C
COBE Intelligence
Data Processing Agreement

Draft — pending legal review

This page is a working draft grounded in how the platform actually operates today. It has not yet been reviewed or approved by a qualified solicitor and should not be relied on as final legal terms until it has. Bracketed fields [like this] mark details COBE Research needs to confirm before publishing.

Template version 2026.10

Data Processing Agreement

This template sets out the terms on which COBE Research CIC processes personal data on behalf of a customer organisation, under UK GDPR Article 28. A customer's procurement or legal team can attach this to their own contract paperwork. [Bracketed fields] are completed when the agreement is executed between the parties.

Parties

1. The parties

This Agreement is entered into between [Customer legal name] ("Controller") and COBE Research CIC, a Community Interest Company registered in England and Wales (company number [registration number], registered office [registered address]) ("Processor"), and supplements the parties' agreement for COBE Research's provision of the COBE Intelligence platform (the "Principal Agreement"), dated [date].

2

Subject matter and duration

Processor processes personal data on Controller's behalf for the duration of the Principal Agreement, for the purpose of providing the COBE Intelligence platform — workplace wellbeing and workplace-equity assessment, aggregate reporting, and related account administration. Full details of the processing are set out in Annex 1.

3

Processor obligations

Processor shall:

  • process personal data only on Controller's documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case Processor will inform Controller before processing, unless prohibited from doing so);
  • ensure that persons authorised to process the personal data are subject to a duty of confidentiality;
  • implement the technical and organisational security measures set out in Annex 2;
  • not engage a sub-processor without Controller's general or specific written authorisation (see clause 5) and shall impose the same data protection obligations on any sub-processor it does engage;
  • assist Controller, at Controller's cost for anything beyond reasonable effort, in responding to requests from data subjects exercising their rights under UK GDPR;
  • assist Controller with its obligations relating to data protection impact assessments and prior consultation with the ICO, taking into account the nature of processing and information available to Processor;
  • notify Controller without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Controller's data, and provide the information set out in clause 6;
  • at Controller's choice, delete or return all personal data to Controller at the end of the Principal Agreement, and delete existing copies, unless retention is required by law (see clause 8);
  • make available to Controller all information reasonably necessary to demonstrate compliance with this Agreement, and allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, on reasonable notice.

4

Controller obligations

Controller warrants that it has, and will maintain throughout the term of this Agreement, a valid lawful basis for the processing described in Annex 1, including — where the processing involves special category data — a valid Article 9 condition, and that its instructions to Processor comply with applicable data protection law.

5

Sub-processors

Controller authorises Processor to engage the sub-processors listed in Annex 3 as at the date of this Agreement. Processor will give Controller at least [30 days'] notice of any intended change (addition or replacement), during which Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the affected part of the service without penalty.

6

Personal data breach notification

Processor's breach notification to Controller will describe, to the extent then known: the nature of the breach and, where possible, categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach, including to mitigate its possible adverse effects. Processor will update Controller as further information becomes available.

7

International transfers

[COBE Research to confirm: whether any sub-processor processes personal data outside the UK, and if so, the transfer mechanism relied on — e.g. the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy regulation.]

8

Return and deletion of data

On termination or expiry of the Principal Agreement, Processor will, at Controller's election, return a full export of Controller's personal data in a commonly-used format and/or delete it, within [30 days], except to the extent applicable law requires Processor to retain some or all of the data, in which case Processor will isolate and protect that data from further processing.

9

Liability

[Liability allocation between the parties for this Agreement — needs drafting by qualified counsel before publication.]

Annex 1

Details of processing

FieldDetail
Subject matter Provision of the COBE Intelligence workplace wellbeing and equity assessment platform
Duration The term of the Principal Agreement, plus any post-termination retention/return period agreed under clause 8
Nature and purpose Collection, storage, aggregation, and anonymised reporting of assessment responses; account administration
Categories of data subjects Controller's employees who use the platform, and Controller's administrator users
Categories of personal data Name, work email, role; assessment and survey responses including open-text answers; where collected, demographic and health-adjacent responses (special category data); technical and security logs
Special category data Yes — processed only with each data subject's explicit consent, captured in-product before any assessment

Annex 2

Technical and organisational security measures

  • Application-layer encryption of open-text and other sensitive response fields, in addition to encryption at rest
  • Mandatory multi-factor authentication for all administrator accounts, with optional enterprise SSO (OIDC/SAML)
  • Role-based access control, scoped so one customer organisation's administrators can never see another's data
  • Encrypted, tested backups against a defined recovery point and recovery time objective
  • Automated suppression of any aggregate report below the Rule of Ten minimum cohort size
  • Error monitoring configured to exclude personal and mental-health-adjacent data by default
  • [Add: penetration testing cadence, employee security training, incident response plan reference — as applicable]

Annex 3

Authorised sub-processors

Sub-processorPurposeLocation
Sentry Error monitoring [region]
[hosting provider] Application hosting and database infrastructure [region]
[email provider] Transactional email delivery [region]

Privacy Policy · Terms of Service · DPA · Accessibility Statement