the request. Zelt need not challenge a request where it reasonably and in good faith believes urgent access is necessary to prevent imminent serious harm, but shall notify the Customer as soon as possible afterwards, unless legally prohibited from doing so. On the Customer’s written request, no more than once every 12 months, Zelt shall provide a summary of the types of binding legal demands for Personal Data it has received, to the extent received.

12. Data Protection Impact Assessments

On the Customer’s reasonable request and at the Customer’s cost, Zelt shall provide reasonable assistance with data protection impact assessments and related prior consultation with the Supervisory Authority, to the extent required under the GDPR or the UK GDPR, as applicable, and to the extent the relevant information is available to Zelt and not otherwise available to the Customer.

13. Modifications

Either party may, on 30 days’ written notice, propose variations to this DPA that are required as a result of a change in, or a regulatory decision under, Data Protection Laws. The parties shall discuss and negotiate any such variation in good faith. If the parties cannot agree a variation within 30 days of notice, either party may terminate the Agreement, on written notice, as to the Services affected by the proposed variation.

14. Liability

This DPA does not create or modify any limitation or exclusion of liability under the Agreement. The parties’ liability arising out of or in connection with this DPA, including in respect of a Security Breach, is subject to the limitations and exclusions of liability set out in clause 13 (Limitation of Liability) of the Agreement.

15. Governing Law and Jurisdiction

This DPA and the Agreement are governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, save as expressly provided otherwise in Schedule 2 in respect of the Standard Contractual Clauses.

Schedule 1 — Details of Processing

Nature and purpose of processing
Zelt processes Personal Data to: (1) provide the Services; (2) perform the Agreement and this DPA; (3) act on the Customer’s documented instructions consistent with the Agreement; (4) share Personal Data with third parties at the Customer’s instruction or configuration (for example, integrations the Customer sets up between the Services and third-party tools); and (5) comply with applicable law.

Duration and frequency
Zelt Processes Personal Data on a continuous basis for the duration of the Agreement, subject to any provision of the Agreement or this DPA dealing with the consequences of expiry or termination.

Types of Personal Data
Depending on the modules the Customer uses, this typically includes: contact details, employment status, and job/performance information (core HR); salary, bank account, and tax information (payroll and benefits); and job application details (recruitment). The Customer controls the extent and nature of the Personal Data it submits.

Categories of Data Subjects
Typically: the Customer’s current and former employees; job applicants and candidates; contractors and consultants engaged by the Customer; and, where relevant, the Customer’s own business contacts and other individuals interacting with the Customer through the Services.

Sub-processors
The current list of Sub-processors is available to the Customer on request, and includes the identity, location, and Processing role of each Sub-processor.

Schedule 2 — International Transfers

Part 1 — EEA Transfers
1. The EU SCCs are incorporated by reference and apply to a transfer of Personal Data from the EEA (an “EEA Transfer“).
2. Module Two (Controller to Processor) applies where the Customer is Controller and Zelt is Processor of the transferred Personal Data. Module Three (Processor to Processor) applies where Zelt is acting as a sub-processor for the Customer in respect of the transferred Personal Data.
3. The optional docking clause at Clause 7 does not apply.
4. Clause 9 (use of sub-processors) is governed by Option 2 (general written authorisation); the notice period for new Sub-processors is as set out in clause 5.3 of this DPA.
5. Clause 11 (redress) — the optional language does not apply.
6. Under Clause 17, the EU SCCs are governed by the law of Ireland. Under Clause 18(b), disputes are resolved before the courts of Ireland.
7. Annex I.A (parties), Annex I.B (description of transfer) and Annex I.C (competent supervisory authority) of the EU SCCs are completed by reference to Schedule 1 of this DPA and, for the competent Supervisory Authority, the Supervisory Authority of the Member State in which the Customer is established (or, if none, the Irish Data Protection Commission).
8. The Security Documentation serves as Annex II (technical and organisational measures) of the EU SCCs.
9. If there is a conflict between the EU SCCs and any other term of this DPA or the Agreement, the EU SCCs prevail.

Part 2 — UK Transfers
1. The UK Addendum is incorporated by reference and applies, together with the EU SCCs as adapted by the UK Addendum, to a transfer of Personal Data from the UK (a “UK Transfer“).
2. Table 1 (Parties), Table 2 (Selected SCCs, Modules and Clauses) and Table 3 (Appendix Information) of the UK Addendum are completed by reference to the corresponding provisions of Part 1 of this Schedule 2 and Schedule 1 of this DPA.
3. Table 4: neither party may terminate the UK Addendum under section 19 of its Mandatory Clauses.
4. The Mandatory Clauses of the UK Addendum are the template issued by the Information Commissioner (version B1.0, 2 F


PRIOR VERSIONS
November 2023
March 2023