Data Processing Agreement
Data Processing Addendum
Data Protection Laws require a written agreement between a Controller and a Processor in order to allow the Processing of Personal Data by the Processor on behalf of the Controller. For this reason, the parties have agreed to enter into this Data Processing Addendum.
This Addendum forms part of the agreement for the provision of the Ploy Platform, which is made up of an Order Form and Ploy’s Terms of Business (together, the Master Services Agreement). In the event of conflict or inconsistency between this Addendum and the Agreement, this Addendum shall prevail, except that each party’s liability under or in connection with this Addendum shall be subject to the limitations and exclusions of liability in the Agreement.
Subject-matter of Processing: | Ploy will Process Protected Data hereunder exclusively within the scope of the provision of the Service(s) to the Customer. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Duration of Processing: | Processing shall continue only for as long as Ploy provides the Service(s) that require the Processing of Protected Data and until the Protected Data is deleted in accordance with Clause 10 of this Addendum. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Nature and purpose of the Processing: | Ploy will Process Protected Data only:
in each case in a manner consistent with this Addendum and the Agreement. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Type of Personal Data: | Ploy Processes employee data to enable user management, automate onboarding and offboarding, and facilitate access control based on a user’s role and employment status. This data is sourced from Identity Providers (IdPs) such as Okta and Azure AD, as well as from optional integrations with Human Resource Information Systems (HRIS) like BambooHR, HiBob, and Humaans. HRIS integrations are entirely optional and are only used if the Customer explicitly configures them. If an HRIS is not integrated, Ploy shall not Process any HRIS-related data. Data Collected The following data may be received from integrated systems. Ploy shall only store and Process the Protected Data required to provide the Service(s), which is outlined in the column Required (yes or discarded) where yes is required and discarded is where the data is immediately discarded.
How data is accessed by data category Employee Information: This data is collected when the Customer integrates Identity Providers (IdPs) such as Okta, Azure AD, or Human Resource Information Systems (HRIS) like BambooHR. Authentication & Login: This data is collected when the Customer integrates Identity Providers (IdPs) such as Okta, Azure AD. Audit & Compliance: Ploy tracks this data through managed application tracking services and access catalogue features. It is used to maintain audit trails and to support the Customer’s access reviews and compliance activities. Data minimisation & Handling of Excess Data When integrating with an HRIS, the API may return more data than Ploy requires. In these cases, Ploy shall immediately discard any data not required to provide the Service(s) and shall not store or use it. Such transient receipt is Processing of Protected Data and is subject to this Addendum. For example, some HRIS platforms may include sensitive data such as employee gender, phone numbers, or nationality details in their API responses. Ploy shall not store or make use of this information in any way. The Service(s) are not intended to process special category personal data. The Customer shall not intentionally provide such data to Ploy unless agreed in writing. Ploy shall retain only the Protected Data necessary for access governance and user lifecycle management, in accordance with the data minimisation principle in Article 5(1)(c) of the UK GDPR and any equivalent requirement under other Data Protection Laws. Purpose of Processing Ploy Processes employee data to:
Ploy shall limit its collection and Processing of Protected Data to that necessary for the purposes set out above. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Categories of Data Subjects: | Authorised Users and other Personnel of the Customer and of each Customer Group Company permitted to use the Service(s). |
1 Definitions
1.1 In this Addendum:
1.1.1 the terms Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processes, Processed and Processing, Processor and Supervisory Authority shall have the meaning ascribed to them in the Data Protection Laws;
1.1.2 the terms defined in the Agreement shall have the meaning ascribed to them in the Agreement.
