> ## Documentation Index
> Fetch the complete documentation index at: https://www.composer.id/llms.txt
> Use this file to discover all available pages before exploring further.

# Data processing agreement

> composerID Data Processing Agreement: Deployed as processor under UK and EU GDPR, with Annexes on processing, security and sub-processors.

These are the terms on which Deployed processes personal data on a customer’s behalf when composerID publishes decisions into that customer’s systems of record. The Annexes describe the processing, the security measures, the sub-processors and the UK Addendum to the EU Standard Contractual Clauses.

<Info>Last updated 22 September 2026</Info>

This Data Processing Agreement, including its Annexes (**“DPA”**), is entered into by Deployed, a company based in London, United Kingdom (**“Deployed”**), and the customer identified in the Agreement (**“Customer”**).

Deployed provides Triage, its decision-intelligence software, and composerID, the integration layer that publishes Triage’s decisions into Customer’s systems of record under one Intent ID (together, the **“Service”**). Providing the Service involves the Processing of Personal Data subject to Data Protection Laws. In the provision of the Service, Customer acts as Controller and Deployed acts as Processor. Where Customer is itself a Processor for its own client, Deployed acts as Sub-processor and references to Controller instructions include the instructions Customer passes on.

<Note>
  **This DPA applies between the parties where a representative of Customer clicks to accept it, transfers Personal Data to Deployed for Processing by means of the Service, or otherwise indicates acceptance.** By doing so you (a) agree to this DPA on behalf of the organisation for which you act (“Customer”) and (b) represent that you have authority to bind Customer and its Affiliates. If you do not have that authority, or do not agree with this DPA, do not transfer Personal Data to Deployed. Deployed may update this DPA; an update takes effect on the earlier of 30 days after posting and Customer’s continued transfer of Personal Data.
</Note>

If Customer and Deployed have signed a written data processing agreement governing the Processing of Personal Data by means of the Service, that signed agreement supersedes this DPA. This DPA is incorporated into and forms part of the Agreement.

## 1. Definitions

Capitalised terms have the meanings given here, in applicable Data Protection Laws, or in the Agreement.

* **“Agreement”** means the terms between Deployed and Customer governing use of the Service, including the [API Terms](/legal/api-terms) or a signed customer agreement.
* **“Controller”**, **“Processor”**, **“Data Subject”**, **“Personal Data”**, **“Processing”** and **“Personal Data Breach”** have the meanings given in the UK GDPR, and “process” is construed accordingly.
* **“Data Protection Laws”** means all applicable data protection and privacy laws, as amended or replaced from time to time, including: (i) the UK General Data Protection Regulation (**UK GDPR**) and the Data Protection Act 2018; (ii) the Privacy and Electronic Communications (EC Directive) Regulations 2003; (iii) Regulation (EU) 2016/679 (**EU GDPR**) and national laws implementing it, where they apply; (iv) the Swiss Federal Act on Data Protection, where it applies; and (v) any other data protection law that applies to the Processing.
* **“End User”** means an individual at Customer whose request, decision or record is Processed by the Service.
* **“EU SCCs”** means the standard contractual clauses for the transfer of personal data to third countries adopted by European Commission Implementing Decision (EU) 2021/914.
* **“IDTA”** means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, and **“UK Addendum”** means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under the same section, each as revised from time to time.
* **“Restricted Transfer”** means a transfer of Personal Data that would be prohibited by Data Protection Laws in the absence of a transfer mechanism.
* **“Sub-processor”** means a third party engaged by Deployed to Process Personal Data on Customer’s behalf.
* **“Supervisory Authority”** means the Information Commissioner’s Office for UK Personal Data and the competent authority under the EU GDPR for EU Personal Data.

## 2. Compliance with laws

Each party will comply with the Data Protection Laws applicable to it in connection with the Service.

## 3. Customer’s obligations

Customer warrants that its instructions for the Processing of Personal Data under the Agreement and this DPA comply with Data Protection Laws and will not cause Deployed to breach them; that it has a lawful basis for the Processing and has given Data Subjects the information Data Protection Laws require; and that, to the extent it shares Personal Data with Deployed, it is responsible for the means by which that Personal Data was obtained. Customer is responsible for configuring the Service, including its Channel Map and the Destinations it connects, in a way that is consistent with those instructions.

