Data Processing Agreement & Sub-processors
Version 1.0 ยท Updated 25 August 2026How Adesto shares personal data with clients and the sub-processors we use to run the platform.
1. Introduction
This document describes how Adesto Recruitment Limited ("Adesto", "we", "us", "our"), a recruitment business, processes personal data in connection with the supply of locum workers to client organisations, and lists the sub-processors we engage to operate the platform. It is intended to satisfy the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 ("Data Protection Law").
2. Roles and responsibilities
Independent controllers. In the usual arrangement for the supply of temporary workers, Adesto (the recruitment business / employment business) and the client organisation are each independent data controllers of the personal data they hold and process in connection with the placement. Each party:
- is independently responsible for complying with Data Protection Law in relation to its own processing;
- ensures it has an appropriate lawful basis for its own processing;
- implements appropriate technical and organisational measures to protect personal data; and
- is responsible for handling its own data subject requests, personal data breaches and complaints.
Controllers and processors. Where Adesto engages a third-party supplier (a "processor") to process personal data on its behalf โ for example our hosting, email or payroll providers โ those arrangements are governed by a written contract containing the standard UK GDPR processor clauses (including confidentiality, security, sub-processing, breach notification, and deletion/return obligations). Our clients and workers are referred to our Privacy Policy and Fair Processing Notice for details of how their data is used.
3. Data we share with clients
When a locum worker is offered or placed with a client organisation, we share only the personal data necessary for that placement, which may include: name, professional role and registration details, compliance status and documents, DBS status, right-to-work status, mandatory training records, and shift/timesheet information. Clients must only use this data for the purposes of the placement, keep it secure, and process it in accordance with Data Protection Law.
4. Security
We implement appropriate technical and organisational measures to protect personal data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access. These include: encrypted data transmission (HTTPS), secure password storage, role-based access controls, audit logging, regular backups, and staff training on data protection.
5. Data subject rights and breaches
Each party is responsible for responding to data subject requests (such as access, rectification, erasure) made to it, and for notifying the relevant authorities and individuals where a personal data breach requires notification under Data Protection Law. We will cooperate with each other in relation to any data subject request or breach concerning the personal data we share.
6. Sub-processors
The following sub-processors process personal data on our behalf to operate the platform. We review this list periodically and update it when we add, remove or change a provider. All sub-processors are bound by written contracts containing the standard UK GDPR processor obligations.
| Provider | Service / purpose | Data processed | Location |
|---|---|---|---|
| Cloud server / hosting provider | Hosting the application and database (our production server) | All platform data (stored securely) | EU / UK |
| PostgreSQL database | Storing application records (users, shifts, compliance, timesheets) | All platform data | Same as hosting |
| Email delivery provider | Sending transactional and notification emails (shift confirmations, compliance reminders, password resets) | Names, email addresses, notification content | UK / EU / US |
| Object / file storage | Storing uploaded documents (compliance certificates, timesheets, forms, ID badges) | Uploaded personal documents | Same as hosting |
| Backup storage | Encrypted backups of the database and uploads | All platform data (backed up) | UK |
| Google Places API | Address search / autocomplete on registration and site forms | Address text you type (transient) | US / EU |
| Companies House API | Looking up client/agency company details at registration | Company name/number and registered address | UK |
| Professional registration checks (NMC, GMC, HCPC) | Verifying professional registration and status | Name, registration number, status | UK |
| DBS Update Service | Checking DBS certificate status | Name, DBS certificate number, check result | UK |
| Training providers (e.g. Health & Safety Group, Train Healthcare) | Syncing and verifying locum training certificates | Name, email, training records and certificates | UK |
| Payroll / payment processing | Processing PAYE payroll and payments to locums | Bank details, National Insurance number, pay records | UK |
Where a provider processes data outside the UK, we ensure appropriate safeguards are in place (such as UK International Data Transfer Agreements or adequacy decisions) and reflect this in our contracts.
7. International transfers
Your data is primarily stored and processed in the United Kingdom. Where we or our sub-processors transfer personal data outside the UK, we ensure appropriate safeguards are in place under Data Protection Law.
8. Retention and deletion
We retain personal data only for as long as necessary for the purposes for which it was collected, and in line with our retention schedule (see our Privacy Policy). When data is no longer needed, it is securely deleted or anonymised.
9. Contact
For questions about this agreement or our sub-processors, contact our data protection contact at [DPO contact โ to be confirmed], or write to Adesto Recruitment Limited, [Registered office address โ to be confirmed].