Legal

Data Processing Agreement

How we process personal data on behalf of our customers, as their processor.

Last updated: 25 June 2026

This overview summarises the Data Processing Agreement (DPA) that forms part of the contract between Aqlaan and each HRMSTONE customer. The executed DPA is the binding document; this page is a plain-language summary.

1. Roles

The customer is the controller of the personal data in its workspace. Aqlaan acts solely as the processor, processing that data on the customer's documented instructions and for no other purpose.

2. Scope of processing

We process employee and HR data only to provide the contracted service — payroll, time & attendance and HR — for the duration of the agreement.

3. Security measures

We apply technical and organisational measures including per-tenant isolation, encryption (with customer-managed keys on sovereign and on-prem deployments), least-privilege access, and an immutable audit trail.

Support access is just-in-time and consented; on-premise it is escorted and customer-recorded with zero standing access.

4. Sub-processors

We maintain a list of sub-processors and provide notice of changes as set out in the DPA. On on-premise deployments, no vendor sub-processing of customer data occurs.

5. Data subject rights & assistance

We assist the controller in responding to data subject requests and in meeting security, breach-notification and impact-assessment obligations, as described in the DPA.

6. Return and deletion

On termination, we return or delete customer personal data in line with the agreement. On deployments where you hold the keys, revoking them renders the data inaccessible immediately.