## 4. Processing by Deployed

### 4.1 Instructions

Deployed will Process Personal Data solely to provide the Service and in accordance with Customer’s documented instructions, which are set out in the Agreement, this DPA and Customer’s configuration of the Service, and otherwise only as required by law. Unless prohibited by law, Deployed will inform Customer if in its opinion an instruction infringes Data Protection Laws, and may suspend performance of that instruction without liability until Customer confirms in writing that it is lawful. Additional instructions require the parties’ written agreement.

### 4.2 Government requests

Deployed will not disclose Personal Data to any government or public authority except as required by law or a valid and binding order such as a court order. If Deployed receives such an order it will notify Customer before disclosing, unless legally prohibited from doing so, and will disclose only the minimum required.

### 4.3 Personnel

Deployed will ensure that persons authorised to Process Personal Data are bound by appropriate obligations of confidentiality and receive suitable training.

### 4.4 No sale, no other use

Deployed will not sell or share Personal Data, will not Process it for any purpose other than providing the Service under the Agreement and this DPA, will not combine it with Personal Data obtained from other sources except as the Service requires, and will not use it to train generalised artificial intelligence or machine-learning models.

### 4.5 Minimisation by design

The Service is designed so that a Destination receives only the fields it requires for a valid record plus the Intent ID. Diagnostic answers, scores and the Compliance File are never transmitted to a Destination. Deployed will maintain this design and publish, per Destination, what crosses the boundary and what is never sent.

### 4.6 Details of Processing

The duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are specified in Annex I and, more generally, in the Agreement.

## 5. International transfers

### 5.1 General

Deployed will make a Restricted Transfer only in accordance with Data Protection Laws and this Section 5.

### 5.2 Transfers from the United Kingdom

Where a Restricted Transfer of UK Personal Data is made to a country not covered by UK adequacy regulations, the parties agree that the IDTA applies or, where the EU SCCs are also in place for the same transfer, that the UK Addendum in Annex IV applies to those EU SCCs.

### 5.3 Transfers from the European Economic Area

Where a Restricted Transfer of EU Personal Data is made to a country not the subject of an adequacy decision, the EU SCCs are incorporated into this DPA as follows: Module Two (controller to processor) applies where Customer is a Controller and Module Three (processor to processor) where Customer is a Processor; Clause 7 (docking clause) is included; the option in Clause 9(a) is Option 2 (general written authorisation) with the notice period in Section 11; the option in Clause 11(a) is not selected; Clauses 17 and 18 are completed as set out in Section 12; and Annexes I, II and III to this DPA serve as Annexes I, II and III to the EU SCCs.

### 5.4 Transfers from Switzerland

Where the Swiss Federal Act on Data Protection applies, the EU SCCs apply as modified to the extent necessary to satisfy it, with the Swiss Federal Data Protection and Information Commissioner as competent authority for Swiss Personal Data.

### 5.5 Alternative mechanism

If Deployed adopts an alternative lawful transfer mechanism recognised under Data Protection Laws, that mechanism applies in place of the above to the extent it covers the transfer, and Customer will reasonably cooperate in implementing it. If a transfer mechanism is amended or replaced by the competent authority, the replacement applies.

## 6. Technical and organisational measures

Deployed will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the risks presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. The measures are described in Annex II. Deployed may update them provided the overall level of security is not reduced.

## 7. Data Subject rights

Deployed will assist Customer in responding to requests from Data Subjects exercising their rights under Data Protection Laws. Deployed will, to the extent permitted by law, promptly notify Customer of any request it receives directly from a Data Subject without responding to it except to direct the Data Subject to Customer, and will, on Customer’s written request, provide the information reasonably available to it to help Customer respond within the statutory deadline. The Service’s Intent ID and append-only timeline are designed to make locating a Data Subject’s records straightforward.

## 8. Data protection impact assessments

Where Customer is required to carry out a data protection impact assessment, or to consult a Supervisory Authority beforehand, Deployed will on written request provide reasonable assistance in relation to Customer’s use of the Service, to the extent Customer does not otherwise have access to the relevant information.

## 9. Audit

Deployed will make available to Customer the information necessary to demonstrate compliance with this DPA. On written request, not more than once in any 12-month period unless required by a Supervisory Authority or following a Personal Data Breach, Customer may verify Deployed’s compliance by (i) submitting a reasonable security questionnaire and, (ii) if the responses do not reasonably satisfy Customer, conducting an audit by way of interviews with Deployed’s security and engineering leads and review of relevant documentation, on a mutually agreed date and with minimum disruption to Deployed’s operations. Customer may use a mutually agreed independent auditor bound by a non-disclosure agreement, and is responsible for its auditor’s actions and for its own costs. Information disclosed under this Section is Deployed’s Confidential Information, and Customer will not share an audit report with any third party except as required by law or a Supervisory Authority. Deployed will remedy material deficiencies identified by an audit within a mutually agreed timeframe.

