Legal

Data Processing Agreement

How we process personal data on your behalf, the safeguards we apply, and our sub-processors.

Last updated 1 June 2026
Jurisdiction England & Wales
Applies to scim.ninja and all services
Questions? privacy@scim.ninja
01

Background and roles

This Data Processing Agreement ("DPA") forms part of the agreement for the supply of the SCIM.ninja service (the "Principal Agreement") between Objective Labs LTD, a company registered in England and Wales under company number 17303955, whose registered office is at 124 City Road, London EC1V 2NX ("Processor", "we", "us"), and the customer identified in the Principal Agreement ("Controller", "you") — each a "party" and together the "parties".

1.1 This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the SCIM.ninja service (the "Service").

1.2 The Service provisions, updates, deprovisions, and synchronises user records between the Controller's identity provider and the Controller's connected applications. In doing so, the Processor processes personal data relating to the Controller's end users on the Controller's behalf.

1.3 For the personal data processed under this DPA, the Controller is the controller and the Processor is the processor, as those terms are defined in the UK GDPR.

1.4 This DPA does not apply to personal data for which the Processor is itself the controller (for example, the account, billing, and login data of the Controller's administrative users). That data is governed by the Processor's privacy policy.

02

Definitions

Capitalised terms used in this DPA have the meanings set out below.

  • "UK GDPR" — the retained EU law version of the General Data Protection Regulation (Regulation (EU) 2016/679) as it forms part of the law of England and Wales, Scotland, and Northern Ireland, as supplemented by the Data Protection Act 2018.
  • "Data Protection Laws" — the UK GDPR, the Data Protection Act 2018, and all other applicable laws relating to the processing of personal data and privacy.
  • "Personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given to them in the UK GDPR.
  • "Sub-processor" — any third party engaged by the Processor to process personal data in connection with the Service.

Capitalised terms not defined in this DPA have the meaning given in the Principal Agreement.

03

Processing on documented instructions

3.1 The Processor shall process personal data only on the documented instructions of the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by law. Where the Processor is required by law to process personal data other than on the Controller's instructions, it shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.

3.2 The Controller's instructions are set out in this DPA, the Principal Agreement, and the configuration choices the Controller makes within the Service (for example, which applications to connect and which attributes to synchronise). The Controller may issue further written instructions during the term.

3.3 The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.

3.4 The details of the processing — its subject matter, duration, nature and purpose, the types of personal data, and the categories of data subjects — are set out in Annex 1.

04

Confidentiality

4.1 The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2 The Processor shall limit access to the personal data to those personnel who need access to it in order to provide the Service.

05

Security

5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR.

5.2 The measures implemented by the Processor are described in Annex 2.

06

Sub-processors

6.1 The Controller provides general written authorisation for the Processor to engage Sub-processors, subject to the conditions in this clause. The Sub-processors engaged as at the date of this DPA are listed in Annex 3.

6.2 The Processor shall impose on each Sub-processor, by way of a written contract, data protection obligations equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.

6.3 The Processor shall give the Controller prior notice of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds within 14 days. If the Controller objects and the parties cannot resolve the objection, the Controller may terminate the affected part of the Service.

07

International transfers

7.1 The Processor shall not transfer personal data to a country outside the United Kingdom unless it has taken such measures as are necessary to ensure the transfer is in compliance with Data Protection Laws. Such measures may include transferring to a country subject to UK adequacy regulations, transferring to a recipient certified under the UK Extension to the EU-US Data Privacy Framework, or entering into an International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

7.2 The transfer mechanism relied upon for each Sub-processor located outside the United Kingdom is identified in Annex 3.

08

Assistance with data subject rights

8.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests by data subjects exercising their rights under the UK GDPR.

8.2 If the Processor receives a request directly from a data subject in relation to personal data processed under this DPA, it shall not respond to the request itself (other than to acknowledge it where appropriate) but shall promptly forward the request to the Controller.

09

Assistance with the Controller's wider obligations

9.1 Taking into account the nature of processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with the Controller's obligations under Articles 32 to 36 of the UK GDPR, namely security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation with the supervisory authority.

10

Personal data breaches

10.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA.

10.2 The notification shall, to the extent the information is available to the Processor, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.

11

Deletion or return of personal data

11.1 At the choice of the Controller, the Processor shall delete or return all personal data processed under this DPA to the Controller after the end of the provision of the Service, and shall delete existing copies unless retention is required by law.

11.2 The Processor shall comply with a request under clause 11.1 within 30 days of the end of the Service or such longer period as is reasonably necessary to give effect to the request.

12

Audit and information

12.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this DPA.

12.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice, confidentiality undertakings, and the Processor's reasonable security and operational requirements. The parties may agree that the Processor's provision of an independent third-party audit report or certification satisfies this obligation in whole or in part.

13

General

  • Order of precedence. In the event of any conflict between this DPA and the Principal Agreement on matters relating to the processing of personal data, this DPA prevails.
  • Governing law. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, unless the Principal Agreement specifies otherwise.
  • Liability. Any liability arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.
14

Annex 1 — Details of processing

Subject matter of the processing

The provision of the SCIM.ninja user-provisioning service, which synchronises user records between the Controller's identity provider and the Controller's connected applications.

Duration of the processing

For the term of the Principal Agreement, plus any period reasonably necessary to give effect to deletion or return of personal data under clause 11.

Nature and purpose of the processing

Creating, reading, updating, deactivating, and deleting user records in the Controller's connected applications; logging provisioning activity for monitoring, error diagnosis, and audit; and otherwise operating and maintaining the integration.

Types of personal data

User identifiers, names, email addresses, usernames, and such other user attributes, roles, and group memberships as the Controller chooses to synchronise through the Service.

Categories of data subjects

The Controller's end users whose records are provisioned through the Service, typically the Controller's employees, contractors, or other personnel.

15

Annex 2 — Technical and organisational security measures

The Processor implements technical and organisational measures appropriate to the nature, scale, and risk of the Service. As a developing business, these measures are kept under review and will evolve over time. As at the date of this DPA, they include:

  • Encryption of personal data in transit (TLS) and encryption of sensitive credentials at rest
  • Access to personal data restricted to authorised personnel on a need-to-know basis
  • Authentication controls for access to systems that process personal data
  • Logging of access to systems that process personal data
  • Short rolling retention (24 hours) for integration response logs containing end-user personal data
  • Logical separation of each customer's data through access controls, so that one customer cannot access another customer's data
  • Confidentiality obligations imposed on personnel with access to personal data
  • Investigation of, and response to, personal data breaches, including notification to the Controller in accordance with clause 10
16

Annex 3 — Authorised sub-processors

This annex lists only Sub-processors that process the Controller's end-user personal data (the personal data described in Annex 1). Providers that only process data for which the Processor is itself the controller (for example usage analytics, bot/fraud prevention, call scheduling, and billing/payment) are not Sub-processors under this DPA and are addressed in the Processor's privacy policy.

Sub-processorService providedLocationTransfer mechanism (if outside UK)
Xano, Inc. (WOODLAND HILLS, CA)Platform hosting, data storage, and processing of provisioning activity and logsUnited StatesUK-US Data Bridge (UK Extension to the EU-US Data Privacy Framework)
Postman, Inc. (San Francisco, CA)Validation and testing of integration endpointsUnited StatesUK-US Data Bridge (UK Extension to the EU-US Data Privacy Framework)