Data Processing Agreement
The terms on which CoDash processes personal data as a processor on behalf of its customers under UK GDPR.
When you use CoDash to manage your people, you are the controller of your employees' personal data and CoDash is your processor. This agreement sets out how we process that data only on your instructions, keep it secure and isolated, use limited vetted sub-processors, and help you meet your UK GDPR obligations.
1. Parties and scope
This Data Processing Agreement ("DPA") is between the Customer ("Controller") and CoDash Ltd, a company registered in England and Wales (company no. 17390939, ICO registration ZC223521) whose registered office is at 66 Paul Street, London EC2A 4NA, United Kingdom ("CoDash", "Processor"), and forms part of the Terms of Service (the "Agreement"). It applies to CoDash's processing of personal data contained in Customer Data on the Controller's behalf. Terms such as "personal data", "processing", "controller", "processor" and "data subject" have the meanings in UK GDPR and the Data Protection Act 2018.
2. Roles and instructions
The Controller determines the purposes and means of processing. CoDash will process personal data only on the Controller's documented instructions (including as set out in the Agreement and through use of the Service), unless required by law, in which case it will inform the Controller unless legally prohibited. If CoDash believes an instruction breaches data protection law, it will tell the Controller.
3. Nature and purpose of processing
The nature, purpose, duration, types of personal data and categories of data subjects are set out in Annex A. In summary, CoDash processes HR and people-management data to provide the CoDash platform for the duration of the Controller's subscription.
4. Confidentiality
CoDash ensures that personnel authorised to process personal data are bound by confidentiality and access it only as needed to provide the Service.
5. Security measures
CoDash implements appropriate technical and organisational measures, described in Annex B. These include tenant isolation (each customer on a separate database and instance), encryption of data in transit, role-based access controls, audit logging, and privacy-by-design features such as k-anonymity gating of aggregate reports and anonymous feedback stored without an author field.
6. Sub-processors
The Controller authorises CoDash to engage the sub-processors listed in Annex C to process personal data. CoDash imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance. CoDash will give the Controller reasonable prior notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data-protection grounds.
7. AI features
Where the Controller enables AI coaching features, limited content (for example anonymous feedback text and aggregated team statistics) may be processed by an AI sub-processor to generate themes and coaching suggestions. This content is de-identified - it contains no author or user identifier - and individual mood check-ins are never sent. If no AI provider is configured, these features run on a built-in, on-instance fallback and no data leaves the instance. See Annex C.
8. Assistance to the Controller
Taking into account the nature of processing, CoDash will assist the Controller, by appropriate technical and organisational measures and so far as possible, with: (a) responding to data subject rights requests (the Service includes self-service tooling such as subject-access exports and a "who accessed my record" panel); (b) security, breach notification and data protection impact assessments; and (c) prior consultation with the ICO where required.
9. Personal data breaches
CoDash will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available to help the Controller meet its own notification duties.
10. International transfers
CoDash hosts personal data in the UK/EU and will not transfer it outside the UK/EEA except where an appropriate safeguard applies (UK adequacy, the International Data Transfer Agreement, or Standard Contractual Clauses), as noted per sub-processor in Annex C.
11. Return or deletion on termination
On expiry or termination of the Agreement, CoDash will, at the Controller's choice, return and/or delete the personal data (and delete existing copies) within 3 months (90 days), unless retention is required by law. The Service provides export tooling and supports anonymise-on-exit and retention auto-purge.
12. Audits
CoDash will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an authorised auditor, subject to reasonable notice, confidentiality and frequency limits.
13. Liability and precedence
Liability under this DPA is subject to the limitations in the Agreement. If there is a conflict on data protection matters, this DPA prevails over the rest of the Agreement.
Annex A - Details of processing
- Subject matter: provision of the CoDash HR and employee-experience platform.
- Duration: the term of the Controller's subscription, plus the deletion window in clause 11.
- Nature and purpose: hosting, storing and processing HR data so the Controller can manage people, time off, documents, performance, engagement and related workflows.
- Categories of data subjects: the Controller's employees, workers, contractors and administrators (and, where entered, their emergency contacts).
- Types of personal data: identity and contact details, job and organisational data, time-off and absence records, documents, performance and 1:1 notes, recognition, survey responses and mood check-ins, and account/usage data. Special category data may be present where the Controller records it (for example health-related absence reasons); the Controller controls what is entered.
Annex B - Technical and organisational measures
- Tenant isolation - each customer runs on a separate database, instance and subdomain; nothing is shared between customers.
- Encryption in transit (HTTPS/TLS) and encrypted credentials.
- Access control - role-based permissions, least-privilege staff access, optional SSO and 2FA on higher plans.
- Privacy by design - k-anonymity gating of manager-facing aggregates; anonymous feedback stored with no author column; individual moods never exposed to managers.
- Auditability - audit logging and a per-employee "who accessed my record" panel.
- Resilience - regular encrypted backups with rotation, and restore procedures.
- GDPR tooling - subject-access exports, anonymise-on-exit, configurable retention auto-purge.
- Operational security - regular patching, restricted infrastructure access and incident-response procedures.
Annex C - Authorised sub-processors
| Sub-processor | Purpose | Location / transfer basis |
|---|---|---|
| JonesDigital | Cloud hosting and storage of the platform (affiliated hosting company) | European Union |
| Brevo SAS | Transactional and notification email (invites, reminders) | France (EU) |
| Google (Google Workspace) | Business correspondence email | UK/EU; US under UK IDTA / SCCs |
| Sentry (Functional Software Inc.) | Error monitoring - diagnostic data only; configured to transmit no user identifiers, IP addresses or request bodies | EU (Frankfurt region) |
| Stripe | Billing and payment processing | UK/EU; US under adequacy / SCCs |
| Anthropic (Claude) - only if AI coaching is enabled | Generating coaching themes from de-identified, author-less feedback and aggregate stats | US under UK IDTA / SCCs |
Contact
Questions about this DPA? Email hello@codash.co.uk or call 07337 158671. See also our Terms of Service and Privacy Policy.