Last updated: April 2026
This page is a summary of our Data Processing Agreement (DPA) under GDPR Article 28. A full signed DPA is available on request — see section 8.
This DPA is between:
By using OnboardZero to collect and store employee data, you (as controller) instruct us (as processor) to process personal data on your behalf under the terms set out below.
The subject matter of this DPA is the processing of employee and contractor personal data using the OnboardZero onboarding platform. Processing commences when you send your first invite and continues for the duration of your active subscription.
Upon termination of the subscription, data is retained for a maximum of 30 days to allow export, after which it is permanently deleted.
OnboardZero processes employee personal data on your behalf solely to:
We do not use employee personal data for any purpose other than providing the Service to you.
Data subjects: Employees and contractors of the controller who are invited to complete the onboarding form.
Categories of personal data processed:
OnboardZero commits to the following obligations under GDPR Article 28:
OnboardZero uses the following approved sub-processors. By using the Service, you consent to these sub-processors. We will notify you of any changes at least 14 days in advance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | EU (AWS eu-west-1) |
| Stripe | Payment processing (billing data only) | EU |
| Resend | Transactional email (invite & confirmation) | EU (eu-west-1) |
| Sentry | Error monitoring (no PII in error logs) | EU |
| Upstash | Rate limiting (IP addresses only, not retained) | EU |
| Personio | HR system sync (only if you configure this integration) | EU |
All processing by OnboardZero and our sub-processors takes place within the European Union / European Economic Area. We do not transfer personal data to third countries outside the EU/EEA.
If a future sub-processor requires a transfer outside the EU/EEA, we will implement appropriate safeguards (Standard Contractual Clauses as required under GDPR Chapter V) and notify you in advance.
This page provides an overview of our data processing commitments. For customers who require a formal signed Data Processing Agreement — for example for enterprise procurement, insurance purposes, or compliance audits — a full DPA document is available upon request.
To request a signed DPA, email hello@onboardzero.com with the subject line "DPA Request". We will respond within 5 business days.