Legal
Data Processing Agreement
This agreement governs how Native Keeper processes personal data on behalf of customers using the Service.
Last updated: 10 June 2026 · Version 1.0
1. Introduction and Acceptance
This Data Processing Agreement ("DPA") forms part of the agreement between NeonStack Ltd, a company registered in England and Wales under company number 16933096, with its registered office at The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD, trading as Native Keeper ("Native Keeper", "we", "us", "our", or "Processor"), and the customer identified in the Native Keeper account or order form ("Customer", "you", or "Controller") (together, the "Parties").
This DPA governs the Processing of Personal Data by Native Keeper on behalf of the Customer in connection with the use of the Native Keeper service (the "Service") as set out in the Native Keeper Terms of Service (the "Agreement").
By accepting the Terms of Service, subscribing to a paid plan, or otherwise using the Service to Process Personal Data, the Customer accepts this DPA, which is incorporated by reference into the Agreement. If there is any conflict between this DPA and the Agreement, this DPA prevails in respect of the Processing of Personal Data.
Native Keeper is an HR and workforce compliance platform. Its ordinary purpose is to hold and process employment-related Personal Data — including, where appropriate, Special Category Personal Data and criminal-offence data. This DPA is drafted to support those purposes lawfully.
2. Definitions
Terms not defined in this DPA have the meanings given to them in the Agreement or in Applicable Data Protection Law.
"Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK General Data Protection Regulation as incorporated into UK law ("UK GDPR"), the UK Data Protection Act 2018 ("DPA 2018"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any other national, sub-national, or supranational data-protection legislation applicable to a Party in respect of the Processing.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Special Categories of Personal Data" (or "Special Category Personal Data"), and "Supervisory Authority" have the meanings given in the EU GDPR (or their equivalents under other Applicable Data Protection Law).
"Criminal-Offence Data" means Personal Data relating to criminal convictions and offences or related security measures, as defined in Art. 10 UK GDPR / EU GDPR and Section 11 DPA 2018.
"Customer Personal Data" means any Personal Data Processed by Native Keeper on behalf of the Customer under the Agreement, including data uploaded by the Customer or its Admin Users about the Customer's employees, workers, contractors, applicants, or any other individuals whose records are held in the Service.
"Data Subject" in this DPA primarily refers to the Customer's employees, workers, contractors, applicants, or other individuals whose Personal Data is Processed in the Service.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission Decision (EU) 2021/914 of 4 June 2021.
"UK IDTA" means the International Data Transfer Agreement, or the UK Addendum to the EU SCCs, issued by the UK Information Commissioner's Office, as applicable.
"Sub-processor" means any third party engaged by Native Keeper to Process Customer Personal Data on Native Keeper's behalf.
"Service" means the Native Keeper platform and any related services provided by Native Keeper under the Agreement.
3. Roles and Scope of Processing
3.1 Roles of the Parties
The Parties acknowledge and agree that:
The Customer is the Controller of Customer Personal Data submitted to or held in the Service, including data about the Customer's employees, workers, contractors, applicants, and any other individuals whose records the Customer maintains in the Service.
Native Keeper is the Processor of Customer Personal Data and Processes such data only on the documented instructions of the Customer.
In respect of Personal Data of the Customer's own account users (for example, the individuals who register a Native Keeper account, billing contacts, administrators acting in their capacity as authorised representatives of the Customer, and other customer-side users of Native Keeper's own services), Native Keeper acts as an independent Controller, and such processing is governed by Native Keeper's Privacy Policy, not this DPA.
3.2 Customer Instructions
Native Keeper will Process Customer Personal Data only:
(a) to provide, maintain, secure, and improve the Service as described in the Agreement and this DPA;
(b) in accordance with the Customer's documented instructions, including configurations made through the Service interface, API, or written communications;
(c) to send compliance, expiry, and other notifications configured by the Customer;
(d) as required to comply with applicable law (in which case Native Keeper will inform the Customer of such requirement before Processing, unless legally prohibited).
The Customer warrants that its instructions, including this DPA, comply with Applicable Data Protection Law and that it has obtained all necessary consents, provided all necessary notices, and established all necessary legal bases for the Processing.
3.3 Subject Matter, Duration, Nature, and Purpose
The details of the Processing are set out in Annex 1 (Details of Processing) to this DPA.
4. Customer Responsibilities
The Customer shall:
(a) Be solely responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which the Customer acquired it.
(b) Ensure it has, and will continue to have, a valid legal basis under Applicable Data Protection Law for collecting and Processing Customer Personal Data, including for instructing Native Keeper to Process it.
