Data Processing Agreement

Last updated 4 October 2026

This agreement covers how Peoplume processes personal data on your behalf. It forms part of the terms of service and takes precedence over them, and over the privacy page, on any conflict about processing.

It binds both of us as soon as you accept the terms — there is nothing to sign. If your procurement needs an executed copy, write to [email protected] and we will sign this text as it stands.

1. Who is who

You are the controller of the personal data in Annex I. You decide who is recorded, what is recorded about them, what documents are uploaded and how long any of it is kept. Plumeware LLC, of Wyoming, United States, operating Peoplume, is the processor and acts only on your instructions.

For our own account and billing data — who your administrators are, your subscription status and seat count — we are an independent controller and this agreement does not apply. That processing is described on the privacy page.

You confirm you have a lawful basis for what you record, and that you have given your staff whatever notice your local law requires. We cannot establish that basis for you and do not try to.

“GDPR” means Regulation (EU) 2016/679 and, where it applies, the UK GDPR and Data Protection Act 2018. “Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” carry their GDPR meanings.

2. Our instructions are yours

We process personal data only on your documented instructions, including about transfers to another country, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law forbids it on important grounds of public interest.

Your instructions are: the terms, this agreement, whatever you configure in the product, and any further written instruction we accept. If we think an instruction breaches data protection law we will say so, and may pause it until it is withdrawn or changed.

We do not use your data to train AI models, and we do not sell it. A model sees your data in two optional places, both in Annex III: the receipt-reading feature, which runs only when an employee presses the button for one receipt, and the AI assistant, which is off until an administrator switches it on and then sends each question with the rows looked up to answer it — never more than the asking person could already open.

3. Confidentiality and access

Everyone authorised to process personal data under this agreement is bound by confidentiality, and access to production data is limited to the people who operate the service and only where they need it.

4. Security

We implement the measures in Annex II, taking account of the state of the art, cost, and the nature and risk of the processing, as Article 32 requires. We may change them, but not in a way that lowers the overall level of security. Annex II also names what we do not do — a security annex listing only strengths tells you nothing.

5. Sub-processors

You give general authorisation for the sub-processors in Annex III. Each is bound by terms no less protective than this agreement, and we stay fully liable to you for what they do.

We will give you thirty days’ notice, by email to your administrators, before adding or replacing one. If you object on reasonable data protection grounds within that window we will look for an alternative; if there is none, you may stop using the affected part of the service and we will refund the unused part of what you have prepaid for it.

6. Helping you meet your own obligations

Requests from individuals. The product answers most of these without us. You can export everything held about one person as a set of spreadsheets from their profile, correct any field, and erase a former employee’s personal data while keeping the payroll record. Employees can download their own bundle from the portal without asking anyone. Where a request cannot be answered through those features we will assist you as far as we reasonably can.

If one of your employees contacts us directly we will not answer on the substance — we will point them to you and tell you promptly.

Breaches. We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting data processed under this agreement. The notice will describe what happened, the categories and rough number of people and records involved, the likely consequences, what we have done or propose to do, and who to talk to. Where we cannot give you all of that at once we will follow up as we learn more. Any notification to a regulator or to the people affected is yours to make — you are the controller and only you know the context.

Impact assessments. We will give you the information about the product you reasonably need to carry out a data protection impact assessment, and to consult a supervisory authority where Article 36 requires it.

7. Deletion and return

You can export your data at any time, including after cancelling, and can erase an individual or delete records outright. Those are self-service and take effect immediately.

Otherwise we keep your data for 90 days after the agreement ends so you can retrieve it, then delete or return it at your choice, unless a law requires us to keep something — in which case we will tell you what and why. Return is by export in a structured, commonly used, machine-readable format.

Backups are the exception to immediate deletion. Data erased from the live system stays in existing backup copies until those rotate out. Backups are used for nothing but restoring the service.

One deliberate limit on erasure: erasing a former employee blanks their identifying fields but keeps payslips, attendance and salary history. A right to erasure does not entitle anyone to rewrite what a company reported it paid, and deleting payroll records would change an accounting record after the fact. The audit entry recording the erasure keeps the name, so you can still answer “did you action my request?” a year later.

8. Audits

We will give you the information needed to show we comply with Article 28 and this agreement, and will allow for and contribute to audits by you or an auditor you appoint.

In practice: we answer security questionnaires and provide documentation on request. A deeper audit may be carried out once in any twelve months, on thirty days’ notice, in business hours, without unreasonably disrupting the service, subject to confidentiality and at your cost — except where the audit follows a breach we notified or a regulator requires it, when none of those limits apply.

