TrainMeUK LogoTrainMeUK
Home
How It Works
Product
Reports
Pricing
Resources
Login
Back

Data Processing Addendum

Last updated: 1 September 2026

1. Scope and Purpose

This Data Processing Addendum ("DPA") forms part of the agreement between TrainMeUK Ltd ("TrainMeUK", "Processor") and the customer organisation ("Customer", "Controller") for the provision of the TrainMeUK Service.

This DPA applies where TrainMeUK processes Customer Personal Data on behalf of the Customer in connection with the Service. It sets out the parties' data-protection obligations under applicable Data Protection Law.

For customers with a signed Order Form and Software Subscription Agreement, this DPA is incorporated by reference into that agreement. For self-serve customers, this DPA forms part of the website Terms of Service. Where no other written agreement between the parties applies to the Service, TrainMeUK's Terms of Service applicable to the Customer's use of the Service and accepted by the Customer are incorporated into this DPA solely to the extent necessary to govern liability, payment, termination and dispute-related matters.

2. Definitions

  • Customer Personal Data means personal data that TrainMeUK processes on behalf of the Customer in connection with the Service.
  • Data Protection Law means the UK GDPR, the Data Protection Act 2018, and any other applicable UK data-protection or privacy legislation, as amended from time to time.
  • Restricted Transfer means a transfer of Customer Personal Data that is subject to the restrictions on international transfers under Data Protection Law.
  • Service means the TrainMeUK compliance-training platform and related services provided to the Customer.
  • Subprocessor means any third party engaged by TrainMeUK to process Customer Personal Data on behalf of TrainMeUK in connection with the Service.
  • Terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in Data Protection Law.

3. Roles of the Parties

  • Customer as Controller: Customer determines the purposes and means of processing Customer Personal Data and remains responsible for the lawfulness of its processing purposes, instructions, collection and use of that data.
  • TrainMeUK as Processor: TrainMeUK processes Customer Personal Data only on documented instructions from the Customer, unless otherwise required by domestic law to which TrainMeUK is subject.
  • Independent controller processing: Each party may separately act as an independent controller in respect of personal data it processes for its own legitimate business administration, billing, security, legal or regulatory purposes. That processing is outside the scope of this DPA and is described in TrainMeUK's Privacy Policy where TrainMeUK acts as controller.
  • Customer as processor / TrainMeUK as Subprocessor: Where the Customer processes Customer Personal Data on behalf of another controller, references in this DPA to the Customer acting as Controller shall be construed as the Customer acting as processor and TrainMeUK acting as its Subprocessor, as applicable. The Customer warrants that it is authorised to appoint and instruct TrainMeUK to process that Customer Personal Data.

The Customer is responsible for its users, configurations, data entered or uploaded to the Service, notices, lawful bases, retention settings, optional feature enablement, and for determining whether the Service is appropriate for its processing activities. TrainMeUK does not determine the lawfulness, fairness or appropriateness of the Customer's employment, training, performance, disciplinary or biometric decisions made using the Service.

The Customer instructs TrainMeUK to process Customer Personal Data as necessary to provide, secure, maintain and support the Service in accordance with the Agreement, this DPA, the Customer's configuration and use of the Service, and any additional documented instructions consistent with the Agreement. Additional instructions beyond ordinary Service functionality are subject to technical feasibility, reasonable costs and written agreement between the parties.

Schedule 1 — Processing Details

The following describes the processing of Customer Personal Data under this DPA for the core Service. Schedules 1A and 1B apply only to the extent the corresponding optional feature is enabled for the Customer.

Detail Description
Subject matter Provision, hosting, security and support of the TrainMeUK compliance-training platform
Duration For the subscription term and the post-termination return or deletion period under this DPA
Nature and purpose User administration, authentication, training delivery, progress tracking, certificates, compliance reporting, notifications, support, security, and customer-requested integrations
Data subjects Customer personnel, workers, contractors, administrators, managers and other authorised users
Personal data Names, work contact details, account identifiers, roles, authentication data, training assignments, progress, results, certificates, audit records, uploaded evidence, support information and technical/security logs
Special-category and criminal-offence data Not required or intended for ordinary use of the core Service. Such data may be processed where the Customer elects to include it in uploaded evidence, support information or other Customer-provided content, in which case the Customer remains responsible for the lawfulness of that processing
Controller's rights To issue lawful documented instructions (subject to this DPA), receive compliance information, audit processing (subject to this DPA), object to new Subprocessors (subject to this DPA), and require return or deletion of Customer Personal Data
Controller's obligations To ensure its instructions, purposes and collection of Customer Personal Data are lawful and to give any required notices to data subjects

Schedule 1A — Learner Verify (optional)

Where the Customer enables Learner Verify, the following applies in addition to Schedule 1. Learner Verify data is not ordinary account data.

