Data Processing Agreement
Last updated: July 22, 2026
This Data Processing Agreement (DPA) describes how StaffGPT processes personal data on behalf of customers who act as controllers. It is made available to enterprise customers and, when executed alongside an order or agreement, forms part of that agreement.
Roles of the parties
For personal data that a customer submits to the service, the customer is the controller (or a processor acting for its own customers) and StaffGPT is the processor (or subprocessor). StaffGPT processes such data only on the customer's documented instructions, including as set out in the agreement and the customer's use of the service.
Subject matter and details
Subject matter: provision of the StaffGPT service. Duration: the term of the agreement. Nature and purpose: hosting, processing, and generating outputs to deliver the service. Categories of data subjects and personal data are determined by the customer through its use of the service.
Confidentiality and security
StaffGPT ensures that personnel authorized to process personal data are bound by confidentiality obligations and implements technical and organizational measures appropriate to the risk, as described in our Security overview and the measures schedule referenced in the agreement.
Subprocessors
The customer authorizes StaffGPT to engage the subprocessors listed in our Subprocessor List. We impose data-protection obligations on subprocessors and remain responsible for their performance. We provide a mechanism to receive notice of new subprocessors and to object on reasonable data-protection grounds.
International transfers
Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
Assistance, breach, and deletion
Taking into account the nature of processing, StaffGPT assists the customer with data-subject requests, data-protection impact assessments, and consultations with regulators. We notify the customer without undue delay after becoming aware of a personal-data breach affecting their data. On termination, we return or delete personal data as instructed, subject to legal-retention requirements.
AI processing and training
StaffGPT does not use customer data submitted to the service to train general-purpose models except where the customer expressly authorizes it in writing. To request the executed DPA or discuss data-protection terms, contact privacy@staffgpt.net.