## 10. Personal Data Breach notification

If Deployed becomes aware of a Personal Data Breach affecting Personal Data it Processes for Customer, Deployed will notify Customer without undue delay and in any event within 72 hours of becoming aware, providing the information reasonably available to it at that time and updating it as the investigation progresses: the nature of the breach, the categories and approximate numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Deployed will cooperate with Customer and take the reasonable steps agreed with Customer to investigate, mitigate and remediate the breach, and will provide the support Customer reasonably needs to meet its own notification obligations. Notification is not an acknowledgement of fault or liability.

## 11. Sub-processing

Customer gives Deployed general written authorisation to engage Sub-processors, including Deployed’s Affiliates, to provide the Service. Deployed will restrict each Sub-processor’s Processing to what is necessary for that purpose, will impose on it written data protection obligations no less protective than those in this DPA, and remains responsible for the Sub-processor’s performance of those obligations.

Deployed’s current Sub-processors are listed in Annex III. Deployed will give Customer at least 15 days’ notice, by email to the contact address for Customer under the Agreement or by updating Annex III and the changelog, before adding or replacing a Sub-processor. Customer may object in writing on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected part of the Service, and the Agreement to the extent it depends on it, without penalty, and Deployed will refund any prepaid fees for the terminated period.

## 12. Governing law and the EU SCCs

This DPA is governed by the law of England and Wales and is subject to the jurisdiction provisions of the Agreement, unless Data Protection Laws require otherwise. For the purposes of Clause 17 of the EU SCCs, where they apply, the parties select Option 1 and agree that the EU SCCs are governed by the law of Ireland; for Clause 18, disputes arising from the EU SCCs are resolved by the courts of Ireland. For Clause 13, the competent Supervisory Authority is the authority applicable to the data exporter. Where the IDTA or UK Addendum applies, the law of England and Wales governs and the courts of England and Wales have jurisdiction, as those instruments provide.

## 13. Return and deletion

On termination or expiry of the Agreement, and at Customer’s written election, Deployed will return Personal Data to Customer in a structured, machine-readable format (Intent Records, timelines and receipts as JSON conforming to the published schemas) or delete it, and will delete existing copies, within 30 days of the election or, absent an election, within 90 days of termination, except to the extent Data Protection Laws or other law require retention, in which case Deployed will isolate and protect the retained data. Copies in routine backups are deleted in the ordinary backup cycle.

## 14. Term and termination

This DPA takes effect when Customer accepts it and continues until the later of termination or expiry of the Agreement and the completion of the deletion or return under Section 13. It cannot be terminated separately from the Agreement except where Processing ends earlier, in which case it terminates automatically on completion of Section 13.

## 15. Entire agreement; conflict

Except as amended by this DPA, the Agreement remains in full force and effect. In the event of conflict between the Agreement and this DPA, this DPA controls with respect to the Processing of Personal Data. In the event of conflict between this DPA and the EU SCCs, IDTA or UK Addendum, that transfer instrument controls.

## Annex I: Description of the Processing

### A. List of parties

|                                     | Data exporter                                                     | Data importer                                                                                                         |
| ----------------------------------- | ----------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| Party                               | Customer, as identified in the Agreement                          | Deployed, London, United Kingdom                                                                                      |
| Role                                | Controller (or Processor, where Customer acts for its own client) | Processor (or Sub-processor)                                                                                          |
| Activities relevant to the transfer | Purchase of access to and use of the Service under the Agreement  | Processing of Personal Data to provide the Service under the Agreement                                                |
| Contact                             | The account owner identified in the Agreement                     | Jamie Gannaway, Chief Technology and Product Officer, [jamie.gannaway@deployed.co](mailto:jamie.gannaway@deployed.co) |