(c) Provide all required notices and obtain all required consents from Data Subjects in connection with the Processing, including disclosing the use of Native Keeper as a Processor in the Customer's own privacy notice and (where relevant) employment documentation.
(d) Special Category Personal Data. Where the Customer uses the Service to Process Special Category Personal Data (for example, health data, disability information, sickness absence records, trade-union membership, ethnic origin, or biometric data), the Customer:
(i) Warrants that it has a lawful basis under Art. 9(2) UK/EU GDPR (and, where applicable, a condition under Schedule 1 DPA 2018 or the equivalent under its local law);
(ii) Is responsible for maintaining any policy document or appropriate policy document required by law where relying on the "employment, social security and social protection" or similar condition;
(iii) Acknowledges that Native Keeper Processes such data solely as Processor, on the Customer's instructions, and applies the technical and organisational measures set out in Annex 2.
(e) Criminal-Offence Data. Where the Customer uses the Service to Process Criminal-Offence Data (for example, DBS certificates, background checks, spent-conviction disclosures), the Customer:
(i) Warrants that it has a lawful basis under Art. 10 UK/EU GDPR and a condition under Section 10 and Schedule 1 DPA 2018 (or equivalent under its local law) for such Processing;
(ii) Acknowledges that such data is Processed under the safeguards in Annex 2 and is subject to the same access, storage, and deletion controls as other Customer Personal Data;
(iii) Is solely responsible for onward disclosures, retention decisions, and the lawful use of such data within its organisation.
(f) Data of children and young workers. Where the Customer uses the Service to hold Personal Data of individuals under the age of digital consent in the applicable jurisdiction (typically 13–16), the Customer is responsible for verifying that its legal basis, notices, and (where required) parental consent are in place.
(g) Employment law. The Customer is responsible for compliance with all applicable employment law in each jurisdiction where it operates, including obligations to inform, consult with, or obtain consent from workers, works councils, or trade unions in respect of workforce monitoring, records held about workers, or the use of an HR platform.
(h) Not to use the Service in any manner that violates Applicable Data Protection Law.
5. Native Keeper's Obligations
5.1 Confidentiality
Native Keeper shall ensure that any person authorised to Process Customer Personal Data is bound by appropriate contractual or statutory confidentiality obligations. Access is granted on a need-to-know basis and is logged.
5.2 Security Measures
Native Keeper shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as set out in Annex 2 (Technical and Organisational Measures). In view of the sensitivity of HR data and the presence of Special Category and Criminal-Offence Data, these measures are set at a level appropriate to that sensitivity.
5.3 Assistance to the Customer
Taking into account the nature of the Processing and the information available to Native Keeper, Native Keeper shall provide reasonable assistance to the Customer in:
(a) Responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making);
(b) Ensuring compliance with security obligations (Art. 32 GDPR);
(c) Notifying Personal Data Breaches (Arts. 33-34 GDPR);
(d) Conducting data protection impact assessments and prior consultations with Supervisory Authorities (Arts. 35-36 GDPR);
(e) Responding to enquiries or inspections from regulators and auditors relevant to the Customer's industry (for example, care regulators, sector inspectorates, or professional bodies) to the extent this involves Customer Personal Data held in the Service.
Native Keeper provides self-service tools within the Service to enable the Customer to respond to most Data Subject requests directly (including export, rectification, and deletion of records). Where further assistance is required, Native Keeper may charge a reasonable fee for assistance that is excessive or manifestly unfounded.
5.4 Personal Data Breach Notification
Native Keeper shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Such notification will include, to the extent known:
The nature of the breach, including categories and approximate number of Data Subjects and records affected;
The likely consequences of the breach;
Measures taken or proposed to address the breach and mitigate its effects;
Contact details of Native Keeper's data-protection contact.
Native Keeper's notification or response to a Personal Data Breach shall not be construed as an acknowledgment of fault or liability.
6. Sub-processors
6.1 General Authorisation
The Customer provides general written authorisation for Native Keeper to engage Sub-processors to Process Customer Personal Data, subject to the conditions in this Section 6.
6.2 Current Sub-processors
A current list of Sub-processors engaged by Native Keeper is available at nativekeeper.com/legal/sub-processors. The Customer may subscribe to notifications of changes to this list via the mechanism described on that page.
6.3 New Sub-processors
Native Keeper shall provide at least 30 days' prior notice of any intended addition or replacement of Sub-processors (the "Notice Period"). During the Notice Period, the Customer may object to the new Sub-processor on reasonable data-protection grounds by sending written notice to legal@nativekeeper.com.
