Data Processing Agreement (DPA)  

Introduction 

This Data Processing Agreement (“DPA”) sets out the terms and conditions under which GoodCorporation Ltd (“GC”) processes personal data on behalf of the Client in connection with the services and platform access provided by GC. This DPA is incorporated by reference into, and forms an integral part of, the contractual relationship between GC and the Client. Any Capitalised term used in this document that is not defined is defined within the Master Agreement.  

 

1 Interpretation 

1.1 In this Data Processing Agreement: 

“Adequate Country” means a country or territory recognised as providing an adequate level of protection for Personal Data under an adequacy decision made by the UK Secretary of State or the European Commission. 

“Applicable Law” means all relevant legislation, regulations, and binding decisions relating to personal data and privacy, including UK GDPR, EU GDPR, Data Protection Act 2018, and other applicable laws. 

“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. 

“DP Law” means all Applicable Law relating to the processing of personal data and privacy. 

“Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, “Sub-processor” have the meanings given in DP Law. 

“Sub-Processor” means any third party engaged by GC to process Personal Data on behalf of the Client. 

“Third Country” means a country which is neither in the UK, an EU member, an EEA member, nor an Adequate Country. 

 

2 Parties and Scope  

2.1 Controller: The Client (and its group companies, as applicable) 

2.2 Processor: GoodCorporation Ltd (“GC”) 

2.3 Scope: GC processes Personal Data on behalf of the Client in connection with consulting services and GCAP platform access. 

 

3 Nature, Purpose, and Duration of Processing 

3.1 Nature: Collection, storage, analysis, reporting, and deletion of Personal Data. 

3.2 Purpose: Delivery of compliance assessments, risk mapping, reporting, and platform access. 

3.3 Duration: For the term of the Master Agreement and as required for legal or contractual purposes. 

 

4 Types of Personal Data and Data Subjects 

4.1 Types: Names, contact details, internal compliance data, whistleblowing reports, survey responses, assessment data, and other information provided by the Client. 

4.2 Data Subjects: Client employees, contractors, personnel, third parties, and other individuals identified by the Client. 

4.3 Special Category Data: GC will not process special categories of Personal Data (as defined in GDPR Article 9) unless expressly agreed in writing. 

 

5 Processor Obligations  

5.1 GC shall: 

5.1.1 Process Personal Data only on documented instructions from the Client, unless required by law (and will inform the Client unless prohibited). 

5.1.2 Ensure persons authorised to process Personal Data are contractually bound to confidentiality. 

5.1.3 Implement appropriate technical and organisational security measures, including encryption, access controls, regular backups, and monitoring. 

5.1.4 Assist the Client with data subject requests (access, rectification, erasure, etc.). • Assist the Client with security, breach notification, DPIAs, and transfer impact assessments. • Maintain records of processing activities. 

5.1.5 Make available to the Client all information necessary to demonstrate compliance and allow for audits and inspections. 

5.1.6 Notify the Client without undue delay and, where feasible, within 48 hours of becoming aware of a Data Breach. 

5.1.7 Following termination or expiry, promptly delete or return all Personal Data at the Client’s choice, and certify deletion if requested. 

5.1.8 Immediately inform the Client if, in GC’s opinion, an instruction infringes DP Law. 

 

6 Sub-processors 

6.1 GC may engage sub-processors (e.g. hosting providers, analytics tools) with the Client’s prior written consent. 

6.2 GC will notify the Client in writing of any intended changes to sub-processors, giving the Client the opportunity to object on reasonable grounds. If the Client objects, GC will use reasonable efforts to propose a replacement sub-processor. 

6.3 GC shall ensure sub-processors are subject to the same data protection obligations as GC. 

6.4 A current list of sub-processors is available at [URL] or on request. 

 

7 Data Hosting and Processing Locations 

7.1 GC shall process Personal Data only in the UK, EEA, or Adequate Countries, unless otherwise agreed in writing. 

7.2 GC shall notify the Client in advance of any intended changes to processing locations. 

7.3 International Transfers: 

7.3.1 Transfers outside the UK/EEA will be subject to appropriate safeguards (e.g. Standard Contractual Clauses, UK International Data Transfer Agreement). 

