Data Processing Agreement
Last updated: July 28, 2026
1. Parties and scope
This Data Processing Agreement ("DPA") is between the Status Quo 247 customer identified in the applicable Order Form or online sign-up ("Customer") and [Status Quo 247 — legal entity name and jurisdiction to be filled] ("Status Quo 247"). It forms part of, and is subject to, the Terms of Service or Master Services Agreement between the parties (the "Agreement").
The Customer is the controller of personal data processed through Status Quo 247. Status Quo 247 is the processor. Where the Customer is itself a processor for a further controller (for example, when the Customer provides HR services to another employer), Status Quo 247 acts as a sub-processor.
2. Nature and purpose of processing
Status Quo 247 processes personal data only to provide, secure, support and improve the Status Quo 247 service in accordance with the Customer's documented instructions. The Agreement, this DPA, and the Customer's configuration of the product are the Customer's documented instructions.
Status Quo 247 supports workforce productivity monitoring, activity capture, attendance tracking, and payroll administration. The purposes of processing are limited to those functions.
3. Categories of data and data subjects
Categories of personal data that may be processed depending on Customer configuration:
- Identifiers — name, work email, employee ID, role, team
- Device and activity data — active window titles, keystroke counts (not content), mouse activity levels, application usage time, website URLs visited during working hours
- Screenshots on a configurable interval
- GPS location from the mobile app
- Attendance events — clock-in and clock-out timestamps
- Payroll data — salary, deductions, bank details, and statutory identifiers (for Indian customers, this can include PAN and Aadhaar)
Categories of data subjects: the Customer's employees, contractors, interns, and job applicants whose data the Customer chooses to place in the service.
4. Duration
This DPA applies for the term of the Agreement and for the additional period during which Status Quo 247 processes personal data on the Customer's behalf, including the return-or-delete window described in section 10.
5. Processor obligations
Status Quo 247 will:
- Instructions. Process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required otherwise by applicable law. In that case, we will inform the Customer of the legal requirement before processing, unless the law prohibits it on public-interest grounds.
- Confidentiality. Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Security. Implement the technical and organisational measures described in Annex II and maintain them at a level appropriate to the risk.
- Sub-processors. Use only the sub-processors listed in Annex III, on written terms that impose data-protection obligations no less protective than this DPA. We will give the Customer at least 30 days' prior notice of any addition or replacement of a sub-processor and give the Customer a reasonable opportunity to object on legitimate grounds.
- Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, and provide the information the Customer reasonably needs to meet its own regulatory notice obligations.
- Data subject requests. Provide reasonable assistance, taking into account the nature of processing, to enable the Customer to respond to requests from data subjects to exercise their rights. When we receive a request directly from a Customer employee, we will pass it to the Customer without responding to the substance.
- Assistance with obligations. Assist the Customer in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available to us.
- Records. Maintain records of processing carried out on the Customer's behalf as required by Article 30(2) GDPR.
6. Sub-processors
The Customer authorises the use of the sub-processors listed in Annex III to process Customer personal data as described in that annex.
7. International transfers
Where personal data is transferred from the EEA, UK or Switzerland to a jurisdiction that does not have an adequacy decision, the parties incorporate the Module 2 (controller to processor) or Module 3 (processor to processor) Standard Contractual Clauses adopted by the European Commission on 4 June 2021, and the UK International Data Transfer Addendum where the UK GDPR applies. The Clauses are completed as follows: docking clause applies; option for independent supervisory authority is the authority of the country in which the Customer's establishment is located; governing law and forum follow the Clauses' defaults where not otherwise specified.
8. Audit rights
Status Quo 247 will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Independent audit reports and certifications will be made available if and when they are obtained.
No more than once per calendar year, and on at least 30 days' written notice, the Customer (or an independent auditor engaged by the Customer that is not a competitor of Status Quo 247 and is bound by confidentiality) may conduct an audit of Status Quo 247's controls relevant to the processing of Customer personal data. Audits will be scoped to avoid disrupting the service and to protect other customers' data. The Customer bears its own audit costs. Where a supervisory authority requires an audit, this cap does not apply.
9. Liability and indemnity
Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement. Nothing in this DPA excludes or limits either party's liability where such exclusion or limitation is not permitted by applicable data protection law.
10. Return or deletion
On expiry or termination of the Agreement, and at the Customer's choice, Status Quo 247 will either return all Customer personal data in a commonly used format, or delete it, within 60 days. Deletion covers primary systems and backups within the backup rotation cycle described in Annex II. We may retain personal data to the extent required by law, in which case we will keep protecting it under this DPA.
Annex I — Details of processing
A. List of parties
Data exporter (controller): the Status Quo 247 customer identified in the Order Form.
Data importer (processor): [Status Quo 247 — legal entity name and jurisdiction to be filled].
B. Description of processing
Categories of data subjects: Customer's employees, contractors, interns, applicants.
Categories of personal data: identifiers, device/activity signals, screenshots, application usage, URLs, GPS location, attendance events, payroll data (including PAN / Aadhaar where the Customer chooses to store them).
Sensitive data: to the extent the Customer inputs sensitive data (for example, statutory identifiers under Indian law), Status Quo 247 applies the safeguards in Annex II. The Customer is responsible for the lawful basis for including any sensitive data.
Frequency: continuous, for the term of the Agreement.
Nature of processing: hosting, storage, transmission, aggregation, reporting, backup, security monitoring, support.
Purpose: to provide the Status Quo 247 service as configured by the Customer.
Retention: as configured by the Customer within the limits described in the product documentation. On termination, per section 10.
Annex II — Technical and organisational measures
Status Quo 247 maintains at least the following measures:
- Encryption in transit: TLS between clients and the Status Quo 247 service.
- Access control: role-based access with least-privilege defaults; production access is limited to personnel who need it for their role.
- Audited views: access to screenshots, recordings and payroll fields is recorded in the in-product audit log.
- Rate limiting and abuse controls: request-level rate limiting on the public API and login endpoints.
- Incident response: a documented process for triaging and responding to security incidents, with a 72-hour customer-notification target where required by law.
- Personnel: confidentiality obligations on all personnel with access to Customer personal data.
- Sub-processor governance: written data-protection terms with each sub-processor listed in Annex III.
Additional controls (such as at-rest encryption of specific data stores, independent audits, and third-party penetration testing) will be added to this Annex as they are put in place. Status Quo 247 does not represent that any control not listed above is currently in operation.
Annex III — Approved sub-processors
Approved sub-processors as of the date of this DPA:
- Cloud hosting and object storage — [cloud provider — to be filled, e.g. AWS, region(s)]
- Transactional email — [email provider — to be filled, e.g. Postmark]
- Error monitoring and logging — [observability provider — to be filled]
- Customer support ticketing — [support provider — to be filled]
- Payment processing — [payment provider — to be filled]
- Payroll disbursement rails (where the Customer uses payroll modules) — [payroll rails provider — to be filled]
An up-to-date list is maintained at legal@statusquo247.com on request. Changes are notified per section 5.