1.Overview
This Data Processing Addendum (DPA) describes how HarmoniHRM processes personal data on behalf of customers who use the service, and reflects the requirements of data protection laws such as the EU and UK GDPR and similar regimes worldwide. It forms part of the agreement between the customer (the controller) and HarmoniHRM (the processor). Where there is a conflict on data protection matters, this DPA is intended to prevail over the general Terms of Service.
2.Roles of the parties
For workforce data entered into the service, the customer is the controller and determines the purposes and means of processing, and HarmoniHRM is the processor that processes that data on the customer’s documented instructions. Each party is responsible for complying with the data protection laws that apply to it. HarmoniHRM acts as a controller only for limited data such as account administration and billing, which is covered by our Privacy Notice.
3.Scope and instructions
HarmoniHRM processes personal data only to provide and support the service, and on the customer’s documented instructions, including as configured through the product. The subject matter is the provision of the workforce operating system; the nature and purpose is hosting and processing workforce records; the duration is the term of the agreement; the data subjects are the customer’s workers and related individuals; and the categories of data are those the customer chooses to store. We will inform the customer if, in our view, an instruction breaches applicable law.
4.Confidentiality
We ensure that personnel authorised to process customer personal data are bound by appropriate confidentiality obligations and are granted access on a least-privilege, need-to-know basis.
5.Security measures
We implement appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs of implementation and the risks involved. These include encryption in transit and at rest, tenant isolation through row-level security, access controls, audit logging and incident response, as described on our Security page.
6.Sub-processors
The customer authorises HarmoniHRM to engage sub-processors to help provide the service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. A current list is published on our Sub-processors page, and we will give notice of intended changes so customers can review them.
7.Assistance with data subject rights
Taking into account the nature of the processing, we will provide reasonable assistance, including appropriate product features, to help the customer respond to requests from individuals to exercise their rights, such as access, correction, deletion and portability.
8.International transfers
Where processing involves transferring personal data across borders, we use appropriate safeguards recognised under applicable law, such as standard contractual clauses or equivalent mechanisms, and apply consistent protections regardless of where data is processed.
9.Personal data breaches
We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data, and will provide the information reasonably available to help the customer meet its own notification obligations.
10.Audits
On reasonable request and subject to confidentiality, we will make available the information needed to demonstrate compliance with this DPA, and will allow for and contribute to reasonable audits, including through summaries, security documentation, or third-party reports as they become available.
11.Return and deletion of data
On termination of the service, and at the customer’s choice, we will return or delete customer personal data within a reasonable period, unless retention is required by law. Backups are deleted in line with our standard backup cycle.
12.Contact us
To request a countersigned copy of this DPA, or for questions about data processing, contact hello@harmonihrm.com.