7.3.2 GC will not transfer Personal Data outside the UK/EEA without the Client’s prior written consent. 

7.3.3 For any transfer of Personal Data to a third country, GC will conduct and document a transfer impact assessment and implement supplementary measures as required by DP Law. 

 

8 Data Security, Audit and Inspection  

8.1 GC shall implement security measures including encryption, access controls, regular backups, and monitoring. 

8.2 A summary of GC’s technical and organisational security measures is available at [URL] or as a schedule to this agreement. 

8.3 The Client has the right to audit GC’s processing and security measures, subject to reasonable notice and confidentiality. 

 

9 Data Breach Notification 

9.1 GC shall notify the Client without undue delay and, where feasible, within 48 hours of becoming aware of a Data Breach. 

9.2 GC will assist the Client with making any mandatory notifications to regulators and/or affected data subjects. 

9.3 GC will maintain records regarding any Data Breach for at least three years from the date of the breach. 

 

10 Termination and Data Return/Deletion 

10.1 Upon termination of the Master Agreement, GC shall, at the Client’s choice, return or securely delete all Personal Data, except where retention is required by law. 

10.2 GC will certify deletion if requested by the Client. 

 

11 Liability and Indemnity 

11.1 Client shall be responsible for ensuring that its processing of Personal Data and its instructions to GC comply with applicable DP Laws. 

 

11.2 GC will not be liable for any loss, claim, cost, expense, regulatory action or fine arising from GC”s compliance with Client’s documented instructions unless GC knew or ought reasonably to have known that such instructions infringed DP Laws. 

 

11.3 Any liability of GC arising under or in connection with DP Law shall be subject to the exclusions and limitations of liability set out in the Master Agreement. 

 

11.4 GC maintains cyber and privacy liability insurance with coverage appropriate to the nature and volume of Personal Data processed. 

 

Governing Law 

This Schedule is governed by English law and subject to the exclusive jurisdiction of the courts of England and Wales. 

 

Contact for Data Protection Issues 

GC’s Data Protection Officer can be contacted at: dpo@goodcorporation.com 

 

Appendices 

Appendix A: Data Mapping Table 

Subject Matter:  

  • Compliance assessment, risk mapping, supplier/partner evaluation, platform access, consulting services, due diligence, audit, and reporting activities conducted via the GoodCorporation Assessment Platform (GCAP). 

Duration: 

  • For the term of the Agreement, including any renewal periods, plus any additional retention required by law or contractual obligations. 

Nature and Purpose of Processing: 

  • Collection of data from business units, parent organisations, suppliers, partners, and third parties. 
  • Storage of assessment responses, supporting documents, and contact information. 
  • Analysis of compliance, risk, ethics, performance, and supplier management data. 
  • Automated and manual reporting, benchmarking, and dashboard generation. 
  • Aggregation and central review of results across regions, business units, or supplier networks. 
  • Deletion or return of data at contract end, as instructed by the client. 
  • Provision of technical support, user management, and platform maintenance. 

Categories of Data Subjects: 

  • Employees, contractors, business unit representatives, parent organisation staff. 
  • Supplier employees, contractors, business partners, third-party representatives. 
  • Individuals participating in assessments, audits, surveys, or due diligence processes. 

Categories of Data: 

  • Names, contact details (email, phone, address), job titles, organisational affiliation. 
  • Assessment responses, survey data, risk scores, compliance records, performance metrics. 
  • Supporting documents (policies, certifications, audit reports, evidence uploads). 
  • Whistleblowing reports, incident logs, due diligence questionnaires. 
  • User account information, access logs, platform usage data. 

Data Hosting Location: 

  • Data is hosted and processed in the United Kingdom, European Economic Area (EEA), or Adequate Countries as defined by applicable data protection law. 
  • No data is processed or transferred outside these locations without prior written consent and appropriate safeguards. 

Security Measures: 

  • Encryption of data at rest and in transit. 
  • Access controls, user authentication, and role-based permissions. 
  • Regular backups, monitoring, and incident response procedures. 
  • Physical and logical security of hosting environments. 
  • Sub-processor due diligence and contractual safeguards. 