If the Customer objects on reasonable grounds and the Parties are unable to resolve the objection within 30 days, the Customer may terminate the affected portion of the Service by written notice to Native Keeper and receive a pro-rata refund of any prepaid fees for unused Service.
6.4 Sub-processor Obligations
Native Keeper shall:
(a) Enter into a written agreement with each Sub-processor imposing data-protection obligations no less protective than those in this DPA;
(b) Remain fully liable to the Customer for the performance of each Sub-processor's obligations.
7. International Transfers
7.1 Permitted Transfers
The Customer authorises Native Keeper and its Sub-processors to transfer Customer Personal Data outside the European Economic Area, the United Kingdom, or Switzerland, provided that such transfers are made in accordance with Applicable Data Protection Law.
7.2 Transfer Mechanisms
Where Native Keeper transfers Customer Personal Data from the EEA, the UK, or Switzerland to a country not deemed adequate by the European Commission, UK Government, or Swiss Federal Data Protection and Information Commissioner respectively, such transfers shall be governed by:
(a) For EEA transfers: the EU Standard Contractual Clauses (Module 2: Controller-to-Processor or Module 3: Processor-to-Processor), hereby incorporated into this DPA by reference, with Annexes completed as set out in Annex 3;
(b) For UK transfers: the UK International Data Transfer Addendum to the EU SCCs, hereby incorporated by reference;
(c) For Swiss transfers: the EU SCCs as adapted for Switzerland by the Swiss Federal Data Protection and Information Commissioner.
7.3 Regional Data Residency
Where the Customer has selected a regional data residency option (where available on the Customer's plan — for example, EU-only or UK-only storage), Native Keeper will store Customer Personal Data at rest within the selected region. Some operational Processing (for example, support access) may still involve limited transfers, which are covered by the safeguards in Section 7.2.
7.4 Customers outside the UK, EEA, and Switzerland
Where the Customer is established outside the UK, EEA, and Switzerland, the Customer is responsible for compliance with any applicable cross-border transfer restrictions under its own local law. Native Keeper will cooperate reasonably to provide information required to meet such obligations.
8. Audits and Compliance
8.1 Audit Rights
Native Keeper shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR.
8.2 Audit Reports
The Customer's audit right shall be satisfied by Native Keeper's provision of:
(a) Native Keeper's most recent SOC 2 Type II report (when available);
(b) Native Keeper's ISO 27001 certification (when available);
(c) Other third-party certifications and reports relevant to Native Keeper's Processing;
(d) Responses to reasonable written questions from the Customer or its auditors.
8.3 On-site Audits
Where the audit reports referenced in Section 8.2 are not sufficient to demonstrate compliance with a Customer's specific obligations under Applicable Data Protection Law, the Customer may request an on-site audit no more than once per calendar year, subject to:
60 days' prior written notice;
Agreement of scope, timing, and confidentiality terms;
The Customer bearing its own costs and Native Keeper's reasonable costs;
The audit being conducted during normal business hours and in a manner that does not unreasonably interfere with Native Keeper's operations, other customers, or the security of the Service.
A Supervisory Authority's audit rights are unaffected by this Section.
9. Automated Processing, AI, and Employment Decisions
9.1 AI Features
Where the Service includes or introduces features powered by artificial intelligence or machine learning (the "AI Features"), the following principles apply:
(a) Native Keeper does not use the content of Customer Personal Data — including the content of workforce records, uploaded documents, or notes about individuals — to train its own or any third party's general-purpose AI models.
(b) Native Keeper may use aggregated, anonymised, and statistical insights derived from usage of the Service to improve the Service, where such insights cannot be used to identify any Data Subject, the Customer, or any individual.
(c) Where AI Features rely on third-party model providers, those providers are listed on the Sub-processors page and are subject to contractual restrictions prohibiting the use of Customer Personal Data for training their general-purpose models.
9.2 Automated Decisions About Employees
Employment decisions — including decisions about hiring, firing, discipline, pay, promotion, performance evaluation, or other decisions that produce legal or similarly significant effects on Data Subjects — are made by the Customer, not by Native Keeper.
Where the Customer uses features of the Service that support such decisions:
(a) The Customer remains solely responsible for the decision, including compliance with Art. 22 UK/EU GDPR (automated individual decision-making) and equivalent provisions under other law;
(b) The Customer is responsible for providing meaningful information to Data Subjects about the logic involved and the right to human intervention where required;
(c) Native Keeper does not warrant that any feature is suitable for making such decisions without human review.
10. Return and Deletion of Data
10.1 During the Term
The Customer may export and delete Customer Personal Data at any time during the term of the Agreement using the export and deletion tools provided in the Service.