### B. Description of the transfer

* **Categories of Data Subjects**: End Users interacting with the Service at Customer: requesters, hiring managers, approvers, procurement and HR staff. Individuals named in a work request where Customer’s process requires it, such as a named contractor or supplier contact.
* **Categories of Personal Data**: Business contact details of End Users (name, work email, role, organisational unit). Work request content Customer chooses to route through the Service: role title, location, dates, rates and budget references, cost centre, supplier or worker identifiers, and free-text descriptions of the work. Identifiers issued by Destinations (external IDs, deep links). The Intent ID and the audit timeline (who did what, when). The Service does not require special category data; Customer should not route it through the Service.
* **Sensitive data**: None by design. Any special category data would be present only because Customer’s End Users entered it in free text; Deployed processes it only as part of the record and applies the measures in Annex II.
* **Frequency**: Continuous during the term of the Agreement, as End Users submit requests.
* **Nature of the Processing**: Receiving decisions from Triage; minting an Intent ID; validating against Destination requirements; publishing records into Destinations via their APIs; receiving Destination events by webhook or polling; reconciling drift; maintaining the append-only timeline; making records available to Customer through the API.
* **Purpose**: To provide the Service to Customer under the Agreement: publishing Customer’s workforce decisions into its systems of record under one Intent ID with a complete audit trail.
* **Retention**: For the term of the Agreement and until return or deletion under Section 13, or earlier deletion by Customer through the Service.
* **Transfers to Sub-processors**: Subject matter, nature and duration as above, limited to the function of each Sub-processor listed in Annex III, for the term of the Agreement.

### C. Competent Supervisory Authority

The Information Commissioner’s Office for UK Personal Data; for EU Personal Data, the Supervisory Authority applicable to the data exporter, as notified to Deployed under Section 12.

## Annex II: Technical and organisational measures

Deployed Processes Personal Data received from or for Customer under this DPA in conformity with the following measures.

<AccordionGroup>
  <Accordion title="Information security organisation" description="Ownership, risk assessment and incident review" icon="shield-check">
    * Deployed’s information security policy defines roles and responsibilities for the security, availability and confidentiality of the Service. Jamie Gannaway, Chief Technology and Product Officer, is accountable for the design, implementation and management of the security programme, which is reviewed at least annually.
    * A formal risk assessment is performed at least annually, identifying internal and external threats to security, availability and confidentiality; identified risks are recorded in a risk register with owners and mitigation strategies, and controls are adjusted accordingly.
    * Security incidents are tracked to resolution under the incident response plan, and a lessons-learned record is produced for high or critical incidents and shared with engineering.
  </Accordion>

  <Accordion title="Personnel security" description="Confidentiality, checks and training" icon="users">
    * Personnel are bound by written confidentiality obligations and acknowledge the code of conduct, acceptable use, data protection and information security policies on joining.
    * Background checks are performed on employees with access to production systems or Personal Data, as permitted by local law; reference checks are performed on contractors with such access.
    * Personnel receive information security and data protection training on joining.
  </Accordion>

  <Accordion title="Access control" description="Least privilege, authentication and scopes" icon="lock">
    * Access to systems holding Personal Data is granted on the principle of least privilege, based on role, and reviewed at least quarterly; access is removed within one business day of a person no longer requiring it.
    * Every person accessing production systems has a unique identity; multi-factor authentication is required for administrative access and for access to systems holding Personal Data.
    * API access to the Service is authenticated by per-tenant API keys compared in constant time and stored only as hashes, or by OAuth 2.0 client-credentials tokens that expire after one hour and carry only the scopes granted to the client; every route enforces its scope and refuses tokens that lack it.
    * Inbound webhooks from Destinations are accepted only with a valid HMAC-SHA256 signature over the raw request body, verified with a timing-safe comparison; unverifiable deliveries are rejected, not queued.
    * Destination credentials are held per tenant by the Service and injected by the adapter; they are never supplied by, or returned to, API callers.
    * Administrative actions on production systems are logged and the logs reviewed periodically.
  </Accordion>

  <Accordion title="Data protection by design" description="The never-sent boundary, idempotency and the append-only timeline" icon="layers">
    * A Destination receives only the fields it requires for a valid record plus the Intent ID. Diagnostic answers, scores and the Compliance File are never transmitted to a Destination; each platform page publishes what crosses the boundary and what is never sent, and automated tests assert the boundary.
    * Publishing is idempotent on a deterministic key, so retries cannot create duplicate records in a Destination.
    * The audit timeline is append-only: corrections are new events, never edits or deletions of earlier events.
    * Documentation and API contracts are generated from a single source and checked for drift on every change, so the published description of the Processing matches the running Service.
  </Accordion>

