Skip to content
5th Anniversary
Celebrating five years of engineering-led delivery and client success.Our story
Celebrating five years of engineering-led delivery and client success.Our story

Legal & GDPR

Data Processing Agreement

Our standard terms under Article 28 GDPR for when RefactorQ processes personal data on a client's behalf. Procurement and privacy teams can review them before an engagement starts.

Version 1.0, effective 3 October 2026

How to use this DPA. It becomes binding when it is referenced in, or signed alongside, your agreement with RefactorQ. To request a countersigned copy, our current sub-processor list or a transfer impact assessment, email info@refactorq.com.

For how we handle personal data submitted through this website, see our privacy policy.

1.Scope and roles

This Data Processing Agreement ("DPA") forms part of the services agreement, statement of work or order form (the "Agreement") between RefactorQ Consulting LLP ("RefactorQ") and the client named in it (the "Client").

It applies whenever RefactorQ processes personal data on behalf of the Client while providing the services. For that processing the Client is the controller and RefactorQ is the processor, as those terms are defined in the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and other applicable data protection law.

If this DPA conflicts with the Agreement on data protection matters, this DPA prevails.

2.Details of the processing

  • Subject matter and purpose: delivering the consulting, engineering, testing, assessment and support services described in the Agreement.
  • Duration: the term of the Agreement, plus any period needed to return or delete data under clause 11.
  • Nature of processing: access, storage, analysis, transformation, testing and other operations needed to perform the services.
  • Categories of data subjects: as determined by the Client, typically the Client's employees, contractors, customers and end users whose data is held in the systems we work on.
  • Types of personal data: as determined by the Client, typically names, contact details, account identifiers, usage and log data. Special category data is processed only if the Agreement says so and extra safeguards are agreed in writing.

3.Processing only on documented instructions

RefactorQ processes personal data only on the Client's documented instructions, including the Agreement and this DPA, unless required to do otherwise by law. In that case RefactorQ will tell the Client before processing, unless the law forbids it.

RefactorQ will inform the Client promptly if, in its opinion, an instruction infringes data protection law.

Wherever practical, RefactorQ works with anonymized, masked or synthetic data in development and test environments, and asks the Client to provide data in that form.

4.Confidentiality of personnel

Everyone at RefactorQ authorized to process Client personal data is bound by a written duty of confidentiality, receives data protection training, and has access only to the data needed for their role.

5.Security of processing

RefactorQ implements appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the cost of implementation and the risks to data subjects. These include:

  • Least-privilege, role-based access to Client systems, with multi-factor authentication and prompt removal of access when it is no longer needed.
  • Encryption of personal data in transit and, where RefactorQ stores it, at rest.
  • Working inside Client-controlled environments and accounts wherever possible, rather than copying data to RefactorQ systems.
  • Managed and patched company devices with disk encryption and endpoint protection.
  • Logging of access to systems that hold personal data, where the environment supports it.
  • Secure development practices, including code review and automated security scanning in delivery pipelines.
  • Regular review of these measures.

6.Sub-processors

The Client gives general authorization for RefactorQ to use sub-processors to deliver the services. The current list of sub-processors is available on request and will be included in the Agreement or statement of work.

RefactorQ will notify the Client of any intended addition or replacement of a sub-processor at least 30 days in advance. The Client may object on reasonable data protection grounds within that period; the parties will then work in good faith to find a solution, and if none is found the Client may terminate the affected services.

RefactorQ imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to the Client for the sub-processor's performance.

7.International transfers

RefactorQ operates from Ireland and India. Personal data from the European Economic Area, the United Kingdom or Switzerland is transferred outside those regions only where an adequate safeguard is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses (Module 2 or Module 3 as applicable), with the UK International Data Transfer Addendum where relevant.

By entering into the Agreement, the parties agree that those Standard Contractual Clauses are incorporated by reference for any transfer that requires them. RefactorQ will carry out and share, on request, a transfer impact assessment for its processing in India.

8.Assistance to the Client

Taking into account the nature of the processing, RefactorQ will help the Client to:

  • Respond to requests from data subjects exercising their rights under Chapter III GDPR. RefactorQ will pass on any request it receives directly, without responding itself unless authorized.
  • Meet its obligations on security, breach notification, data protection impact assessments and prior consultation with supervisory authorities under Articles 32 to 36 GDPR.

9.Personal data breaches

RefactorQ will notify the Client without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Client personal data.

The notice will describe, as far as is then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. RefactorQ will provide further information as it becomes available and will cooperate with the Client's investigation and remediation.

10.Records, information and audits

RefactorQ keeps a record of processing activities as required by Article 30(2) GDPR.

RefactorQ will make available the information reasonably needed to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, by the Client or an independent auditor it appoints. Audits require at least 30 days' written notice, take place during business hours, are limited to once a year unless a breach or a regulator requires otherwise, and are subject to confidentiality.

11.Return and deletion of data

At the end of the services, or earlier on the Client's written request, RefactorQ will at the Client's choice return or delete all Client personal data and existing copies within 30 days, and confirm this in writing, unless law requires RefactorQ to keep the data.

12.Liability and general terms

Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where data protection law does not allow liability to be limited.

This DPA is governed by the law and jurisdiction specified in the Agreement. It stays in force for as long as RefactorQ processes Client personal data.

Start a conversation

Have a production bottleneck or modernization initiative?

Tell us where your software architecture or cloud environment is experiencing friction. A senior engineer will review your challenge and outline an actionable technical roadmap.

A senior engineer reads every enquiry and replies within one business day