GDPR
Data Protection and GDPR
Employee Zero is committed to protecting personal data and to complying with the UK GDPR, the EU GDPR and the Data Protection Act 2018. When we deliver managed services, we usually process personal data on our clients’ instructions as a data processor. This page summarises how we do that. Our full Data Processing Addendum (DPA) is available to clients and forms part of their contract.
Controller and processor roles
For our own activities — our website, marketing, enquiries and recruitment — we are the data controller, and our Privacy Policy explains what we do. When we process personal data to deliver services to a client, that client is the controller and we are the processor.
Our processor commitments
As a processor, and in line with Article 28 of the UK GDPR, we:
- process personal data only on the client’s documented instructions
- ensure the people who process the data are bound by confidentiality
- apply appropriate technical and organisational security measures (Article 32)
- engage sub-processors only under the client’s general written authorisation, giving advance notice of changes and a right to object
- assist the client with data-subject requests
- notify the client without undue delay if we become aware of a personal data breach
- delete or return personal data at the end of the contract
- make available the information needed to demonstrate compliance, and allow for audits
Sub-processors
We maintain a single, published Sub-processor List covering the providers we may engage, and we give advance notice of new or replacement sub-processors so clients can object. Where a client enables the optional Slack or Microsoft Teams support integration, messages create a Zendesk ticket and we do not retain the message data beyond that ticket.
International transfers
Where personal data is transferred outside the UK — for example to the United States or Singapore — we use appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Requesting our DPA
Clients can request our executable Data Processing Addendum and our schedule of technical and organisational measures. Please contact privacy@empzer.com.
Sub-processor List
This page lists the third parties (sub-processors) that Employee Zero may engage to process personal data when delivering services to our clients. We engage sub-processors under our clients’ general written authorisation, as set out in our GDPR / Data Processing Addendum, and we give advance notice of any new or replacement sub-processor so clients can object.
Whether a particular sub-processor is involved depends on the services a client takes; not every client’s data is processed by every provider listed. Some providers below are tools we use to operate, rather than sub-processors of client personal data — we confirm the precise role for each engagement.
Sub-processor Service / purpose Processing location(s)
- Microsoft Microsoft 365 and Azure — productivity, email and cloud hosting UK / EU / US/ SG (tenant dependent)
- Google Google Workspace and Google Cloud — productivity, email and hosting UK / EU / US/ SG
- Amazon Web Services (AWS) Cloud infrastructure and hosting UK / EU / US/ SG (region dependent)
- Apple Apple Business Manager — device enrolment and management EU / US
- Jamf Apple device management (MDM) EU / US
- JumpCloud Identity, directory and device management US (EU where available)
- Okta Identity and access management EU / US
- Rippling Identity, device and workforce management US
- Zendesk Support ticketing and Client Portal EU / US
- NinjaOne Remote monitoring and management (RMM) EU / US (region selectable)
- Cloudflare DNS, content delivery and web security Global edge network
- CrowdStrike Endpoint detection and response EU / US
- Bitdefender Endpoint protection EU / US
- Huntress Managed detection and response US
- Acronis Backup and disaster recovery EU / US (data-centre selectable)
- Wasabi Cloud storage UK/ EU / US/ SG (data centre selectable)
- Xero Accounts and invoicing NZ
- HubSpot CRM UK
- Salesbuildr Quoting EU
- Pax8 SaaS vendor UK/ EU/ US/ SG (tenant dependent)
- TD Synnex Hardware vendor UK/ US/ EU/ SG (customer location dependent)
- Cisco Hardware and software provider UK/ US/ EU/ SG (customer location dependent)
- Dell Hardware vendor UK/ US/ EU/ SG (customer location dependent)
- Hewlett Packard Hardware vendor UK/ US/ EU/ SG (customer location dependent)
- Exclusive Networks Hardware vendor UK
- Adobe SaaS vendor UK/ EU/ US/ SG (tenant dependent)
- Fortinet Hardware vendor UK/ US/ EU/ SG (customer location dependent)
- Ninja SaaS vendor UK/ EU/ US/ SG (tenant dependent)
- Clickup Project management tool US
- SentinelOne Endpoint protection US/ EU
Where a sub-processor processes personal data outside the UK, we rely on appropriate safeguards — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
Changes to this list
We may update this list as our services change. We give clients advance notice of new or replacement sub-processors through [your notification method — for example email to the account contact, or a subscribe option on this page] so they can raise any objection before the change takes effect.
Processors for our own website and marketing
For personal data we handle as a controller — for example website visitors, enquiries and marketing — we use providers such as Cloudflare (hosting and content delivery), HubSpot (contact forms, CRM and marketing analytics) and Zendesk (Client Portal). See our Privacy Policy for details.