Data Processing Addendum
Last updated: 6 October 2026
This Data Processing Addendum ("DPA") forms part of the Staff Checklist Terms of Service between IT Nest Limited ("IT Nest") and the business that uses Staff Checklist ("Customer"). It applies whenever IT Nest processes personal data in Customer Data on the Customer's behalf.
1. Definitions
- Data Protection Law: the UK GDPR and the Data Protection Act 2018; the EU GDPR (Regulation (EU) 2016/679) and national laws that supplement it; the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486); and any other data protection law that applies to the processing.
- "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR or the EU GDPR.
- Customer Personal Data: personal data in Customer Data, as defined in the Terms.
- Sub-processor: a third party engaged by IT Nest to process Customer Personal Data.
- SCCs: the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force from 21 March 2022), as amended from time to time.
2. Roles and instructions
2.1 The Customer is the controller (or, where it acts for another controller, a processor). IT Nest is the Customer's processor (or sub-processor).
2.2 IT Nest processes Customer Personal Data only on the Customer's documented instructions. These are: the Terms; this DPA; the settings and actions of the Customer's Users in the Service; and other reasonable written instructions agreed with IT Nest. They include the instructions that Users may download their own records; that members of a closed business may download records for 30 days after closure; and that records a User created stay in the Customer's account when that User deletes their own account.
2.3 IT Nest will tell the Customer if it believes an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or changed.
2.4 If law requires IT Nest to process Customer Personal Data in another way, IT Nest will tell the Customer before doing so, unless the law prohibits this.
2.5 The Customer is responsible for the lawfulness of its instructions and of the data it puts into the Service. This includes giving its staff the information required by law (a template is available at staffchecklist.com/legal/staff-notice) and following local rules on monitoring at work.
2.6 IT Nest uses Customer Personal Data only to provide, secure and support the Service, and may create aggregated, anonymised statistics from it that identify no one. IT Nest does not sell Customer Personal Data, does not use it for its own marketing, and does not use it, or allow its AI providers to use it, to train AI models.
3. Confidentiality
IT Nest ensures that everyone authorised to process Customer Personal Data is bound by an obligation of confidentiality.
4. Security
IT Nest implements the technical and organisational measures in Annex II. It may update them, provided the overall level of protection does not decrease.
5. Sub-processors
5.1 The Customer gives IT Nest general authorisation to use sub-processors. The current list is at staffchecklist.com/legal/subprocessors.
5.2 IT Nest will email account owners and update the list at least 30 days before adding or replacing a sub-processor. If the Customer objects on reasonable data protection grounds, the parties will discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected part of the Service before the change takes effect, and IT Nest will refund any fees prepaid for the period after termination.
5.3 IT Nest imposes on each sub-processor data protection obligations no less protective than this DPA, and remains responsible to the Customer for each sub-processor's performance.
6. Assistance
6.1 The Service lets the Customer access, correct, export and delete Customer Personal Data. If IT Nest receives a request from a data subject about Customer Personal Data, it will pass the request to the Customer where it can identify the Customer, and will not respond itself except to confirm that it has done so.
6.2 IT Nest will give reasonable help with data protection impact assessments and prior consultations with supervisory authorities, including information about how the Service's monitoring-related features work: time stamps, photo proof, review of work and the on-site check.
7. Personal data breaches
IT Nest will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data (we aim to do so within 48 hours), and will provide the information the Customer reasonably needs to meet its own obligations as that information becomes available. A notification is not an admission of fault.
8. Deletion and return
8.1 The Customer can export its records (as JSON and CSV, without media files) at any time while its account exists, and can download photos and files from the app, as described in section 10 of the Terms.
8.2 IT Nest applies the Customer's retention settings automatically. It deletes Customer Personal Data 30 days after the Customer closes its account (after the download window), and as described in the Terms for inactive Free accounts. Backups are overwritten within a further 30 days. IT Nest may keep data where the law requires it to, and then only for that purpose.
9. Audits
9.1 IT Nest will make available the information reasonably necessary to demonstrate compliance with this DPA, including answers to a reasonable security questionnaire once a year.
9.2 If that information is not sufficient, or a supervisory authority requires it, the Customer may have IT Nest's compliance audited by an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, no more than once in any 12 months (except after a personal data breach), and at the Customer's cost.
10. International transfers
10.1 IT Nest is established in Hong Kong. Customer Personal Data may be processed in Hong Kong, the UK, the EU, the United States and other countries where IT Nest, its personnel or its sub-processors operate.
10.2 EU. Where the Customer is subject to the EU GDPR and the transfer to IT Nest is a restricted transfer, the SCCs are incorporated into this DPA as follows: Module 2 (controller to processor) applies where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor; Clause 7 (docking clause) applies; under Clause 9(a), Option 2 (general written authorisation) applies, with the 30-day notice in section 5.2; the optional wording in Clause 11 does not apply; under Clause 13, the competent supervisory authority is the one determined under Clause 13(a); under Clauses 17 and 18, the SCCs are governed by the law of Ireland and disputes are resolved by the courts of Ireland; Annexes I and II of the SCCs are completed by Annexes I and II of this DPA, and Annex III by the sub-processor list.
