AdminHQ

AdminHQ Data Processing Agreement

Last updated: 21 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Customer”) and Melissa Burrows trading as AdminHQ (“AdminHQ”) for use of the AdminHQ software service (“Service”).

For the purposes of UK data protection law, where AdminHQ processes personal data on behalf of the Customer through the Service, the Customer is the Controller and AdminHQ is the Processor.

1. Scope and purpose

AdminHQ provides a subscription-based business administration platform enabling customers to manage employee and business administration including employee records, compliance requirements and renewal dates, tasks, annual and other leave, reminders and related administrative records.

AdminHQ will process Customer Personal Data only as necessary to provide, secure, maintain and support the Service and in accordance with the Customer’s documented instructions.

The Customer’s use and configuration of the Service constitutes documented instructions to AdminHQ.

AdminHQ will notify the Customer if, in its reasonable opinion, an instruction infringes applicable data protection law, unless prohibited from doing so by law.

2. Details of processing

Subject matter:

Provision of the AdminHQ business administration software service.

Duration:

For the duration of the Customer’s use of AdminHQ plus the applicable retention period described in this DPA.

Nature and purpose:

Storage, organisation, retrieval, transmission and other processing necessary to provide AdminHQ’s employee administration, compliance tracking, task management, leave management, reminder and associated functionality.

Categories of data subjects may include:

  • employees;
  • workers and contractors;
  • Customer administrators and managers; and
  • other authorised users added by the Customer.

Personal data may include:

  • names;
  • work email addresses;
  • job titles;
  • departments;
  • employment/active status;
  • compliance requirement information;
  • issue, renewal and expiry dates;
  • training or qualification information;
  • tasks, due dates and completion information;
  • annual and other leave information;
  • account and authentication information;
  • activity/audit information; and
  • other information entered by authorised users within permitted fields.

AdminHQ is not designed for the storage of medical information, DBS results, criminal-offence information or other special-category personal data in free-text fields, and the Service instructs users not to enter such information.

AdminHQ does not currently provide functionality for uploading employee documents or certificates.

3. Customer responsibilities

The Customer is responsible for:

  • determining the purposes and lawful basis for its processing of Customer Personal Data;
  • ensuring its instructions to AdminHQ comply with applicable law;
  • providing appropriate privacy information to its employees and other data subjects;
  • ensuring that Customer Personal Data entered into AdminHQ is appropriate, accurate and limited to what is necessary;
  • ensuring authorised users use the Service appropriately;
  • managing user permissions and access;
  • not intentionally entering medical information, DBS results, criminal-offence information or other special-category personal data into fields not designed for that purpose; and
  • responding to data-subject requests as Controller.

4. AdminHQ obligations

AdminHQ shall:

  • process Customer Personal Data only on documented instructions from the Customer unless required otherwise by applicable UK law;
  • ensure persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations;
  • implement appropriate technical and organisational security measures;
  • assist the Customer, taking into account the nature of the processing, with responding to individuals exercising their data-protection rights;
  • provide reasonable assistance regarding security obligations, personal-data breaches and data-protection impact assessments;
  • maintain appropriate records relating to processing where required by law; and
  • make information reasonably necessary to demonstrate compliance with this DPA available to the Customer.

These provisions reflect the minimum processor-contract requirements set out by the ICO.

5. Security

AdminHQ will maintain appropriate technical and organisational measures proportionate to the nature and risks of the processing.

Current measures include, where applicable:

  • authenticated user access;
  • company-level separation of customer information;
  • role-based access controls;
  • database security and access policies;
  • expiring and rotating public access tokens;
  • restricted access to production information;
  • activity/audit logging;
  • defined retention and deletion controls;
  • secure infrastructure providers; and
  • measures designed to protect against unauthorised access, alteration, disclosure, loss or destruction.

AdminHQ will periodically review these measures and may update them as technology and risks change.

6. Confidentiality

AdminHQ will ensure that any person authorised to process Customer Personal Data is subject to an appropriate obligation of confidentiality and only accesses such information where necessary for their role.

7. Sub-processors

The Customer provides AdminHQ with general written authorisation to engage sub-processors necessary to provide the Service.

AdminHQ will maintain a current Sub-processor List identifying relevant sub-processors.

AdminHQ will ensure that sub-processors processing Customer Personal Data are subject to contractual data-protection obligations providing an appropriate level of protection.

Where AdminHQ intends to make a material change involving a new sub-processor that processes Customer Personal Data, AdminHQ will provide reasonable notice where required, allowing the Customer an opportunity to raise legitimate data-protection concerns.