Detail Description
Feature Optional identity-assurance feature for course completion, enabled by the Customer at tenant and/or course level
Nature of processing Capture and comparison of facial images (baseline, checkpoint and completion images) using Microsoft Azure AI Face API for biometric identity comparison, with human review by the Customer where required
Personal data / special category Facial images, temporary comparison identifiers generated for verification, comparison or confidence scores, verification outcomes, timestamps and associated learner identifiers. Facial information constitutes special-category biometric data where technical processing is used for uniquely identifying or verifying the identity of a learner
Data subjects Learners assigned to courses where Learner Verify is enabled
Customer responsibilities Before enabling Learner Verify, the Customer must identify and document an applicable lawful basis under Article 6 UK GDPR and a separate condition under Article 9 UK GDPR for the processing of special-category biometric data. Where the selected Article 9 condition requires a basis, authorisation or additional safeguards under Schedule 1 to the Data Protection Act 2018, the Customer must satisfy those requirements, including any requirement to maintain an Appropriate Policy Document. The Customer must complete and document a data protection impact assessment (DPIA) before enabling Learner Verify, provide required information to learners, and ensure that a suitable non-biometric alternative is available where reliance is placed on consent. Explicit consent may be used only where it is valid, specific, informed and freely given and can be withdrawn without detriment. TrainMeUK does not determine whether the Customer's use of Learner Verify is lawful; the DPIA, Article 6/9 assessment, employment-law implications and consent assessment remain the Customer's responsibility.
TrainMeUK assistance TrainMeUK will provide reasonable information and assistance requested by the Customer for the purpose of completing that DPIA, taking into account the nature of the processing and the information available to TrainMeUK, subject to reasonable fees where the assistance requires material work beyond ordinary Service functionality or documentation.
TrainMeUK commitments TrainMeUK will process Learner Verify data only on the Customer's documented instructions and will not use facial images to train facial-recognition or other artificial-intelligence models. TrainMeUK supplies the feature as a processor and does not decide whether biometric verification is appropriate or lawful for the Customer's workforce or learners.
Subprocessor Microsoft Azure AI Face API (United Kingdom region), as listed at trainmeuk.co.uk/subprocessors
Retention and storage During an active Learner Verify attempt, TrainMeUK stores the baseline image and any checkpoint images captured for that attempt in the Customer's tenant storage, together with verification outcomes, confidence scores, timestamps and associated learner identifiers. Comparison is performed using Microsoft Azure AI Face API in the United Kingdom region. For the Detect / temporary Face ID and Verify operations used by the Service, Microsoft does not retain the input images after analysis, and temporary Face IDs expire within 24 hours; TrainMeUK does not maintain persistent PersonGroup-style biometric templates with Microsoft. When an attempt is verified, checkpoint images are deleted in accordance with TrainMeUK's Learner Verify retention and cleanup processes. Where an attempt remains unverified pending review, checkpoint images may be retained until the attempt is resolved or cleaned up under those processes. Subject to any longer retention required by domestic law, TrainMeUK retains the baseline image (as the verification reference / audit image) until the earliest of: (a) the related course validity/expiry date; (b) 12 months from verification; or (c) deletion following learner deactivation, after which that baseline image and related Learner Verify records are deleted in accordance with TrainMeUK's Learner Verify retention and cleanup processes.

Schedule 1B — Performance Management (optional)

This Schedule applies only to the extent Performance Management is enabled for the Customer. Where enabled, the following applies in addition to Schedule 1.

Detail Description
Subject matter Performance reviews, objectives, feedback and related HR / people-development records within the Service
Data subjects Employees, workers and other individuals subject to performance processes configured by the Customer
Personal data Names, roles, objectives, review notes, ratings, feedback, action plans, meeting records and related audit metadata
Special-category and criminal-offence data Not required for ordinary use of the feature. Such data may nevertheless be included by the Customer in free-text records or supporting information. Where the Customer instructs TrainMeUK to process such data, the Customer is responsible for identifying an applicable lawful basis and, for special-category data, an applicable Article 9 condition and any applicable condition or requirement under Schedule 1 to the Data Protection Act 2018, and for criminal-offence data, satisfying the requirements of Article 10 UK GDPR and the Data Protection Act 2018, together with any other required safeguards
Nature and purpose Support the Customer's performance-management and appraisal workflows within the Service
Customer responsibilities Ensure a lawful basis for the processing, provide required workforce notices, and configure access appropriately within the Service. TrainMeUK does not determine the appropriateness, fairness or legality of performance decisions, ratings, disciplinary decisions or employment actions made using the Service.

