We use cookies to enhance your experience and analyze site traffic. By accepting, you consent to our use of analytics cookies. Learn more about our cookie policy

    Skip to main content

    Data Processing Addendum

    Version 1.0 · Published 9 March 2026

    Data Processing Addendum

    TRM Flex Ltd ("Processor")
    Effective Date: 9 March 2026

    This Data Processing Addendum ("DPA") forms part of the agreement between TRM Flex Ltd ("Processor") and the entity agreeing to these terms ("Controller") for the provision of services via the TRM Flex platform ("Services").

    This DPA is entered into pursuant to, and supplements, the applicable Platform Terms. Where there is a conflict between this DPA and the Platform Terms, this DPA shall prevail in respect of data protection matters.

    1. Definitions and Interpretation

    1.1 In this DPA, the following terms shall have the meanings set out below:

    • "Data Protection Laws" means the UK General Data Protection Regulation (UK GDPR) as retained under the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018, together with all applicable secondary legislation, guidance, and codes of practice issued by the Information Commissioner's Office ("ICO"), as amended from time to time.
    • "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor", and "Personal Data Breach" shall have the meanings given to them in the Data Protection Laws.
    • "Controller Personal Data" means the Personal Data described in Schedule 1 that is Processed by the Processor on behalf of the Controller pursuant to or in connection with the Services.
    • "Approved Jurisdiction" means the United Kingdom.
    • "International Data Transfer Agreement" or "IDTA" means the International Data Transfer Agreement issued by the ICO under section 119A of the Data Protection Act 2018.

    2. Scope and Roles

    2.1 The parties acknowledge that for the purposes of Data Protection Laws, the Controller is the Controller and the Processor is the Processor of Controller Personal Data.

    2.2 The subject matter, duration, nature and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are set out in Schedule 1.

    3. Processor Obligations

    3.1 The Processor shall:

    • (a) Process Controller Personal Data only on documented instructions from the Controller, unless required to do so by applicable law;
    • (b) ensure that persons authorised to Process Controller Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
    • (c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR, including as appropriate:
      • (i) the pseudonymisation and encryption of Personal Data;
      • (ii) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services;
      • (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
      • (iv) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures;
    • (d) assist the Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to Data Subject rights requests under Chapter III of the UK GDPR;
    • (e) assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 of the UK GDPR;
    • (f) at the choice of the Controller, delete or return all Controller Personal Data after the end of the provision of Services, and delete existing copies unless applicable law requires storage;
    • (g) make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections.

    4. Sub-processing

    4.1 The Controller provides general authorisation for the Processor to engage Sub-processors for the Processing of Controller Personal Data.

    4.2 The Processor shall:

    • (a) maintain a list of Sub-processors, available to the Controller upon request;
    • (b) inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller a reasonable opportunity to object;
    • (c) impose on each Sub-processor, by way of a written contract, data protection obligations no less onerous than those set out in this DPA;
    • (d) remain fully liable to the Controller for the performance of any Sub-processor's obligations.

    4.3 If the Controller objects to a new Sub-processor on reasonable grounds relating to data protection, the Processor shall use reasonable endeavours to make available an alternative. If no alternative is reasonably available, either party may terminate the affected Services.

    5. International Transfers

    5.1 The Processor shall not transfer Controller Personal Data outside the Approved Jurisdiction unless:

    • (a) the transfer is to a jurisdiction determined by the Secretary of State to provide adequate protection; or
    • (b) the Processor has provided appropriate safeguards, including by entering into the IDTA or UK Addendum to the EU Standard Contractual Clauses; and
    • (c) enforceable Data Subject rights and effective legal remedies are available.

    5.2 The Processor shall conduct a transfer impact assessment where required under applicable ICO guidance.

    6. Personal Data Breach

    6.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Controller Personal Data.

    6.2 Such notification shall include:

    • (a) a description of the nature of the breach, including approximate numbers of Data Subjects and records concerned;
    • (b) the name and contact details of the Processor's data protection point of contact;
    • (c) a description of the likely consequences;
    • (d) a description of the measures taken or proposed to address the breach.

    6.3 The Processor shall co-operate with the Controller to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

    7. Data Protection Impact Assessments

    7.1 The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with the ICO, as required under Articles 35 and 36 of the UK GDPR.

    8. Records of Processing Activities

    8.1 The Processor shall maintain records of all categories of Processing activities carried out on behalf of the Controller in accordance with Article 30(2) of the UK GDPR.

    9. Audit Rights

    9.1 The Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this DPA.

    9.2 The Processor shall allow the Controller (or its appointed third-party auditor) to carry out audits, subject to:

    • (a) reasonable prior written notice of not less than 30 days;
    • (b) the audit being conducted during normal business hours;
    • (c) compliance with the Processor's reasonable security and confidentiality requirements;
    • (d) audits being limited to once per calendar year unless required by a supervisory authority or following a Personal Data Breach.

    10. Term and Termination

    10.1 This DPA shall remain in effect for the duration of the Processing of Controller Personal Data by the Processor.

    10.2 Upon termination, the Processor shall, at the Controller's election, return or securely delete all Controller Personal Data within 90 days, unless retention is required by applicable law.

    11. Limitation of Liability

    11.1 The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set out in the Platform Terms.

    12. Governing Law

    12.1 This DPA shall be governed by and construed in accordance with the laws of England and Wales.

    12.2 The parties submit to the exclusive jurisdiction of the courts of England and Wales.


    Schedule 1 — Processing Details

    Subject Matter and Duration

    The Processing of Controller Personal Data in connection with the provision of the TRM Flex platform Services, for the duration of the agreement between the Controller and the Processor.

    Nature and Purpose of Processing

    The provision of an event operations and workforce coordination platform, including:

    • shift creation, assignment, and management;
    • workforce availability and booking;
    • check-in/check-out and time recording;
    • invoicing and financial record keeping;
    • communication between parties;
    • identity verification and right-to-work checks;
    • platform analytics and reporting.

    Types of Personal Data

    • Names, email addresses, telephone numbers;
    • Business and company information;
    • Location data (event venues, check-in coordinates);
    • Financial data (bank details, invoice records, payment amounts);
    • Identity documents and right-to-work documentation;
    • Skills profiles and work history;
    • Platform usage data, device identifiers, and IP addresses.

    Categories of Data Subjects

    • Client personnel (employees, agents, and representatives of the Controller);
    • Independent marketplace workers engaged via the platform;
    • Supplier personnel;
    • Event attendees (where applicable).

    Sub-processors

    A current list of approved Sub-processors is available upon request by contacting hello@trmflex.com.


    This Data Processing Addendum is effective as of the date of acceptance via the TRM Flex platform.

    TRM Flex Ltd
    London, United Kingdom