Skip to content

Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Soon Technologies B.V. (“Soon”) and the organization using the Soon platform (“Customer”). It sets out the terms required by Article 28(3) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and, to the extent the UK GDPR and the Data Protection Act 2018 apply to the processing, the equivalent provisions of those laws. References to the GDPR include the UK GDPR where it applies.

Where Customer and Soon have signed a separate negotiated data processing agreement, that agreement takes precedence over this one.

1. Roles of the parties

Customer is the controller of the personal data it and its personnel place in the platform. Soon is the processor, acting on Customer’s behalf. Customer determines the purposes and means of processing; Soon processes only as set out in this DPA.

Customer is responsible for having a lawful basis for the processing, for informing its own personnel as data subjects, and for the accuracy and lawfulness of the data it enters.

2. Subject matter and details of processing

The subject matter, duration, nature, purpose, types of personal data and categories of data subject are set out in Annex I. Processing continues for as long as Customer’s subscription is active, and then for the deletion period in section 9.

3. Processing on documented instructions

Soon processes personal data only on Customer’s documented instructions, including as to international transfers, unless required otherwise by Union or Member State law. The Terms of Service, this DPA and Customer’s use of the platform’s features constitute those instructions.

Where Soon is required by law to process beyond those instructions, it will inform Customer of that legal requirement before processing, unless the law prohibits it. If Soon considers an instruction to infringe the GDPR or other data protection law, it will inform Customer without delay.

4. Confidentiality

Soon ensures that every person authorized to process Customer personal data, including employees, directors and contractors, is bound by a written confidentiality obligation that survives the end of their engagement. Access is granted on a need-to-know basis and reviewed periodically, at intervals determined by risk, and when responsibilities or access needs materially change.

5. Security of processing

Soon implements appropriate technical and organizational measures under Article 32 GDPR, described in Annex II. Soon maintains an information security management system aligned to ISO/IEC 27001 and keeps these measures under review; measures may change over time, but Soon will not materially reduce the overall level of security during Customer’s subscription.

6. Sub-processors

Customer gives general authorization for Soon to engage sub-processors. The current list is in Annex III.

Soon will inform Customer of any intended addition or replacement of a sub-processor at least 30 days before that sub-processor begins processing Customer personal data, by email to Customer’s account administrators and by updating Annex III on this page, giving Customer a reasonable opportunity to object on reasonable data protection grounds. This page is the authoritative sub-processor list. If Customer objects on reasonable data protection grounds and the parties cannot agree a resolution, Customer may terminate the affected subscription by written notice. Soon will not charge an early termination fee or fees for service periods after termination takes effect. Fees already paid, including prepaid fees for the unused portion of the subscription, are non-refundable unless a refund is required by applicable law or expressly agreed in a separate written agreement. Any other refund or credit is at Soon’s sole discretion. This provision does not restrict Customer’s statutory remedies for Soon’s breach of contract or any rights that cannot lawfully be excluded.

Soon imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for their performance.

7. Assisting with data subject rights

The platform provides features allowing Customer to access, correct, export and delete personal data itself. Where Customer cannot fulfil a data subject request through those features, Soon will provide reasonable assistance and will respond to such a request within five working days.

If a data subject contacts Soon directly about data processed on Customer’s behalf, Soon will refer them to Customer rather than respond substantively, and will tell Customer promptly.

8. Personal data breaches, DPIAs and prior consultation

Soon will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and in any event within 48 hours, so that Customer can meet its own 72-hour obligation under Article 33. Notice will not be delayed pending completion of a forensic investigation or a risk assessment; Soon will notify on the information available and update as more becomes known. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed โ€” providing information in stages where it is not all available at once.

Soon will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to Soon.

9. Deletion and return

At the Customer’s choice, Soon will delete or return Customer personal data after the end of the provision of services, as Article 28(3)(g) requires.

Customer may export its data at any time while the subscription is active, and for 30 days after termination through the platform’s export features. Within that period Customer may instead ask Soon to return the data in a structured, commonly used format, and Soon will do so at no charge.

