Draft — pending legal review
This page is a working draft grounded in how the platform actually operates today. It has not yet been reviewed or approved by a qualified solicitor and should not be relied on as final legal terms until it has. Bracketed fields [like this] mark details COBE Research needs to confirm before publishing.
Template version 2026.10
This template sets out the terms on which COBE Research CIC processes personal data on behalf of a customer organisation, under UK GDPR Article 28. A customer's procurement or legal team can attach this to their own contract paperwork. [Bracketed fields] are completed when the agreement is executed between the parties.
Parties
This Agreement is entered into between [Customer legal name] ("Controller") and COBE Research CIC, a Community Interest Company registered in England and Wales (company number [registration number], registered office [registered address]) ("Processor"), and supplements the parties' agreement for COBE Research's provision of the COBE Intelligence platform (the "Principal Agreement"), dated [date].
2
Processor processes personal data on Controller's behalf for the duration of the Principal Agreement, for the purpose of providing the COBE Intelligence platform — workplace wellbeing and workplace-equity assessment, aggregate reporting, and related account administration. Full details of the processing are set out in Annex 1.
3
Processor shall:
4
Controller warrants that it has, and will maintain throughout the term of this Agreement, a valid lawful basis for the processing described in Annex 1, including — where the processing involves special category data — a valid Article 9 condition, and that its instructions to Processor comply with applicable data protection law.
5
Controller authorises Processor to engage the sub-processors listed in Annex 3 as at the date of this Agreement. Processor will give Controller at least [30 days'] notice of any intended change (addition or replacement), during which Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the affected part of the service without penalty.
6
Processor's breach notification to Controller will describe, to the extent then known: the nature of the breach and, where possible, categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach, including to mitigate its possible adverse effects. Processor will update Controller as further information becomes available.
7
[COBE Research to confirm: whether any sub-processor processes personal data outside the UK, and if so, the transfer mechanism relied on — e.g. the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy regulation.]
8
On termination or expiry of the Principal Agreement, Processor will, at Controller's election, return a full export of Controller's personal data in a commonly-used format and/or delete it, within [30 days], except to the extent applicable law requires Processor to retain some or all of the data, in which case Processor will isolate and protect that data from further processing.
9
[Liability allocation between the parties for this Agreement — needs drafting by qualified counsel before publication.]
Annex 1
| Field | Detail |
|---|---|
| Subject matter | Provision of the COBE Intelligence workplace wellbeing and equity assessment platform |
| Duration | The term of the Principal Agreement, plus any post-termination retention/return period agreed under clause 8 |
| Nature and purpose | Collection, storage, aggregation, and anonymised reporting of assessment responses; account administration |
| Categories of data subjects | Controller's employees who use the platform, and Controller's administrator users |
| Categories of personal data | Name, work email, role; assessment and survey responses including open-text answers; where collected, demographic and health-adjacent responses (special category data); technical and security logs |
| Special category data | Yes — processed only with each data subject's explicit consent, captured in-product before any assessment |
Annex 2
Annex 3
| Sub-processor | Purpose | Location |
|---|---|---|
| Sentry | Error monitoring | [region] |
| [hosting provider] | Application hosting and database infrastructure | [region] |
| [email provider] | Transactional email delivery | [region] |
Privacy Policy · Terms of Service · DPA · Accessibility Statement