Data processing agreement
Last updated 27 August 2026
This sets out how Vicis processes personal data on behalf of a customer, and forms part of the agreement between us. It is written to be read before you have an account.
Roles
The customer is the controller and Vicis is the processor, for all personal data entered into or generated by the service.
Subject matter and duration
Processing covers employee identity and contact details, working availability, schedules, recorded working time and pay rates, for as long as the customer's account is open, plus the return period below.
Instructions
Vicis processes personal data only on the customer's documented instructions, which the use of the service constitutes. We do not process it for our own purposes, we do not sell it, and we do not use it as training data.
Confidentiality
Everyone with access is bound by confidentiality. Access is limited to what a role requires, enforced in the data layer rather than in the interface, and cross-organisation access is impossible for any customer role.
Security
Data is encrypted in transit and at rest. Tenant isolation is enforced on every query rather than in the interface. Every change to recorded time or money is written to an append-only audit log naming who made it, when, and what it replaced.
Sub-processors
Clerk for authentication, receiving name and email address. MongoDB Atlas for database hosting, receiving all operational data. Vercel for application hosting, receiving all operational data in transit. Resend for email delivery, receiving address and message content. Firebase Cloud Messaging for push notifications, receiving a device token. We give notice before adding another, and the customer may object.
Assisting the controller
The service produces a complete machine-readable export for any individual, and an erasure that anonymises identity while preserving the payroll record, both without our involvement. Where a request needs more than that, we assist.
Return and deletion
On termination the customer may export all data. Thirty days later it is deleted, except where retention is required by law that applies to the customer.
Audit
The customer may request the information needed to demonstrate compliance with this agreement, and may audit, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise.
Questions about this agreement, or a request under it, reach us at the address in your contract.