After that 30-day window Soon deletes Customer personal data from live systems within a further 60 days โ€” 90 days from termination in total. Copies held in encrypted backups are not individually deleted; they are overwritten as those backups age out, within 30 days of the deletion from live systems, and remain subject to this DPA until they do. Soon retains data beyond these periods only where Union or Member State law requires it, and will tell Customer if that applies. Soon will confirm deletion in writing on request.

10. Audits and information

Soon will make available to Customer the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates.

In the first instance Soon will provide its current independent assessment or certification report where one is available, together with responses to reasonable written security questionnaires. Where that information does not reasonably address Customer’s concern, Customer retains its right to an inspection.

Inspections are ordinarily limited to once in any twelve-month period. Customer may request an additional inspection where it has substantiated grounds to believe Soon is not complying with this DPA, following a personal data breach affecting its data, or where a supervisory authority requires it. Inspections must be scheduled with reasonable notice, must not unreasonably disrupt Soon’s business, and must respect the confidentiality of other customers’ data and Soon’s security information.

11. International transfers

The platform’s primary database and backups are hosted in the European Union (Amazon Web Services, Ireland region). Sub-processors may also store or otherwise process limited personal data outside the EEA in the locations listed in Annex III. Where that happens, Soon relies on the European Commission’s Standard Contractual Clauses (and, for UK customers, the UK International Data Transfer Addendum) or another valid transfer mechanism, together with supplementary measures where required.

12. Liability, governing law and term

This DPA is governed by the law that governs the Terms of Service, and the limitations of liability in the Terms apply to it, except that nothing in this DPA limits either party’s liability to a data subject under Article 82 GDPR or any liability that cannot lawfully be limited. The aggregate liability cap is based on fees actually paid in the twelve months preceding the event giving rise to the claim and is zero where no fees were paid in that period, including during a free trial, subject to those exceptions. This DPA takes effect when Customer first uses the platform and remains in force for as long as Soon processes Customer personal data.

13. Order of precedence

In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. A separately signed data processing agreement between the parties prevails over both.

Annex I โ€” Details of processing

Subject matter: provision of the Soon workforce management platform.
Duration: the term of Customer’s subscription, plus the deletion period in section 9.
Nature and purpose: hosting, storing and processing workforce data so that Customer can plan schedules, record time and attendance, manage leave and absence, forecast demand, and communicate with its personnel.

Categories of data subject: Customer’s employees, workers and contractors, and Customer’s administrative users.

Types of personal data: name, work email address, job role, team, skills and qualifications; schedules, shifts, worked hours, availability and leave or absence records (recorded as a category and period, not the nature of an illness); account and authentication identifiers; device push tokens and IP addresses; and any additional data Customer chooses to enter into free-text fields.

Special categories of data. The platform records absence as a category and a period โ€” for example “sick leave, 3–5 March” โ€” and does not ask for a diagnosis, symptoms, medical certificates or any other clinical detail. Customer must not enter such detail, including in free-text fields.

Recording that a person was absent through sickness may nonetheless reveal information about their health, and so may amount to data concerning health under Article 9 GDPR. Soon processes that limited category only on Customer’s instructions and only to provide absence and scheduling functionality. Customer, as controller, is responsible for identifying the Article 9(2) condition it relies on โ€” in an employment context this is typically Article 9(2)(b), read with national law such as the Dutch rules on the sick employee. Soon applies the measures in Annex II to this data as it does to all Customer personal data, and access to it within the platform is governed by the roles and permissions Customer configures.

Annex II โ€” Technical and organizational measures

Encryption. Data in transit is protected with TLS 1.2 or higher. Data at rest, including database storage and backups, is encrypted with AES-256 using managed keys.

Access control. Access to production systems is individually assigned on a least-privilege basis, protected by multi-factor authentication, and reviewed periodically at intervals determined by risk and when responsibilities or access needs materially change. The production database has no public endpoint; administrative access is brokered through a logged session service rather than an open network path.

