LEGAL
Data Processing Agreement
When a company uses FairGrade, it stays in control of its employees' data and we process that data on its behalf. These are the terms of that arrangement, as Article 28 GDPR requires.
Version 1.0 · July 2026
1. Parties and scope
This Data Processing Agreement ("DPA") applies between the customer company using FairGrade (the "Controller") and FairGrade (the "Processor"). It forms part of the agreement under which the Controller uses the service.
It governs the processing of personal data that the Controller enters into, or generates within, the FairGrade platform. It is concluded in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
2. Subject matter, nature and purpose
The Processor stores and processes employment-related personal data so that the Controller can evaluate roles, build pay structures, compare pay to market ranges, calculate gender pay gaps, produce compliance reports, and give employees access to information about their own pay.
Processing consists of collection, storage, structuring, calculation, retrieval, disclosure to authorised users of the Controller, and erasure. The Processor does not use the data for any other purpose.
3. Duration
Processing continues for as long as the Controller maintains an active workspace. It ends when the agreement terminates, subject to the deletion and return provisions in section 10.
4. Categories of data subjects
Employees, workers and job holders of the Controller whose roles or pay are recorded in the platform.
Users authorised by the Controller to access the workspace, such as HR staff, managers and external advisers.
5. Categories of personal data
Identity and employment data: full name, the role held, hire date.
Pay data: base salary, total cash, allowances, currency, and the effective dates of each record, including historical pay records.
Gender, where the Controller chooses to record it, for the purpose of calculating a gender pay gap. This is optional in the platform.
Transparency records: whether an employee has reviewed how their pay is determined and the timestamp of that confirmation; information requests submitted by employees and the Controller's answers.
Access data for authorised users: name, email address, role within the workspace.
6. Obligations of the Processor
The Processor processes personal data only on documented instructions from the Controller, including as to transfers to third countries, unless required otherwise by Union or Member State law.
The Processor ensures that persons authorised to process the data are bound by confidentiality.
The Processor implements the technical and organisational measures set out in section 8.
The Processor assists the Controller, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations under Articles 32 to 36 GDPR.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, and provides the information the Controller needs to meet its own notification duties.
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
7. Obligations of the Controller
The Controller determines the purposes and means of processing and is responsible for having a lawful basis for it, including for recording gender data.
The Controller is responsible for informing its employees about the processing, for the accuracy of the data it enters, and for granting workspace access only to persons who need it.
The Controller is responsible for distributing employee portal links only to the employee they belong to, and for revoking access when an employment relationship ends.
8. Technical and organisational measures
Data is encrypted in transit using TLS and encrypted at rest.
Tenant isolation is enforced at the database level through row-level security policies, so a request for data belonging to another company cannot succeed even if the application layer is bypassed.
Access within a workspace is role-based: owner, administrator, editor and viewer, each with distinct permissions.
Employee portal access uses long, cryptographically random tokens, and exposes only the record of the employee that token belongs to.
Data used to generate role evaluations is limited to job titles, role descriptions and company context. Employee names, gender and pay figures are not sent to any language model provider.
Access to production systems is restricted, authenticated and logged.
Backups are taken regularly and stored within the European Union.
9. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors. The Processor imposes on each sub-processor the same data protection obligations set out in this DPA, and remains fully liable for their performance.
Current sub-processors: Supabase (database, authentication and storage; data hosted in Frankfurt, Germany, on AWS eu-central-1) and Vercel (application hosting and delivery). Payment providers are engaged when a paid subscription is taken out.
The Processor informs the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.
10. Deletion and return
On termination, the Controller may export its data from the platform. At the Controller's choice, the Processor deletes or returns all personal data and deletes existing copies within 30 days, unless Union or Member State law requires continued storage.
The Controller acknowledges that evaluation records, consent evidence and audit trails may need to be retained to demonstrate compliance in an inspection or dispute, and that the decision to retain or delete them rests with the Controller.
11. International transfers
Personal data is stored within the European Union. The Processor does not transfer personal data outside the European Economic Area.
If a transfer becomes necessary, the Processor will inform the Controller in advance and will only proceed on the basis of an adequacy decision or appropriate safeguards under Chapter V GDPR.
12. Liability and precedence
Liability under this DPA is governed by the main agreement between the parties. Where this DPA conflicts with the main agreement in respect of data protection, this DPA prevails.
DRAFT — PENDING LEGAL REVIEW
This text is a working draft prepared from how the platform actually operates. It must be reviewed and signed off by a qualified data protection lawyer before it is offered to customers for signature.