ClockFence Data Processing Agreement
Pilot version. This agreement is offered to companies taking part in the ClockFence pilot. It has been prepared with care but has not yet been reviewed by a solicitor; it will be reviewed and reissued before ClockFence is offered commercially. Square-bracketed items are completed for each customer when the agreement is signed.
Version: 1.0 draft, 8 September 2026
### Before you sign: what the Customer needs to do ClockFence records where a worker's phone is at the moment they clock in or out, and can record a photo of them. This is workplace monitoring. Under UK GDPR and the ICO's guidance on monitoring workers, location monitoring of employees is listed as a type of processing that is likely to result in high risk. That means the Customer, as the controller, must carry out a Data Protection Impact Assessment (DPIA) before switching ClockFence on for its workers. Meridia will provide a DPIA template and answer technical questions, but the assessment is the Customer's legal responsibility and Meridia cannot complete it on the Customer's behalf. The Customer must also tell workers, in plain language and before they first use the app, what is recorded, why, how long it is kept and who to contact. Meridia provides a one-page worker notice the Customer can adapt and hand out. Failure to do either of these things is a breach of this Agreement and may expose the Customer to regulatory action. See ICO guidance on monitoring workers.
Parties
This Data Processing Agreement (the "Agreement") is made between:
- [CUSTOMER NAME], a company registered in [England and Wales] with company number [CUSTOMER COMPANY NUMBER] and registered office at [CUSTOMER ADDRESS] (the "Customer" or "Controller"); and
- Meridia Projects Ltd, a company registered in England and Wales with company number 17434937 and registered office at 4-6 Greatorex Street, London, England, E1 5NF ("Meridia" or "Processor").
It supplements the agreement under which Meridia provides the ClockFence service to the Customer (the "Principal Agreement").
1. Definitions
1.1 In this Agreement:
"Data Protection Law" means the UK GDPR (the retained version of Regulation (EU) 2016/679 as it forms part of UK law under the European Union (Withdrawal) Act 2018), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any successor or amending legislation, including the Data (Use and Access) Act 2025 to the extent in force.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in Data Protection Law.
"Customer Personal Data" means the Personal Data described in Annex 1 that Meridia Processes on behalf of the Customer in providing the Service.
"Service" means the ClockFence progressive web application and associated services described in the Principal Agreement.
"Sub-processor" means any third party engaged by Meridia to Process Customer Personal Data.
"Worker" means an employee, agency worker or self-employed subcontractor of the Customer whose details are entered into the Service.
1.2 Words in the singular include the plural and vice versa. Clause and Annex headings are for convenience only.
2. Roles of the parties
2.1 The parties agree that, in respect of Customer Personal Data, the Customer is the Controller and Meridia is the Processor.
2.2 Meridia is a separate Controller of personal data relating to the Customer's account holders, managers and billing contacts (such as login credentials and invoicing details) which it Processes for its own purposes as described in the ClockFence Privacy Notice. That Processing is outside the scope of this Agreement.
2.3 The Customer warrants that it has, and will maintain, a lawful basis for the Processing described in Annex 1, that it has provided Workers with the information required by Articles 13 and 14 UK GDPR, and that it has carried out and will keep under review a DPIA in respect of its use of the Service.
3. Subject matter, duration, nature and purpose
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 This Agreement takes effect on the date the Customer accepts the Principal Agreement and continues until Meridia has deleted or returned all Customer Personal Data in accordance with clause 11.
4. Controller instructions
4.1 Meridia shall Process Customer Personal Data only on the documented instructions of the Customer, including with regard to transfers of Personal Data outside the UK, unless required to do so by law. In that case Meridia shall inform the Customer of the legal requirement before Processing, unless the law prohibits this on important grounds of public interest.
4.2 The Customer's instructions are set out in this Agreement, the Principal Agreement, and the configuration choices the Customer makes in the Service (for example, drawing site boundaries, enabling or disabling selfie capture, and setting photo retention). Further instructions must be given in writing to privacy@clockfence.co.uk.
4.3 Meridia shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Meridia may suspend the relevant Processing until the instruction is confirmed or withdrawn.
4.4 The Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data and of the means by which it was obtained.
5. Confidentiality
5.1 Meridia shall ensure that every person it authorises to Process Customer Personal Data is bound by a written confidentiality obligation or is under an appropriate statutory duty of confidentiality, and has received suitable data protection training.
5.2 Meridia shall limit access to Customer Personal Data to those personnel who need it to provide the Service, operate support, or maintain security.
6. Security
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects, Meridia shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as a minimum the measures in Annex 2.
6.2 Meridia may update the measures in Annex 2 from time to time provided the overall level of security is not reduced.
6.3 The Customer is responsible for the security of its own systems and for the conduct of its users, including keeping manager login credentials confidential, removing users who leave the business, and configuring the Service appropriately.
