Data Processing Agreement
Version 1.0 · Effective 2026-06-15
This Data Processing Agreement ("DPA") is entered into between iHybrid Ltd trading as TeamZap (the "Processor") and you, the customer organisation (the "Controller"), and forms part of the TeamZap Terms of Service.
1. Subject Matter and Duration
The Processor will process Controller personal data on the Controller's behalf solely to provide the TeamZap Service for the duration of the Terms of Service.
2. Nature and Purpose of Processing
Workforce management: scheduling, time tracking, leave management, payroll-relevant data calculation, internal messaging, analytics.
3. Categories of Data Subjects
- Controller's employees, contractors, and applicants
- Controller's administrators and managers
4. Categories of Personal Data
- Identification data: name, employee ID, email, phone
- Work data: role, location, schedule, attendance, leave, payroll-relevant
- Authentication data: hashed credentials, session tokens
- Optional: emergency contacts, qualifications, profile photo
5. Processor Obligations
- Process personal data only on documented Controller instructions
- Ensure personnel processing data are bound by confidentiality
- Implement appropriate technical and organisational security measures (see Annex 1)
- Assist the Controller in fulfilling data-subject rights requests
- Notify the Controller without undue delay (within 72 hours) of any personal data breach
- Make available all information necessary to demonstrate compliance and allow audits
- Delete or return all personal data to the Controller on termination, subject to applicable retention obligations
6. Sub-Processors
The Controller authorises the Processor to engage sub-processors listed at /legal/sub-processors. The Processor will notify the Controller of any intended additions or replacements at least 30 days in advance and will give the Controller the opportunity to object on reasonable grounds.
7. International Transfers
Personal data is primarily stored in the European Economic Area. Where transfers outside the EEA occur, they are governed by Standard Contractual Clauses or other lawful transfer mechanisms.
8. Data Subject Rights
The Processor provides in-product tooling that enables the Controller to respond to data-subject access, rectification, erasure, restriction, and portability requests within statutory deadlines.
9. Audits
The Controller may, on reasonable notice and no more than once per year (or more frequently following a breach), audit the Processor's compliance with this DPA. Audits will be conducted during business hours, at the Controller's cost, and subject to reasonable confidentiality undertakings.
10. Liability
The liability provisions of the Terms of Service apply equally to this DPA.
11. Annex 1 — Security Measures
- TLS 1.2+ for all data in transit
- AES-256 envelope encryption at rest for sensitive fields
- Per-tenant data isolation enforced at the database query layer
- Role-based access control with least-privilege defaults
- Multi-factor authentication available for all administrator accounts
- Rate limiting, anomaly detection, automated alerting
- Continuous backup with point-in-time recovery (30-day retention)
- Penetration testing performed prior to general availability
- Personnel security training; confidentiality agreements in place
- Incident response procedure with 72-hour breach notification
12. Annex 2 — Sub-Processors
See /legal/sub-processors for the current list of sub-processors with their location and the processing activities they perform.
13. Contact
Data Protection enquiries: [email protected]