Back to YokeConnect

Official English legal document

DATA PROCESSING AGREEMENT

Employer data-processing addendum for YokeConnect

Last updated: 21 July 2026Version 1.0

YokeConnect Ltd, company number 17334598, registered office: The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom

This is the approved, authoritative English legal document. Contact support@yokeconnect.com if you need help understanding any term.

Website: https://yokeconnect.com | Email: admin@yokeconnect.com

1. Parties and incorporation

This Data Processing Agreement ("DPA") forms part of the Employer Subscription Terms between YokeConnect Ltd, company number 17334598, registered office The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom ("YokeConnect"), and the Employer identified in the Account or order ("Employer").

It applies from the date the Employer accepts the Employer Subscription Terms or otherwise uses a feature in which YokeConnect processes personal data on the Employer's documented instructions.

2. Definitions

Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, EU GDPR where applicable, and other mandatory data-protection law applying to the Processing.

Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given in Applicable Data Protection Law.

Employer Personal Data means Personal Data processed by YokeConnect as Processor on the Employer's behalf under this DPA. Subprocessor means a third party engaged by YokeConnect to process Employer Personal Data on YokeConnect's behalf.

3. Role allocation and scope

3.1 Independent-controller processing

YokeConnect is an independent Controller for Account registration, Candidate profiles and visibility, Platform security, subscriptions, general messaging infrastructure, fraud prevention, moderation, business verification, legal compliance, service administration and other purposes it determines and explains in the Privacy Policy.

The Employer is an independent Controller for recruitment decisions and for Candidate Personal Data it accesses, exports, records or uses in its own systems or processes. The parties are not joint controllers merely because they process some of the same data for different purposes.

3.2 Processor processing

YokeConnect acts as Processor only to the extent it handles Employer Personal Data solely to provide an Employer-directed workspace function, such as hosting Employer-supplied recruitment notes, routing Employer communications, storing Employer-configured application or pipeline information, or performing another documented instruction that does not serve an independent YokeConnect purpose.

If the factual circumstances make YokeConnect a Controller for a Processing activity, the Privacy Policy and Applicable Data Protection Law apply to that activity and this DPA does not reclassify it.

4. Processing instructions

The Employer instructs YokeConnect to process Employer Personal Data only to provide, secure, maintain and support the Services described in the Employer Subscription Terms and Annex 1, and to comply with documented instructions submitted through authorised Platform features or in writing.

YokeConnect will not process Employer Personal Data for another purpose unless required by law, in which case it will inform the Employer before Processing unless legally prohibited. If YokeConnect reasonably believes an instruction breaches Applicable Data Protection Law, it may suspend the affected Processing and notify the Employer.

5. YokeConnect obligations

YokeConnect will:

process Employer Personal Data only on documented instructions and in accordance with this DPA;

ensure authorised personnel are bound by confidentiality and have access only where needed;

implement the technical and organisational measures in Annex 2, taking account of risk, state of the art and implementation cost;

engage Subprocessors in accordance with section 7;

provide reasonable assistance with Data Subject rights, security, breach assessment, data-protection impact assessments and regulator consultation, taking account of the nature of Processing and information available;

maintain records and information reasonably necessary to demonstrate compliance with processor obligations; and

delete or return Employer Personal Data under section 11.

6. Employer obligations

The Employer warrants and undertakes that it will:

comply with Applicable Data Protection Law and issue lawful, documented instructions;

have a valid lawful basis and provide all required privacy information for Employer Personal Data;

collect and use only data that is adequate, relevant and necessary for genuine recruitment or related lawful purposes;

not instruct YokeConnect to process prohibited identity documents or unnecessary special-category or criminal-offence data;

configure access, permissions, retention and exports appropriately and protect data downloaded from the Platform;

respond to Data Subject requests and regulator enquiries for which it is Controller; and

notify YokeConnect promptly of suspected Personal Data Breaches or unlawful instructions involving the Services.

