Data Processing Agreement

Last updated July 2026

This Data Processing Agreement ("DPA") is entered into between Alpaka Ltd, a company incorporated in England and Wales under company number 10461680, registered office 6 The Leys, Northampton, NN2 6QZ ("Alpaka", "Processor"), and the Customer who has accepted Alpaka's Terms & Conditions ("Controller").

This DPA forms part of and is incorporated into Alpaka's Terms & Conditions. By accepting the Terms & Conditions, the Customer agrees to the terms of this DPA. This DPA governs the processing of personal data by Alpaka on behalf of the Customer in connection with the Alpaka workforce management platform and the Alpaka Presence app.

Article 28 UK GDPR. This agreement satisfies the requirement under Article 28 of the UK GDPR for a written contract governing the processing of personal data by a processor on behalf of a controller.

1. Definitions

"Controller" has the meaning given to it in the UK GDPR and refers to the Customer in this context.

"Processor" has the meaning given to it in the UK GDPR and refers to Alpaka in this context.

"Data Subject" means an identified or identifiable natural person whose personal data is processed under this DPA, including the Customer's employees and other Users of the Software.

"Personal Data", "Processing" and "UK GDPR" have the meanings given to them in the UK GDPR and the Data Protection Act 2018.

"Services" means the Alpaka workforce management platform and the Alpaka Presence app.

"Sub-processor" means any third party engaged by Alpaka to process Personal Data in connection with the Services.

2. Roles and Scope

2.1 In connection with the Services, the Customer submits Personal Data relating to its employees and other Users to Alpaka for processing. In respect of that data, the Customer is the data controller and Alpaka is the data processor.

2.2 Alpaka processes Personal Data only on the documented instructions of the Customer, as set out in this DPA and the Terms & Conditions, and only to the extent necessary to provide the Services.

2.3 The Customer's configuration of which clock-in methods are enabled for its Users - including whether Alpaka Presence is configured for facial recognition only, facial recognition alongside keypad PIN or ID badge, or non-biometric methods only - constitutes a documented instruction for the purposes of this DPA. Alpaka processes Biometric Data strictly in accordance with that configuration and takes no independent decision as to which clock-in method any User is required or permitted to use. The Customer is solely responsible for determining its lawful basis for the configuration it selects, for any consequent restriction of biometric processing to specific Users, and for informing its Users accordingly.

2.4 Alpaka will inform the Customer promptly if, in its opinion, an instruction given by the Customer infringes the UK GDPR or other applicable data protection law.

3. Nature and Purpose of Processing

Subject matter: Operation of the Alpaka workforce management platform, including scheduling, absence, timesheet, HR records and attendance tracking, and facial recognition clocking via Alpaka Presence.

Duration: For the term of the Customer's Contract, plus the 30-day post-termination retention period set out in clause 7.6 of our Terms & Conditions. Biometric Data is retained on a shorter cycle - see below.

Nature: Collection, storage, retrieval, comparison (face matching, where enabled), transmission and deletion of HR, scheduling, attendance and biometric data.

Purpose: To enable the Customer to manage its workforce, including recording attendance via facial recognition, keypad PIN, ID badge, or mobile clock-in.

Types of Personal Data: Names, work email addresses, postal addresses, telephone numbers, employment and HR records, qualifications, absence and time off in lieu records, scheduling and timesheet data, and - where Alpaka Presence is used for clocking - a reference photo used for facial matching and, where enabled, location data.

Categories of Data Subjects: Employees and other Users of the Customer whose attendance, HR or scheduling data is processed through the Services.

Special category data: Reference photos processed for clock-in/clock-out facial matching purposes ("Biometric Data"). Alpaka does not generate or store facial geometry, templates or embeddings - face matching is performed by a third-party facial matching service which returns only a match or no-match result and does not retain the photo. Reference photos are retained by Alpaka for up to 3 months and then automatically discarded, or sooner if the Customer removes the individual as a User or requests deletion. Further detail is in our Privacy Policy and Security & Data Protection page.

