GDPR-compliant by design
DPA, TOMs and a DPIA template your DPO can sign off.
teamly is built for the UK and EU regulatory stack: ICO-aligned monitoring controls, EU hosting, full DPA, DUAA 2025-ready and a pre-filled DPIA template. Designed so your DPO has less to do, not more.
Processing employee data needs an Article 6 lawful basis (usually performance of contract or legitimate interest), and any special category data needs an Article 9 condition. Document this in writing.
Every SaaS employee app processing personal data needs a Data Processing Agreement. teamly provides a ready-to-sign standard DPA, with TOM appendix and a public sub-processor list, no SCCs needed for EU/UK clients.
Encryption in transit and at rest, role-based access controls, backups, incident response, awareness training. teamly's data centres are ISO 27001 certified, with the certification used as evidence of TOMs to your DPO.
The ICO and the Irish DPC both expect transparency, proportionality and a clear lawful basis when monitoring staff. teamly is built around these principles.
A Data Processing Agreement (DPA) is only valid if it covers every mandatory element under Article 28(3) GDPR. These are the points it must include.
With teamly, the list of sub-processors is fully transparent: during onboarding you receive a table of every sub-processor, their role and their location. Changes to this list are announced in advance, not after the fact.
Hosting in the EU means EU GDPR applies directly, with no US CLOUD Act exposure, and UK-to-EU transfers benefit from the adequacy decision. For sensitive employee data, that is the cleanest path.
A deletion concept sets out, for every data category, how long it is kept and when it is deleted. Without one, data tends to be kept indefinitely, which breaches the storage limitation principle (Article 5(1)(e) GDPR).
| Data category | Retention period | Legal basis |
|---|---|---|
| Ongoing employment relationship | As long as necessary | Employment contract |
| Payroll and salary records | 3 to 6 years after employment ends | HMRC PAYE rules, Companies Act 2006 |
| Rejected candidate data | Typically 6 months | Equality Act 2010 claims window (best practice) |
| App messaging and usage data | Short, defined periods | teamly's deletion concept |
| Working time records | 2 years | Working Time Regulations 1998 (reg. 9) |
teamly enforces these periods technically through automated deletion routines, rather than relying on manual housekeeping. Every automated deletion is logged with a timestamp, so evidence is always ready for your DPO.
teamly enforces retention periods technically and logs every automated deletion. Evidence for your DPO is always current.
Everyone whose data is processed has six core rights against their employer. teamly supports fulfilling these rights with structured, documented processes.
Employees can ask at any time what data is held about them. teamly supports this with a structured data export instead of manual research.
Inaccurate or outdated data must be corrected. Employees can maintain some of their own core details in their profile.
The right to be forgotten: once a retention period expires, or on request, data is deleted and logged in the deletion log.
Instead of deletion, a record can be flagged and restricted in disputed cases. The data is kept but blocked from further processing.
Employees can request their data in a structured, machine-readable format, for example when changing employer.
Certain processing can be objected to. teamly logs the handling of every objection so it stays traceable.
Eight classic TOM categories, each with an example measure at teamly. ISO 27001 certification of our data centres serves as external evidence to your DPO.
Physical access to the data centres is restricted through biometric checks and CCTV monitoring.
Multi-factor authentication and strict password policies prevent unauthorised system use.
A role-permission model ensures each person only sees the data they need for their role.
All data is TLS-encrypted throughout transmission, including between the app and the server.
Timestamped audit logs record who entered or changed which data, and when.
Sub-processors' contractual duty to act only on instruction is set out in the DPA and made transparent in the sub-processor table.
Redundant backups and a disaster-recovery plan protect against data loss from outages.
Data belonging to different client organisations is processed and stored in logical separation.
30 minutes, specific to your organisation: we'll walk through the DPA, TOM appendix and consultation-agreement template live in the demo, no sales pressure.
These four risks are routinely underestimated, until it's too late.
UK GDPR breaches carry fines of up to £17.5 million or 4% of global annual turnover, whichever is higher (the EU GDPR equivalent is €20 million). An unprepared app provider gets expensive fast.
Employees can claim compensation for data protection breaches under Article 82 GDPR. Every breach risks becoming a precedent inside your own organisation.
A publicised data incident involving employee data damages staff trust and feeds straight through into recruitment and employer branding.
Without a proper information-and-consultation process under the ICE Regulations 2004, staff representatives can challenge the rollout and delay or block adoption.
Concrete, ready to sign, and no extra work for your IT team.
teamly provides a complete Data Processing Agreement under Article 28 GDPR during onboarding, including a TOM appendix and sub-processor table.
All data sits exclusively in German (EU) data centres, with no sub-processors outside the EU.
Defined retention periods are enforced technically, and every deletion is documented in the deletion log.
A ready-made template for staff consultation under the ICE Regulations 2004, agreed with staff representatives before rollout.
What HR leadership, IT directors and DPOs ask most often.
30 minutes, your industry, your real questions. Alexander, Maximilian or Michael listen first. If it fits, the demo with all your decision-makers comes next.