Relating to the processing of personal data
This Data Processing Agreement (the “Agreement”) is made between:
(1) Employees Global Ltd, trading as HeroPerks, a company registered in England and Wales (Company No. 15032559), whose registered office is at Colony Fabrica, Great Ancoats Street, Manchester, England, M4 7DB (the “Controller”); and
(2) 3manfactory Ltd, a company registered in England and Wales (Company No. 07642302), whose registered office is at Old Docks House, 90 Watery Lane, Preston, Lancashire, PR2 1AU (the “Processor”),
each a “Party” and together the “Parties”.
Background
A. The Controller operates a Licensed Instance of the EAPP Platform (the “Platform”) under the brand HeroPerks.
B. The Processor provides hosting, maintenance, and technical operation of the Platform to the Controller under a separate Platform Licence & Revenue Share Agreement between the Parties dated 11 February 2026 (the “Licence Agreement”). The Processor is the Licensor and the Controller is the Licensee under the Licence Agreement.
C. In the course of providing those services, the Processor processes personal data on behalf of the Controller. This Agreement sets out the terms on which the Processor processes that personal data and is entered into to satisfy the requirements of Article 28 of the UK GDPR.
D. This Agreement supplements and forms part of the Licence Agreement. In the event of conflict between this Agreement and the Licence Agreement in relation to the processing of personal data, this Agreement prevails.
1. Definitions and Interpretation
1.1 In this Agreement, the following definitions apply:
“Data Protection Legislation” means all applicable laws relating to the processing of personal data and privacy, including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, in each case as amended or replaced from time to time.
“UK GDPR” means the retained EU law version of the General Data Protection Regulation (Regulation (EU) 2016/679) as it forms part of the law of England and Wales by virtue of the European Union (Withdrawal) Act 2018.
“Personal Data” means personal data (as defined in the UK GDPR) processed by the Processor on behalf of the Controller under this Agreement, as further described in Annex 1.
“Processing” has the meaning given in the UK GDPR, and “Process” and “Processed” are construed accordingly.
“Data Subject” means an identified or identifiable natural person to whom the Personal Data relates.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
“Sub-Processor” means any third party engaged by the Processor to process Personal Data in connection with the provision of services under the Licence Agreement.
“Sub-Processor Charges” means the Revenue Share and other charges payable by the Controller to the Processor under the Licence Agreement.
1.2 Terms not otherwise defined in this Agreement have the meaning given in the Licence Agreement.
1.3 References to any statute or statutory provision include that statute or provision as amended, replaced, or re-enacted from time to time.
2. Roles of the Parties
2.1 The Parties acknowledge that, for the purposes of the Data Protection Legislation, the Controller is the data controller and the Processor is the data processor in respect of the Personal Data.
2.2 The Controller is responsible for determining the purposes and means of the Processing of Personal Data, and for ensuring that it has a valid lawful basis for the Processing and that all necessary notices and consents are in place to enable the lawful transfer of Personal Data to the Processor for the duration and purposes of this Agreement.
2.3 The Processor processes Personal Data only on behalf of the Controller and in accordance with this Agreement.
3. Processor Obligations
The Processor shall:
3.1 process the Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest;
3.2 ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
3.3 implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR, as further described in Annex 2;
3.4 respect the conditions set out in clause 4 of this Agreement for engaging Sub-Processors;
3.5 taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligation to respond to requests for exercising Data Subject rights under the Data Protection Legislation;
3.6 assist the Controller in ensuring compliance with its obligations relating to security of Processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with the Information Commissioner’s Office, taking into account the nature of Processing and the information available to the Processor;
3.7 at the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies unless the law requires storage of the Personal Data; and
3.8 make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and allow for and contribute to audits, including inspections, in accordance with clause 7.
3.9 The Processor shall immediately inform the Controller if, in its opinion, an instruction given by the Controller infringes the Data Protection Legislation.
3.10 The assistance and cooperation described in clauses 3.5, 3.6, and 3.8 shall be provided by the Processor, and the Controller shall reimburse the Processor’s reasonable costs incurred in providing such assistance, save where such assistance is required as a direct result of the Processor’s breach of this Agreement.
4. Sub-Processors
4.1 The Controller grants the Processor general written authorisation to engage the Sub-Processors listed in Annex 3 for the Processing of Personal Data.
4.2 The Processor may engage additional or replacement Sub-Processors provided that it gives the Controller prior written notice of the intended change, thereby giving the Controller the opportunity to object to such changes. Notice may be given by email or by updating the Sub-Processor list published on the HeroPerks Trust Centre and notifying the Controller of the update.
4.3 If the Controller objects to a new or replacement Sub-Processor on reasonable data protection grounds within fourteen (14) days of notice, the Parties shall work together in good faith to resolve the objection. If no resolution is reached, the Processor may either decline to appoint the Sub-Processor or, where this is not commercially practicable, either Party may terminate the affected services on reasonable notice.
4.4 Where the Processor engages a Sub-Processor, it shall do so by way of a written contract imposing data protection obligations substantially equivalent to those set out in this Agreement. The Processor remains liable to the Controller for the performance of the Sub-Processor’s obligations in accordance with the liability provisions in clause 9.
