Data processing agreement

Last updated 4 October 2026

1. Who this agreement is between

This agreement is between the company that sets up a Dayworks account (“the customer”) and Gregory Thomas Kemp, trading as Dayworks, a sole trader (egyéni vállalkozó) registered in Hungary (registration number 58887712, VAT number 48989473-1-42), of Szondi utca 44. B ép. 2. em. 3., 1063 Budapest, Hungary (“we” or “us”). The customer agrees to it when its account is created, through the person who creates it. It forms part of our terms of service.

The customer is the controller of the personal information in its records, and we are its processor. “Data protection law” means the UK GDPR, the Data Protection Act 2018 and the EU GDPR, as far as each applies.

2. What we process

  • Why: to provide Dayworks to the customer: planning each day on site, recording hours, keeping site diaries, and producing and sending documents from them.
  • Whose information: the customer's staff and users; workers on its sites, including agency and subcontract workers; and anyone named in its records, such as visitors or people documents are sent to.
  • What information: names, email addresses, employers, trades and roles; hours worked and absences; what people did on site, as recorded in briefings and diaries; photos taken on site; and who made each change and when. Dayworks isn't designed for special categories of information, such as health records, and the customer shouldn't put them in it.
  • For how long: while the customer has an account, and then as section 9 describes.

3. Following the customer's instructions

We process the customer's personal information only on its instructions. Its instructions are these terms, and the way it uses and configures Dayworks. If the law requires us to process it in some other way, we will tell the customer first, unless the law forbids that. If we think an instruction breaks data protection law, we will tell the customer.

4. Confidentiality

Everyone we allow to handle the customer's personal information is bound to keep it confidential.

5. Security

We keep the customer's information safe with measures that include:

  • hosting the database, files and app in London, encrypted in transit and at rest;
  • keeping each company's records apart with row-level security, enforced by the database on every request;
  • giving each person in a company only the access their role allows, as the customer sets it;
  • keeping photos in private storage, available only to members of the company;
  • storing passwords only as one-way hashes;
  • locking a site diary against changes once it is signed off;
  • sending error reports without IP addresses or cookies;
  • limiting administrative access to the live service to us.

6. Sub-processors

The customer allows us to use the sub-processors on our sub-processor list. Before we add or replace one, we will email the people who manage each company account at least 30 days in advance. The customer can object on reasonable data protection grounds. If we can't resolve the objection, the customer can close its account before the change takes effect.

We give each sub-processor data protection obligations that are at least as strong as ours in this agreement, and we remain responsible to the customer for what they do.

7. Helping the customer

We will help the customer, as far as we reasonably can, to answer requests from people exercising their data protection rights, to keep its information secure, and with any data protection impact assessment or consultation with a regulator that involves Dayworks. Most requests can be answered in Dayworks itself; for anything else, write to support@getdayworks.com.

8. Personal data breaches

If we become aware of a breach affecting the customer's personal information, we will tell the customer without undue delay, and in any case within 48 hours. We will give it the information it needs to meet its own obligations, as it becomes available, and help it deal with the breach.

9. When the account closes

When the customer's account closes, its records can still be exported for 90 days. After that we delete them, and they leave our backups within a further 30 days, unless the law requires us to keep them.

10. Showing that we comply

We will give the customer the information it reasonably needs to show that we meet our obligations in this agreement. The customer, or an auditor it appoints who is bound by confidentiality, can audit our compliance once a year, on 30 days' notice and at the customer's cost, and more often if a regulator requires it or after a breach.

11. Transfers outside the UK and EU

The customer's records are stored in London. Some of our sub-processors are American companies, so information can reach the United States. Where it does, we rely on the safeguards data protection law provides, such as the UK–US data bridge, the EU–US Data Privacy Framework, and standard contractual clauses.

12. The customer's part

The customer is responsible for having a lawful basis for the information it records, for telling the people in its records how their information is used, and for making sure its instructions to us are lawful.

13. Liability and law

Each side's liability under this agreement is subject to the limits in our terms of service. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute about it.