7. Subprocessors

The Employer gives general written authorisation for the Subprocessors listed in Annex 3. YokeConnect will impose data-protection obligations appropriate to the services and remains responsible for each Subprocessor's performance of its processor obligations to the extent required by law.

YokeConnect may add or replace a Subprocessor by updating its published list or notifying the Employer at least 14 days before the change takes effect where practicable. The Employer may object within that period on reasonable documented data-protection grounds. The parties will attempt to resolve the objection. If a material objection cannot be resolved and the Subprocessor is necessary, either party may terminate the affected Services; any refund is determined under the Employer Subscription Terms.

8. Security

YokeConnect will maintain measures appropriate to the risk, including as applicable: encryption in transit; provider-managed encryption at rest; HttpOnly and Secure session cookies; role, organisation and permission controls; verified-email and launch gates; CSRF, CORS and host controls; rate limiting; security challenges; private object storage; time-limited file access; logging and audit records; restricted administrator access; health checks; provider backup and recovery capability; and incident procedures.

The Employer acknowledges that messages are not end-to-end encrypted and that no online system can be guaranteed completely secure. The Employer is responsible for endpoint security, Authorised User access, exported data and its own systems.

9. Personal Data Breaches

YokeConnect will notify the Employer without undue delay after becoming aware of a Personal Data Breach affecting Employer Personal Data and will provide available information reasonably required for the Employer's legal assessment, including the nature of the incident, affected data and people, likely consequences and measures taken or proposed.

The Employer remains responsible for determining and making any notification required of it as Controller. YokeConnect will provide reasonable cooperation. A breach notice is not an admission of liability.

10. Data Subject rights and compliance assistance

Taking account of the nature of Processing, YokeConnect will provide reasonable technical and organisational assistance to help the Employer respond to lawful requests for access, correction, deletion, restriction, objection and portability relating to Employer Personal Data.

There is no complete automated export or deletion workflow at launch. Assistance may therefore involve verified manual searches, exports, restriction or deletion using the records and tools reasonably available. YokeConnect may charge reasonable documented fees for exceptional assistance beyond ordinary service obligations where permitted by law and agreed in advance.

11. Return and deletion

On termination of the affected Services or a lawful written instruction, YokeConnect will, at the Employer's choice and to the extent technically and legally applicable, return Employer Personal Data in an available structured format or delete it from active systems within 90 days.

YokeConnect may retain data required by law, for security, audit, fraud prevention or legal claims, and may retain protected copies until provider backup or point-in-time recovery cycles expire. Retained data remains subject to this DPA and is not used for another purpose. Data for which YokeConnect is an independent Controller is handled under the Privacy Policy rather than this section.

12. International transfers

YokeConnect may process or permit access to Employer Personal Data outside the United Kingdom or European Economic Area only where a lawful transfer mechanism applies. Depending on the transfer, this may include adequacy regulations or decisions, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses and supplementary safeguards.

The Employer authorises transfers arising from the Subprocessors and locations in Annex 3. Cloudflare R2 uses Automatic location at launch and does not guarantee UK or EU-only storage.

13. Audit and information

On reasonable written request, YokeConnect will provide information necessary to demonstrate compliance with this DPA, which may include policies, architecture summaries, provider assurances, test results or audit summaries, subject to confidentiality and security.

If that information is insufficient and Applicable Data Protection Law requires an audit, the Employer may conduct one no more than once per year, on at least 30 days notice, during normal business hours and without access to other customers' data or sensitive security information. The Employer bears the cost unless the audit identifies material non-compliance by YokeConnect. Auditors must be independent and bound by confidentiality.

14. Liability and order of precedence

Liability under this DPA is subject to the Employer Subscription Terms, except to the extent Applicable Data Protection Law prohibits a limitation. If this DPA conflicts with the Employer Subscription Terms on processor obligations, this DPA prevails for that issue. The Privacy Policy governs YokeConnect's independent-controller processing.

15. Term and contact

This DPA continues while YokeConnect processes Employer Personal Data as Processor. Provisions intended to survive, including confidentiality, deletion, audit, liability and transfer safeguards, continue after termination.

