Last updated: April 18, 2024
Our customers are employers located in Europe and the United Kingdom who use Pento to simplify their payroll processes. Customers create an online profile for their business on the Pento platform and upload their employee information (such as the employee’s name, working hours and annual salary). As part of the registration process, the customer must also open an account with a nominated payment service provider (PSP) so that funds can be transferred from the business account to the various payees (whether the employees themselves, or relevant tax authorities and pension providers). The customer also has the choice to integrate Pento with other suppliers that they use which are relevant to the payroll process (such as accounting platforms and HR software).
Whilst Pento makes payroll painless, our services involve the use and sharing of personal data (which is any information which can identify a living person). This Data Processing Agreement (DPA) sets out the relationship and obligations between Pento and its customer to ensure that both parties use and share any personal data in a responsible, compliant and secure way.
This DPA is between the Pento entity and the entity identified as the Customer in a completed Order Form or via the Pento platform. The contracting Pento entity is dependent on the country in which the Customer is incorporated.
This DPA is legally enforceable from the date of the Agreement (the Start Date) and its terms apply in addition to the standard terms set out in the Pento customer Terms and conditions.
The following definitions apply in this DPA:
Controller means organisation or person that makes decisions about what and why Personal Data is being collected from individuals.
Customer means the entity identified in the completed Order Form which uses Pento services to facilitate the payroll process.
Data Protection Laws means applicable laws and regulations relating to privacy or Processing of Personal Data, including any relevant guidance or codes of practice issued by a regulator.
Data Subject(s) means the living person who is or could be identified by the Personal Data.
European Economic Area (EEA) means the countries which are party to the European Economic Area Treaty.
Pento means the Pento entity identified in the completed Order From, which will be one of the following:
The definition of Pento shall also include the HiBob subsidiaries, as detailed here – HiBob Group Subsidiaries
Personal Data means any information which can (or could be used to) identify a living person.
Process(ing) means any action in relation to personal data – ranging from actively using or analysing the information to simply having access to or storing the information.
Processor means the organisation or person that carries out a task for the Controller which requires them to Process Personal Data.
Personal Data Breach means a security incident in which Personal Data has been accidentally or illegally destroyed, lost, changed or shared with, accessed or used by someone who did not have permission.
Standard Contractual Clauses or SCC means the ICO’s International Data Transfer Agreement for the transfer of personal data from the UK and/or the ICO’s International Data Transfer Addendum to EU Commission Standard Contractual Clauses and/or the European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 as set out in the Annex to Commission Implementing Decision (EU) 2021/914 and/or the European Commission’s Standard Contractual Clauses for the transfer of Personal Data from the European Union to processors established in third countries (controller-to-processor transfers), as set out in the Annex to Commission Decision 2010/87/EU as adapted for the UK, or such alternative clauses as may be approved by the European Commission or by the UK from time to time.
Service means the payroll support service provided by Pento to the Customer, including any ancillary services (such as customer service support and installation).
Sub-Processor means an organisation or person engaged by the Processor to assist the Processor carry out the task for the Controller, where the assistance requires them to Process Personal Data.
1. A reference to writing or written includes email.
1. Where Pento receives Personal Data from the Customer or Pento is required to Process Personal Data to deliver its Service to the Customer, the Customer is the Controller of that Personal Data and Pento is the Processor.
1. It is the responsibility of the Customer as the Controller to inform Data Subjects how their Personal Data is used and maintain the mandatory records required under Data Protection Laws.
1. Where Pento Processes Personal Data for which the Customer is the Controller , Pento shall:
1.The Customer is deemed to authorise the list of Sub-Processors as set out in Schedule 2 at the Start Date and provides general prior authorisation to Pento to appoint Sub-Processors, provided that such Sub-Processors are appointed on terms that comply with Data Protection Laws and are consistent with the obligations imposed on Pento under this DPA. Where the Customer chooses to integrate Pento with any of the Customer’s suppliers (such as a HR software tool or accounting platform the Customer uses), it warrants it has a separate agreement with those suppliers which contains any contractual clauses required by the Data Protection Laws.
2.Where Pento uses a Sub-Processor which is located outside of the European Economic Area or United Kingdom (whichever is applicable in the circumstances):
3. Pento shall, and shall procure that any Sub-Processor shall only process, or permit the processing, of the Personal Data outside the EEA under the following conditions:
1. Pento is only liable for data protection losses, costs and expenses incurred by the Customer where:
2.Except where prohibited by law, Pento’s total liability to the Customer under this DPA in contract, tort (including negligence) or restitution, or for breach of statutory duty or misrepresentation, or any other claims of any nature arising under or in connection with this DPA shall in all circumstances be limited to 3 (three) times the fees paid by the Customer to Pento in respect of the 12 (twelve) months prior to the event giving rise to the claim.
3.Subject to clause 6.1 and 6.2, each party shall indemnify the other against all claims and proceedings and all liability, loss, costs and expenses incurred by the other as a result of any claim made or brought by a Data Subject or other legal person in respect of any loss, damage or distress caused to them as a result of any breach by the other party of the Data Protection Laws by that party, its employees or agents, provided that the indemnified party gives to the indemnifier prompt notice of such claim, full information about the circumstances giving rise to it, reasonable assistance in dealing with the claim and sole authority to manage, defend or settle it.
This DPA, and any dispute arising in relation to it, will be governed by the law in which the Pento contracting entity is located. The parties agree that the courts of the country in which Pento is located will have exclusive jurisdiction to settle any dispute arising out of or in relation this DPA.
Schedule 1
Subject Matter of Processing The service that Pento will provide to the Customer | Pento simplifies the payroll process for the Customer by: processing and storing relevant employee and payment information all in one place (on the Pento platform) providing visibility of employee payment information and when payments are due to be made calculating monies owed to employees, including a breakdown of tax and pension contributions arranging for payments to be made by the PSP |
Nature of Processing The ways in which we will use the Personal Data | The Customer uploads Personal Data to the Pento platform, indicates where Pento should integrate with any of its existing suppliers and opens an account with its chosen PSP. Pento Processes Personal Data in the following ways: stores Personal Data on Pento systems uses Personal Data to calculate monies due transfers Personal Data to the PSP (to allow the PSP to conduct AML checks, open an account and make payments from the Customer account) analyses Personal Data to provide trends to the Customer (e.g. month on month comparisons) deletes Personal Data upon the Customer request or within twelve (12) months from the end of the contractual relationship |
Purpose of Processing | Personal Data will be processed for the purpose of providing the Services to the Customer in accordance with the terms of the Agreement. |
Types of Personal Data | Full name, home address, email, phone number, employment status, date of birth, gender, bank account information, national insurance information, PAYE reference number, salary information. |
Types of Special Category Data | Pento does not intentionally collect special category data but this could be inferred from types of payment that are made (for example, statutory sickness pay). |
Categories of data subjects | Customer employees. |
Schedule 2
List of Sub-Processors