4. Obligations of Alpaka as Processor

Alpaka shall:

4.1 process Personal Data only on documented instructions from the Customer, except where required to do so by applicable law;

4.2 ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations;

4.3 implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access;

4.4 not engage any Sub-processor without prior general authorisation from the Customer (given under clause 6 below), and ensure Sub-processors are bound by equivalent obligations under a written contract;

4.5 assist the Customer in responding to requests from Data Subjects exercising their rights under the UK GDPR, insofar as this is possible given the nature of the processing;

4.6 assist the Customer in ensuring compliance with its obligations in respect of security, breach notification, and data protection impact assessments;

4.7 at the Customer's election, delete or return all Personal Data on termination of the Services, and delete existing copies unless otherwise required by law, in accordance with clause 7.6 of our Terms & Conditions;

4.8 make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and allow for and contribute to reasonable audits.

5. Security Measures

5.1 Alpaka maintains technical and organisational measures appropriate to the risk, including:

5.1.1 encryption of Personal Data at rest and in transit using industry-standard protocols;

5.1.2 access controls limiting access to Personal Data to authorised personnel only, logged and reviewed;

5.1.3 a configurable permission structure allowing the Customer to control which of its own staff can access HR records, timesheets or Biometric Data;

5.1.4 routine backups and incident response procedures.

5.2 Customer Data is hosted on AWS infrastructure in Dublin, Ireland (eu-west-1), within the UK/EEA. Personal Data is not transferred outside the UK or EEA for storage purposes without appropriate safeguards. Further detail is on our Security & Data Protection page.

6. Sub-processors

6.1 The Customer grants Alpaka general authorisation to engage the following sub-processors in connection with the Services:

  • Amazon Web Services (AWS) - eu-west-1, Dublin, Ireland - infrastructure, hosting, storage, compute.
  • Facial matching provider - UK/EEA - facial comparison for Alpaka Presence clock-in (match/no-match result only - no image data retained by the provider).

We do not use a third-party payment processor. Customers are invoiced directly by Alpaka and pay by bank transfer (BACS) - no card or payment data is collected or processed by Alpaka or any sub-processor.

6.2 Alpaka will notify the Customer of any intended changes to sub-processors, whether by updating this DPA or by notice via the Software or email. The Customer may object to a new sub-processor on reasonable grounds within 14 days of notice.

7. Data Subject Rights

7.1 Alpaka will, to the extent possible and within a reasonable timeframe, assist the Customer in fulfilling its obligations to respond to requests from Data Subjects exercising rights under the UK GDPR, including rights of access, rectification, erasure, restriction, portability and objection.

7.2 Where a Data Subject contacts Alpaka directly, Alpaka will direct the request to the Customer without undue delay.

7.3 The Customer is responsible for ensuring its employees and other Users are provided with appropriate privacy notices explaining how their data, including Biometric Data, will be processed through the Services.

8. Personal Data Breaches

8.1 Alpaka will notify the Customer without undue delay, and in any event within 72 hours where feasible, after becoming aware of a personal data breach affecting Personal Data processed under this DPA.

8.2 Notification will include, to the extent then known: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach.

8.3 The Customer remains responsible for notifying the ICO and affected Data Subjects where required.

9. Transfers Outside the UK and EEA

Personal Data processed under this DPA is stored and processed within the UK/EEA (AWS eu-west-1, Dublin). Where any sub-processor processes data outside the UK or EEA, Alpaka ensures appropriate transfer mechanisms are in place, including reliance on adequacy decisions or standard contractual clauses as applicable.

10. Term and Termination

10.1 This DPA remains in force for the duration of the Customer's Contract with Alpaka.

10.2 On termination, Alpaka will, at the Customer's election, delete or return all Personal Data within 30 days, except where retention is required by applicable law, in accordance with clause 7.6 of our Terms & Conditions.

11. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising in connection with this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.

12. Contact

For any questions about this DPA or data protection matters, contact Alpaka at support@alpaka.io.