AdminHQ remains responsible for its obligations concerning processing carried out on its behalf by its sub-processors as required by applicable law.

The ICO specifically requires prior specific or general written authorisation for sub-processors and equivalent data-protection obligations to be imposed downstream.

8. International transfers

AdminHQ’s primary production database is hosted in France within the European Economic Area (EEA).

Certain sub-processors or their infrastructure may process Customer Personal Data outside the United Kingdom.

Where AdminHQ makes a restricted transfer of Customer Personal Data, AdminHQ will ensure that an appropriate transfer mechanism is used where required by UK data-protection law.

This may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another lawful transfer mechanism recognised under UK law.

AdminHQ will take reasonable steps to ensure appropriate safeguards apply to such transfers. The ICO confirms that processors initiating restricted transfers must follow the Controller’s documented instructions and ensure appropriate safeguards and security measures are in place.

9. Data-subject rights

Taking into account the nature of the processing, AdminHQ will provide reasonable assistance to enable the Customer to respond to requests from individuals exercising rights under applicable data-protection law.

Where AdminHQ receives a request directly from an individual concerning Customer Personal Data for which the Customer is Controller, AdminHQ will normally direct the individual to the relevant Customer and/or notify the Customer where appropriate.

AdminHQ will not independently respond to such a request on the Customer’s behalf unless authorised or legally required to do so.

10. Personal-data breaches

If AdminHQ becomes aware of a personal-data breach affecting Customer Personal Data, AdminHQ will notify the affected Customer without undue delay.

Where reasonably available, AdminHQ will provide information to assist the Customer in assessing the incident and complying with applicable notification obligations.

AdminHQ will take reasonable steps to contain, investigate and remediate incidents within its control.

11. DPIAs and regulatory assistance

Taking into account the nature of the processing and information available to AdminHQ, AdminHQ will provide reasonable assistance where the Customer is required to:

  • assess the security of processing;
  • investigate a personal-data breach;
  • conduct a Data Protection Impact Assessment; or
  • consult the Information Commissioner's Office or another competent regulator.

This assistance requirement is one of the Article 28 provisions identified by the ICO.

12. Retention and deletion

When a Customer’s AdminHQ subscription ends, Customer Personal Data will ordinarily enter a 90-day retention period.

During this period:

  • Customer data remains scheduled for deletion;
  • the Customer may reactivate the Service to retain its data; and
  • AdminHQ will provide notifications before scheduled deletion.

At the end of the 90-day period, AdminHQ will permanently delete Customer Personal Data from the active Service in accordance with its deletion process.

Customers may request/perform permanent account deletion sooner through the available account-deletion functionality. Immediate deletion bypasses the 90-day recovery period and cannot be reversed through AdminHQ.

Deletion may include employee records, compliance information, tasks, leave records, reminders, memberships, audit records, Customer profiles and associated accounts as applicable.

This does not require deletion of information independently retained by third parties acting in another capacity where they have their own legal obligations. For example, Paddle may retain payment, invoice and taxation records according to its applicable legal requirements.

Where UK law requires AdminHQ to retain particular information, AdminHQ may retain that information for the legally required period.

The ICO requires processor contracts to provide for deletion or return of personal data at the end of the services, subject to legal retention requirements.

13. Audit and compliance information

AdminHQ will make information reasonably necessary to demonstrate compliance with its obligations under this DPA available to the Customer.

Where reasonably necessary and legally required, AdminHQ will permit and contribute to appropriate audits or inspections concerning processing carried out on behalf of the Customer.

Audits must, where possible:

  • be requested with reasonable notice;
  • avoid unnecessary disruption to AdminHQ or other customers;
  • respect confidentiality and security obligations; and
  • be proportionate to the nature and risk of the processing.

Where appropriate, AdminHQ may first satisfy reasonable audit requests through existing documentation, policies, security information or independent evidence.

14. Changes to sub-processors or processing

AdminHQ may update its infrastructure and sub-processors as the Service develops.

Where a change materially affects the processing of Customer Personal Data, AdminHQ will update its relevant documentation and provide notice where required by applicable data-protection law or this DPA.

15. Order of precedence

If there is a conflict between this DPA and AdminHQ’s general Terms of Service regarding the processing of Customer Personal Data, this DPA will take precedence to the extent of that conflict.

16. Governing law

This DPA is governed by the laws of England and Wales, unless applicable law requires otherwise.

17. Contact

Questions relating to this DPA or AdminHQ’s processing of Customer Personal Data can be sent to:

privacy@adminhq.app

Processor:

Melissa Burrows trading as AdminHQ

United Kingdom