Data Processing Addendum
The controller-to-processor terms for private data a business manages through GoSavis
Status and scope
This Data Processing Addendum (DPA) forms part of the Operator Agreement, and of the Terms of Use, between GoSavis Limited, registered in England and Wales under company number 12899784 with its registered office at 32 Eyre Street, Sheffield, England, S1 4QZ (GoSavis), and the business or organisation using GoSavis Business (the Operator). It applies only where GoSavis processes Operator Personal Data on the Operator’s behalf. It becomes binding when the Operator accepts the Operator Agreement or the Terms of Use.
This DPA does not turn every exchange of personal information into processor activity. The role follows the real purpose and control for each processing operation, regardless of the label used in a contract. If this DPA conflicts with the Operator Agreement or the Terms of Use on a processor obligation, this DPA takes priority for that obligation.
In this DPA, Data Protection Law means the UK GDPR, the Data Protection Act 2018 and other data-protection law that applies to the processing. Operator Personal Data means personal information for which the Operator is the controller and which GoSavis processes solely on its behalf through the private operator workspace.
Controller and processor boundary
The Operator is the controller and GoSavis is its processor for private workforce, rota, internal customer-management and operational information which the Operator chooses to manage in its workspace and for which the Operator determines the purpose. The Operator decides what to enter, who may access it and how its authorised users use it.
The parties act as independent controllers, not as controller and processor, where each determines its own purposes. The processor terms therefore do not cover:
GoSavis controller processing: Platform accounts and identity, marketplace discovery and listings, booking orchestration, platform messages, content and reviews, payment administration and fees, fraud and security, moderation and safety, support, analytics, legal evidence and compliance
Operator controller processing: The service supplied to the customer, staff and contractor management, the Operator’s own tax and legal records, direct communications outside GoSavis and any marketing the Operator chooses to conduct
Controller-to-controller disclosures: Booking and customer information each party needs for its own responsibilities. Each party must provide its own privacy information and lawful basis for that processing
Nothing in this DPA creates a joint-controller arrangement. If a feature later requires the parties jointly to determine a purpose and essential means, GoSavis will document that arrangement separately before the feature is used.
Details of the processing
The processing covered by this DPA is described below:
Subject matter and purpose: Providing the private GoSavis Business workspace and the hosting, organisation, retrieval, transmission, support, security, backup, export and deletion needed to operate workforce, rota, internal customer-management and related tools on the Operator’s instructions
Duration: For the period the Operator uses the relevant service, followed by the return, deletion and backup-expiry periods described below, unless Data Protection Law requires longer processing
Nature of processing: Collecting from authorised users, recording, structuring, storing, retrieving, displaying, transmitting to authorised recipients, restricting, backing up, exporting, correcting and deleting information
Data subjects: The Operator’s owners, employees, workers, contractors and invited team members; its customers, prospective customers and booking participants; and other people whose information an authorised user lawfully enters in the private workspace
Types of personal data: Names and contact details; workspace identity and permissions; roles, skills, availability, shifts and work records; operator-created internal records and customer-management notes tied to bookings or services; service locations; operator workspace files and media; and technical records needed to secure and administer the workspace
Potential sensitive data: A customer may volunteer accessibility, health or other special-category information in a booking note or in a free-text answer. The Operator must not ask for information of that kind in a service’s intake questions, as the Operator Agreement provides, and must not instruct GoSavis to process it unless the Operator has identified a lawful basis and an applicable condition for that processing
The Operator retains all rights and obligations of a controller. It is responsible for the lawfulness, fairness and accuracy of its instructions, its privacy information, its lawful bases and special-category conditions, and the access it grants to authorised users.
Documented instructions
GoSavis will process Operator Personal Data only on the Operator’s documented instructions, including the instructions expressed through its configuration and authorised use of the service, unless UK law requires different processing. If law requires processing outside those instructions, GoSavis will tell the Operator before processing unless the law prohibits that notice.
GoSavis will promptly tell the Operator if, in our reasonable opinion, an instruction infringes Data Protection Law. We may pause the affected processing while the parties resolve the issue. GoSavis will not sell Operator Personal Data or use it for advertising, independent profiling or another purpose of our own.
Confidentiality and security
GoSavis ensures that people authorised to process Operator Personal Data are subject to an appropriate duty of confidentiality and receive access only where their role requires it. We maintain technical and organisational measures appropriate to the risk, including:
TLS for data in transit and managed-provider encryption at rest where supported
Hashed passwords, HttpOnly session cookies, multi-factor and step-up authentication for sensitive operations
Role and capability-based access, least-privilege production access and separate production and staging credentials
Private object storage for non-public uploads, controlled upload and download paths, and limits on file types and sizes
CSRF protection, input validation, request and rate-limit controls, dependency and application patching, and audit records for sensitive operations
Logging and incident-response procedures designed to avoid recording passwords, raw card data, authentication secrets and private form contents
Documented backup, continuity, recovery, deletion and vulnerability-handling procedures
Security measures may evolve as technology and risk change. GoSavis will not materially reduce the overall protection of Operator Personal Data during the service term.
