Data Processing Agreement
Last updated: 7 October 2026
UK GDPR Article 28 processor terms for customer employee and payroll data.
1. Roles and scope
For Customer Personal Data processed through PayRivo, the customer is the controller and Rivo Bookkeeping & Payroll Services Ltd is the processor. The subject matter is provision of the PayRivo service for the term of the customer agreement. The nature and purpose are hosting, organising, displaying, calculating, transmitting and supporting payroll, people, document, holiday, rota and related workflow functions.
2. Data and people covered
Customer Personal Data may include identity, contact, employment, payroll, tax, pension, bank, document and leave information relating to employees, workers, applicants, directors, customer users and authorised contacts. The categories depend on what the customer chooses to use in the service.
3. Documented instructions
We will process Customer Personal Data only on the customer’s documented instructions, including these terms and the customer’s use of the service, unless UK law requires otherwise. If required by law, we will inform the customer unless prohibited from doing so.
4. Confidentiality and security
We will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and will implement appropriate technical and organisational measures designed to meet Article 32 UK GDPR requirements.
5. Sub-processors
The customer gives general written authorisation for us to use carefully selected sub-processors to operate PayRivo, including hosting, authentication, payment, communications and security providers. We will impose data-protection obligations materially equivalent to this agreement and remain responsible for our sub-processors’ performance of those obligations. We will give reasonable notice of material sub-processor changes where required.
6. Assistance
Taking account of the nature of processing and information available, we will provide reasonable assistance for data-subject requests, security obligations, personal-data breach assessment and notification, data-protection impact assessments and prior consultation with the ICO.
7. Personal-data incidents
If we become aware of a personal-data breach affecting Customer Personal Data, we will notify the customer without undue delay and provide information reasonably available to help the customer meet its obligations.
8. Return or deletion
At the end of the service, we will, at the customer’s choice, return or delete Customer Personal Data unless retention is required by law. Backups may be retained beyond the active account only for a limited secure deletion cycle and will not be put back into active use.
9. Information and audit
On reasonable written request, we will provide information reasonably necessary to demonstrate compliance with this agreement and allow proportionate audits or inspections, subject to confidentiality, security, cost and operational safeguards.
10. Precedence
If this Data Processing Agreement conflicts with the Terms of Service solely about Customer Personal Data processing, this agreement takes precedence.
These documents provide general information about PayRivo’s service and data handling. They are not legal advice. They should be reviewed by a qualified UK solicitor before reliance for a regulated activity, bespoke enterprise agreement or a material change in service.