7. Sub-processors
7.1 The Customer gives Meridia general written authorisation to engage the Sub-processors listed in Annex 3.
7.2 Meridia shall give the Customer at least 30 days' written notice (by email to the Customer's account holder, and by updating the sub-processor list published at [URL]) before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection within a further 14 days, the Customer may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees.
7.3 Meridia shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this Agreement, and shall remain fully liable to the Customer for the performance of each Sub-processor's obligations.
8. International transfers
8.1 Meridia shall Process Customer Personal Data in the United Kingdom and the European Economic Area and shall not transfer it to any other country without the Customer's prior written authorisation.
8.2 Where a transfer to a country outside the UK is authorised and that country is not covered by UK adequacy regulations, Meridia shall ensure the transfer is protected by the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, or another valid mechanism under Data Protection Law.
9. Assistance to the Customer
9.1 Data subject requests. Meridia shall promptly (and in any event within 5 working days) notify the Customer if it receives a request from a Worker or other Data Subject to exercise rights under Data Protection Law, and shall not respond to the request except on the Customer's documented instructions or as required by law. Meridia shall provide the Customer with self-service export, correction and deletion tools within the Service and reasonable further assistance so the Customer can meet its one-month deadline.
9.2 Security, breach and DPIA assistance. Taking into account the nature of the Processing and the information available to it, Meridia shall assist the Customer in meeting its obligations under Articles 32 to 36 UK GDPR, including by providing a DPIA template, a description of the Service's data flows, and answers to reasonable technical questions.
9.3 Meridia may charge reasonable fees for assistance that goes materially beyond the self-service tools and standard documentation, and will agree these in advance.
10. Personal Data Breach
10.1 Meridia shall notify the Customer without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification shall be sent to the Customer's nominated contact by email and, where the breach is likely to result in a high risk, also by telephone.
10.2 The notification shall, so far as the information is available, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact. Information may be provided in phases if it is not all available at once.
10.3 Meridia shall cooperate with the Customer and take reasonable steps to contain, investigate and mitigate the breach. Meridia shall not inform any Supervisory Authority or Data Subject of a breach affecting Customer Personal Data unless required by law or instructed by the Customer.
11. Deletion and return
11.1 On termination or expiry of the Principal Agreement, the Customer may, within 30 days, export Customer Personal Data using the Service's CSV and photo export tools or request a copy in a commonly used machine-readable format.
11.2 Unless UK law requires retention, Meridia shall delete all Customer Personal Data (including copies held by Sub-processors) within 30 days after the end of that export window, and on request shall confirm deletion in writing. Encrypted backups shall be overwritten in the ordinary backup cycle, and in any event within 90 days.
11.3 The Customer acknowledges that it, not Meridia, is responsible for retaining any records needed to meet its own legal duties (for example, HMRC and CIS record-keeping and employment claim time limits) after termination, and should export those records before the deadline in clause 11.1.
12. Audit
12.1 Meridia shall make available to the Customer all information reasonably necessary to demonstrate compliance with this Agreement, including summaries of any independent security assessments or certifications it holds (for example, Cyber Essentials).
12.2 Where the information provided under clause 12.1 is not reasonably sufficient, the Customer (or an independent auditor bound by confidentiality) may audit Meridia's compliance no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, in a manner that does not disrupt Meridia's business or compromise the security of other customers' data. Additional audits may be carried out where required by a Supervisory Authority or following a Personal Data Breach.
12.3 Each party bears its own costs of an audit unless the audit reveals a material breach by Meridia, in which case Meridia shall bear the Customer's reasonable costs.
13. Liability
13.1 Each party's liability arising out of or in connection with this Agreement is subject to the exclusions and limitations of liability in the Principal Agreement, and the aggregate liability caps in the Principal Agreement apply to liability under this Agreement and the Principal Agreement combined.
13.2 Nothing in this Agreement limits either party's liability to Data Subjects or to a Supervisory Authority under Data Protection Law.
14. General
14.1 If there is a conflict between this Agreement and the Principal Agreement in relation to the Processing of Customer Personal Data, this Agreement prevails.
14.2 If any provision of this Agreement is held to be invalid, the remainder continues in force and the parties shall negotiate in good faith a valid replacement provision with as close as possible the same effect.
14.3 Meridia may update this Agreement to reflect changes in Data Protection Law or the Service on 30 days' notice, provided the changes do not materially reduce the protection given to Customer Personal Data.
14.4 Governing law and jurisdiction. This Agreement and any dispute arising out of it are governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
Signatures
| Customer | Meridia Projects Ltd | |
|---|---|---|
| Signed | ||
| Name | ||
| Position | ||
| Date |
Where the Customer accepts the Principal Agreement online, clicking "I agree" constitutes signature of this Agreement.
Annex 1: Description of Processing
Subject matter. Provision of the ClockFence attendance recording service, in which Workers clock in and out of geofenced construction sites and the Customer's managers review the resulting records.
Duration. The term of the Principal Agreement plus the deletion period in clause 11.
