Data Processing Agreement (Art. 28 GDPR)
v2026-09-21
This agreement governs the personal data Klyra processes on behalf of the customer using the platform. The customer is the controller; Klyra acts as processor.
Template provided to support compliance. The customer remains the controller and should have it reviewed by its own adviser.
1. Subject matter and duration
Klyra processes personal data solely to provide the platform services: staff management, scheduling and attendance, HACCP records, inventory, production, costs and internal communications.
Processing lasts for the term of the service contract. On termination data is returned or deleted per the customer instructions, subject to statutory retention duties.
2. Data subjects and data categories
Data subjects: the customer employees and collaborators, supplier contacts, administrator users.
Data: identity and contact details, contractual and payroll data entered by the customer, attendance and shifts, signatures and photos uploaded to records, technical usage data.
3. Documented instructions
Klyra processes data only on the documented instructions of the customer, including settings configured in the platform, and never for its own purposes nor for third-party commercial use.
4. Confidentiality and authorised staff
Access is restricted to authorised Klyra staff bound by confidentiality and trained on data protection. Administrative access is logged.
5. Security measures
Encryption in transit and at rest, tenant isolation per organisation and site enforced at database level, role and permission based access control, activity logging, provider-managed backups, throttling of authentication attempts.
Sensitive staff data is reachable only through dedicated procedures available to the data subject, company administrators and staff managers at the same site.
6. Sub-processors
Klyra relies on infrastructure providers for hosting, database, email and notification delivery, all bound by Art. 28 compliant terms and processing within the EU or under adequate safeguards.
The customer is informed of sub-processor changes with reasonable notice and may object on reasonable grounds.
7. Assistance to the controller
Klyra assists the customer with data subject requests (access, rectification, erasure, portability), impact assessments and breach handling.
The platform provides self-service export of personal data and a deletion procedure that irreversibly anonymises identifying data while preserving mandatory records.
8. Personal data breaches
Klyra notifies the customer of any personal data breach without undue delay after becoming aware of it, providing the information needed to notify the supervisory authority.
9. Audits
On reasoned request and with reasonable notice, Klyra provides the information needed to demonstrate compliance and allows audits, including by an appointed auditor, without compromising other customers security.