Data Processing Agreement
Version 1.0 — Effective date: 28 March 2026
This agreement forms part of the Crewkind Terms of Service.
1. Definitions and Roles
In this Data Processing Agreement (“DPA”):
- “Customer” means the organisation that has signed up for the Crewkind Service. The Customer is the Data Controller — they determine the purposes and means of processing personal data about their employees.
- “Crewkind” is the Data Processor — we process personal data only on the documented instructions of the Customer, for the purpose of providing the Service.
- “Personal Data” has the meaning given in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- “Processing” means any operation performed on Personal Data, including storage, retrieval, use, disclosure, or deletion.
2. Processing Details
| Subject matter | HR data management — employee records, leave, onboarding, compliance tracking |
| Duration | For the duration of the Customer's subscription, plus 30 days after termination |
| Purpose | To provide the Crewkind HR platform features as described in the Terms of Service |
| Data types | Employee names, contact details, employment records, working patterns, leave records, HR notes, right to work documents, onboarding documents, payroll reference data, bank account details (where entered) |
| Data subjects | The Customer's employees, workers, and contractors |
3. Crewkind's Obligations
Crewkind shall:
- Process Personal Data only on documented instructions from the Customer (as established through use of the Service) and not for any other purpose
- Ensure that all personnel with access to Personal Data are bound by appropriate confidentiality obligations
- Implement and maintain appropriate technical and organisational security measures (see Section 5)
- Not engage any sub-processor without the Customer's general authorisation (see Section 6)
- Assist the Customer in responding to data subject rights requests within reasonable timescales
- Notify the Customer of a personal data breach within 72 hours of becoming aware of it
- Delete or return all Personal Data upon termination of the Service (see Section 7)
- Make available all information necessary to demonstrate compliance with this DPA, and allow for audits (see Section 8)
4. Customer's Obligations
The Customer, as Data Controller, is responsible for:
- Ensuring they have a lawful basis for processing employee Personal Data (typically legitimate interests or performance of an employment contract)
- Providing employees with appropriate privacy notices about the use of the Crewkind platform
- Ensuring the accuracy and lawfulness of all data entered into the Service
- Managing data subject rights requests from their employees (Crewkind will assist technically where required)
- Notifying Crewkind promptly of any instructions that would cause Crewkind to breach applicable data protection law
5. Security Measures
Crewkind implements the following technical and organisational measures to protect Personal Data:
- Encryption in transit: All data transmitted over TLS 1.2 or higher
- Encryption at rest: All data encrypted at rest in Supabase (AES-256)
- Access control: Role-based access control — employees can only access their own data; managers their team; admins their organisation
- Tenant isolation: Row-Level Security (RLS) enforced at database level — data is strictly segregated between customers
- Authentication: Magic link authentication — no passwords stored
- Infrastructure: Hosted on Vercel (application) and Supabase (database), both with SOC 2 Type II certification
- Security reviews: Regular internal security reviews of code and infrastructure
6. Sub-processors
The Customer provides general authorisation for Crewkind to engage the following sub-processors. Crewkind will notify the Customer of any changes to this list with at least 30 days' notice, giving the Customer the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc | Database hosting, authentication, and file storage | EU (Ireland) |
| Vercel Inc | Application hosting and edge delivery | EU regions (Netherlands / Frankfurt) |
| Resend Inc | Transactional email (login links, invites, notifications) | EU regions |
| Stripe Inc | Payment processing and billing (billing contact only — no employee data) | EU regions (Standard Contractual Clauses) |
| Anthropic PBC | AI candidate screening and forecast nudges (anonymised prompts only — no employee PII transmitted). Anthropic does not use API data for model training. | US (Standard Contractual Clauses) |
| TrustID Ltd | Right-to-work and identity document verification (Recruit module — used only where enabled) | UK |
| Google LLC, Mozilla Foundation, Apple Inc | Browser push notification delivery (device push endpoint only — no message content) | US (Standard Contractual Clauses) |
All sub-processors are bound by data processing agreements providing equivalent protection to this DPA. Crewkind also uses Xero for its own accounting; no customer employee data is shared with Xero.
7. Data Retention and Deletion
Upon termination or expiry of the Customer's subscription:
- The Customer's data will be retained for 30 days, during which the Customer may request a full data export at no charge
- After 30 days, all Personal Data will be permanently and irreversibly deleted from Crewkind's systems and all sub-processor systems
- Crewkind will provide written confirmation of deletion upon request
Employee data retention within an active subscription: Employee records for staff who have left are retained in accordance with the Customer's instructions and UK statutory requirements (typically 6 years from the end of employment for payroll records). Customers can mark employees as “Left” and set a specific deletion date within the platform.
8. Audit Rights
The Customer may audit Crewkind's data processing activities relevant to this DPA no more than once per calendar year, with at least 30 days' written notice. Audits shall be conducted during normal business hours and in a manner that does not unreasonably disrupt Crewkind's operations. The Customer shall bear the costs of any third-party auditor.
Crewkind may satisfy audit requests by providing up-to-date third-party audit reports (e.g., SOC 2 reports from Supabase and Vercel) in lieu of a direct audit.
9. International Transfers
Personal Data is stored primarily in the EU (Ireland and Frankfurt). The AI HR assistant feature uses Anthropic (US-based); prompts sent to this service are anonymised and contain no employee Personal Data. Where any transfer outside the UK/EEA is required, Crewkind will ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent).
10. Contact
For data protection queries, contact us at privacy@crewkind.app.