Data Processing Agreement
This is the standard DPA that forms part of every Ubique client contract. It is published in full so your legal and security teams can review it before a sales conversation. The signed version is identical to this page.
Last updated: 15 September 2026. Version 3.1. Applies to all clients from 15 October 2026; earlier clients remain on version 3.0 until renewal unless they opt in.
The PDF is this page, printed. For a countersigned copy on your company's paper, request one and our legal team sends it within two business days.
1. Parties and purpose
This Data Processing Agreement ("DPA") is between the client named on the order form ("Client") and Ubique Group Limited, company number 12348871, of 71-75 Shelton Street, London WC2H 9JQ ("Ubique"), together with any Ubique subsidiary that provides services under the order form. It forms part of the terms of service and sets out how the parties handle personal data in connection with the services. Where this DPA and the terms conflict, this DPA prevails for data protection matters.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR, the California Consumer Privacy Act, and any other law that applies to the processing of personal data under this DPA.
2. Roles of the parties
The services involve two kinds of personal data, and the roles differ for each.
- Employment records: Ubique is an independent controller. Where Ubique or its local partner is the legal employer of a team member, it must by law collect and keep certain records: the employment contract, payroll and tax filings, social security enrolments, right-to-work evidence, leave and sick records, and termination documentation. Ubique determines the purposes and means of this processing because the law requires it to, and is a controller in its own right. Ubique's privacy policy governs this data. Ubique cannot delete these records on the Client's instruction before the statutory retention period ends.
- Client HR data: Ubique is a processor. For everything the Client chooses to put in the platform beyond what the law requires Ubique to hold, such as performance notes, internal job titles, org charts, manager assignments, equipment records, custom fields, uploaded documents, contractor engagement details and the Client's own employee data in Global Payroll or PEO, the Client is the controller and Ubique processes it only on the Client's documented instructions.
- Client user accounts. For the Client's own administrators and users, Ubique is a processor for account data used to deliver the service and an independent controller for security logging, billing and legal compliance.
Where Ubique acts as a processor, clauses 3 to 10 apply. Where Ubique acts as a controller, Ubique complies with Data Protection Law directly and the parties cooperate as set out in clause 11.
3. Subject matter and details of processing
- Subject matter: provision of employer of record, contractor management, global payroll, PEO and VEO services and the related platform.
- Duration: the term of the order form, plus the retention periods in clause 9.
- Nature and purpose: collecting, storing, organising, transmitting and deleting data to employ, pay, manage and offboard team members and contractors, and to operate the Client's account.
- Categories of data subjects: the Client's employees, team members employed through Ubique, contractors, the Client's administrators and users, and emergency contacts and dependants where provided.
- Categories of personal data: identification and contact details, employment and contract terms, compensation and bank details, tax and social security identifiers, identity and right-to-work documents, leave, expenses and performance-related data, and platform usage logs.
- Special category data: health data (sick leave, disability-related adjustments), trade union membership and, where local law requires, religion or ethnicity for statutory reporting. Processed only where local employment law requires or permits it.
4. Ubique's obligations as processor
Ubique will: process Client HR data only on the Client's documented instructions, including via the platform settings, unless required by law, in which case Ubique will inform the Client before processing unless the law prohibits it; ensure that everyone with access to the data is bound by confidentiality; implement the security measures in clause 6; assist the Client with data subject requests, impact assessments and consultations with supervisory authorities; delete or return the data in accordance with clause 9; and make available the information needed to demonstrate compliance, including through audits under clause 8. Ubique will tell the Client promptly if it believes an instruction infringes Data Protection Law.
5. Subprocessors
The Client gives general authorisation for Ubique to use the subprocessors listed on the security page, which at the date of this version are: Amazon Web Services (hosting, Ireland and Frankfurt); local employment and payroll partners in the 120 partner-served countries, each named in the Client's dashboard for the countries it uses; an e-signature provider (EU); a transactional email provider (EU); and payment and foreign exchange providers (UK and EU).
Ubique will notify the Client by email at least 30 days before adding or replacing a subprocessor. The Client may object in writing on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Client may terminate the affected services without penalty. Ubique imposes on every subprocessor data protection obligations no less protective than this DPA and remains fully liable for their performance.
