Data Processing Agreement

Version dpa-2026-06-06 · Last updated: 6 June 2026

This Data Processing Agreement ("Agreement") forms part of the agreement between Maxword Ltd, trading as Compliance Track UK ("Processor", "we", "us") and the customer that accepts it ("Customer", "Controller", "you") for the use of the Compliance Track service ("Service"). It governs how we process personal data on your behalf.

By accepting our terms or using the Service to record data about workers, you accept this Agreement.

1. Background and roles

1.1 You use the Service to keep records relating to right to work and visa sponsorship compliance for your workers.

1.2 In doing so, you enter personal data about your workers and others into the Service. For that data, you are the controller and we are the processor. You decide the purposes for which that data is processed. We process it only on your behalf and on your instructions.

1.3 This Agreement applies to our processing of that personal data. It does not apply to data for which we are ourselves the controller, such as your account and billing details, which is covered by our Privacy Policy.

2. Definitions

2.1 "Data Protection Law" means the UK General Data Protection Regulation, the Data Protection Act 2018, and any other data protection law applicable in the United Kingdom, in each case as amended or replaced.

2.2 The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Data Protection Law.

2.3 "Customer Personal Data" means the personal data we process on your behalf through the Service, as described in Annex 1.

2.4 "Sub-processor" means any third party we engage to process Customer Personal Data.

3. Our obligations as processor

We will:
  • 3.1 Process only on your instructions. Process Customer Personal Data only on your documented instructions, including with regard to transfers, unless required to do otherwise by law, in which case we will inform you first unless the law prevents us. Your instructions are the provision of the Service in accordance with our terms and your use of it. We will tell you if, in our opinion, an instruction infringes Data Protection Law.
  • 3.2 Keep it confidential. Ensure that the people authorised to process Customer Personal Data are bound by confidentiality.
  • 3.3 Keep it secure. Implement appropriate technical and organisational measures to protect Customer Personal Data, as set out in Annex 2, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risks involved.
  • 3.4 Use sub-processors responsibly. You give us general authorisation to engage the sub-processors listed in Annex 3 and at /sub-processors. We will impose data protection obligations on each sub-processor that are no less protective than those in this Agreement, and we remain responsible to you for their performance. We will inform you of any intended change to our sub-processors and give you a reasonable opportunity to object on reasonable data protection grounds.
  • 3.5 Help you respond to data subjects. Taking account of the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights. The Service provides tools to export and to delete worker records, which you can use for this purpose.
  • 3.6 Help you meet your obligations. Assist you, taking account of the nature of processing and the information available to us, in meeting your obligations relating to the security of processing, the notification of personal data breaches, data protection impact assessments and prior consultation with the supervisory authority.
  • 3.7 Notify you of breaches. Notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to us to help you meet any obligation to report the breach to the supervisory authority or affected data subjects.
  • 3.8 Return or delete data. At the end of the provision of the Service, at your choice, delete or return all Customer Personal Data and delete existing copies, unless we are required by law to keep it.
  • 3.9 Demonstrate compliance. Make available to you the information reasonably necessary to demonstrate compliance with this Article, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and not more than once a year unless a breach or regulator requires otherwise.

4. Your obligations as controller

You will:
  • 4.1 Ensure you have a lawful basis to process the Customer Personal Data and to have us process it on your behalf, including for any sensitive data such as immigration and identity information.
  • 4.2 Provide any privacy information required to your workers and others whose data you enter.
  • 4.3 Ensure your instructions to us comply with Data Protection Law, and that the data you enter is accurate and that you are entitled to enter it.

5. International transfers

5.1 We will not transfer Customer Personal Data outside the United Kingdom except as described in Annex 3 or with your authorisation, and where we do, we will ensure an appropriate safeguard recognised under Data Protection Law is in place.

6. Liability

6.1 The liability position between the parties is set out in the main Terms of Service and applies to this Agreement.

7. Term and termination

7.1 This Agreement takes effect when you accept it or first use the Service to process Customer Personal Data, and continues for as long as we process Customer Personal Data on your behalf. The provisions that are intended to survive termination, including those on return and deletion of data, will do so.

Annex 1: Details of the processing

Subject matter of the processing. The provision of the Compliance Track service, which records and tracks right to work and visa sponsorship compliance information.

Duration. For as long as the Customer uses the Service, plus any period required for return or deletion of data.

Nature and purpose. Storing, organising, displaying, flagging and producing records relating to the Customer's compliance duties as an employer, and sending related reminders and notifications.

Types of personal data. Worker name, date of birth, contact details, job title and role, salary and pay details, identity documents such as a passport, immigration and visa status, right to work share codes and check results, Certificate of Sponsorship details, attendance and absence, reportable events, and uploaded documents and evidence.

Categories of data subjects. The Customer's workers, including sponsored workers and other employees or staff whose records the Customer chooses to hold, and the Customer's own personnel who use the Service.

Annex 2: Technical and organisational security measures

We apply measures including:
  • Logical separation of each customer's data, enforced at the database level, so one customer's data cannot be accessed from another customer's account.
  • Encryption of personal data in transit and at rest.
  • Access controls, with administrator access restricted and recorded in an access log.
  • Authentication controls on user accounts.
  • Regular backups and the ability to restore data.
  • Deletion of data on the Customer's instruction or at the end of the Service.

Annex 3: Sub-processors

The current list of sub-processors is maintained at /sub-processors. At the date of this version, the sub-processors are Lovable (application platform and backend), Supabase (database, authentication and storage infrastructure), Stripe (payment processing) and Resend (sending service emails).

Contact

Maxword Ltd, trading as Compliance Track UK
118 Downland, Two Mile Ash, MK8 8HW
admin@compliancetrackuk.com