๐Ÿ“ฑ
Please rotate your device to portrait mode

Data Processing Agreement & Sub-processors

Version 1.0 ยท Updated 25 August 2026

How Adesto shares personal data with clients and the sub-processors we use to run the platform.


1. Introduction

This document describes how Adesto Recruitment Limited ("Adesto", "we", "us", "our"), a recruitment business, processes personal data in connection with the supply of locum workers to client organisations, and lists the sub-processors we engage to operate the platform. It is intended to satisfy the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 ("Data Protection Law").

2. Roles and responsibilities

Independent controllers. In the usual arrangement for the supply of temporary workers, Adesto (the recruitment business / employment business) and the client organisation are each independent data controllers of the personal data they hold and process in connection with the placement. Each party:

  • is independently responsible for complying with Data Protection Law in relation to its own processing;
  • ensures it has an appropriate lawful basis for its own processing;
  • implements appropriate technical and organisational measures to protect personal data; and
  • is responsible for handling its own data subject requests, personal data breaches and complaints.

Controllers and processors. Where Adesto engages a third-party supplier (a "processor") to process personal data on its behalf โ€” for example our hosting, email or payroll providers โ€” those arrangements are governed by a written contract containing the standard UK GDPR processor clauses (including confidentiality, security, sub-processing, breach notification, and deletion/return obligations). Our clients and workers are referred to our Privacy Policy and Fair Processing Notice for details of how their data is used.

3. Data we share with clients

When a locum worker is offered or placed with a client organisation, we share only the personal data necessary for that placement, which may include: name, professional role and registration details, compliance status and documents, DBS status, right-to-work status, mandatory training records, and shift/timesheet information. Clients must only use this data for the purposes of the placement, keep it secure, and process it in accordance with Data Protection Law.

4. Security

We implement appropriate technical and organisational measures to protect personal data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access. These include: encrypted data transmission (HTTPS), secure password storage, role-based access controls, audit logging, regular backups, and staff training on data protection.

5. Data subject rights and breaches

Each party is responsible for responding to data subject requests (such as access, rectification, erasure) made to it, and for notifying the relevant authorities and individuals where a personal data breach requires notification under Data Protection Law. We will cooperate with each other in relation to any data subject request or breach concerning the personal data we share.

6. Sub-processors

The following sub-processors process personal data on our behalf to operate the platform. We review this list periodically and update it when we add, remove or change a provider. All sub-processors are bound by written contracts containing the standard UK GDPR processor obligations.

Provider Service / purpose Data processed Location
Cloud server / hosting provider Hosting the application and database (our production server) All platform data (stored securely) EU / UK
PostgreSQL database Storing application records (users, shifts, compliance, timesheets) All platform data Same as hosting
Email delivery provider Sending transactional and notification emails (shift confirmations, compliance reminders, password resets) Names, email addresses, notification content UK / EU / US
Object / file storage Storing uploaded documents (compliance certificates, timesheets, forms, ID badges) Uploaded personal documents Same as hosting
Backup storage Encrypted backups of the database and uploads All platform data (backed up) UK
Google Places API Address search / autocomplete on registration and site forms Address text you type (transient) US / EU
Companies House API Looking up client/agency company details at registration Company name/number and registered address UK
Professional registration checks (NMC, GMC, HCPC) Verifying professional registration and status Name, registration number, status UK
DBS Update Service Checking DBS certificate status Name, DBS certificate number, check result UK
Training providers (e.g. Health & Safety Group, Train Healthcare) Syncing and verifying locum training certificates Name, email, training records and certificates UK
Payroll / payment processing Processing PAYE payroll and payments to locums Bank details, National Insurance number, pay records UK

Where a provider processes data outside the UK, we ensure appropriate safeguards are in place (such as UK International Data Transfer Agreements or adequacy decisions) and reflect this in our contracts.

7. International transfers

Your data is primarily stored and processed in the United Kingdom. Where we or our sub-processors transfer personal data outside the UK, we ensure appropriate safeguards are in place under Data Protection Law.

8. Retention and deletion

We retain personal data only for as long as necessary for the purposes for which it was collected, and in line with our retention schedule (see our Privacy Policy). When data is no longer needed, it is securely deleted or anonymised.

9. Contact

For questions about this agreement or our sub-processors, contact our data protection contact at [DPO contact โ€” to be confirmed], or write to Adesto Recruitment Limited, [Registered office address โ€” to be confirmed].