DATA PROCESSING AGREEMENT

A usable Article 28-style processing baseline for customer pilots and subscriptions.

The customer controls its project data. Hirentra processes it to provide the service, with clear subprocessor, breach, deletion and assistance commitments.

1. Scope and roles

This DPA applies where TheBigBangWorks Ltd processes personal data on behalf of a Hirentra customer under a Pilot Order, subscription order or other service agreement (“Service Agreement”). The Customer is the controller (or a processor acting for another controller) and TheBigBangWorks Ltd is the processor for that Customer Personal Data, except for processing where TheBigBangWorks Ltd independently determines purposes and means.

2. Processing details

Subject matter: provision, support, security and operation of Hirentra. Duration: the Service Agreement plus agreed retention/close-out periods. Nature: collection, hosting, organisation, retrieval, display, transmission, backup, support, security analysis and deletion. Purpose: construction hire, project, commercial, document/evidence and related account workflows configured by the Customer.

Data subjects may include Customer personnel, site users, supplier contacts and other individuals whose information the Customer chooses to place in Hirentra. Data categories may include identity/contact data, role/site assignments, operational records, images/documents, timestamps, audit/security records and other Customer-provided data.

3. Documented instructions

Hirentra will process Customer Personal Data only on documented Customer instructions contained in the Service Agreement, configured use of the service and lawful support requests, unless UK law requires otherwise. If we believe an instruction infringes applicable data-protection law, we will inform the Customer where legally permitted.

4. Confidentiality and security

Persons authorised to process Customer Personal Data are subject to confidentiality obligations. Hirentra will maintain appropriate technical and organisational measures having regard to the nature of processing and risk, including access controls, tenant/role scoping, authentication, auditability, controlled backups and security monitoring appropriate to the service.

5. Subprocessors

The Customer gives general authorisation for the subprocessors required to operate Hirentra. The current list and purposes are published at /subprocessors.html. Hirentra remains responsible for its subprocessor obligations to the extent required by applicable data-protection law and will impose appropriate data-protection obligations on subprocessors.

6. International transfers

Hirentra will not intentionally transfer Customer Personal Data outside the UK except under a lawful transfer mechanism. Depending on provider configuration/support, data may be processed in the EEA or other locations. Customer-specific residency commitments must be recorded in the Service Agreement or DPA schedule; this DPA does not invent a hosting region that has not been contractually confirmed.

7. Data-subject requests

Taking account of the nature of processing, Hirentra will provide reasonable assistance to enable the Customer to respond to requests by data subjects. If a request relating to Customer Personal Data is received directly, Hirentra may redirect it to the Customer unless law requires a direct response.

8. Personal-data breaches

Hirentra will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to assist the Customer with investigation, risk assessment and legally required notifications. Notification is not an admission of fault or liability.

9. DPIAs and regulatory assistance

Taking account of the nature of processing and information available to it, Hirentra will provide reasonable assistance with data-protection impact assessments and regulator consultations where required for the Customer's use of Hirentra.

10. Return and deletion

On termination or expiry, Hirentra will, at the Customer's choice and subject to the Service Agreement, return/export Customer Personal Data reasonably available in supported formats and delete it after the applicable close-out period, unless law requires retention. Backup copies may persist until they age out of the controlled backup cycle and remain protected while retained.

11. Audit information

Hirentra will make available information reasonably necessary to demonstrate compliance with processor obligations. Audits should first use available security, policy and technical evidence and must protect other customers' confidentiality and service security. On-site or intrusive audits require reasonable notice and agreement on scope, timing and cost unless a regulator or applicable law requires otherwise.

12. Order of precedence and law

If this DPA conflicts with the Service Agreement on processing of Customer Personal Data, this DPA prevails to the extent of the conflict unless a separately signed DPA states otherwise. This DPA is governed by the law/jurisdiction stated in the Service Agreement; otherwise England and Wales.

Version 1.0 · Effective 8 September 2026.