1.2 The following terms have the meanings given below:
Addendum | this data processing addendum, including Schedules 1 and 2. |
Agreement | the agreement for the provision of the Ploy Platform, made up of the Order Form and Ploy’s Terms of Business (together, the Master Services Agreement). |
Applicable Law | the laws of the United Kingdom, the European Union or an EU Member State to which Ploy is subject. |
Customer Group Company | any entity that directly or indirectly controls, is controlled by, or is under common control with the Customer, where control means the ownership of more than 50% of the voting rights in that entity or the power to direct its management and policies, whether by contract or otherwise. |
Data Protection Laws | as applicable and binding on either party or the Service(s): (a) the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003; (b) the GDPR, to the extent applicable to the Processing of Protected Data; (c) any other laws and regulations relating to data protection, privacy or the Processing of Personal Data; (d) any laws which implement any such laws; and (e) any laws that replace, extend, re-enact, consolidate or amend any of the foregoing. |
Data Subject Request | a request made by or on behalf of a Data Subject to exercise any of their rights under Data Protection Laws in relation to Protected Data. |
GDPR | Regulation (EU) 2016/679 (General Data Protection Regulation). |
List of Sub-Processors | Set out in Schedule 1 to this Addendum, as updated from time to time in accordance with Clause 5.2. |
Processing Instructions | the Customer’s documented instructions as set out in this Addendum and the Agreement, and in particular in the table at the start of this Addendum, as updated from time to time. |
Protected Data | the Personal Data contained within the Customer Data. |
Sub-Processor | a sub-processor engaged by Ploy for Processing of Protected Data on behalf of the Customer. |
Transfer | a transfer of Personal Data to a third country or international organisation within the meaning of Chapter V of the UK GDPR or the GDPR (as applicable). |
UK GDPR | has the meaning given in section 3(10) of the Data Protection Act 2018 (as supplemented by section 205(4) of that Act). |
Update Notice | a written notice given by Ploy under Clause 5.2 of a new Sub-Processor, stating the Sub-Processor’s identity, location and the Processing it will carry out. |
2 Processor and Controller
2.1 The parties agree that, for the Protected Data, the Customer and/or the relevant Customer Group Company (as applicable) shall be the Controller and Ploy shall be the Processor. Nothing in this Addendum relieves the Customer of any responsibilities or liabilities under any Data Protection Laws.
2.2 Ploy shall Process Protected Data in compliance with:
2.2.1 the obligations of Processors under Data Protection Laws in respect of the performance of its obligations under the Agreement; and
2.2.2 the terms of this Addendum.
2.3 The Customer shall ensure that it, and each Authorised User, complies at all times with:
2.3.1 all Data Protection Laws in connection with the Processing of Protected Data, the use of the Service(s) and the exercise and performance of its respective rights and obligations under this Addendum, including maintaining all relevant regulatory registrations and notifications as required under Data Protection Laws; and
2.3.2 the terms of this Addendum and the Agreement.
2.4 The Customer warrants, represents and undertakes, that at all times:
2.4.1 it shall take reasonable steps to ensure that the Protected Data is accurate and, where necessary, kept up to date;
2.4.2 it shall establish and maintain adequate security measures to safeguard the Protected Data in its possession or control (including from unauthorised or unlawful destruction, corruption, Processing or disclosure) and maintain complete and accurate backups of all Protected Data provided to Ploy (or anyone acting on its behalf) so as to be able to recover within a reasonable time and reconstitute such Protected Data in the event of loss, damage or corruption of such Protected Data by any person (provided that this shall not limit Ploy’s obligations under this Addendum or its liability under the Agreement where Ploy or any Sub-Processor causes such loss, damage or corruption); and
2.4.3 all instructions given by it to Ploy in respect of Protected Data shall always be in accordance with Data Protection Laws.
2.5 Where the Customer permits any Customer Group Company to use the Service(s) in accordance with the Agreement:
2.5.1 the Customer enters into this Addendum on its own behalf and on behalf of each such Customer Group Company, and warrants that it is authorised to do so;
2.5.2 the Customer shall be Ploy’s sole point of contact and shall give all Processing Instructions and notices, and exercise all rights (including objection and audit rights) under this Addendum, on behalf of each such Customer Group Company;
2.5.3 the Customer shall procure that each such Customer Group Company complies with the Customer’s obligations under this Addendum as if it were the Customer, and shall be responsible for its acts and omissions; and
2.5.4 only the Customer may enforce this Addendum (on its own behalf and on behalf of each such Customer Group Company), and Ploy’s aggregate liability to the Customer and all Customer Group Companies together under or in connection with this Addendum shall be subject to Clause 13 of the Agreement as if they were a single person.