5. Security of Processing
5.1 The Processor shall implement and maintain the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of Data Subjects.
5.2 The current technical and organisational measures applied to the Platform are also published and maintained on the HeroPerks Trust Centre. The measures set out in Annex 2 represent the agreed baseline as at the date of this Agreement. The Processor may update its measures from time to time provided that any update does not materially reduce the overall level of security.
6. Personal Data Breach
6.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Personal Data.
6.2 Such notification shall, to the extent reasonably available to the Processor, describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
6.3 The Processor shall cooperate with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of the Personal Data Breach.
6.4 The Controller is responsible for any notification of a Personal Data Breach to the Information Commissioner’s Office and to affected Data Subjects, as required under the Data Protection Legislation.
7. Audit and Inspection
7.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and shall, on reasonable prior written notice, allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller.
7.2 Audits shall be limited to once per calendar year, save where an audit is required following a Personal Data Breach or by a supervisory authority. Audits shall be conducted during normal business hours, with a minimum of thirty (30) days’ prior written notice, in a manner that minimises disruption to the Processor’s business, and subject to appropriate confidentiality undertakings.
7.3 The Controller shall bear its own costs and the Processor’s reasonable costs in relation to any audit, save where the audit reveals a material breach of this Agreement by the Processor, in which case the Processor shall bear its own costs.
8. International Transfers
8.1 The Processor shall not transfer Personal Data to a country outside the United Kingdom without the prior written consent of the Controller, except as already provided for through the Sub-Processors listed in Annex 3.
8.2 Where any transfer of Personal Data outside the United Kingdom is authorised, the Processor shall ensure that an appropriate transfer mechanism recognised under the Data Protection Legislation is in place.
9. Liability and Indemnity
9.1 Subject to clause 9.3, the total aggregate liability of the Processor arising out of or in connection with this Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall not exceed a sum equal to the total Sub-Processor Charges paid by the Controller to the Processor in the twelve (12) month period immediately preceding the event giving rise to the liability.
9.2 The Controller shall indemnify and keep indemnified the Processor against all losses, claims, damages, liabilities, fines, costs, and expenses (including reasonable legal fees) arising out of or in connection with: (a) any breach by the Controller of its obligations under this Agreement or the Data Protection Legislation; (b) any Processing carried out by the Processor in accordance with the Controller’s documented instructions; and (c) any claim that the Controller did not have a valid lawful basis for the Processing or failed to provide required notices to or obtain required consents from Data Subjects.
9.3 Nothing in this Agreement shall limit or exclude either Party’s liability for: (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; (c) any matter for which it would be unlawful to limit or exclude liability; (d) the Controller’s indemnity obligations under clause 9.2; or (e) either Party’s breach of its confidentiality obligations.
9.4 The limitation of liability in clause 9.1 is without prejudice to any limitation or exclusion of liability set out in the Licence Agreement, and the two shall be read together; where both apply to the same loss, the lower applicable cap shall prevail and the Controller shall not recover more than once in respect of the same loss.
10. Term and Termination
10.1 This Agreement takes effect on the Effective Date of the Licence Agreement and shall remain in force for the same term as the Licence Agreement, including any renewal periods, terminating automatically on termination or expiry of the Licence Agreement.
10.2 On termination or expiry of this Agreement, the Processor shall, at the choice of the Controller, delete or return all Personal Data in accordance with clause 3.7, save that the Processor may retain Personal Data to the extent required by applicable law and for the period of any backup retention cycle, after which it shall be securely deleted.
11. General
11.1 This Agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction to settle any dispute arising out of or in connection with it.
11.2 No variation of this Agreement is effective unless made in writing and signed by or on behalf of each Party.
11.3 If any provision of this Agreement is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
11.4 This Agreement, together with the Licence Agreement, constitutes the entire agreement between the Parties in relation to the Processing of Personal Data and supersedes any prior arrangement in respect of the same subject matter.
This Agreement was executed by both parties and took effect on 11 February 2026.
Annex 1 — Details of Processing
Subject matter: Processing of Personal Data necessary for the hosting, maintenance, and technical operation of the HeroPerks Platform.
Duration: For the term of the Licence Agreement, including any renewal periods, and any subsequent retention period permitted under clause 10.2.
Nature and purpose: Storage, hosting, transmission, and processing of Personal Data to enable user registration, account management, delivery of platform functionality, and platform communications.
Type of Personal Data: Name; email address; platform activity data; profile data. No special category data is processed.
Categories of Data Subject: Members; Local Suppliers; Recommended Professionals.
Annex 2 — Technical and Organisational Measures
The technical and organisational measures agreed under this Agreement are those maintained on the platform and published across the Security and Platform sections of this Trust Centre. See Platform Security Principles, Platform Access Controls, and Platform Infrastructure & Hosting.
Annex 3 — Authorised Sub-Processors
The authorised sub-processors under this Agreement are listed on the Platform Sub-Processors page, which is maintained as the current record.
Legal responsibility for the content on this page sits with Employees Global Ltd.