Sub-processors: 

  • Hosting providers, IT support, analytics tools, CRM platforms, as listed in Appendix B. 
  • Sub-processors are subject to the same data protection obligations and are approved by the client. 

International Transfers: 

  • Transfers outside the UK/EEA/Adequate Countries are subject to Standard Contractual Clauses, UK International Data Transfer Agreement, or other appropriate safeguards. 
  • Transfer impact assessments and supplementary measures are implemented as required. 

Retention and Deletion: 

  • Data is retained for the duration of the Agreement and deleted or returned to the client upon termination, unless retention is required by law. 

 

Appendix B: Technical and Organisational Measures 

This Appendix forms part of the Data Processing Agreement (the “DPA”) and describes the technical and organisational measures (TOMs) implemented by the Processor under Article 32 UK GDPR / EU GDPR to ensure a level of security appropriate to the risk. It applies to both the Processor’s consulting services and the GCAP platform (Software-as-a-Service), except where a measure is marked as specific to one or the other. 

These measures sit on top of, and are governed by, GoodCorporation’s Information Security Policy, which is operated as part of an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022. 

  • Information Security Policy reference: GoodCorporation Information Security Policy, version 2.1, owned by the ISMS Manager and approved by the Managing Director.  
  • Certifications / attestations held: ISMS operated in accordance with ISO/IEC 27001:2022. Certificate no. 459072024, issued by Citation ISO valid to 13/10/27  

 

  1. Pseudonymisation and encryption
  • Encryption in transit: All Personal Data transmitted over public networks is encrypted using TLS 1.2 or higher. This covers the GCAP web application (gcap.app), its APIs (api.gcap.app and mcf-api.gcap.app, comprising MCF-API and GoodCorpAPI/Core) and all email containing Personal Data. 
  • Encryption at rest: Personal Data stored by the GCAP platform is held in Azure Database for MySQL (Flexible Server) and is encrypted at rest using Azure provider-managed AES-256 encryption. Backups are encrypted to the same standard. 
  • Key management: At-rest encryption keys are managed by the Azure platform (service-managed keys). Access to the hosting environment and key configuration is restricted to authorised personnel only. 
  • Password storage: User account passwords are stored as salted hashes using bcrypt. 
  • Pseudonymisation: Where appropriate, the Processor pseudonymises or anonymises Personal Data used for testing, analytics and benchmarking so that it cannot be attributed to a data subject without separately held information. 
  1. Confidentiality
  • Access control: Access to Personal Data is granted on a least-privilege, need-to-know basis and reviewed at least annually. Access is removed promptly on role change or termination. TODO: confirm the access-review cadence with the ISMS Manager. 
  • Authentication: Access to systems holding Personal Data requires individual named accounts; shared accounts are prohibited. The GCAP platform supports single sign-on through Microsoft Entra ID. 
  • Personnel: All employees and agents acting on GoodCorporation’s behalf are bound by written confidentiality obligations in their Contract of Employment, which survive termination. Adherence to the Information Security Policy is a contractual duty, and breach may result in disciplinary action up to and including dismissal. Staff receive security and data protection awareness training appropriate to their role. 
  • Third parties: Mutual non-disclosure / confidentiality agreements are entered into with third-party companies as appropriate. 
  • Segregation: Controller data is logically segregated from that of other customers within the GCAP platform. 
  1. Integrity
  • Change management: Changes to production systems follow a documented change-control process including peer review, testing and approval before release. Source control and CI/CD run through GitHub and GitHub Actions. 
  • Input / transmission control: Application logging records access to and changes affecting Personal Data. Audit logs are retained for 90 days and protected against tampering. 
  • Malware protection: Endpoints and servers run Bitdefender anti-malware / endpoint protection with automatic updates.  
  • Vulnerability management: Systems are patched on a risk-based schedule; critical vulnerabilities are remediated within 1 month. Independent penetration testing of the GCAP platform is performed at least annually; last test 15/09/2025.  
  1. Availability and resilience
  • Backups: Personal Data in the GCAP platform is backed up. Backups are tested by restore at least quarterly. 
  • Business continuity / disaster recovery: A documented Disaster Recovery / Business Continuity Plan is in place, maintained, tested and subject to regular review by the ISMS Committee (per the Information Security Policy). 
  • Hosting and redundancy: Production infrastructure is hosted on Microsoft Azure. GCAP production data resides in the UK South region and MCF production data in the UK West region; development and test environments reside in West Europe. Azure provides regional high-availability and redundancy options. 
  • Capacity / monitoring: Application health, errors and performance are monitored via Sentry (EU / Germany region). System and infrastructure health is monitored through the Azure platform. 
  1. Process for regular testing, assessment and evaluation
  • Security reviews: The Information Security Policy and these TOMs are regularly reviewed by the ISMS Manager or Managing Director and updated to maintain continuing viability, applicability and legal compliance, and after any material change or significant incident. 
  • Risk assessment: Information security risks are assessed and recorded; a Risk Assessment / Statement of Applicability is maintained and made available to employees and is reviewed by the ISMS Committee. 
  • Statutory and regulatory monitoring: All statutory and regulatory requirements are met and regularly monitored for changes. 
  • Secure development: GCAP is developed following secure-by-design practices including peer code review and dependency management including Dependabot dependency-scanning tooling. 
  1. Personal data breach management
  • The Processor maintains a documented incident response process. All employees and agents have a duty to report any suspected security breach without delay to the ISMS representative. 
  • The Processor notifies the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller’s data, providing the information the Controller needs to meet its own notification obligations. 
  • Incidents are logged, investigated, remediated and reviewed for lessons learned by the ISMS Committee. 
  • GoodCorporation maintains a data protection complaints-handling process in accordance with the duty introduced by the Data (Use and Access) Act 2025 (in force 19 June 2026). 
  1. Sub-processors and transfers
  • The Processor engages sub-processors only under written terms imposing data protection obligations equivalent to those in the DPA. The current list is at Appendix B. 
  1. Data minimisation, retention and deletion
  • The Processor processes only the Personal Data necessary to provide the services. 
  • On termination or expiry of the services, the Processor deletes or returns Personal Data in accordance with the DPA body, within 7 years, save where retention is required by law. 
  1. Physical security
  • Production infrastructure is hosted in Microsoft Azure data centres certified to ISO/IEC 27001 and SOC 2, with physical access controls managed by Microsoft. 
  • GoodCorporation offices holding Personal Data on local devices apply the controls set out its Information Security Policy, including device and laptop care for staff working off-site.  
  1. Governance and responsibilities