9. International transfers

We are established in the United States, and we are not certified under the EU–US Data Privacy Framework. The European Commission’s adequacy decision for the United States covers only organisations that hold that certification, so it does not cover transfers to us, and we would rather lead with that than leave you to find it. Personal data is also processed by the sub-processors in Annex III, in the regions stated there.

Where you are established in the EEA, the United Kingdom or Switzerland, or the GDPR otherwise applies to your processing, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this agreement and apply to transfers to us, completed as follows:

  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2, general written authorisation, with the thirty days’ notice in section 5 above.
  • Clause 11: the optional independent dispute resolution paragraph does not apply.
  • Clause 17: governed by the law of Ireland.
  • Clause 18(b): the courts of Ireland.
  • Annexes I, II and III of the Clauses are the correspondingly numbered annexes below.

For transfers under the UK GDPR, the UK International Data Transfer Addendum (version B1.0) applies to those Clauses, with Table 4 completed as “neither party”. For Switzerland, references to the GDPR are read as references to the Swiss FADP and the Federal Data Protection and Information Commissioner is the competent authority.

As Clause 14 requires, we each warrant that we have no reason to believe the laws and practices of the destination countries, applied to the transfer and to the measures in Annex II, stop us meeting our obligations. We will document that assessment, make it available on request, and tell you without delay if we become unable to comply.

10. Other data protection laws

Where another data protection law applies to this processing — a United States state privacy law, or the law of a country where you or the people you record are located — we comply with the obligations it places on us as a processor or service provider. We do not sell the personal data you put into Peoplume or use it for any purpose other than providing the service to you. Nothing here reduces a protection such a law gives.

11. Liability, term and changes

Liability under this agreement is subject to the limits in section 10 of the terms, except where the GDPR or the Standard Contractual Clauses do not permit that — the Clauses govern liability between us for the transfers they cover.

This agreement starts when you accept the terms and runs until the service ends and deletion under section 7 is complete. Sections 3, 7, 8, 9 and 11 survive. We may update it to reflect a change in law, in the product, or in our sub-processors; material changes are notified as the terms require, and we will not apply a change that reduces your protection or our obligations without your agreement.

Annex I — What is processed

Parties. Exporter and controller: the organisation that accepted the terms, as employer of the people recorded; contact is the administrators on the account. Importer and processor: Plumeware LLC, Wyoming, United States, operating Peoplume; contact [email protected].

Data subjects. Your employees and former employees, their dependents where you record them, job applicants — including people who apply through your public careers page — and the administrators and managers who use the console.

CategoryWhat it includes
Identity and contactName, employee number, work email, phone, address, date of birth, gender, nationality, marital status, emergency contact name and phone. Everything except name and employee number is optional.
EmploymentHire date, probation end, employment type, department, job title, branch, shift, reporting manager, status, termination date, free-text notes.
PayBasic salary or hourly rate, allowances and deductions, loans and advances, bank name and IBAN, payslips, and the history of salary changes.
TimeAttendance records, leave requests, timesheets and project hours. Portal check-ins may carry browser geolocation where the employee's device allows it; the punch is never blocked if it does not.
DocumentsWhatever you upload: employment contracts, identity documents such as passports and visas, certificates, expense receipts, candidate CVs, company policies.
FamilyDependents you record: name, relationship, optional date of birth and nationality, sponsorship, and one identity document's type, number and expiry date.
Performance and developmentGoals, reviews and ratings, self-assessments, peer feedback, praise, training enrolments and certificates, succession plans.
RecruitmentApplicant name, email, CV, interview notes, scorecards and offers.
Account and securityLogin email, a bcrypt hash of the password, two-factor secrets where enrolled, last login time, and an append-only audit log of sensitive changes recording who made them.

Special category data has no field in Peoplume, but two things can carry it anyway. Leave types are named by you, so a type called “Sick leave” makes the requests against it health data; and an uploaded document can be a medical certificate or anything else. Whether to record either is your decision, and Annex II describes the controls that exist around uploaded files. Engagement survey responses are the opposite case — they carry no employee reference and no timestamp, and there is no path in the product from a score back to a person.

Purpose. Running HR for you: employee records, attendance and shifts, leave, timesheets, expenses, payroll, performance, recruitment, training, the employee portal, notifications and exports.

Duration. Continuous while the account exists, then as section 7 says.

Competent supervisory authority. Per Clause 13 of the Standard Contractual Clauses: the authority of the Member State where you are established; or, where you are not established in the EEA but are subject to the GDPR under Article 3(2) and have appointed a representative, the authority where that representative is; or, failing that, the authority of a Member State where the data subjects are.