10.2 On Termination
Upon termination or expiry of the Agreement, Native Keeper shall:
(a) Continue to make Customer Personal Data available to the Customer for export, at no additional charge, for a period of at least 30 days from the effective date of termination, consistent with Section 3.5 of the Terms of Service;
(b) At the Customer's choice exercised within 30 days of termination, either:
(i) Delete all Customer Personal Data; or
(ii) Return all Customer Personal Data to the Customer in a commonly used machine-readable format (currently CSV, JSON, and original-format attachments).
(c) If the Customer does not make an election within 30 days, Native Keeper will delete Customer Personal Data within a further 30 days, except where retention is required by applicable law.
The 30-day export period may be extended on request where the Customer has a genuine business, regulatory, or legal need for additional time.
10.3 Backup Retention
Customer Personal Data may persist in routine backups for up to 90 days after deletion, after which it is permanently deleted. While in backup, such data is not accessed except for disaster recovery purposes and remains subject to this DPA.
10.4 Customer-Directed Retention
The Customer may configure retention rules within the Service to retain Customer Personal Data for periods that may extend beyond typical SaaS retention windows, reflecting HR-specific statutory retention obligations (for example, payroll records, pension records, occupational health records). Native Keeper does not automatically delete Customer Personal Data during the term of the Agreement.
11. Liability
The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits liability where such limitation is not permitted under Applicable Data Protection Law (for example, liability to Data Subjects under Art. 82 GDPR).
12. Term and Termination
This DPA takes effect on the date the Customer accepts it (or commences use of the Service to Process Personal Data, whichever is earlier) and continues for the duration of the Agreement. The provisions of this DPA that by their nature should survive termination (including Sections 10, 11, and applicable parts of the SCCs) shall survive.
13. Governing Law and Jurisdiction
This DPA is governed by the laws of England and Wales, except that:
Where the SCCs apply, they are governed by the law specified within them;
Where EU GDPR applies, this DPA shall be interpreted consistently with EU law;
Nothing in this DPA limits Data Subjects' rights to bring claims in their place of habitual residence under Art. 79 GDPR.
The Parties submit to the exclusive jurisdiction of the courts of England and Wales for any dispute arising out of or in connection with this DPA, save as set out above.
14. Miscellaneous
14.1 Amendments
Native Keeper may amend this DPA from time to time to reflect changes in law, regulation, or operational practice, provided that no amendment will materially reduce the protections afforded to Customer Personal Data without the Customer's consent. Material changes will be notified at least 30 days in advance.
14.2 Entire Agreement
This DPA, together with the Agreement, constitutes the entire agreement between the Parties regarding the Processing of Customer Personal Data.
14.3 Severability
If any provision of this DPA is found invalid or unenforceable, the remaining provisions remain in effect.
14.4 Contact
For any questions about this DPA or to exercise rights under it:
Email: legal@nativekeeper.com
Postal address: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD
Data Protection Officer: Not appointed. Native Keeper is not required to appoint a DPO under Art. 37 GDPR at this time. Privacy enquiries are handled by the contact above.
EU Representative (Art. 27 GDPR): Not currently appointed. Native Keeper will appoint an EU Representative prior to offering the Service at scale to Data Subjects located in the EEA where required by Art. 27 GDPR, and this DPA will be updated accordingly.
UK Representative: Not required, as NeonStack Ltd is established in the United Kingdom.
Annex 1 — Details of Processing
A. Subject matter and duration
Processing of Personal Data by Native Keeper on behalf of the Customer for the duration of the Agreement and as required for the post-termination obligations in Section 10.
B. Nature and purpose of Processing
Hosting and serving the Service and Customer accounts;
Storing, indexing, and making available Customer Personal Data uploaded by the Customer and its Admin Users;
Sending compliance, expiry, and notification emails as configured by the Customer;
Producing reports, exports, and inspection-ready summaries as configured by the Customer;
Providing analytics, dashboards, and search functionality;
Securing the Service and preventing fraud and abuse;
Providing customer support;
Facilitating the Customer's export and deletion rights.
C. Types of Personal Data
Depending on the Customer's configuration, Personal Data Processed may include:
Identifiers: name, employee ID, photo, date of birth, gender;
Contact details: personal and work email addresses, phone numbers, address, emergency-contact information;
Employment details: job title, department, start date, employment type, location, line manager, contract details;
Compliance records and documents: copies of Right to Work evidence, DBS or other background-check certificates, professional qualifications, mandatory training certificates, driving licences, insurance certificates, and similar documents;
Training and competency records;
Absence, leave, and attendance data (as this functionality is available);
Performance and review data (as this functionality is available);
Health, safety, and incident records (as this functionality is available);
Payroll-related identifiers (as integrations are available) — for example, National Insurance number, tax code, bank account details;
Content of free-text notes entered by the Customer's Admin Users;
Special Category Personal Data, including but not limited to: health data, sickness absence records, disability information, trade-union membership, ethnic origin (where collected for equality-monitoring purposes), and biometric data (as this functionality is available);
Criminal-Offence Data, including but not limited to: DBS certificates, other background-check results, and spent-conviction disclosures.