4. Processor Obligations

TrainMeUK shall:

  • process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Customer Personal Data to a third country or international organisation, unless required to do so by domestic law to which TrainMeUK is subject (in which case TrainMeUK shall inform the Customer of that legal requirement before processing, unless that domestic law prohibits such information on important grounds of public interest);
  • immediately inform the Customer if, in TrainMeUK's opinion, an instruction infringes Data Protection Law;
  • ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Schedule 2;
  • taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer's obligation to respond to requests for exercising data subjects' rights under Data Protection Law;
  • taking into account the nature of processing and the information available to TrainMeUK, assist the Customer in ensuring compliance with obligations relating to security of processing, personal data breach notification, data protection impact assessments and prior consultation with a supervisory authority;
  • notify the Customer without undue delay and in any event within 24 hours after becoming aware of a personal data breach affecting Customer Personal Data and provide such information as is reasonably available to assist the Customer in meeting its obligations under Data Protection Law. TrainMeUK may provide information in phases as further information becomes available;
  • at the choice of the Customer, delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless domestic law requires storage of the personal data, in accordance with section 8; and
  • make available all information necessary to demonstrate compliance with this DPA and Article 28 UK GDPR, and permit and contribute to audits, in accordance with section 7.

Except where assistance is required as a result of TrainMeUK's breach of this DPA or Data Protection Law, TrainMeUK may charge reasonable fees for material assistance requested by the Customer that exceeds the functionality, documentation or support ordinarily provided as part of the Service.

Nothing in this section limits TrainMeUK's obligation to provide the assistance expressly required of a processor under Article 28 UK GDPR. Any fees charged relate only to reasonable additional work involved in providing that assistance beyond TrainMeUK's standard functionality, documentation and support.

Additional Customer instructions that go beyond ordinary Service functionality are subject to technical feasibility, reasonable costs and written agreement, but nothing in those limitations reduces TrainMeUK's processor obligations under this DPA or Data Protection Law.

5. Subprocessors

The Customer gives general written authorisation for TrainMeUK to engage the Subprocessors published at trainmeuk.co.uk/subprocessors to support delivery of the Service.

The core TrainMeUK platform is hosted on Microsoft Azure within the United Kingdom, including the primary database, file and blob storage, and core training and compliance records. Certain ancillary or optional services may involve processing outside a UK-only environment. Where this applies, appropriate UK GDPR safeguards are used and the relevant services are documented within TrainMeUK's subprocessor information and this DPA.

TrainMeUK will provide reasonable advance notice of any intended addition or replacement of a Subprocessor that will process Customer Personal Data. Notice will be sent to the Customer's designated notices or account email address and may also be published on TrainMeUK's Subprocessor list. As a guide, TrainMeUK aims to give at least seven (7) days' notice where practicable.

The Customer may object on reasonable and documented data-protection grounds relating specifically to the proposed Subprocessor before that Subprocessor begins processing Customer Personal Data on behalf of the Customer. Where the Customer raises a valid objection, TrainMeUK will use commercially reasonable efforts to make available a change in the Service or recommend a commercially reasonable alternative that avoids processing by the proposed Subprocessor. If TrainMeUK determines that no commercially reasonable alternative is available, TrainMeUK may terminate the affected portion of the Service on written notice. The Customer's objection shall not prevent TrainMeUK from using the Subprocessor for customers that have not objected.

TrainMeUK will impose on each Subprocessor, by way of a written contract, the same data-protection obligations as apply to TrainMeUK under this DPA, to the extent applicable to the Subprocessor's processing.

TrainMeUK remains fully liable to the Customer for the performance of each Subprocessor's data-protection obligations.

6. International Transfers

TrainMeUK will not make a Restricted Transfer of Customer Personal Data unless the transfer is permitted by applicable Data Protection Law. Where an adequacy regulation or applicable exception is unavailable, TrainMeUK will implement an appropriate safeguard under Article 46 UK GDPR, including the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses where appropriate, complete the applicable data protection test (commonly referred to by the ICO as a transfer risk assessment or TRA), and implement any additional measures identified as necessary.

