Legal

Data Processing Agreement

Last updated 23 July 2026

This agreement governs our processing of personal data on your behalf, and is designed to meet Article 28 of the UK and EU GDPR. It forms part of, and is subject to, the Terms of Service. Where the two conflict on the handling of personal data, this agreement wins.

1. Parties and roles

Between [LEGAL ENTITY NAME] of [REGISTERED BUSINESS ADDRESS](“processor”, “we”) and the organization subscribing to Embaro (“controller”, “you”).

You are the controller of the personal data you put into Embaro — principally the employees named in your requests. You decide what is collected and why. We are your processor and act only on your instructions.

Separately, we are the controller of the accounts of people who sign in to Embaro. That is not covered here; it is described in our Privacy Policy.

This agreement applies automatically to every customer and needs no signature. If your procurement process requires a signed copy, email privacy@embaro.app.

2. Processing only on your instructions

We process personal data only on your documented instructions, including as to transfers outside the UK or EEA. Your instructions are: this agreement, the Terms, and your configuration and use of the product — the form you build, the requests you file, and the address you nominate for delivery.

We will tell you if we believe an instruction breaches data protection law, and may pause that processing until it is resolved. Where the law requires us to process for another reason, we will tell you first unless the law forbids it.

We do not use your personal data for our own purposes. We do not sell it, and we do not use it to train AI models.

3. Confidentiality

Everyone we authorise to process your personal data is bound by confidentiality obligations, is told what those obligations are, and has access only where their role requires it.

4. Security

We implement appropriate technical and organisational measures under Article 32. Those measures are described in Annex II, which reflects what the product actually does today rather than an aspiration.

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed in Annex III. Each is bound by data protection obligations no less protective than these, and we remain fully liable to you for their performance.

We will give at least 30 days’ notice by email to account administrators before adding or replacing a sub-processor. If you have a reasonable data-protection objection you may raise it within that period, and if we cannot resolve it you may terminate the affected subscription without penalty and receive a pro-rata refund of any prepaid fees.

6. Helping you answer data subjects

Embaro is built so you can handle most requests yourself: administrators can search, export, correct and delete employee records and filed requests directly.

Where a request cannot be satisfied that way, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing. If a data subject contacts us directly about data you control, we will not respond substantively — we will refer them to you and tell you promptly.

7. Breach notification, DPIAs, and consultation

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.

We will provide reasonable assistance with your obligations under Articles 32 to 36, including data protection impact assessments and any prior consultation with a supervisory authority, taking into account the information available to us.

8. Return and deletion

You can export your data at any time while the subscription is active.

On termination we delete your personal data on the schedule described in the Terms: an account that lapses becomes read-only after 5 days and is permanently deleted 14 days later. You may ask for deletion sooner, or for a final export before it happens, by emailing privacy@embaro.app.

We retain data after that point only where the law requires it, and it stays subject to this agreement for as long as we hold it. Backups age out on our providers’ own cycles and are not restored selectively.

9. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits or inspections you or an auditor you mandate conduct.

In practice we ask that you start with a written request to privacy@embaro.app; that audits happen no more than once a year unless a regulator requires otherwise or a breach has occurred; that they respect confidentiality and do not disrupt the service; and that you bear your own costs.

10. International transfers

Our infrastructure is in the United States, so processing your data involves a transfer outside the UK and EEA.

Where such a transfer requires a safeguard under Chapter V, the parties agree that the European Commission’s standard contractual clauses (Module Two, controller-to-processor) are incorporated into this agreement, together with the UK International Data Transfer Addendum where UK data is involved. Annexes I, II and III below populate the corresponding annexes of those clauses.

11. Liability and precedence

Liability under this agreement is subject to the limitations and exclusions in the Terms. Nothing here limits a data subject’s rights, or either party’s liability under data protection law where that liability cannot be limited.

This agreement is governed by the same law as the Terms, except where data protection law requires otherwise.

Annex I — The processing

Subject matter and duration. Providing the Embaro service, for as long as your subscription lasts plus the deletion window in section 8.

Nature and purpose. Collecting employee details through a form you design, storing them, routing them for approval, and delivering the completed request by email to an address you nominate. Maintaining a directory of those employees so past details can be reused, and an audit log of actions taken.

Categories of data subject. Your employees, contractors and new starters named in requests; and the people at your organization who file and approve them.

Types of personal data. Determined by the form you build. Typically name, work email, job title, department, manager, start or leave date, work location, and which systems and access the person needs. Also the identity of the person filing or approving, with timestamps and IP address.

Special category data. None. Embaro is not designed to hold health, biometric or other special category data, and the Terms ask you not to enter it.

Frequency. Continuous, for as long as the service is in use.

Annex II — Technical and organisational measures

These are measures the product implements today, not intentions:

  • Tenant isolation.Every organization’s data is separated, and the organization for any request is derived from the signed-in session — never from anything the browser supplies.
  • Access control. Role-based permissions (administrator, approver, member), with non-administrators able to see only the requests they filed.
  • Authentication. Passwords hashed with scrypt. Optional two-factor authentication. Sessions are opaque server-side tokens stored hashed, so access can be revoked immediately rather than waiting for a token to expire.
  • Encryption. TLS in transit. Encryption at rest by our database provider. Two-factor secrets and stored mail-server passwords additionally encrypted with AES-256-GCM under a key held only in the server environment.
  • Abuse resistance. Rate limiting on sign-in, registration, password reset and two-factor verification, keyed by an irreversible digest so no email address or IP is stored in that system.
  • Accountability. An audit log recording actor, action, target, timestamp and IP for changes, readable by your administrators.
  • Data minimisation. The AI form builder, when used, receives only your written description and the names in your resource catalog — never employee records or filed requests.
  • Resilience. Managed hosting and database with automated backups and point-in-time recovery.
  • Deletion. Automated deletion of lapsed accounts on a fixed schedule, removing all tenant-owned records.

Annex III — Sub-processors

Sub-processorPurposeData involved
VercelApplication hosting and content deliveryEverything transiting the app, plus request logs and IP addresses
NeonManaged PostgreSQL databaseAll account data and customer content stored by the service
Resend (using Amazon SES)Transactional email — verification, invitations, password resets, and delivery of completed requests to your IT deskRecipient addresses and the contents of those messages
UpstashRate limiting on sign-in and other sensitive endpointsCounters only, keyed by an irreversible digest — no email address or IP is stored
OpenAIGenerating a draft request form from a description, when you use that featureOnly the description you type and your resource catalog names. No employee records or filed requests are ever sent
StripeSubscription billingBilling contact and payment details, which are collected by Stripe directly — Embaro never receives card numbers

Questions about this agreement, or to request a signed copy: privacy@embaro.app.