10.3 UK. Where the Customer is subject to the UK GDPR, the UK Addendum is incorporated into this DPA: Table 1 is completed with the parties' details in Annex I; in Table 2, the Addendum EU SCCs are the SCCs with the modules and options set out in section 10.2, which apply for the purposes of the UK Addendum whether or not the EU GDPR applies; Table 3 is completed by Annexes I and II and the sub-processor list; and under Table 4 either party may end the UK Addendum as set out in its Section 19. The UK Addendum is governed by the laws of England and Wales.
10.4 IT Nest has assessed the laws and practices of the countries where Customer Personal Data is processed, including Hong Kong and the United States, and applies supplementary measures: encryption in transit and at rest, access control and data minimisation, and a policy of challenging government requests that lack a valid legal basis and notifying the Customer where the law allows. IT Nest will tell the Customer if it believes it can no longer comply with the SCCs.
10.5 For onward transfers to sub-processors, IT Nest relies on an adequacy decision (including the EU-US Data Privacy Framework and its UK Extension where the sub-processor is certified) or on the SCCs and the UK Addendum.
11. Hong Kong
Where the Personal Data (Privacy) Ordinance applies, IT Nest will not keep Customer Personal Data longer than necessary for the processing, and will protect it against unauthorised or accidental access, processing, erasure, loss or use. These are the contractual measures the Customer adopts as a data user under Data Protection Principles 2(3) and 4(2).
12. Liability, precedence and term
12.1 Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law or the SCCs do not allow liability to data subjects to be limited.
12.2 If there is a conflict, the SCCs and the UK Addendum prevail over this DPA, and this DPA prevails over the Terms.
12.3 This DPA applies for as long as IT Nest processes Customer Personal Data.
Annex I. Details of the processing
A. Parties
Data exporter: the Customer, with the name, address and contact details held in its Staff Checklist account (the account owner is the contact person). Role: controller, or processor where it acts for another controller. Activities: using Staff Checklist to run its business.
Data importer: IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen's Road Central, Central, Hong Kong (Business Registration Number 77297048). Contact: privacy@staffchecklist.com. Role: processor. Activities: providing Staff Checklist.
Accepting the Terms in the Service counts as signing this DPA, the SCCs and the UK Addendum.
B. Description of the processing
Data subjects: the Customer's owners, managers, staff and contractors (some may be aged 16 or 17), and people who appear incidentally in records, such as guests in room photos, suppliers' delivery staff and inspectors whose email address is entered to receive a report.
Categories of personal data:
- identity and contact: name, email address, optional phone number and photo;
- work organisation: role, positions, teams, locations, and absence marks without reasons;
- work records: dates and times, who did what, check results and readings, notes, photos stamped with time, date, name and location name, videos, voice notes and their transcripts, signatures, QR scans, review outcomes, and the on-site check result (on site: yes or no);
- communications: comments, announcements, read confirmations and issue reports;
- technical: push subscriptions, device type, hashed IP address and kiosk PIN (stored hashed).
Sensitive data: not required by the Service. Notes, photos or issue reports may incidentally contain health information. Safeguards: role-based access, prompts in the app not to record health details, deletion tools and retention settings.
Frequency: continuous while the Customer uses the Service.
Nature of the processing: hosting and storage, organising and displaying, transmitting (email, push notifications, share links and emailed PDFs), translating, transcribing and AI drafting when a User asks, generating reports and PDFs, backups and deletion.
Purpose: providing the Service under the Terms.
Duration and retention: for as long as the Terms apply, then as described in section 8.
Sub-processors: as listed at staffchecklist.com/legal/subprocessors, for the purposes shown there.
C. Competent supervisory authority
As determined under Clause 13 of the SCCs. For the UK, the Information Commissioner.
Annex II. Technical and organisational measures
- Encryption: TLS on all connections; stored data encrypted at rest by our hosting provider.
- Access to accounts: passwordless sign-in with one-time codes and links (valid 15 minutes, single use, stored hashed); rotating session tokens stored hashed; kiosk PINs stored hashed with a per-record salt and a server-side secret, with lockout after repeated wrong attempts; rate limits and bot checks on sign-in.
- Separation: every request and query is limited to the User's own business; role-based permissions within each business.
- Accountability: an append-only audit log of changes in each business.
- Personnel: production access limited to IT Nest personnel who need it, using accounts protected by strong authentication, under confidentiality obligations.
- Resilience: managed database with 30-day point-in-time recovery; offline queue on devices.
- Data minimisation: the on-site check stores only whether a User was on site; analytics use random IDs and hide on-screen text; personal data is removed from application logs.
- Development: code review, automated tests and regular dependency updates.
- Providers: data protection terms with every sub-processor; AI providers set up not to train on Customer Data.
- Incidents: a documented response procedure and notification under section 7.
- Deletion: automatic retention and post-closure deletion; share links and generated PDFs expire and are deleted.
Related: Terms of Service · Privacy Policy · Sub-processors