Legal
Data Processing Agreement
This Data Processing Agreement (DPA) is subject to and forms a part of the agreement referencing this DPA between Sona and the applicable Customer (the Agreement).
1. Definitions#
For purposes of this DPA, the terms below have the meanings set forth below. Capitalized terms that are used but not defined in this DPA have the meanings given in the Agreement.
(a)Applicable Data Protection Laws the privacy, data protection and data security laws and regulations applicable to Sona’s Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws and the GDPR.
(b)Controller the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including, as applicable, any “business” as that term is defined by the California Consumer Privacy Act.
(c)Customer the entity contracting with Sona in the Agreement.
(d)Customer Data has the meaning given to it in the Agreement.
(e)Data Subject the identified or identifiable natural person to whom Personal Data relates.
(f)GDPR as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 and the Data Use and Access Act 2025), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation.
(g)Information Security Incident a breach of Sona’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Sona’s possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
(h)Personal Data Customer Data that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Laws, except that Personal Data does not include such information received by Sona directly or from other sources (such as its other customers) independent of Sona’s relationship with Customer.
(i)Process or Processing any operation or set of operations which is performed by Sona on behalf of Customer under the Agreement, on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(j)Processor the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any “service provider” as that term is defined by the California Consumer Privacy Act.
(k)Service Data data relating to the use, support and/or operation of the Services, which is collected directly by Sona for use for Sona’s own purposes.
(l)Services as defined in the Agreement.
(m)Sona the Sona entity contracting with Customer in the Agreement.
(n)State Privacy Laws collectively, the comprehensive U.S. state data privacy laws from time to time in effect and applicable to Sona’s Processing of Personal Data under the Agreement.
(o)Sub-processors third parties that Sona engages to Process Personal Data in relation to the Services.
(p)Supervisory Authority any entity with the authority to enforce Applicable Data Protection Laws.
2. Duration and Scope of DPA#
(a)This DPA will remain in effect so long as Sona Processes Personal Data in its capacity as Processor, notwithstanding the expiration or termination of the Agreement.
(b)Processing of Personal Data subject to the GDPR shall be subject to Annex 2 (European Annex) of this DPA.
(c)Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider (as such terms are defined in State Privacy Laws) shall be subject to Annex 3 (State Privacy Laws Annex) to this DPA.
3. Customer Instructions#
(a)Sona will Process Personal Data in its capacity as Processor only in accordance with Customer’s instructions to Sona. By entering this DPA, Customer instructs Sona to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The parties acknowledge and agree that the details of Sona’s Processing of Personal Data (including the respective roles of the parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.
4. Security#
(a)Sona Security Measures. Sona will implement and maintain technical, administrative, physical, and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data.
(b)Security Compliance by Sona Staff. Sona shall ensure that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.
(c)Information Security Incidents. Sona will notify Customer without undue delay of any Information Security Incident of which Sona becomes aware. Sona’s notification of or response to an Information Security Incident will not be construed as Sona’s acknowledgment of any fault or liability with respect to the Information Security Incident. If Customer determines that an Information Security Incident must be notified to any Supervisory Authority, any Data Subject(s), the public or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Sona, where permitted by applicable laws, Customer agrees to (i) notify Sona in advance, and (ii) in good faith, consult with Sona and consider any clarifications or corrections Sona may reasonably recommend or request to any such notification, which: (A) relate to Sona’s involvement in or relevance to such Information Security Incident; and (B) are consistent with applicable laws.
(d)Customer’s Security Responsibilities. Customer agrees that, without limitation of Sona’s obligations under this Clause (Security), Customer is solely responsible for its use of the Services, including (i) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (ii) securing the account authentication credentials, systems and devices Customer uses to access the Services; and (iii) securing Customer’s systems and devices that Customer uses to access the Services.
5. Data Subject Rights#
(a)Data Subject Request Assistance. Sona will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (Data Subject Requests) with respect to Personal Data in Sona’s possession or control.
(b)Customer’s Responsibility for Requests. If Sona receives a Data Subject Request, Sona will (i) notify Customer; and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request.
6. Customer Responsibilities#
(a)Customer shall ensure (and is solely responsible for ensuring) that it has given such notices to and obtained such consents and permissions from third parties (including, without limitation, Data Subjects), and has all rights, in each case, as may be required under applicable law or otherwise for Sona to Process Personal Data as contemplated by the Agreement.
(b)Customer represents and warrants that there is, and will be throughout the term of the Agreement and any subsequent period in which Sona Processes Personal Data, a valid legal basis for the Processing by Sona of Personal Data in accordance with this DPA and the Agreement (including, any and all instructions issued by Customer from time to time in respect of such Processing) for the purposes of all Applicable Data Protection Laws.
7. Sub-processors#
(a)Consent to Sub-processor Engagement. Customer generally authorizes Sona to engage third parties as Sub-processors in accordance with this Section (Sub-processors).