7. Audits and Inspections

TrainMeUK will make available to the Customer all information necessary to demonstrate compliance with this DPA and Article 28 UK GDPR. Where the Customer reasonably and in good faith determines that such information is insufficient to demonstrate compliance, TrainMeUK will permit and contribute to a reasonable audit or inspection conducted by the Customer or an independent auditor mandated by the Customer.

Audits shall, unless required by a supervisory authority or reasonably necessary following a suspected material breach of this DPA by TrainMeUK, be conducted no more than once in any twelve-month period, on reasonable prior written notice, during normal business hours, and in a manner that minimises disruption to TrainMeUK's operations. The Customer shall ensure that its auditor is subject to appropriate confidentiality obligations and is not a competitor of TrainMeUK. Audits shall not require TrainMeUK to disclose information of other customers or information that would compromise the security of the Service.

The Customer shall bear its own costs and TrainMeUK's reasonable costs arising from an audit, except where the audit identifies a material breach of this DPA by TrainMeUK.

Schedule 2 — Security Measures

TrainMeUK maintains a risk-based security programme designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. The measures currently operated include:

  • Encryption: TLS encryption in transit; encryption at rest for Azure PostgreSQL, Azure Blob Storage and associated platform backups;
  • Access control: role-based access control and least-privilege arrangements for Service users and TrainMeUK operational access;
  • Tenant separation: multi-tenant logical separation of Customer data within the Service;
  • Backup and recovery: automated database backups and documented restore procedures;
  • Vulnerability and patch management: monitoring, assessment and remediation of security vulnerabilities in line with TrainMeUK's security programme;
  • Logging and security monitoring: logging and monitoring of security-relevant events;
  • Incident response: documented incident response procedures, including personal data breach handling;
  • Personnel access controls: authenticated access for authorised personnel, with confidentiality obligations;
  • Business continuity: cloud-hosted infrastructure with backup and recovery arrangements supporting continuity of the Service;
  • Secure deletion: deletion or return of Customer Personal Data in accordance with this DPA and retention requirements; and
  • Periodic testing: periodic testing and review of security measures, including security testing and related assurance activities.

TrainMeUK may update these measures provided that the overall level of security is not materially diminished.

8. Return and Deletion

Upon termination or expiry of the Service, TrainMeUK will, at the Customer's choice, return or delete Customer Personal Data, subject to any retention required by domestic law. Where return is requested, TrainMeUK will provide Customer Personal Data in structured training and compliance records as CSV or Excel; generated reports and certificates as PDF; customer-uploaded documents and files in their original or native format where applicable; and Customer-created Course Builder content in standard SCORM formats where applicable. Standard reporting is also available in CSV, Excel and PDF formats depending on the report. Bespoke extraction, transformation or migration work may be charged at reasonable fees and requires written agreement.

Where Customer Personal Data remains in backups created in the ordinary course of business and cannot reasonably be deleted individually, TrainMeUK will put that data beyond ordinary use, protect it in accordance with this DPA, not restore it except where required for disaster recovery, and permanently overwrite or delete it in accordance with TrainMeUK's documented backup-retention cycle.

9. Order of Precedence

In the event of conflict between this DPA and any other part of the agreement between the parties (including the website Terms of Service, or a signed Order Form and Software Subscription Agreement), this DPA will prevail to the extent of any conflict concerning the processing of Customer Personal Data, except that liability, payment, termination and dispute-related matters continue to be governed by the applicable commercial terms or Terms of Service.

10. Contact

For DPA and data protection queries:

Email: privacy@trainmeuk.co.uk

Address: TrainMeUK Ltd, 8 George Myers Close, Ash, Aldershot, England, GU12 6FW

Phone: 01252 929213

Need Help?

If you have any questions about this policy or our practices, please don't hesitate to contact us.

Contact UsView FAQ
TrainMeUK LogoTrainMeUK Ltd

Connect Microsoft 365 once. TrainMeUK handles reminders, Teams nudges, certificates, and audit-proof reports — automatically.

hello@trainmeuk.co.uk
+44 1252 929213
8 George Myers Close, Ash, Aldershot, Surrey, GU12 6FW

Quick Links

  • Home
  • How It Works
  • Product
  • Reports
  • Pricing
  • Resources
  • Knowledge Base

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
  • Subprocessors
  • Acceptable Use Policy
  • FAQ

Popular Resources

Mandatory Training Requirements for UK BusinessesHow Often GDPR Training Should Be Done in the UKLearning Management Systems in the UK (2026)

© 2026 TrainMeUK Ltd. All rights reserved.

CPD Accredited Provider