Data Processing Addendum
Workforce-data responsibilities, written down.
Preview version: preview-2026-07-12. This draft must receive legal review before public use.
1. Scope and roles
This DPA forms part of the DeskSide Customer agreement. For personal data submitted to a Customer-managed workspace, the Customer is controller and Secure Radio Communications Limited is processor. Each party remains controller for personal data it uses for its own independent purposes.
2. Processing details
Subject matter: operating and supporting DeskSide workspaces. Duration: the Customer term plus documented deletion and backup cycles. Purpose: identity, membership, presence, live voice transport, room participation, activation, security, diagnostics and support. People: Customer personnel, contractors, invitees and administrators. Data: work contact details, identifiers, membership, presence, device, activation, security, service and support data. DeskSide does not record or archive room audio at launch.
3. Documented instructions
We process Customer personal data only on documented instructions, including the Customer agreement, administrator actions and written support requests, unless UK law requires otherwise. We will inform the Customer if an instruction appears to infringe applicable data-protection law.
4. Confidentiality and security
People authorised to process Customer personal data are bound by confidentiality. We maintain measures appropriate to the risk, including access control, authentication, encryption in transit, secrets management, logging, environment separation, vulnerability management, backup/recovery controls and incident procedures.
5. Subprocessors
The Customer gives general written authorisation for subprocessors needed to provide DeskSide. Current categories/providers include Cloudflare for hosting, storage, email and edge security; Google Cloud and Secure Radio infrastructure for product operation; HubSpot for commercial/onboarding records; and Stripe for billing. We remain responsible for subprocessor obligations and will provide reasonable notice of a material new subprocessor.
6. International transfers
Where a restricted transfer occurs, the parties will use an applicable adequacy regulation, the UK International Data Transfer Agreement/Addendum or another lawful safeguard. The Customer authorises transfers inherent in the approved subprocessor arrangement.
7. Assistance
Taking account of the processing and information available, we will reasonably assist with data-subject requests, security obligations, breach notifications, data protection impact assessments and regulator consultation. The Customer remains responsible for deciding and communicating its response as controller.
8. Personal-data breaches
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data and provide information reasonably available to support the Customer's obligations. Notification is not an admission of fault.
9. Return and deletion
At the end of the service, at the Customer's choice and subject to law, we will return or delete Customer personal data and delete copies. Data in protected backups may remain beyond immediate deletion where it is put beyond ordinary use and deleted on the normal cycle.
10. Information and audits
We will provide information reasonably necessary to demonstrate compliance. Audits should normally begin with current documentation and remote questions, occur no more than annually unless a breach or regulator requires otherwise, protect other customers and confidentiality, and avoid unreasonable disruption. The requesting Customer bears its audit costs unless a material breach is found.
11. Customer duties
The Customer must have a lawful basis, give workforce privacy information, issue lawful instructions, configure access appropriately, protect administrator credentials and ensure that its use of DeskSide complies with law and employment obligations.
12. Liability and precedence
Liability under this DPA is subject to the Customer agreement except where law does not permit limitation. This DPA prevails over conflicting Customer Terms for personal-data processing.