6. Security measures
Ubique maintains, at a minimum, the following technical and organisational measures, which are audited annually under SOC 2 Type II:
- Encryption of all data at rest with AES-256 and in transit with TLS 1.2 or higher; field-level encryption of bank details, tax identifiers and identity documents with separate keys.
- Hosting in AWS Ireland and Frankfurt with multi-availability-zone redundancy; EU and UK data does not leave these regions.
- Mandatory multi-factor authentication for all users; single sign-on via SAML 2.0, Okta and Google Workspace; role-based access control with least privilege; quarterly access reviews.
- Logical separation of each client's data by tenant; separate production, staging and development environments.
- Immutable access logging retained for 12 months; monitoring for anomalous access and bulk export.
- Encrypted backups with 35-day point-in-time recovery and 12-month snapshot retention; quarterly restore tests; recovery time objective 4 hours, recovery point objective 15 minutes.
- Independent penetration tests twice a year; automated vulnerability and dependency scanning; a documented patching policy.
- Background checks and annual security training for all staff with data access; managed and encrypted company devices; a documented incident response plan with 24/7 on-call.
Ubique may update these measures provided the overall level of protection does not decrease. The current description is always on the security page.
7. Personal data breach notification
Ubique will notify the Client without undue delay and in any event within 48 hours of confirming a personal data breach affecting Client HR data or, as controller, employment records of the Client's team members. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Ubique will provide updates as the investigation progresses and will cooperate with the Client's own notifications to supervisory authorities and data subjects. Where Ubique is the controller, it will make its own regulatory notifications within 72 hours as required and will inform the Client that it has done so.
8. Audit rights
Ubique will make available to the Client, on request and under NDA, its current SOC 2 Type II report, penetration test summary letters and ISO 27001 certificate once issued. The Client may rely on these to satisfy its audit obligations.
Where these are not sufficient to demonstrate compliance, the Client or an independent auditor appointed by it and bound by confidentiality may audit Ubique's processing once in any 12-month period, on 30 days' written notice, during business hours, in a manner that does not disrupt Ubique's operations or compromise other clients' data. Ubique may charge reasonable costs for audits beyond the first in any year or beyond two days' duration. Audits of local employment partners are conducted by Ubique under its quarterly partner audit programme, and the Client may request the results for the countries it uses. An additional audit is permitted at no cost following a personal data breach affecting the Client.
9. Return and deletion
On termination of the services, Ubique will provide the Client with an export of Client HR data in a standard format within 30 days and will delete it from live systems within 90 days and from backups within a further 12 months, unless retention is required by law. Employment records held by Ubique as controller are retained for the statutory period of the country of employment, typically 5 to 10 years, and then deleted. Ubique will confirm deletion in writing on request.
10. International transfers
Client HR data is stored in the EU. Transfers to Ubique entities, local partners and subprocessors in countries outside the UK and the European Economic Area without an adequacy decision are made under the EU Standard Contractual Clauses (Commission Decision 2021/914, Module 2 or 3 as applicable) and, for UK data, the UK International Data Transfer Addendum, each of which is incorporated into this DPA by reference. Ubique carries out a transfer risk assessment for each country and maintains supplementary measures where needed. Copies of the executed clauses for any country the Client uses are available on request.
11. Cooperation where Ubique is controller
For employment records, the parties will cooperate in good faith on data subject requests, regulatory enquiries and breach response. Ubique will tell the Client what it retains and for how long, will not use employment records for any purpose other than employment, payroll, legal compliance and the defence of legal claims, and will not share them with third parties except as described in its privacy policy. The Client will not instruct Ubique to process employment records in a way that breaches local employment or data protection law.
12. Liability and general
Each party's liability under this DPA is subject to the limitations in the terms of service, except that nothing limits liability for a party's own breach of Data Protection Law to the extent that liability cannot be limited by law. This DPA is governed by the law of England and Wales. Where the Standard Contractual Clauses apply, their governing law and jurisdiction provisions take precedence for the transfers they cover.
13. Signatures
This DPA is accepted by the Client on execution of the order form and does not require separate signature. Clients who need a countersigned standalone copy, or who need to attach their own addendum, can request a signed copy and our legal team will return it within two business days.
Ubique Group Limited. Signed on behalf of Ubique by Benedikt Maier, Head of Legal. Data Protection Officer: privacy@ubiquehq.co.uk.
Need a countersigned copy or a redline?
Request a signed copy and our legal team replies within two business days.