HFS Central
  • Platform
  • How it works
  • Human Factors
  • Pilot programme
  • About
  • FAQs
Register your interest Sign in
Sign in Register your interest

Data processing addendum

Last updated 22 September 2026 Operated by to be confirmed Governing law: England and Wales

The Article 28 terms under which HFS Central processes your employees' personal data on your behalf: instructions, sub-processors, breach notification, audit, deletion and the security measures we commit to.

On this page

  1. Parties and scope
  2. Details of processing
  3. Processor obligations
  4. Controller obligations
  5. Sub-processors
  6. Data subject requests
  7. Breaches
  8. Audit
  9. Return and deletion
  10. International transfers
  11. Liability
  12. Annex 1: security measures

All policies

  1. Privacy policy
  2. Terms of service
  3. Data processing addendum
  4. Cookie policy

1. Parties and scope

This addendum is between the company holding a HFS Central account (the Controller) and to be confirmed (the Processor). It applies whenever we process personal data on your behalf in providing the service and forms part of the terms of service. It is written to satisfy Article 28 of the UK GDPR. Where you also process data of people in the EU, the equivalent EU GDPR provisions apply.

2. Details of processing

Subject matterHosting a register of the Controller's workforce, delivering training modules to them and recording completions.
DurationThe life of the account plus the 90-day read-only period after cancellation, or until earlier deletion on instruction.
Nature and purposeStorage, retrieval, display, sending of transactional email, and export, so that the Controller can meet its duties as an employer.
Categories of dataName, work email, role, sign-in activity, module assignments, completion dates and scores.
Data subjectsThe Controller's employees, workers, contractors and administrators.
Special category dataNone is required. The Controller must not enter any.

3. Processor obligations

We will:

  • process personal data only on your documented instructions, which are these terms, the settings you choose in the application and any written instruction you send us, unless the law requires otherwise, in which case we tell you first where we may;
  • make sure everyone with access is bound by confidentiality;
  • implement the technical and organisational measures in Annex 1;
  • engage sub-processors only under section 5;
  • help you respond to data subject requests under section 6 and meet your obligations on security, breach notification and impact assessments;
  • delete or return the data under section 9;
  • make available the information needed to show compliance and allow audits under section 8;
  • tell you straight away if we think an instruction breaks data protection law.

4. Controller obligations

You warrant that you have a lawful basis for the data you enter, that you have told your people the platform is in use, that you will not enter special category data, and that your instructions comply with the law. You are responsible for the accuracy of the data and for the access you grant to your own owners and admins.

5. Sub-processors

You authorise the sub-processors below. We will give you at least 30 days' notice by email before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel and receive a refund of any prepaid period.

Sub-processorPurposeLocation
Hosting providerServers, database, backupsUnited Kingdom
Stripe Payments Europe LtdPayments and invoicing (Controller's billing contact only)Ireland, United States
Resend, Inc.Transactional emailUnited States
Cloudflare, Inc.DNS, TLS termination, attack protectionGlobal edge, United Kingdom and EU data centres preferred

Each sub-processor is bound by written terms no less protective than this addendum. We remain liable to you for their performance.

6. Data subject requests

If a data subject contacts us directly about data we process for you, we will not respond on the merits but will forward the request to you within five working days. The application lets owners view, correct, export and delete a person's record, which covers most requests without our involvement. Where you need more, we will help at no charge for reasonable requests.

7. Breaches

We will notify you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting your data. The notice will describe what happened, the data and people likely affected, the likely consequences and what we are doing about it, with updates as we learn more. We will not notify a regulator or data subjects on your behalf unless you ask us to.

8. Audit

Once a year, on 30 days' written notice, you may audit our compliance with this addendum by reviewing the documentation we provide, which includes our security measures, sub-processor list and, where available, third-party assessments of our hosting provider. If that is not enough to satisfy a regulator, you may carry out an on-site or remote audit at your cost, during business hours, without disrupting other customers, under confidentiality.

9. Return and deletion

Throughout the agreement you can export your records from the application. When the account is closed we keep the data read-only for 90 days, then delete it from live systems within 30 days and from backups within a further 35 days. You may instruct earlier deletion at any time. We keep only what the law requires us to keep, such as invoices, and only for as long as it requires.

10. International transfers

Your records are stored in the United Kingdom. Where a sub-processor processes data outside the UK, the transfer is covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed. Copies are available on request.

11. Liability

Liability under this addendum is subject to the limits in the terms of service. Each party remains liable to data subjects and regulators as the UK GDPR provides.

Annex 1: security measures

  • Isolation: every company's data is tagged with its company at the row level and every query is constrained to the signed-in person's company. A request with no company context returns nothing rather than everything.
  • Access control: role-based permissions (owner, admin, employee); platform staff access to production is limited to named people with multi-factor authentication and is logged.
  • Encryption: TLS 1.2 or higher in transit; encrypted storage volumes and encrypted backups at rest; passwords stored as salted one-way hashes.
  • Authentication: per-person sign-ins, rate limiting on sign-in attempts, session expiry, signed one-time links for email verification and password reset.
  • Payments: handled entirely by Stripe; card numbers never reach our systems.
  • Resilience: daily encrypted backups retained for 35 days and restore-tested; monitoring and alerting on availability and errors.
  • Development: automated tests, including tests that prove company isolation, run before every release; dependencies are kept current; secrets are held outside the codebase.
  • People: confidentiality obligations for staff and contractors; access removed on departure.

HFS Central — Connected Health, Safety and Human Factors Management

In development. Initial demonstrations use fictional data.

Platform | How it works | Human Factors | Pilot programme | About | FAQs | Contact | Privacy | Cookies
© 2026 HFS Central
[email protected]