Data Processing Agreement
Last updated: 25 August 2026. Draft pending legal review. This DPA forms part of the Terms of Service between Vopria (the Processor) and the employer customer (the Controller) and applies to onboarding personal data processed on the Controller's behalf.
1. Subject matter and duration
Processing of new starter onboarding data (identity, contact, National Insurance number, bank details, emergency contacts, right to work documents, P45 and policy acknowledgements) for the duration of the Controller's use of the service, for the purpose of running employee onboarding.
2. Processor obligations
The Processor shall: process personal data only on the Controller's documented instructions as expressed through use of the platform; ensure persons authorised to process the data are bound by confidentiality; implement the technical and organisational measures in Annex 1; assist the Controller with data subject requests and with obligations under UK GDPR Articles 32 to 36; notify the Controller without undue delay after becoming aware of a personal data breach; and at the end of the relationship delete or return the personal data as described in the Privacy Policy, subject to the employee's independent rights over their own portable profile.
3. Sub-processors
The Controller authorises the following sub-processors: Supabase (database and storage, EU region), Vercel (hosting), Resend (email), Stripe (payments) and Sentry (error monitoring). The Processor will give notice of changes to sub-processors and the Controller may object on reasonable grounds.
4. International transfers
Personal data is stored in the EU. Any transfer outside the UK or EEA is protected by the UK International Data Transfer Agreement or Addendum, or an adequacy regulation.
5. Audit
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA, including the in-product audit trail, and will allow audits by the Controller no more than once per year on 30 days notice at the Controller's cost.
Annex 1: Technical and organisational measures
AES-256 field-level encryption of National Insurance numbers and bank details; encryption in transit (TLS) and at rest; database row-level security restricting access by role, ownership and recorded consent; append-only consent and audit logs; role-restricted service credentials; security headers and rate limiting at the application layer; documents stored in a private bucket with per-user path isolation.