Data-protection notices should be sent to admin@yokeconnect.com or YokeConnect Ltd, The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom.

Annex 1 - Processing details

Item

Description

Subject matter

Employer-directed recruitment workspace and communication functions provided through YokeConnect.

Duration

For the term of the affected Subscription and the deletion, backup and legal-retention periods described in this DPA.

Nature of Processing

Collection where instructed, hosting, organisation, display, routing, access control, transmission, support, retrieval, restriction, export and deletion.

Purpose

To provide the Employer-directed recruitment and application-management functions selected by the Employer.

Data Subjects

Candidates, applicants, prospective candidates, referees, Employer contacts and Authorised Users where their data is processed on the Employer's instructions.

Personal Data

Names, contact details, professional profile and CV information, work history, qualifications, application and screening data, Employer notes, interview or pipeline information, messages, selected documents, access and audit metadata.

Sensitive data

Not intentionally required. Application-scoped right-to-work evidence or incidental special-category data may be processed only where lawful, necessary and instructed. Government identity documents are prohibited at launch.

Frequency

Continuous or ad hoc according to authorised use of Platform features.

Annex 2 - Technical and organisational measures

Governance and access

Named accounts, least privilege, role and organisation permissions, confidentiality duties, protected operations access, access review and offboarding procedures.

Authentication and sessions

ASP.NET Core Identity and JWT validation, server-issued HttpOnly and Secure session cookie, verified-email policies, session expiry, CSRF protections and host/CORS controls.

Network and application security

HTTPS/TLS, Cloudflare DNS and security controls, Turnstile on relevant flows, rate limiting, input validation, logging, health and readiness endpoints.

Storage security

Neon managed PostgreSQL, private Cloudflare R2 object storage, provider-managed encryption at rest, database metadata and time-limited file access.

Resilience and recovery

Provider backup and point-in-time recovery capability, separate development and live database branches, deployment controls and recovery procedures. Exact provider recovery windows are operationally reviewed.

Monitoring and incident handling

Application and provider logs, audit events for sensitive workflows, support and escalation processes, incident assessment and regulator or user notification where required.

Data minimisation and retention

Feature-specific collection, prohibited identity-document rules, Candidate-controlled sharing, retention schedule, manual rights-request process and backup-cycle controls.

Supplier management

Provider due diligence, DPAs and transfer terms where applicable, Subprocessor records and change notifications.

Annex 3 - Authorised Subprocessors and other services

A. Authorised Subprocessors

Provider

Service

Main location / transfer position

Microsoft Azure

API hosting and application logs

UK West; possible global support. Microsoft DPA and transfer terms.

Neon

Managed PostgreSQL database

AWS eu-west-2 London; global provider operations. Neon DPA and transfer terms.

Cloudflare

Security edge, Access, Turnstile and private R2 storage

Global. R2 Automatic location is not a residency guarantee. Cloudflare DPA and transfer terms.

Vercel

Frontend hosting, deployment and edge delivery

United States and global edge. Vercel DPA and transfer terms where applicable.

Postmark

Transactional email and delivery events

United States and global. Postmark DPA, SCCs and UK Addendum.

Zoho Mail

Support and operational email

EU data centre with possible global support/subprocessors. Zoho contractual privacy terms.

Stripe

Payment, invoicing, subscription and fraud-prevention processing

Global. Stripe DPA and transfer terms. Usually limited to billing and account data rather than Candidate content.

B. Other independent or public services

Service

Role

OpenStreetMap Foundation / Nominatim

Map tiles and geocoding under public terms; not evidenced as a contracted YokeConnect Subprocessor.

unpkg / cdnjs

External delivery of Leaflet presentation assets under public CDN terms.

Companies House

Independent UK public service used for advisory company lookup.

GitHub

Source control and developer workflow; production end-user data should not be stored in repositories.

Google Search Console / Bing Webmaster Tools

Search ownership and crawl-performance administration without client-side behavioural tracking.