Annex II — Technical and organisational measures

This describes the product as it is today, including where it falls short. We hold no ISO 27001 or SOC 2 certification and have had no external penetration test. We would rather say so than let either be assumed. The fuller version of this, with the reasoning, is on the security page.

MeasureWhat is actually implemented
Tenant separationEvery record carries the company it belongs to and every query filters on it; there is no shared pool a forgotten filter could expose. Company scope alone is not treated as sufficient — reads are also checked against the relationship that entitles you to them, such as your own record or your own report. Automated tests assert this specifically.
Encryption in transitTLS on every connection, terminated by Cloudflare in front of the application.
Encryption at restUploaded files and database backups are held in Cloudflare R2, which encrypts them at rest. We do NOT encrypt them ourselves before upload, so the storage provider holds them in a form it could read. The database file sits on the hosting provider's volume; we add no application-layer encryption to it.
AuthenticationPasswords hashed with bcrypt and never stored or logged readably. Optional two-factor authentication (TOTP), which an administrator can require for every console user. Single sign-on over OpenID Connect. No SAML, deliberately.
SessionsThe session cookie is httpOnly, sameSite and secure, and carries only a user id — role, company, permissions and branch scope are re-derived from the database on every request, so a permission change takes effect on the holder's next request and nothing can be smuggled in the token. Changing a password, or 'sign out everywhere', invalidates every other session immediately.
Access controlRole-based permissions from a fixed server-side catalogue, with per-company roles and optional branch scoping that limits a user to one location's employees. Permissions are never taken from the request; a role can only grant what the person granting it holds.
Separation of dutiesNobody approves their own record anywhere in the product — leave, expenses, timesheets, offers, compensation proposals. Expense claims above a threshold you set need a second, different approver.
AccountabilityAn append-only audit log records sensitive changes — salary and bank edits, permission and role changes, approvals, deletions, data exports taken by staff about someone else — with who, what and when.
Uploaded filesPrivate object storage, never a public URL. Every download goes through an authorised route that re-checks the session and the relationship: portal users can reach only their own documents. Type and size are restricted on upload.
Data minimisationLimited, and stated as such. Rejected job applicants can be purged on a schedule you set, and a former employee's personal data can be erased on request; otherwise data stays until someone deletes it. There is no general retention timer.
Resilience and recoveryNightly backup with an integrity check and a checksum, copied off-site. Restores are scripted and default to a dry run, so recovery does not begin by overwriting anything.
Abuse and availabilityRate limits on sign-in per account, per IP and globally, and on the public application, kiosk, password-reset and candidate-booking endpoints. API keys are stored only as a hash, carry explicit scopes and are rate limited. Outgoing webhooks are HMAC-signed and refuse private, loopback and link-local addresses; incoming payment webhooks are signature-verified in constant time with a replay window.
Development practiceEvery change runs a build, a type check and an automated test suite in continuous integration before release, including tests that assert tenancy and authorisation behaviour, and an end-to-end browser suite.
Browser hardeningEvery response carries a Content-Security-Policy, HSTS for a year, nosniff, X-Frame-Options: DENY, a referrer policy and a permissions policy that disables camera, microphone, payment and motion sensors and permits location only for our own pages. Scripts are limited to our own origin; inline script is still allowed, because the framework emits it, so the policy blocks loading an attacker's script but not executing an injected inline one.
Known gapsNo independent security certification or penetration test. Inline script is permitted, as above. The public API is read-only.

Annex III — Sub-processors

The current list, with what each one receives, is maintained on the sub-processors page, which is part of this annex. In summary:

Sub-processorPurposeLocation
Railway Corp.Application hosting and the volume holding the database.As deployed — ask before you commit if you have a residency requirement.
Cloudflare, Inc.DNS and reverse proxy; R2 object storage holding every uploaded file and the off-site database backups; Web Analytics, a cookieless page-view counter that receives no employee data.Global, distributed
Paddle.com Market LtdPayments as merchant of record. Receives billing contact and payment details; receives no employee data.United Kingdom / EU
Resend, Inc.Transactional email — notifications, invitations, password resets, messages to candidates. Optional: with no key configured no email is sent and every notification still appears in the app.United States
Google LLC, Apple Inc., Mozilla Corporation (push services)Relay push notifications to devices whose user turned them on. The message is encrypted to the device before it leaves us; the service learns only that a message was sent to that subscription.United States / global
Anthropic PBCOptional receipt reading and the optional AI assistant. Receives one receipt image when an employee presses the button for it; or a question and the HR rows looked up to answer it, only while an administrator has the assistant switched on. No conversation is stored on either side by us.United States

Administrators on the account are notified before this list changes, as section 5 says.

Contact

Questions about this agreement, or to ask for a signed copy: [email protected]. Data protection enquiries: [email protected].