Network and infrastructure. Workloads run inside private cloud networks governed by security group rules, behind managed load balancers terminating TLS; the web application is served through Cloudflare’s edge network.

Monitoring and logging. Infrastructure activity is recorded in a tamper-evident, organization-wide audit log delivered to a separate account. Threat detection, application error monitoring and infrastructure alerting run continuously, with alerts routed to a monitored security address.

Resilience and recovery. The production database runs across multiple availability zones with automated daily encrypted backups retained for 30 days, supporting point-in-time recovery within that window.

Secure development and change control. Soon maintains documented change-control procedures with review and testing proportionate to the nature and risk of production changes. Emergency changes may follow an expedited process, with review and documentation as soon as reasonably practicable afterward. Dependency vulnerability scanning forms part of the security programme, and remediation is prioritized according to severity and risk.

Organizational measures. Documented information security policies, security awareness training with periodic refreshers, written confidentiality undertakings for everyone with access, a documented incident response procedure with a parallel personal data breach procedure, and a maintained information asset inventory and sub-processor register.

Security assessment. Soon maintains a process for regularly testing, assessing and evaluating the effectiveness of its security measures. Soon determines the scope, methods and frequency based on risk, material changes to the service and applicable legal requirements. This may include vulnerability assessments and independent penetration testing where appropriate to the risk.

Customer-side authentication. Soon supports single sign-on via SAML with major identity providers, and sign-in with Google or Microsoft, both of which inherit the identity provider’s own multi-factor authentication. Customers seeking multi-factor assurance today should use one of those methods; native multi-factor authentication for email and password accounts is on our roadmap and not yet available.

Annex III โ€” Sub-processors

The following sub-processors are engaged for all customers. Soon will give notice before adding or replacing any of them, as set out in section 6.

Sub-processorPurposeLocationTransfer mechanism
Amazon Web ServicesPlatform hosting, database, storageEU (Ireland)No transfer โ€” data stays in the EU
Amazon SESTransactional email from the platform (invitations, notifications, password resets)EU (Ireland)No transfer โ€” data stays in the EU
CloudflareDNS, content delivery, web application firewallGlobal edgeEU-US Data Privacy Framework; EU SCCs (Module 3) as fallback
StripeSubscription billing and paymentsEU / USEU-US Data Privacy Framework; EU SCCs as fallback
WorkOSEnterprise single sign-on and directory syncUSEU SCCs, Module 3 (processor to processor)
PostHogProduct analyticsEUNo transfer โ€” data stays in the EU
SentryApplication error monitoringUSEU-US Data Privacy Framework; EU SCCs (Module 3) as fallback
IntercomIn-product support and messagingUSEU-US Data Privacy Framework; EU SCCs (Module 3) as fallback
CloudinaryImage and media hostingEU / USEU-US Data Privacy Framework; EU SCCs as fallback
OpenAIAI scheduling and assistant featuresUSEU SCCs, Module 3 (processor to processor)
Google Maps PlatformAddress lookup in the applicationGlobalEU-US Data Privacy Framework; EU SCCs where not covered by adequacy
Google WorkspaceSoon’s internal email and document storageEUEU-US Data Privacy Framework; EU SCCs where not covered by adequacy

Transfer mechanisms were verified against each provider’s own data processing agreement on 9 September 2026 and are reviewed at least annually. Where a provider relies on the Data Privacy Framework, its certification is checked at the same time; if a certification lapses, the Standard Contractual Clauses named above apply instead. Soon is a processor, so the processor-to-processor module (Module 3) applies to transfers of Customer personal data; Stripe is the exception, since Soon is the controller of its own billing data.

Where a Customer enables an optional integration โ€” for example a calendar or telephony provider โ€” that provider processes data only for that Customer, and enabling the integration constitutes Customer’s authorization of it.

Contact

For questions about this DPA or to raise a data protection matter:

Soon Technologies B.V.
Herengracht 420
1017 BZ Amsterdam
The Netherlands
KvK: 75939401
Email: [email protected]