This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Version Zero Limited (“processor”, “we”) and the customer operating a workspace (“controller”, “you”). It applies where we process personal data on your behalf under the UK GDPR and, where applicable, the EU GDPR.
1. Roles
For participant identity, answers, timing, scores and results, you are the controller and we are your processor. You decide why a test is run and who takes it, and you are responsible for having a lawful basis and for telling participants what happens to their information.
We are an independent controller for the limited data we need to run the business: creator account records, billing records, security and abuse logs, and aggregate service telemetry. Our Privacy Notice covers that.
2. Subject matter and duration
Subject matter: provision of the TestSetGo assessment service.
Duration: the term of your subscription, plus the retention and deletion periods in section 8.
Nature and purpose: hosting, generating, delivering, grading, storing and reporting assessments.
Categories of data subject: participants you invite or admit, and the workspace members you add.
Categories of personal data: name, email address, answers (including free text), timing, scores, results, certificate records, attempt technical credentials, and IP address and user-agent captured for assessment integrity.
TestSetGo is not designed for special category data or criminal offence data. Do not configure a test to collect it.
3. Our obligations
We will:
- process personal data only on your documented instructions, which include your configuration of the service, unless we must do otherwise by law;
- ensure that personnel authorised to process personal data are bound by confidentiality;
- implement the security measures in section 5;
- respect the conditions in section 6 for engaging another processor;
- assist you, so far as reasonably possible, with data subject requests and with your obligations on security, breach notification and impact assessments;
- delete or return personal data at the end of the service as set out in section 8;
- make available the information reasonably needed to demonstrate compliance, and allow audits as set out in section 9.
4. Your obligations
You will ensure you have a lawful basis for the processing, that participants receive the information they are entitled to before a test starts, and that your instructions do not require us to breach data protection law. You control retention for your workspace and the identity mode used for each test.
5. Security measures
We apply technical and organisational measures appropriate to the risk, including:
- encryption in transit using current TLS for all public traffic;
- encryption at rest for database and file backups;
- database and cache services bound to the local host and not exposed to the public internet;
- access control by workspace, with role-based permissions and audited administrative access;
- append-only audit records for published versions, attempts, results and entitlement changes;
- hashed, non-reversible storage of access codes and participant verification codes;
- segregation from other products operated by Version Zero Limited, including separate database, storage, secrets and infrastructure;
- regular patching, host firewalling and restricted administrative access.
6. Sub-processors
You give general authorisation for us to engage sub-processors. We impose data protection obligations on each of them no less protective than this DPA, and we remain liable for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Hetzner Online GmbH | Application, database and file hosting | United States (Ashburn, Virginia) |
| Cloudflare, Inc. | Edge network, DNS, static delivery and object storage | Global edge network |
| Google LLC | Automated question generation from submitted material | United States |
| Sinch Mailgun | Transactional email delivery, including verification codes, invitations and result notifications | United States |
We will give at least 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the affected service without penalty for the remainder of the paid term.
7. International transfers
Application data is hosted in the United States. Where we transfer personal data from the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out a transfer risk assessment. Those clauses are incorporated into this DPA by reference and prevail over it in the event of conflict.
If you require data residency in the UK or EEA, contact us before you subscribe.
8. Retention, return and deletion
Your workspace controls participant retention; the default is 24 months. When records are erased we remove identity, free-text answers and active resume access, and keep only the non-identifying assessment history needed for audit and aggregate integrity.
On termination you may export results for 30 days. After that we delete personal data from live systems, and from backups within the normal backup rotation, unless we must keep it by law.
9. Audit
On reasonable written request, and no more than once in any twelve-month period unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is genuinely required, the parties will agree scope, timing and cost in advance so that it does not compromise the security of other customers.
10. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your personal data. The notice will describe the nature of the breach, the likely consequences and the measures taken or proposed.
11. Data subject requests
Participants should contact the organisation named on the test disclosure. Where a participant contacts us directly, we will refer them to you rather than respond on your behalf, unless the law requires otherwise. Creators can action access, correction and erasure from Workspace and Results.
12. Precedence
If there is a conflict, the Standard Contractual Clauses prevail, then this DPA, then the Terms of Service.