Per the Information Security Policy: 

  • The Managing Director has approved the Information Security Policy and may amend it. 
  • Overall responsibility for Information Security rests with the DPO and ISMS Committee. 
  • Day-to-day responsibility for procedural matters, legal compliance, documentation, security awareness, incident investigation, technical matters and external liaison rests with the ISMS Manager. 
  • Day-to-day responsibility for data protection rests with the Data Protection Officer (DPO). 

Measures summary table 

Art. 32 requirement  Measure(s)  ISP reference  Applies to 
Pseudonymisation & encryption  TLS 1.2+ in transit; Azure AES-256 at rest; bcrypt password hashing  Objective; further policies (backups, passwords)  Consulting + GCAP 
Confidentiality  Least-privilege access, named accounts, Entra ID SSO, employment confidentiality clause, NDAs, training  Responsibilities  Consulting + GCAP 
Integrity  Change control via GitHub/Actions, application logging, patching  Further policies (systems monitoring, virus protection)  GCAP 
Availability & resilience  Azure UK hosting, backups, DR/BCP reviewed by ISMS Committee, Sentry monitoring  DR/BC Plan clause  GCAP 
Testing & evaluation  Regular ISP review, Risk Assessment / Statement of Applicability, statutory monitoring  Review clauses  Consulting + GCAP 
Breach management  IR process, duty to report without delay, 72h Controller notification  Responsibilities; report breach clause  Consulting + GCAP 

 

Appendix C: List of Sub-Processors 

Subprocessor  Service  Data  Status 
1  Microsoft Azure  DB + app hosting  All platform personal data  UK residency 
2  Microsoft Entra ID  SSO / auth  Identity, email, tokens  UK residency 
3  Sentry  Error monitoring  Error context (limited PII)  EU residency (Germany) 

 

Published: 24 June 2026