  <Accordion title="Encryption" description="In transit, at rest and on devices" icon="key-round">
    * All data in transit between End Users, the Service, Destinations and Sub-processors is encrypted using TLS 1.2 or higher.
    * Personal Data at rest, including backups, is encrypted using industry-standard algorithms; credentials and secrets are stored encrypted and API tokens are stored only as cryptographic hashes.
    * Portable devices used by personnel with access to Personal Data have full-disk encryption enabled.
  </Accordion>

  <Accordion title="Change management" description="Review, tests and environment separation" icon="git-branch">
    * Changes to the Service follow a documented process: version control, independent peer review before merge, automated tests that must pass before deployment, and segregation between production and development environments. Production Personal Data is not used in development or testing.
  </Accordion>

  <Accordion title="Availability, backup and incident response" description="Backups, monitoring and breach handling" icon="server">
    * Production data is backed up regularly; backups are encrypted and retained under the backup policy.
    * Monitoring and alerting cover availability and error conditions, and identified issues are tracked to resolution under the incident response plan, which is reviewed after every high or critical incident.
    * Personal Data Breaches are handled under Section 10 of this DPA.
  </Accordion>

  <Accordion title="Vendor and vulnerability management" description="Sub-processor assessment, scanning and docs watch" icon="search">
    * Sub-processors and other vendors are assessed for security and data protection before engagement and periodically thereafter.
    * Dependencies and production systems are scanned for vulnerabilities on a regular cadence; critical and high-risk findings are tracked to remediation under the vulnerability management process.
    * The cited vendor documentation that the Service’s Destination integrations rely on is re-checked monthly for change or removal.
  </Accordion>

  <Accordion title="Return and deletion" description="How Personal Data leaves the Service" icon="database">
    * Deletion and return of Personal Data follow Section 13. Access to delete Customer Personal Data is restricted to authorised engineering personnel and is logged.
  </Accordion>
</AccordionGroup>

## Annex III: Sub-processors

Customer has authorised the use of the following Sub-processors. Changes are notified under Section 11 and recorded in the [changelog](/changelog).

| Sub-processor  | Function                                                                                                                                    | Location of Processing                      |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| Vercel Inc.    | Hosting of the composer.id website and of the sandbox API function at `https://sandbox.composer.id/v1`; server logs                         | United States, with edge delivery worldwide |
| Upstash, Inc.  | The key-value store behind the hosted sandbox, provisioned through Vercel: tenant credential hashes, Intent Records, timelines and receipts | United States                               |
| Mintlify, Inc. | Hosting of the developer documentation, its search index and its documentation assistant                                                    | United States                               |

The hosted sandbox runs over mock Destination tenants and is for test data only, so Personal Data reaches these Sub-processors only to the extent Customer sends it there. Any further provider engaged for the production composerID API will be added to this Annex, with the notice Section 11 requires, before the production service goes live.

## Annex IV: UK Addendum to the EU Standard Contractual Clauses

This Annex IV is the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022), and applies to Restricted Transfers of UK Personal Data where the EU SCCs are also in place under Section 5.3.

### Part 1: Tables

#### Table 1: Parties

* **Start date**: The date Customer accepts this DPA
* **The parties**: Exporter (who sends the Restricted Transfer): Customer, as listed in Annex I. Importer (who receives the Restricted Transfer): Deployed, as listed in Annex I.
* **Parties’ details and key contacts**: As listed in Annex I, Part A
* **Signature**: Acceptance of this DPA in accordance with its opening provisions

#### Table 2: Selected SCCs, Modules and selected clauses

The Addendum EU SCCs are the version of the EU SCCs incorporated into this DPA by Section 5.3, including the Appendix Information, with the modules, options and clauses selected there: Module Two or Module Three as applicable; Clause 7 included; Clause 9(a) Option 2 with a 15-day notice period; Clause 11(a) option not selected; Clauses 17 and 18 as set out in Section 12.

#### Table 3: Appendix Information

“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in: Annex 1A (List of Parties): Annex I, Part A of this DPA. Annex 1B (Description of Transfer): Annex I, Part B of this DPA. Annex II (Technical and organisational measures): Annex II of this DPA. Annex III (List of Sub-processors): Annex III of this DPA.

#### Table 4: Ending this Addendum when the Approved Addendum changes

Which Parties may end this Addendum as set out in Section 19 of the Mandatory Clauses: neither Party.

### Part 2: Mandatory Clauses

The Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the Information Commissioner and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses, are incorporated by reference.