3 Instructions and details of processing
3.1 To the extent Ploy Processes Protected Data on behalf of the Customer, Ploy warrants, represents and undertakes that it shall:
3.1.1 unless required to do otherwise by Applicable Law, (and shall take steps to ensure each person acting under its authority shall) Process the Protected Data only on and in accordance with the Processing Instructions;
3.1.2 if Applicable Law requires it to Process Protected Data other than in accordance with the Processing Instructions, notify the Customer of any such requirement before Processing the Protected Data (unless Applicable Law prohibits such information on important grounds of public interest); and
3.1.3 immediately inform the Customer if Ploy becomes aware of a Processing Instruction that, in Ploy’s opinion, infringes Data Protection Laws, and may suspend the affected Processing until that Processing Instruction is withdrawn or amended.
3.2 The Customer acknowledges and agrees that the execution of any computer command to Process (including deletion of) any Protected Data made in the use of any of the Service(s) by an Authorised User will be a Processing Instruction (other than to the extent such command is not fulfilled due to technical, operational or other reasons, including as set out in the Documentation). The Customer shall ensure that Authorised Users do not execute any such command unless authorised by the Customer (and by all other relevant Controller(s)) and acknowledges and accepts that if any Protected Data is deleted pursuant to any such command Ploy is under no obligation to seek to restore it.
4 Technical and organisational measures
4.1 Ploy shall implement and maintain all necessary technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR and other applicable Data Protection Laws.
4.2 The parties agree that, taking into account the nature of the Processing and the risks to Data Subjects, Ploy shall, as a minimum, implement and maintain the measures set out in Schedule 2, which shall supplement and not limit Ploy’s obligations under Clause 4.1. Ploy may update or replace any of those measures from time to time without the Customer’s consent. Ploy shall not materially reduce the overall level of security provided by those measures and shall provide the Customer with a written description of its current technical and organisational measures on request.
5 Using staff and other Processors
5.1 The Customer hereby gives Ploy a general consent to engage Sub-Processors.
5.2 As at the Commencement Date, Ploy’s Sub-Processors are those listed in the List of Sub-Processors. Ploy shall notify the Customer in writing at least thirty (30) days before transferring any Protected Data to a new Sub-Processor, stating the Sub-Processor’s identity, location and the Processing it will carry out. Following receipt of the Update Notice the Customer shall notify Ploy if it objects to the new Sub-Processor. If the Customer does not object to the Sub-Processor within fourteen (14) days of receiving the Update Notice, the Customer shall be deemed to have accepted the Sub-Processor. If the Customer has raised a reasonable objection to the new Sub-Processor, and the parties have failed to agree on a solution within reasonable time, the Customer may, without penalty, terminate the Agreement by written notice to Ploy on or before the date on which the new Sub-Processor was due to commence Processing Protected Data.
5.3 Ploy shall:
5.3.1 prior to the relevant Sub-Processor carrying out any Processing activities in respect of the Protected Data, ensure each Sub-Processor is appointed under a written contract containing data protection obligations meeting the requirements of Article 28(3) of the UK GDPR and any equivalent provision of other Data Protection Laws (save that a Sub-Processor’s audit and information obligations may be satisfied by the provision of independent third-party certifications and audit reports), in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of Data Protection Laws; and
5.3.2 remain fully liable for all the acts and omissions of each Sub-Processor as if they were its own.
5.4 Ploy shall ensure that all persons authorised by it (or by any Sub-Processor) to Process Protected Data are subject to a binding written contractual obligation to keep the Protected Data confidential (except where disclosure is required in accordance with Applicable Law, in which case Ploy shall, where practicable and not prohibited by Applicable Law, notify the Customer of any such requirement before such disclosure).