D. Categories of Data Subjects
Employees, workers, contractors, consultants, apprentices, temporary staff, agency staff, applicants, and other individuals whose records the Customer maintains in the Service.
E. Duration of Processing
For the term of the Agreement, plus the retention and export periods set out in Section 10. Customer-configured retention may extend Processing periods to reflect statutory HR retention obligations.
F. Frequency
Continuous, on-demand.
Annex 2 — Technical and Organisational Measures
Native Keeper implements the following measures to protect Customer Personal Data. These measures are set at a level appropriate to the sensitivity of HR data, including Special Category and Criminal-Offence Data.
Regulatory Registration
ICO Registration: NeonStack Ltd is registered with the UK Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER — PENDING].
Encryption
In transit: TLS 1.2 minimum, TLS 1.3 preferred, for all connections to the Service.
At rest: AES-256 encryption for all Customer Personal Data stored in primary databases, file storage, and backups.
Key management: managed via cloud provider key management services.
Access Controls
Role-based access controls (RBAC) for all internal systems;
Multi-factor authentication required for all employee and contractor access to production systems;
Principle of least privilege; access reviewed periodically;
All production access logged and monitored;
No routine access by Native Keeper personnel to the content of Customer Personal Data; access is on a break-glass basis for support, security, and legal compliance only.
Network Security
Network segregation between production, staging, and corporate environments;
Web application firewall (WAF) and DDoS protection;
Intrusion detection and monitoring.
Application Security
Secure development lifecycle including code review and dependency scanning;
Regular vulnerability scanning;
Security patches applied per documented timelines based on severity.
Personnel
Confidentiality obligations in all employment and contractor agreements;
Security and privacy training for personnel with access to Customer Personal Data.
Business Continuity
Daily automated backups;
Documented disaster recovery and incident response procedures;
Periodic testing of recovery procedures.
Sub-processor management
Due diligence before onboarding;
Contractual obligations no less protective than this DPA;
Periodic review.
Physical Security
Hosting in third-party data centres operated by Sub-processors certified to ISO 27001, SOC 2, or equivalent standards. Native Keeper does not operate its own physical data centres.
Data Segregation
Logical separation of Customer data within multi-tenant infrastructure;
Row-level security enforcing per-Customer isolation at the database layer.
Monitoring and Logging
Centralised logging of security-relevant events;
Automated alerting on anomalous activity;
Retention of security logs for at least 12 months.
Additional Measures for Sensitive HR Data
Document uploads (including DBS certificates and similar sensitive documents) are stored in the same encrypted-at-rest environment as other Customer Personal Data, with access limited to authorised Admin Users of the relevant Customer account;
Access to individual records within a Customer account is controlled by the Customer through the permissions system in the Service;
Audit logs of admin-level actions are retained and made available to Customers on supported plans.
Annex 3 — Standard Contractual Clauses Details
This Annex completes the Annexes to the EU SCCs (Decision (EU) 2021/914).
Module(s) applicable
Module 2 (Controller to Processor) where the Customer is a Controller located in the EEA/UK/Switzerland.
Module 3 (Processor to Processor) where the Customer is itself a Processor.
Parties
Data Exporter: the Customer.
Data Importer: NeonStack Ltd, trading as Native Keeper, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD.
Categories of Data Subjects, Personal Data, and Processing
As set out in Annex 1 above.
Frequency of transfer
Continuous.
Nature of the processing
As set out in Annex 1, Section B.
Purpose of the data transfer and further processing
As set out in Annex 1, Section B.
Retention period
As set out in Section 10 of this DPA.
Sub-processors
Listed at nativekeeper.com/legal/sub-processors.
Competent Supervisory Authority
For EEA transfers: the supervisory authority of the EU Member State where the Customer is established, or where its EU representative is located. Where the Customer is established outside the EEA, the supervisory authority of the EU Member State in which the EU Representative appointed by Native Keeper (when appointed) is located.
For UK transfers: the UK Information Commissioner's Office (ICO).
For Swiss transfers: the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Technical and organisational measures
As set out in Annex 2 above.
Docking clause
The optional docking clause of the SCCs does not apply unless otherwise agreed in writing.