Nature of Processing. Collection (via the Worker's device), storage, comparison of location against a site boundary, flagging of exceptions, display to authorised managers, generation of timesheets, export to CSV, automated deletion, and backup.
Purpose of Processing. To enable the Customer to record Workers' attendance and hours on site for payroll, CIS and HMRC record-keeping, site security and health and safety, and to review attendance exceptions.
Categories of Data Subjects.
- Workers of the Customer: employees, agency workers and self-employed CIS subcontractors.
- The Customer's managers and supervisors, in respect of review notes they write (their account data is Processed by Meridia as Controller and is outside scope).
Categories of Personal Data.
| Category | Detail |
|---|---|
| Identity | Name, trade, role, employment type (employed or self-employed CIS) |
| Credentials | 4 to 6 digit PIN, stored only as a salted hash |
| Attendance events | Clock In and Clock Out timestamps |
| Location data | GPS latitude, longitude and accuracy captured only at the moment of each clock event; calculated distance from the site boundary. Location data is not special category data under Article 9 UK GDPR but is intrusive, and the parties treat it with heightened care |
| Event flags | Outside boundary, late start, early finish, no clock-out, low GPS accuracy, late sync, simulated location |
| Photos | Selfie captured at clock-in where the Customer has enabled this for a site. Photos are used for visual identity confirmation by a human manager only; the Service performs no facial recognition or biometric matching, so they are not treated as biometric special category data |
| Notes | Free-text notes added by Workers and review notes added by managers, which may incidentally contain other personal data |
| Technical data | Session cookie identifier, IP address, device and browser type in server logs |
Special category data. None is intended to be collected. The Customer shall instruct Workers and managers not to enter health or other special category information in free-text notes.
Processing locations. United Kingdom and EU (see Annex 3).
Retention defaults (configurable where stated).
| Data | Default |
|---|---|
| Clock events, timesheets, location coordinates and flags | 6 years |
| Selfie photos | 90 days (Customer-configurable per site) |
| Session tokens | 90 days |
| Worker profiles and other account-linked data | Until removed by the Customer, and in any event deleted in accordance with clause 11 |
Annex 2: Technical and Organisational Security Measures
- Credential protection. Worker PINs and manager passwords are stored only as salted hashes using an industry-standard algorithm; plaintext credentials are never logged or stored.
- Encryption in transit. All connections between devices, the application and the database use TLS 1.2 or higher. HTTP is redirected to HTTPS.
- Encryption at rest. Database storage, photo storage and backups are encrypted at rest using provider-managed keys.
- Login lockout. Accounts are temporarily locked after repeated failed sign-in attempts, with rate limiting on authentication endpoints.
- Session security. Sessions use a
__Host-prefixed cookie marked HttpOnly and Secure, with a maximum life of 90 days and server-side revocation on sign-out or user removal. - Role-based access control. Data is segregated by Customer account. Managers can only view Workers and sites in their own organisation; Workers can only see their own clock events. Meridia staff access to production data is restricted to named individuals, requires multi-factor authentication and is logged.
- Audit trail. Every manager review of an exception, including the review note and outcome, is recorded with the reviewer's identity and a timestamp and cannot be silently edited or deleted.
- Backups. Encrypted backups are taken at least daily, stored in the UK or EU, retained for a rolling period not exceeding 90 days, and restoration is tested at least twice a year.
- Data minimisation by design. Location is requested from the device only at the moment of a clock event; no background location permission is requested. Photos are captured only where the Customer has enabled the feature.
- Vulnerability management. Dependencies are monitored for known vulnerabilities and patched promptly; security-relevant changes are code-reviewed before deployment.
- Sub-processor due diligence. Each Sub-processor is assessed for security posture and bound by written data protection terms before engagement.
- Incident response. Meridia maintains a documented breach response procedure, including the 48-hour Customer notification commitment in clause 10.
- Personnel. All staff with access to Customer Personal Data sign confidentiality agreements and complete data protection training on joining and annually.
Annex 3: Authorised Sub-processors
| Sub-processor | Service provided | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database and nightly backups | All Customer Personal Data, including selfie photos | United Kingdom (AWS London region, eu-west-2) | None required (UK); IDTA or UK Addendum for any US-based support access |
| Perplexity AI, Inc. | Pilot application hosting (request processing; no data at rest beyond short-lived server logs) | All Customer Personal Data in transit | United States | UK Addendum to EU SCCs. To be replaced by UK/EU hosting before general release |
| Resend, Inc. | Transactional email (invitations, password resets, backup delivery) | Manager names and email addresses; encrypted backup archives sent to the Processor's own mailbox | EU region (Ireland) | UK adequacy (EEA) |
| Stripe Payments Europe, Ltd. | Billing and payment processing for Customer accounts | Customer billing contact data only; no Worker data | Ireland, with group support in the United States | UK Addendum to EU SCCs |
Changes to this Annex are subject to the 30-day notice and objection procedure in clause 7. The current list is published at [URL] and questions may be sent to privacy@clockfence.co.uk.