6 Assistance with compliance and data subject rights
6.1 Ploy shall refer all Data Subject Requests it receives to the Customer without undue delay (and in any event within five (5) Business Days of receipt), shall not respond to any such request except on the Customer’s documented instructions and, where applicable, provide reasonable assistance by making relevant Protected Data available, facilitating access, rectification, restriction, or erasure, and implementing other necessary measures to enable the Customer to fulfil its obligations under applicable Data Protection Laws.
6.2 Ploy shall provide such assistance to the Customer as is reasonably required (considering the nature of Processing and the information available to Ploy) to ensure compliance with the Customer’s obligations under Data Protection Laws with respect to:
6.2.1 security of Processing;
6.2.2 data protection impact assessments (as such term is defined in Data Protection Laws);
6.2.3 prior consultation with a Supervisory Authority regarding high-risk Processing; and
6.2.4 notifications to the Supervisory Authority and/or communications to Data Subjects by the Customer in response to any Personal Data Breach,
provided that, except where the assistance relates to a Personal Data Breach or other matter caused by Ploy’s (or any Sub-Processor’s) breach of this Addendum or Data Protection Laws, the Customer shall pay Ploy for all reasonable work, time, costs and expenses incurred by Ploy or any Sub-Processor(s) in connection with providing the assistance in this Clause 6.2, calculated on a time and materials basis.
7 International Data Transfers
7.1 Ploy will not Transfer any Protected Data outside the United Kingdom or European Economic Area without the Customer’s prior written authorisation (which is given for the Sub-Processors and locations identified in the List of Sub-Processors, as updated from time to time in accordance with Clause 5.2) and unless it has implemented a Transfer mechanism compliant with Data Protection Laws (which may include the documents known as the European Union “Standard Contractual Clauses”, the United Kingdom “International Data Transfer Agreement” or “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses”, or any other appropriate safeguard approved by the relevant authorities).
7.2 The Customer acknowledges that, due to the nature of cloud services, where an Authorised User accesses the Protected Data, such Protected Data may be transferred to the location of the Authorised User. Any such Transfer will be considered a Transfer by the Customer, and not by Ploy, and it is the Customer’s responsibility to ensure that such locations afford an adequate level of protection for the Protected Data.
8 Information and audit
8.1 On request, Ploy shall make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR and this Addendum and shall provide the Customer (or auditors mandated by the Customer) with a copy of the third-party certifications and audits to the extent made generally available to its customers. Such information shall be Ploy’s Confidential Information as defined in the Agreement.
8.2 Ploy will, during the Term and for so long as Ploy or any Sub-Processor holds Protected Data, on at least 10 Business Days’ notice (or such shorter notice as is reasonable following a Personal Data Breach affecting Protected Data) and during normal business hours, permit the Customer and its third-party representatives to audit Ploy’s compliance with its obligations under this Addendum and Data Protection Laws. The Customer may exercise this audit right no more than once in any 12-month period, except where an additional audit is required by a Supervisory Authority or is reasonably necessary following such a breach.
8.3 Ploy will give the Customer and its third-party representatives all reasonably necessary assistance to conduct such audits. The assistance may include, but is not limited to:
8.3.1 physical access to, remote electronic access to, and copies of, records of Ploy’s activities under the Agreement related to the Processing of Protected Data;
8.3.2 access to and meetings with any of Ploy’s personnel reasonably necessary to provide all explanations and perform the audit effectively; and
8.3.3 inspection of all relevant records and the infrastructure, electronic data or systems, facilities, equipment or application software used to store, Process the Protected Data (provided that Ploy shall not be required to breach any of its obligations of confidentiality to any third party (but shall not rely on such obligations to withhold information necessary to demonstrate its compliance with this Addendum), and that Ploy will only be required to grant access to facilities which are under its direct control).
9 Breach notification
9.1 In respect of any Personal Data Breach, Ploy shall, without undue delay (and in any event within 24 hours of Ploy becoming aware of the breach):
9.1.1 notify the Customer of the Personal Data Breach;
9.1.2 provide the Customer with the information referred to in Article 33(3) of the UK GDPR, to the extent available, and further information in phases as it becomes available; and
9.1.3 take all reasonable steps to contain, investigate and mitigate the Personal Data Breach and provide such cooperation as the Customer reasonably requires.