Subprocessors
The Operator gives general written authorisation for GoSavis to use the subprocessors listed below. GoSavis will impose data-protection obligations which provide an equivalent level of protection for the relevant processing, remains responsible for each subprocessor’s performance of those obligations, and limits access to what the service requires.
GoSavis will give at least 30 days’ notice before appointing a new subprocessor for Operator Personal Data or materially changing the purpose of an existing one. The Operator may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may end only the affected service without penalty before the change takes effect.
Current authorised subprocessors are:
Render: Application and API hosting in the Frankfurt region. Processes Operator Personal Data handled by the application. Authorised support access may involve a restricted transfer
Neon: Managed PostgreSQL database in the Frankfurt region. Stores structured Operator Personal Data and related access records
Cloudflare: Web delivery and security, plus EU-jurisdiction R2 object storage for media, attachments and protected uploads. Global request routing and authorised support may involve a restricted transfer
Amazon Web Services: Amazon SES transactional email in the London region. Processes recipient addresses, message routing information and the content of service emails sent on the Operator’s instructions. Authorised support may involve a restricted transfer
Sentry: Error monitoring for the GoSavis API server, hosted in the European Union in the Frankfurt region. Processes the limited, redacted reports of failures the server sends so that faults can be found and fixed: the error type and message, the code location, the route and method, the response status, the request identifier and the release, which can carry Operator Personal Data only where an error message includes it. The account, the contents of the request, cookies, credential headers, records of recent server activity and the values held in the code at the failure are removed, and email addresses, tokens and card-length numbers are redacted, before a report is sent. Authorised support may involve a restricted transfer
Stripe, Google, Apple, map providers, analytics providers and external-media services are not subprocessors for the limited Operator Personal Data covered by this DPA. They are used for separate controller activities or are contacted for a feature chosen by the individual, as explained in the Privacy Policy.
Rights, incidents and compliance assistance
Taking into account the nature of the processing and the information available, GoSavis will provide reasonable assistance so the Operator can:
Respond to requests for access, correction, erasure, restriction, objection and portability
Meet security and personal-data breach duties
Carry out a data-protection impact assessment and any required prior consultation with a supervisory authority
Demonstrate compliance with its obligations for the processing covered by this DPA
If GoSavis receives a rights request relating solely to Operator Personal Data, we will not respond on the Operator’s behalf unless authorised or legally required. We will direct the person to the Operator where practical and notify the Operator without undue delay.
GoSavis will notify the Operator without undue delay after becoming aware of a personal-data breach affecting Operator Personal Data. As information becomes available, the notice will describe the nature and likely consequences, affected data and people, mitigation taken or proposed, and a contact for follow-up. GoSavis will take reasonable steps to contain, investigate and remedy the breach. A notice is not an admission of fault or liability.
Return and deletion
During the service term, available export and account controls allow the Operator to retrieve or delete Operator Personal Data. On termination and on written request, GoSavis will return or delete the remaining Operator Personal Data within a reasonable period, at the Operator’s choice, unless UK law requires us to retain it.
Data in backups is put beyond ordinary use and ages out through the normal backup cycle. Until deletion, this DPA continues to protect it. This section does not require deletion of information GoSavis holds as an independent controller, such as account, transaction, security, moderation or legal records; that information follows the Privacy Policy and applicable retention law.
Information and audits
GoSavis will make available information reasonably necessary to demonstrate compliance with this DPA. We may first provide current security documentation, policies, independent reports or responses to a proportionate questionnaire.
If that information is not sufficient, the Operator may carry out one proportionate audit in any 12-month period on reasonable notice, and an additional audit following a material incident or regulator request. Audits must protect other users, confidential information and service security, take place during normal business hours, and avoid unnecessary disruption. The Operator bears its audit costs unless the audit identifies a material breach by GoSavis.
International transfers
GoSavis will not make a restricted transfer of Operator Personal Data outside the United Kingdom except on the Operator’s documented instructions and with a lawful safeguard. Depending on the recipient, this may be a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism permitted by Data Protection Law. Where required, GoSavis will complete and keep under review the relevant data-protection test and supplementary measures.
The Operator authorises the transfers inherent in the subprocessor services disclosed above, subject to those safeguards. On request, GoSavis will provide information about the safeguard used for a particular restricted transfer, subject to confidentiality and necessary redactions.
General terms and contact
The liability, governing-law and dispute provisions in the Operator Agreement apply to this DPA. If Data Protection Law changes, the parties will work in good faith to make the minimum amendment needed to preserve lawful processing. An amendment which materially changes the protection or use of Operator Personal Data will be notified before it takes effect.
Questions, audit requests, subprocessor objections and data-protection notices should be sent to privacy@gosavis.com. Notices by post may be sent to GoSavis Limited, 32 Eyre Street, Sheffield, England, S1 4QZ.