Version 1.0 · Effective 21 May 2026 · Operated by Salstead Ltd
Salstead Data Processing Agreement
1. Background and parties
This Data Processing Agreement (“DPA”) is entered into between Salstead Ltd, operating the Salstead platform (“Salstead”, “Processor”), and the Customer named on the Order Form (“Controller”). This DPA forms part of, and is subject to, the Salstead Terms of Service and gives effect to Article 28 UK GDPR and the Data Protection Act 2018.
2. Definitions
- “Customer Data” means personal data processed by the Processor on behalf of the Controller through Salstead.
- “Sub-processor” means any third party engaged by the Processor to process Customer Data.
- “Services” means the Salstead staff bank, scheduling, payroll and compliance services at app.salstead.com.
3. Scope and roles
The Controller appoints the Processor as processor for the duration of the underlying service agreement. Schedule 1 sets out the categories of data, data subjects and processing purposes.
4. Processor obligations
- Process Customer Data only on documented instructions from the Controller.
- Ensure authorised persons are bound by confidentiality.
- Maintain the technical and organisational measures in Schedule 2.
- Engage Sub-processors only in accordance with section 5.
- Assist the Controller with data subject rights and Articles 32–36 obligations.
- Delete or return Customer Data on termination.
- Make available all information necessary to demonstrate compliance.
5. Sub-processors
The Controller authorises the Sub-processors in Schedule 3. The Processor will give 30 days’ notice of changes and impose equivalent protections on Sub-processors.
6. Data subject rights
The Processor will forward data subject requests to the Controller and assist as needed, including via in-platform tooling at Settings → My data.
7. Security measures
See Schedule 2. Measures include TLS 1.2+ in transit, AES-256 at rest, application-layer encryption for sensitive identifiers, RBAC with Supabase row-level security, audit logging, vulnerability management and an incident response plan.
8. International data transfers
Transfers outside the UK or EEA require an appropriate mechanism, including the UK IDTA, adequacy or other safeguards. UK / EU region is preferred for primary processing.
9. Personal data breach notification
The Processor will notify the Controller without undue delay and within 48 hours of becoming aware of a breach, with all available detail under Article 33(3) UK GDPR.
10. Audit rights
On 30 days’ notice, the Controller may audit no more than once per 12-month period. The Processor may satisfy audits with third-party reports.
11. Liability
Liability is subject to the underlying Terms of Service limits, save for liability that cannot be limited by law.
12. Term and termination
This DPA remains in force for as long as Customer Data is processed and includes deletion or return obligations on termination.
13. Governing law
Laws of England and Wales; exclusive jurisdiction of the courts of England and Wales.
Schedule 1: Processing details
| Field | Detail |
|---|---|
| Subject matter | Provision of the Salstead platform. |
| Duration | Term of the Terms of Service. |
| Nature and purpose | Workforce management, scheduling, payroll, training, compliance reporting. |
| Categories of data | Identification, contact, employment, regulatory, activity, and limited special category data (occupational health, DBS). |
| Categories of data subject | Care home staff (workers), customer users, and where modules are enabled, residents and family members. |
Schedule 2: Security measures
- TLS 1.2+ in transit; AES-256 at rest.
- Application-layer encryption for National Insurance numbers, bank account details and other sensitive identifiers.
- Role-based access control with Supabase row-level security.
- Multi-factor authentication enforced for admin accounts.
- Audit logging of access and changes to Customer Data.
- Quarterly vulnerability scanning and annual penetration testing.
- Daily encrypted backups with 30-day retention and point-in-time recovery.
- Incident response with 48-hour controller notification commitment.
- Sub-processor due diligence and contractual flow-down.
Schedule 3: Approved sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (AWS) | Hosting, database, file storage | UK / EU |
| Vercel | Application hosting and CDN | UK / EU |
| Stripe | Card payments | UK / EU |
| GoCardless | Direct Debit (Bacs) | UK |
| SendGrid (Twilio) | Transactional email | UK / EU / US (with SCCs) |
| Twilio | SMS notifications | UK / EU / US (with SCCs) |
| Sentry | Error reporting | EU |
| Upstash | Rate-limit + cache | UK / EU |