(b)Information about Sub-processors. Information about Sub-processors, including their functions and locations, is available at https://trust.sona.ai/ (the Sub-processor Site). Sona may continue to use those Sub-processors already engaged by Sona as at the date of this DPA.
(c)Requirements for Sub-processor Engagement. When engaging any Sub-processor, Sona will enter into a written contract with such Sub-processor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Sub-processor. Sona shall be liable for all obligations subcontracted to, and all acts and omissions of, the Sub-processor to the same extent as Sona would have been had it performed the Processing itself.
(d)Opportunity to Object to Sub-processor Changes. When Sona engages any new Sub-processor after the effective date of this DPA, Sona will notify Customer of the engagement by updating the Sub-processor Site or by other written means. If Customer objects to such engagement in a written notice to Sona within 15 days after being informed of the engagement on reasonable grounds relating to the protection of Personal Data, Customer and Sona will work together in good faith to find a mutually acceptable resolution to address such objection.
8. Audits#
Reviews and Audits of Compliance. Customer may audit Sona’s compliance with its obligations under this DPA up to once every 24 months and on such other occasions as may be required by Applicable Data Protection Laws. Sona will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit. If a third party is to conduct the audit, Sona may object to the auditor if the auditor is, in Sona’s reasonable opinion, not independent, a competitor of Sona, or otherwise manifestly unsuitable. Such objection by Sona will require Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Sona at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Sona will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Sona security, privacy, employment or other relevant policies). Sona will work cooperatively with Customer to agree on a final audit plan. Nothing in this Section (Audits) shall require Sona to breach any duties of confidentiality. If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Customer’s audit request and Sona has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Sona’s safety, security or other relevant policies, and may not unreasonably interfere with Sona business activities. Customer will promptly notify Sona of any non-compliance discovered during the course of an audit and provide Sona any audit reports generated in connection with any audit under this Section (Audits), unless prohibited by Applicable Data Protection Laws. Customer may use the audit reports only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Customer’s sole expense. Customer shall reimburse Sona for any time expended by Sona and any third parties in connection with any audits or inspections under this Section (Audits) at Sona’s then-current professional services rates, which shall be made available to Customer upon request. Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.
9. Return and Deletion#
(a)Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the Cessation Date), Sona shall promptly cease all Processing of Personal Data for any purpose other than for storage or as otherwise permitted or required under this DPA.
(b)Subject to Section 9(d), to the extent technically possible in the circumstances (as determined in Sona’s sole discretion), on Customer’s written request to Sona (to be made no later than thirty (30) days after the Cessation Date or such longer period agreed by Sona and Customer (Post-cessation Storage Period)), Sona shall within fourteen (14) days of such request, at Customer’s election either: (i) return a complete copy of all Personal Data within Sona’s possession to Customer by secure file transfer in a common machine readable format, promptly following which Sona shall delete all other copies of such Personal Data, or (ii) delete all Personal Data within Sona’s possession.
(c)In the event that during the Post-cessation Storage Period, Customer does not instruct Sona in writing to either delete or return Personal Data pursuant to Section 9(b), Sona shall after the expiry of the Post-cessation Storage Period be entitled to delete all Personal Data then within Sona’s possession to the fullest extent technically possible in the circumstances.
(d)Sona may retain Personal Data, where required by applicable law, for such period as may be permitted or required by such applicable law, provided that Sona shall (i) maintain the confidentiality of all such Personal Data, and (ii) Process the Personal Data only as necessary for the purpose(s) specified in the applicable law requiring such retention.
10. Service Data#
(a)Customer acknowledges that Sona may collect, use and disclose Service Data for its own business purposes, such as:
(i)for accounting, tax, billing, audit, and compliance purposes;
(ii)to investigate fraud, spam, wrongful or unlawful use of the Services;
(iii)as otherwise set out in the Agreement; and/or
(iv)as otherwise permitted or required by applicable law.
(b)In respect of any such processing described in this Section (Service Data), Sona:
(i)independently determines the purposes and means of such processing;
(ii)shall comply with Applicable Data Protection Laws (if and as applicable in the context);
(iii)shall process such Service Data as described in Sona’s relevant privacy notices/policies, as updated from time to time; and
(iv)shall apply technical and organizational safeguards to any relevant Personal Data.
11. Miscellaneous#
(a)Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement, the parties acknowledge and agree that Sona’s access to Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Sona to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Sona’s primary points of contact with Customer; or (c) to any email provided by Customer for the purpose of providing it with Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid.
(b)Sona agrees to cooperate in good faith with Customer concerning any amendments as may be reasonably necessary to address compliance with the Applicable Data Protection Laws.
(c)Sona may on notice vary this DPA to the extent that (acting reasonably) it considers necessary to address the requirements of Applicable Data Protection Laws from time to time.
(d)Limitation of Liability. The total aggregate liability of either party towards the other party, howsoever arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and shall be subject to any exclusions of, liability and loss agreed by the parties in the Agreement.