10 Deletion of Protected Data and copies
Within thirty (30) days following the end of the provision of the Service(s) (or any part) relating to the Processing of Protected Data, Ploy shall, at the Customer’s written election, return or securely delete all Protected Data (including all copies) in its possession or control, save that Protected Data held in backups shall be deleted in accordance with Ploy’s standard backup cycle and in any event within ninety (90) days (and, until so deleted, such backups shall be put beyond use and not otherwise Processed). If the Customer does not elect whether the Protected Data should be returned or deleted by the end of the provision of the relevant Service(s), Ploy shall securely delete it in accordance with this Clause. Where Applicable Law requires Ploy to keep any Protected Data, Ploy shall notify the Customer, keep that Protected Data confidential and Process it only as that law requires. Ploy shall confirm such return or deletion to the Customer in writing on request.
11 Survival
This Addendum shall survive termination (for any reason) or expiry of the Agreement and continue until no Protected Data remains in the possession or control of Ploy or any Sub-Processor.
Schedule 1 — List of Sub-Processors
Effective date: 14 September 2025. Last updated: 1 May 2026.
Name | Subject matter, nature and purpose of Processing | Location of Processing | Signing entity location | Transfer Mechanism |
Amazon Web Services | Cloud hosting, infrastructure, and Luna AI inference via AWS Bedrock | UK | Luxembourg (EU) | Adequacy |
Datadog | Application monitoring and error tracking | EU | US | Data is stored in the EU, but our contract is with the US entity. Datadog is signed up to the UK Extension to the EU-U.S. Data Privacy Framework. |
Functional Software (Sentry) | Application performance monitoring and error tracking | EU | US | Data is stored in the EU, but our contract is with the US entity. Sentry is signed up to the UK Extension to the EU-U.S. Data Privacy Framework. |
IPstack | IP address location identification | EU | Austria (EU) | Adequacy |
Netlify | Ploy dashboard static files hosting (data is IP address only) | The country of the user | US | Netlify is signed up to the UK Extension to the EU-U.S. Data Privacy Framework. |
Cordnet OU (Featurebase) | Customer feedback and helpdocs | Germany (EU) | Estonia (EU) | Adequacy |
Slack | Error notification handling, which may occasionally contain Protected Data | US | Ireland (EU) | Adequacy |
Schedule 2 — Technical and organisational measures
Ploy maintains an information security programme that is independently audited against SOC 2 Type 2 (or an equivalent recognised standard) and will provide its most recent report on request in accordance with Clause 8.1. Its current controls are summarised at trust.ploy.io. As a minimum, Ploy shall maintain the following measures:
1.Governance and people. Documented information security policies; a designated security officer; background checks and confidentiality agreements for all staff; security awareness training; and regular risk assessments.
2.Hosting and separation. Protected Data hosted on Amazon Web Services in the United Kingdom, with backups held in the same region, and each customer’s data logically separated. Certain Sub-Processors Process Protected Data in other locations, as set out in the List of Sub-Processors.
3.Access control. Role-based access on a least-privilege basis; multi-factor authentication for critical systems; restricted production access; regular access reviews; and prompt removal of access for leavers.
4.Encryption. Protected Data encrypted at rest and in transit using industry-standard encryption.
5.Infrastructure and endpoint security. Firewalls and a web application firewall; infrastructure defined as code, with changes reviewed and logged; and centrally managed, encrypted company devices with anti-malware.
6.Monitoring and incident response. Collection and review of audit logs; continuous infrastructure monitoring; and a documented incident response process, with Personal Data Breaches notified in accordance with Clause 9.
7.Vulnerability management. Automated vulnerability scanning and patching, and penetration testing at least annually, with findings remediated.
8.Resilience. Automated, encrypted backups isolated from production, and a business continuity and disaster recovery plan tested at least annually.
9.Sub-Processors. A maintained inventory of vendors and a risk assessment of each vendor, reviewed regularly.
10.Artificial intelligence. Protected Data is not used to train or fine-tune any artificial intelligence model.