Minor amendment in the Data Processing Agreement
Published: September 8, 2026
-
Section 6.1: We have moved the details for how audits are done from the DPA to the T&C's section 8.3 and 8.4.
-
We do this to have less cross references between appendixes. See below...
-
- In the list of sub-processors, AWS is being decommissioned in favour of Azure for Employee Surveys. No change in EU data residency or in processing activities. Customers will not notice any change.
- We do this to consolidate our technology stack and reduce complexity.
Amendments in T&C's to address recurring customer feedback
Published: September 8, 2026
We have adjusted the T&C's to address customer recurring feedback, and to avoid misunderstandings:
-
New section 8.3 — commitment to an annual independent third-party audit of security controls against recognised standards (ISO/IEC 27001), with an audit summary available on request.
-
We do this as a next step on becoming ISO27001 certified and replacing our ISAE3000 reporting with ISO27001 certificate.
-
-
New section 8.4 — audit-rights fallback: where audit reports and compliance documentation don't satisfy the customer's legal audit requirements, they may request further information.
-
We do this to comply with customers that have extended audit requirements.
-
-
New section 16.4.4 — GDPR Art. 82 liability is carved out of the 16.4.1 cap and handled per Art. 82; Art. 83 administrative fines are borne individually.
-
We do this to comply with customers requirements on GDPR Art. 82.
-
-
Open Source removed — the "Open-Source Software" definition in clause 2.1 and the whole old clause 10.4 are gone; old 10.5 (third-party integrations) is now 10.4.
-
We do this to leave no doubt that Simployer takes full responsibility for any open source components we use in our products.
-
-
Clause 20 rewritten — the merger/demerger wording is removed from 20.1, and 20.2 now gives Simployer an express right to transfer or assign to an Affiliate or a transferee of the business/assets on 14 days' notice, with other assignments needing the customer's consent (not unreasonably withheld).
-
We do this to better comply with customer requirements on merger/demerger.
-
Expansion of AI Processing Activities — Google Vertex AI
Published: April 29, 2026Summary
Simployer has introduced Google Vertex AI as an additional AI platform for our products, alongside the existing Microsoft Azure OpenAI platform. Both platforms operate within the EU. This change expands the processing activities performed by an existing sub-processor and does not require any action from customers.
Background
Simployer uses AI capabilities to power features across our product suite. Until now, all AI processing has been performed exclusively through Microsoft Azure OpenAI, hosted within the EU.
To increase platform flexibility and operational resilience, Simployer has added Google Vertex as a secondary AI platform. Google Vertex AI is used for the same types of processing activities as Microsoft Azure OpenAI.
Sub-processor status
Google (Google Cloud / GCP) is an existing sub-processor already listed in our Data Processing Agreement documentation. This change represents an expansion of the processing activities performed by Google — not the introduction of a new sub-processor.
Data protection and security
- All AI processing on Google Vertex AI takes place within the EU, consistent with Simployer's existing data residency commitments.
- Google Cloud has been evaluated by Simployer in accordance with our information security and data protection requirements.
- A Data Processing Agreement is in place with Google, in line with GDPR Article 28.
- The processing is covered by the existing Data Processing Agreement between Simployer and the customer.
Updated documentation
The following Trust Center pages have been updated to reflect this change:- Processing activities in Simployer One
- Use of AI in Simployer One HRM
- Data Flow and Storage in SIA
- Use of AI in Handbooks
- Sub-processors