Annex 1#
Data Processing Details
Subject matter, nature, scope and purposes of the Processing | To provide the Services in accordance with the Agreement. |
Duration of the Processing | For the term of the Agreement or the duration of the relevant part of the Services governed by the Agreement (as applicable), including any Post-cessation Storage Period or other period permitted by this DPA. |
Types of Personal Data (general) | Contact and personal details. Names, email addresses, telephone numbers, addresses, dates of birth, job titles, and any additional information individuals add to their profile. |
Special category Personal Data | Depending on the Services subscribed to and Customer’s own configuration and instructions, the Personal Data processed may include special category Personal Data, for example: Health data. Within sickness and other absence records. Racial or ethnic origin, and other equality and diversity data. Where Customer records it. Data concerning sex life or sexual orientation. Where Customer records it. In the case of Sona’s Applicant Tracking System, special category Personal Data may also be volunteered by a job candidate. |
Categories of Data Subject (general) | All personnel of Customer who use the Services, and other categories of data subject which Customer may use the Services in connection with, such as job candidates. Incidental categories of data subject may also be captured, such as next of kin or, in the case of the Sona Applicant Tracking System, referees. |
Data Processing Details by Services type (as applicable) | ||
Services type | Categories of Data Subject | Types of Personal Data |
Scheduling & T&A | Customer personnel | Names, contact details, job roles, skills, attributes and qualifications, contracted hours, shift and rota/schedule data, clock-in and time and attendance records, and (with the individual’s permission) location from mobile clock-in. |
HR | Customer personnel | Employment records, contract types, rates of pay, holiday entitlements and booked holiday, sickness and other absence records, disciplinary and grievance records, and compliance records, plus equality and diversity data where Customer records it. Documentation, including copies of passports, drivers' licenses and employment contracts. |
Time to Gross Pay Engine | Customer personnel | Worked and absence hours, pay rates, pay rules, and calculated gross pay outputs by pay group. |
Sona Pay | Customer personnel | Salary and wage data, bank account details, tax numbers, pension scheme and contribution data, deductions and court orders, and the data required for tax authority submissions and payment files. |
Bureau Service | Customer personnel | As for Sona Pay, processed by Sona's bureau team to run Customer's payroll, including producing pay slips, P45s, and P60s. |
Comms & Engagement | Customer personnel | Individual profile data, newsfeed content, and wellbeing check-in responses. Communication content that individuals send and receive including: (a) the message content itself, which can include messages, pictures, files and video among other types of file; and (b) when messages or files were sent and by whom, when or if they were seen by certain individuals, and where an individual received them (in a channel, private group, or direct message, for example). |
Labor AI | Customer personnel | Customer's operational data (for example sales, bookings, covers) together with external signals and, for auto-scheduling, worker data from Sona HR (contracted hours, working preferences, holidays, primary location), used to suggest optimized rosters. |
Applicant Tracking System (ATS) | Job candidates | Candidate-supplied data: names, contact details, CVs and application content, work history, screening responses and scores, interview and offer data, and onboarding documents. Candidates may be given limited access to track their application. |
Learning Management System (LMS) | Customer personnel | Training records, course enrollments and completions, assessment results, and competency, certification and compliance data. |
Raffy AI | Customer personnel | Queries submitted to Raffy and the workforce data needed to answer them, accessed in line with the querying individual’s permissions. Input information: Personal Data which may be inputted by users of Sona's generative AI tools. |
Annex 2#
UK and European Annex
1. PROCESSING OF PERSONAL DATA#
1.1.Where Sona receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Sona shall inform Customer.
1.2.Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Personal Data by or on behalf of Sona pursuant to or in connection with the Agreement shall comply with the GDPR and all other applicable laws.
2. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION#
Sona, taking into account the nature of the Processing and the information available to Sona, shall provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which Customer reasonably considers to be required of it by Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Personal Data by Sona.
3. TRANSFERS#
Sona shall not transfer Personal Data outside of the countries that comprise the United Kingdom and the European Economic Area other than in accordance with Applicable Data Protection Laws.
Annex 3#
State Privacy Laws Annex
1.For purposes of this Annex, the terms “business,” “commercial purpose,” “sell,” “share” and “service provider” shall have the respective meanings given thereto in the State Privacy Laws, and “personal information” shall mean Personal Data that constitutes personal information governed by the State Privacy Laws.
2.It is the parties’ intent that with respect to any personal information, Sona is a service provider. Sona (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Sona’s use of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Sona that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
3.Sona shall not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Sona and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Sona’s own interaction with any consumer to whom such personal information pertains, except as and to the extent necessary as a part of Sona’s provision of the Services. Sona hereby certifies that it understands its obligations under this Section and will comply with them.
4.Giving Customer notice of Sub-processor engagements in accordance with the DPA shall satisfy Sona’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
5.Sona agrees that Customer may conduct audits, in accordance with the DPA, to help ensure that Sona’s use of personal information is consistent with Sona’s obligations under the State Privacy Laws.
6.The parties acknowledge that Sona’s retention, use and disclosure of personal information authorized by Customer’s instructions documented in the DPA are integral to Sona’s provision of the Services and the business relationship between the parties.